{"investigation":{"slug":"fortress-loans","entity_name":"Fortress Loans","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Fortress Loans (fortress.loans) was an algorithmic money market and lending protocol on BNB Chain (Binance Smart Chain), launched in April 2021 by the JetFuel Finance team. On May 8, 2022, the protocol was drained of all funds — approximately $2.98 million — through a combined governance manipulation and oracle price manipulation attack. The protocol has been effectively inactive since, with DefiLlama recording a TVL of approximately $1,168 as of 2024, and the FTS governance token has lost effectively all of its value.","sections":[{"content":"Fortress Loans operated as a decentralized, algorithmic money market and lending protocol on Binance Smart Chain (BNB Chain). It was developed and launched by the JetFuel Finance team in April 2021. The protocol enabled users to supply and borrow a range of assets including BNB, USDC, USDT, BUSD, ETH, BTC, and several others. Its governance and rate modification token was FTS (Fortress Lending), a BEP-20 token with a total supply of 10,000,000. The protocol also featured a synthetic stablecoin called FAI. The JetFuel Finance team cited over 30 years of combined DeFi experience. The protocol was audited by Hash0x and EtherAuthority prior to launch. Despite these audits, critical vulnerabilities in the oracle integration and governance contract were not identified, ultimately leading to the complete loss of protocol funds in May 2022.","heading":"Overview","sources":[{"url":"https://bsc.news/post/fortress-credit-and-lending-project-insight","name":"bsc.news","type":"other","credibility":3},{"url":"https://jetfuelfinance.medium.com/how-to-use-the-fortress-protocol-lending-borrowing-and-collecting-fts-rewards-aa6812389b9b","name":"jetfuelfinance.medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/fortress-loans","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On May 8, 2022, Fortress Loans was exploited via a two-pronged attack exploiting weaknesses in both its on-chain governance mechanism and the Umbrella Network price oracle it relied upon. The attacker had begun preparation approximately 19 days prior, sourcing 20 ETH from Tornado Cash on the Ethereum mainnet and bridging funds to BNB Chain via cBridge on April 29, 2022.\n\nThe attacker's wallet (0xA6AF2872176320015f8ddB2ba013B38Cb35d22Ad) deployed an unverified custom contract and purchased approximately 400,000 FTS tokens — the minimum required for governance quorum — at a cost of roughly $8,000 to $11 ETH at the time. Using these tokens, the attacker submitted and passed Proposal FIP-11 (Proposal #11) through the Fortress Governor Alpha contract, which changed the collateral factor of FTS from 0 to 70% (encoded as 700000000000000000).\n\nSimultaneously, the attacker exploited a critical vulnerability in Umbrella Network's Chain oracle smart contract. A required verification statement on line 142 of the submit() function had been commented out, meaning the contract did not verify whether a signer had the authority to feed a price. This allowed the attacker to submit an arbitrary price signature and inflate the oracle-reported price of FTS to nearly $1 trillion. With FTS collateral now recognized at an astronomically inflated price and a 70% collateral factor in place, the attacker borrowed all available tokens from the protocol's fToken contracts — including BNB, USDC, USDT, BUSD, BTCB, ETH, LTC, XRP, ADA, DAI, DOT, and SHIB.\n\nThe stolen assets were consolidated to approximately 1,048.1 ETH (~$2.58 million) and 400,000 DAI (~$400,000), totaling approximately $2.98 million USD. The funds were bridged from BNB Chain to Ethereum via Anyswap/Multichain and cBridge, then deposited into Tornado Cash to obscure their trail. The attack contract address is 0xcd337b920678cf35143322ab31ab8977c3463a45.","heading":"Governance and Oracle Manipulation Exploit (May 