Cointime

Download App
iOS & Android

Crypto Lender Polter Finance Shuts Down After Hack Drains Nearly All Funds

Cointime Official

From decrypt by Vismaya V

Decentralized lending platform Polter Finance suffered a devastating exploit on the Fantom blockchain, essentially wiping out most of its assets.

The breach, discovered early Sunday, involved the manipulation of the platform’s token pricing mechanisms, leaving its users in shock.

The attacker began by funneling funds through Tornado Cash, an Ethereum-based coin mixer that conceals the origin of funds. These assets were then bridged—transferred from Ethereum to the Fantom network—where the exploit was executed.

Once the breach was identified, Polter Finance took immediate action by pausing its platform to contain the damage and notified key bridge operators.

The pseudonymous founder of Polter Finance, known as “Whichghost,” filed a police report in Singapore following the breach. The hack resulted in losses exceeding 16.1 million SGD (approximately $12 million USD).

The newly deployed smart contract on the platform was exploited, causing unauthorized transactions to drain user assets, says the report. The founder also reported personal losses of $223,219.

While the police report claims total losses of around $12 million, other reports from web3 security firms suggest the actual amount stolen was closer to $7 million.

According to DeFi Llama data, Polter Finance’s TVL was approximately $9.7 million before the attack, indicating substantial losses.

In a statement on X (formerly Twitter), the team wrote, ““We identified wallets involved and traced it to Binance. We are still investigating the nature of the exploit. We are in the processing of contacting the Authorities.”

The platform also sent an on-chain message to the attacker, saying the team would be willing to negotiate without pursuing legal action if the stolen funds are returned.

Web3 security experts think the root cause of the exploit was linked to a price manipulation attack using oracles—external data feeds that platforms use to determine token prices.

Smart contract audit firm QuillAudits shared their findings with Decrypt which shows the vulnerability was tied with how Polter Finance calculated the value of the SpookySwap BOO token.

“The price of the SpookySwap BOO token in the lending pool was determined by the spot price from the SpookySwap v3 pool and v2 pair; calculated based on the token balance ratio in the pool,” QuillAudits told Decrypt.

By artificially increasing the price of the BOO token, the hacker could deposit a very small amount (just 1 BOO token) and withdraw a much larger amount of other assets, effectively draining the platform of its funds.

“This case exemplifies a classic Oracle manipulation exploit. The BOO token price is manipulated by the attacker using a flash loan to artificially inflate the BOO token's price,” Hakan Unal, Senior Blockchain Scientist at Cyvers Ai, told Decrypt.

Polter Finance announced it has since colllaborated with the Security Alliance Information Sharing and Analysis Center (SEAL-ISAC) to track down the hacker.

This incident adds to the growing list of security breaches in the crypto sector. The total amount lost to the exploits has surpassed $2 billion in 2024 alone, with code vulnerabilities resulting in $39.6 million in losses over 44 incidents, per a recent Certik report.

Comments

All Comments

Recommended for you

  • Michael Saylor Releases New Bitcoin Tracker Information, Potential Disclosure of Increased Holdings Next Week

    On April 26, Strategy founder Michael Saylor released new information related to the Bitcoin Tracker, captioned: 'The ₿eat Goes On..'. According to previous patterns, Strategy typically discloses information about increased Bitcoin holdings the day after relevant news is released.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,042.78, with a 24-hour increase of 0.69%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Trump: Does Not Believe Shooting Incident is Related to Iran Conflict

    On April 26, U.S. President Trump stated (when asked if the shooting incident was related to the Iran conflict) that he does not believe so. (Jinshi)

  • Latest Progress on DeFi United Ecological Rescue Initiative: Over 100,000 ETH Raised at Designated Donation Address

    On April 26, the DeFi United ecological rescue initiative, led by Aave, continues to advance. The Arbitrum DAO has released 30,765 ETH that was frozen after the rsETH incident on April 18. Currently, the designated donation address has raised a total of 100,360 ETH to address the collateral asset gap caused by the rsETH incident. The plan aims to restore the backing assets of rsETH through multi-party collaboration, stabilize the market, and prevent the spread of bad debts across protocols. The funds will be used to support the restoration of collateral rates and to gradually normalize the market in conjunction with relevant protocols. Key contributors or participants currently include: Arbitrum DAO releasing 30,765 ETH frozen after the rsETH incident, Mantle proposing to contribute 30,000 ETH, Aave DAO proposing to contribute 25,000 ETH, Aave founder Stani Kulechov confirming a contribution of 5,000 ETH, EtherFi proposing to provide 5,000 ETH, Lido proposing to provide 2,500 stETH, and the Golem Foundation and related projects contributing a total of 1,000 ETH, among others. Additionally, LayerZero, Ethena, Frax Finance, and Ink Foundation have also confirmed their participation, although the specific amounts have not yet been disclosed. It is important to note that the progress of this rescue initiative still relies on several external key conditions, including KelpDAO's restoration of rsETH redemptions and the Arbitrum Security Council's release of frozen assets, resulting in uncertainty regarding the overall recovery time and effectiveness.

  • Trump Evacuated from White House Correspondents' Dinner Due to Security Incident

    On April 26, local time April 25, U.S. President Trump was urgently evacuated from the White House Correspondents' Dinner due to a security incident. (CCTV News)

  • Shooting Incident at White House Correspondents' Dinner; Gunman Dead

    On April 26, local time on April 25, a shooting incident occurred in the hall of the White House Correspondents' Dinner, and the gunman is now deceased. (CCTV News)

  • Trump States He Will Not Allow Banks to Undermine Cryptocurrency Market Legislation

    On April 26, CoinDesk reported, citing attendees at a Trump cryptocurrency event, that Trump stated he would not allow banks to undermine cryptocurrency market legislation.

  • Iranian Officials to Depart Pakistan Without Meeting U.S. Representatives

    On April 25, according to a reporter from the New York Post: The Iranian delegation is set to leave Islamabad, the capital of Pakistan, and has consistently emphasized that they did not meet with U.S. officials during their brief visit.

  • Foreign Media: Second Round of Iran-U.S. Talks Scheduled for April 27

    On April 25, according to New Delhi Television: The second round of talks between Iran and the United States is scheduled to take place on April 27.

  • Iranian Lawmaker: Comprehensive Plan for Managing the Strait of Hormuz Formed

    On April 25, according to a report by Iran's Mehr News Agency, Iranian Islamic Parliament member Behnam Saidi stated that Iran has developed a comprehensive plan for managing the Strait of Hormuz. In an interview with Mehr News Agency, Saidi mentioned that an important aspect of this plan is the exclusive recognition of the name 'Persian Gulf' in all correspondence and commercial documents, rejecting any other names. Vessels and ships navigating in the region must obtain permission from Iran. Sovereignty over the Strait of Hormuz will be entirely under Iran's control. He also stated that vessels identified as hostile by the Supreme National Security Council or the General Staff of the Armed Forces of Iran are not allowed to pass through the Strait of Hormuz, and Israeli vessels are absolutely prohibited from entering the area. Ships passing through the region must pay relevant fees concerning safety, environmental protection, shipping management, and licensing, with priority given to payments in rials.