2022)","sources":[{"url":"https://www.certik.com/resources/blog/k6eZOpnK5Kdde7RfHBZgw-fortress-loans-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://rekt.news/fortress-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-fortress-protocol-hack-analysis-19af24af723c","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://therecord.media/defi-protocol-fortress-announces-3-million-hack","name":"therecord.media","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/examination-of-the-fortress-protocol-hack-e261c96ea450","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Umbrella Network, the decentralized oracle provider whose price feed was exploited, subsequently acknowledged the vulnerability as an internal process failure. In a post-mortem published via Medium, the Umbrella Network team stated that the buggy smart contract had been introduced in August 2021 and went unaudited due to a lean development team and inadequate peer review processes. Umbrella Network acknowledged that \"relentless pursuit has led to process breakdowns when it came to proper and consistent peer reviews and code audits.\"\n\nUmbrella Network confirmed the exploit affected two protocols: Fortress Loans (~$2.2 million) and MahaDAO (~$700,000). As part of its response, Umbrella deployed a hotfix the same day and provided compensation to Fortress of $500,000 USDC and 10,000,000 UMB tokens on a one-year linear vesting schedule. MahaDAO received $500,000 USDC and 2,500,000 UMB tokens. Umbrella also pledged structural improvements including a Security Subcommittee, Quality Assurance hiring, slowed development rollouts, and third-party audit partnerships.","heading":"Oracle Provider Responsibility: Umbrella Network","sources":[{"url":"https://medium.com/umbrella-network/update-on-umbrella-oracle-exploit-67ac0fe4414b","name":"medium.com","type":"other","credibility":3},{"url":"https://therecord.media/defi-protocol-fortress-announces-3-million-hack","name":"therecord.media","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the exploit, Fortress Loans had been audited by two firms: Hash0x and EtherAuthority. Neither audit identified the oracle vulnerability because the flaw resided in Umbrella Network's oracle contract rather than in Fortress's own smart contracts, placing it outside the defined scope of the Fortress-specific audits. Security researchers have cited this incident as an example of the limitations of smart contract audits when protocols depend on third-party infrastructure that itself contains unreviewed code. The CertiK post-incident analysis confirmed that the exploit was rooted in the Umbrella oracle's submit() function, where a required signature verification statement had been commented out.","heading":"Audit Failures","sources":[{"url":"https://www.certik.com/resources/blog/k6eZOpnK5Kdde7RfHBZgw-fortress-loans-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://sayfer.io/blog/3-hacks-an-audit-could-not-find/","name":"sayfer.io","type":"other","credibility":3},{"url":"https://fortress.loans/audit_hash0x.pdf","name":"fortress.loans","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the JetFuel Finance team paused the protocol's UI and issued an announcement confirming the attack. The team stated they had alerted Binance, Umbrella Network, BitMart, and other centralized exchanges, and were engaging with security analysis firms and Tornado Cash tracking specialists.\n\nA compensation plan was announced via JetFuel Finance's Medium account on May 14, 2022. The plan outlined over $1 million in total compensation: $300,000 USDC to be dispersed immediately by the JetFuel team, an additional $200,000 USDC reserved for unrecoverable losses, and the 10,000,000 UMB tokens received from Umbrella Network on a one-year vesting schedule. The compensation also relied on a speculative condition: if UMB tokens reached $0.18 per coin, the total stolen amount could theoretically be fully reimbursed. Additional funds were to come from JetFuel ecosystem revenue including IJO proceeds, DEX revenue, partnerships, and treasury investments.\n\nA protocol restart was scheduled for May 13–14, 2022, with removal of on-chain governance planned for May 16–17. However, there is no publicly verifiable record confirming that the full compensation was delivered to all affected users. The FTS token has since lost effectively all of its value, and DefiLlama recorded the protocol's TVL at approximately $1,168 as of 2024, with zero active loans. The fortress.loans domain now appears to redirect to a for-sale page.","heading":"Post-Hack Response and Compensation","sources":[{"url":"https://jetfuelfinance.medium.com/fortress-attack-update-and-compensation-e7a66621cfe6","name":"jetfuelfinance.medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/fortress-loans","name":"defillama.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/fortress-protocol-hacked-for-3-million-drained-of-all-funds/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FTS (Fortress Lending) governance token has declined approximately 100% from its all-time high following the exploit. CoinMarketCap and CoinGecko list the token with a market capitalization of approximately $13,900 as of available data. DefiLlama shows the protocol with a TVL of approximately $1,168 — down from several million dollars prior to the hack — with zero recorded active loans. The protocol is considered effectively defunct. JetFuel Finance's broader ecosystem (including JetSwap DEX) also appears to have experienced significant decline in activity following the incident.","heading":"Token and Protocol Status","sources":[{"url":"https://coinmarketcap.com/currencies/fortress-lending/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/fortress-loans","name":"defillama.com","type":"other","credibility":3},{"url":"https://coingecko.com/en/coins/fortress","name":"coingecko.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The stolen funds — 1,048.1 ETH and 400,000 DAI — were laundered through Tornado Cash on the Ethereum mainnet. The attacker's primary externally owned account (EOA) address is 0xA6AF2872176320015f8ddB2ba013B38Cb35d22Ad, and the attack contract address is 0xcd337b920678cf35143322ab31ab8977c3463a45. Funds were bridged from BNB Chain using Anyswap (Multichain) and cBridge before being mixed through Tornado Cash. No individual or group has been publicly identified or charged in connection with the attack as of the date of this investigation. Law enforcement has not publicly announced any action.","heading":"Stolen Funds and On-Chain Activity","sources":[{"url":"https://www.certik.com/resources/blog/k6eZOpnK5Kdde7RfHBZgw-fortress-loans-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://rekt.news/fortress-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-fortress-protocol-hack-analysis-19af24af723c","name":"slowmist.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-04","event":"Fortress Loans launches on Binance Smart Chain as an algorithmic lending protocol developed by JetFuel Finance.","source":"","date_original":"2021-04-01"},{"date":"2021-08","event":"Umbrella Network introduces buggy oracle smart contract code that would later be exploited; the code goes unaudited.","source":"","date_original":"2021-08-01"},{"date":"2022-04-19","event":"The attacker first interacts with Fortress Loans, deploying an unverified custom contract in preparation for the later exploit.","source":""},{"date":"2022-04-29","event":"Attacker obtains 20 ETH via Tornado Cash on Ethereum mainnet and bridges 12.4 ETH to BNB Chain via cBridge.","source":""},{"date":"2022-05-08","event":"Exploit occurs: attacker purchases ~400,000 FTS tokens (~$8,000–$11 ETH), passes malicious Proposal FIP-11 raising FTS collateral factor to 70%, manipulates Umbrella oracle to inflate FTS price to near $1 trillion, and drains approximately $2.98 million in assets from all fToken markets.","source":""},{"date":"2022-05-08","event":"Fortress Protocol team pauses platform UI and announces hack on social media. FTS token price falls more than 45%. Umbrella Network deploys oracle hotfix.","source":""},{"date":"2022-05-08","event":"Stolen funds (1,048.1 ETH and 400,000 DAI) are bridged to Ethereum via Anyswap/Multichain and deposited into Tornado Cash.","source":""},{"date":"2022-05-14","event":"JetFuel Finance publishes compensation plan via Medium: over $1 million in compensation announced including $300,000 USDC immediate disbursement, $200,000 USDC reserve, and 10,000,000 UMB tokens from Umbrella Network on one-year vesting.","source":""},{"date":"2022-05-14","event":"Protocol restart scheduled; on-chain governance removal planned for May 16–17.","source":""},{"date":"2024","event":"DefiLlama records Fortress Loans TVL at approximately $1,168 with zero active loans; FTS token market cap approximately $13,900; protocol effectively dormant.","source":"","date_original":"2024-01-01"}],"sources_used":[{"url":"https://bsc.news/post/fortress-credit-and-lending-project-insight","name":"bsc.news","type":"other","archive_url":"http://web.archive.org/web/20260310162712/https://bsc.news/post/fortress-credit-and-lending-project-insight","credibility":3,"archive_timestamp":"2026-03-10T16:27:12+00:00"},{"url":"https://jetfuelfinance.medium.com/how-to-use-the-fortress-protocol-lending-borrowing-and-collecting-fts-rewards-aa6812389b9b","name":"jetfuelfinance.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/fortress-loans","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250905145658/https://defillama.com/protocol/fortress-loans","credibility":3,"archive_timestamp":"2025-09-05T14:56:58+00:00"},{"url":"https://www.certik.com/resources/blog/k6eZOpnK5Kdde7RfHBZgw-fortress-loans-exploit","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829145225/https://www.certik.com/blog/k6eZOpnK5Kdde7RfHBZgw-fortress-loans-exploit","credibility":3,"archive_timestamp":"2026-08-29T14:52:25+00:00"},{"url":"https://rekt.news/fortress-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513172158/https://rekt.news/fortress-rekt","credibility":3,"archive_timestamp":"2026-05-13T17:21:58+00:00"},{"url":"https://slowmist.medium.com/slowmist-fortress-protocol-hack-analysis-19af24af723c","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250909135534/https://slowmist.medium.com/slowmist-fortress-protocol-hack-analysis-19af24af723c","credibility":3,"archive_timestamp":"2025-09-09T13:55:34+00:00"},{"url":"https://therecord.media/defi-protocol-fortress-announces-3-million-hack","name":"therecord.media","type":"other","archive_url":"http://web.archive.org/web/20260611151443/https://therecord.media/defi-protocol-fortress-announces-3-million-hack","credibility":3,"archive_timestamp":"2026-06-11T15:14:43+00:00"},{"url":"https://medium.com/coinmonks/examination-of-the-fortress-protocol-hack-e261c96ea450","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260726002950/https://medium.com/coinmonks/examination-of-the-fortress-protocol-hack-e261c96ea450","credibility":3,"archive_timestamp":"2026-07-26T00:29:50+00:00"},{"url":"https://medium.com/umbrella-network/update-on-umbrella-oracle-exploit-67ac0fe4414b","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://sayfer.io/blog/3-hacks-an-audit-could-not-find/","name":"sayfer.io","type":"other","archive_url":"http://web.archive.org/web/20260725144808/https://sayfer.io/blog/3-hacks-an-audit-could-not-find/","credibility":3,"archive_timestamp":"2026-07-25T14:48:08+00:00"},{"url":"https://fortress.loans/audit_hash0x.pdf","name":"fortress.loans","type":"other","archive_url":"http://web.archive.org/web/20251130202339/https://fortress.loans/audit_hash0x.pdf","credibility":3,"archive_timestamp":"2025-11-30T20:23:39+00:00"},{"url":"https://jetfuelfinance.medium.com/fortress-attack-update-and-compensation-e7a66621cfe6","name":"jetfuelfinance.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260726041828/https://jetfuelfinance.medium.com/fortress-attack-update-and-compensation-e7a66621cfe6","credibility":3,"archive_timestamp":"2026-07-26T04:18:28+00:00"},{"url":"https://cryptopotato.com/fortress-protocol-hacked-for-3-million-drained-of-all-funds/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260726041841/https://cryptopotato.com/fortress-protocol-hacked-for-3-million-drained-of-all-funds/","credibility":3,"archive_timestamp":"2026-07-26T04:18:41+00:00"},{"url":"https://coinmarketcap.com/currencies/fortress-lending/","name":"coinmarketcap.com","type":"other","archive_url":"https://web.archive.org/web/20260829234031/https://coinmarketcap.com/currencies/fortress-lending/","credibility":3,"archive_timestamp":"2026-08-29T23:40:31+00:00"},{"url":"https://coingecko.com/en/coins/fortress","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:49.520648+00:00","updated_at":"2026-08-30T05:14:13.459561+00:00"}}