{"investigation":{"slug":"ola-finance","entity_name":"Ola Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Ola Finance is a multi-chain decentralized lending protocol offering a 'lending-as-a-service' platform that allows third parties to deploy isolated Compound-style lending pools across multiple blockchains. On March 31, 2022, the protocol's deployment on the Fuse Network was exploited via a reentrancy vulnerability in ERC677 token logic, resulting in approximately $4.67 million in stolen assets. The attacker used Tornado Cash to obscure initial funding, laundered proceeds through Ethereum and BNB Chain wallets, and was never publicly identified; a partial compensation plan was offered but fell materially short of full victim restitution.","sections":[{"content":"At approximately 05:00 UTC on March 31, 2022, an unknown attacker exploited Ola Finance's lending deployment on the Fuse Network. The vulnerability was a reentrancy bug arising from incompatibility between Compound Finance fork architecture and the ERC677 token standard's built-in callback mechanism. The attacker's workflow: (1) withdrew initial capital from Tornado Cash and bridged it to Fuse Network via the Fuse Bridge; (2) deposited assets as collateral and minted oTokens; (3) called the borrow() function, which triggered an external ERC677 callback before internal borrow-balance state was updated; (4) during that callback, redeemed the collateral — effectively removing it without having repaid the loan. The sequence was repeated across multiple asset pools. For non-ERC677 assets (fUSD and FUSE), the attacker reused previously stolen WETH as collateral in the same pattern. Blockchain security firm PeckShield assisted Ola Finance in diagnosing the exploit and published on-chain attribution.","heading":"March 2022 Reentrancy Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/04/01/ola-finance-says-attackers-stole-47m-in-re-entrancy-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","name":"ola-finance.medium.com","type":"other","credibility":3},{"url":"https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","name":"therecord.media","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/ola-finance-hack-a-post-mortem-analysis-7bf498f73a54","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The total confirmed stolen amount was approximately $4.67 million, comprising: 216,964.18 USDC; 507,216.68 BUSD; 200,000.00 fUSD; 550.45 WETH; 26.25 WBTC; and 1,240,000.00 FUSE. PeckShield's tracking of the hacker's net gain reported approximately $3.6 million, with the discrepancy reflecting differing methodologies. Following the exploit, stolen assets were bridged from Fuse Network to Ethereum and BNB Chain wallets, substantially impeding recovery. The attacker's initial seed capital was sourced via Tornado Cash, a privacy mixer, prior to execution. Voltage Finance, which co-operated the affected network, requested Circle (USDC issuer), Etherscan, and centralized exchange teams to blacklist the identified attacker addresses. No public confirmation of successful blacklisting or fund freezing was reported.","heading":"Stolen Assets and Fund Movement","sources":[{"url":"https://www.coindesk.com/tech/2022/04/01/ola-finance-says-attackers-stole-47m-in-re-entrancy-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://beincrypto.com/ola-finance-loses-4-6m-in-latest-defi-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","name":"therecord.media","type":"other","credibility":3},{"url":"https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","name":"ola-finance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Ola Finance and Voltage Finance issued a joint post-mortem and a subsequent transparency report. Immediate mitigations included pausing borrowing on all lending networks, halting new oToken minting, setting borrower interest rates to 0% APY, and disabling RainMaker rewards. The teams attempted to contact the attacker via an on-chain Ethereum transaction on March 31, 2022, offering a 10% bounty (approximately $467,000) for the return of stolen funds; no response was ever received. The partial compensation plan announced combined contributions from three parties: Fuse Foundation pledged 250,000 USDC plus 1 million FUSE distributed over one year; Voltage Finance treasury pledged 250,000 USDC plus 40 million VOLT over one year; Ola Finance pledged 400,000 OLA tokens (0.4% of a planned 100 million token supply) plus up to $200,000 in USDC at $1 per future token for victims who signed up by June 30, 2022. The combined USDC contributions of $500,000 represent approximately 10.7% of the $4.67 million stolen, with the remainder paid in native protocol tokens (FUSE, VOLT, OLA) whose value was subject to market volatility. No independent confirmation of full victim repayment has been identified.","heading":"Team Response and Compensation Plan","sources":[{"url":"https://ola-finance.medium.com/ola-voltage-exploit-on-fuse-network-transparency-report-compensation-plan-and-future-steps-98d858b9e5a3","name":"ola-finance.medium.com","type":"other","credibility":3},{"url":"https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","name":"ola-finance.medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/04/01/ola-finance-says-attackers-stole-47m-in-re-entrancy-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Ola Finance's core design positions it as a 'lending-as-a-service' layer, enabling third-party protocols (such as Voltage Finance on Fuse and SpiritSwap on Fantom) to deploy isolated Compound-style lending pools with custom token parameters. The exploit demonstrated a known class of vulnerability: Compound forks are not natively compatible with ERC677 or ERC777 tokens because these standards include transfer callbacks that can re-enter the lending contract before state is finalized. The Ola team stated in its post-mortem that this attack vector could not be replicated on other supported chains at that time, and committed to auditing token transfer logic across all deployments. No public pre-exploit audit report covering the Fuse deployment's ERC677 compatibility has been surfaced in available sources. PeckShield assisted in post-exploit forensics. Chainlink Price Feeds were integrated as the oracle solution across Fantom and other deployments.","heading":"Smart Contract Architecture and Security Audit History","sources":[{"url":"https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","name":"ola-finance.medium.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/140012/ola-finance-on-fuse-network-suffers-3-6-million-hack","name":"theblock.co","type":"other","credibility":3},{"url":"https://ola-finance.medium.com/ola-finance-upgrades-oracles-to-include-chainlink-price-feeds-on-fantom-142a27811f5c","name":"ola-finance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Ola Finance positioned itself as the 'Uniswap for lending' — a permissionless factory for launching Compound-style lending pools on any EVM-compatible chain. Prior to the exploit, active deployments included Fuse Network (co-operated with Voltage Finance), Fantom (via SpiritSwap integration), Moonbeam, Boba Network, and additional chains. The Chainlink oracle integration on Fantom was announced as a key reliability upgrade. Following the March 2022 exploit, the Fuse lending network was taken offline; the team estimated a 1-2 month remediation period. Public activity on Ola Finance's official Medium channel and social channels became sparse after mid-2022. The app.ola.finance interface remained accessible as of research date, but independently verifiable data on current total value locked (TVL) or active lending volume is not available from Tier 1 or Tier 2 sources for the period 2023-2025.","heading":"Multi-Chain Deployment and Operational Context","sources":[{"url":"https://olafinances.gitbook.io/ola-finance","name":"olafinances.gitbook.io","type":"other","credibility":3},{"url":"https://medium.com/fusenet/lending-powered-by-ola-finance-a-new-paradigm-in-defi-on-fuse-230cd407125c","name":"medium.com","type":"other","credibility":3},{"url":"https://spiritswap.medium.com/spiritswap-leveraging-chainlink-price-feeds-through-ola-finance-to-power-fantom-lending-services-3a48cd6a07b0","name":"spiritswap.medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/04/01/ola-finance-says-attackers-stole-47m-in-re-entrancy-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The identity of the attacker remains unknown as of available public reporting. No law enforcement charges, regulatory actions, or court filings related to the March 2022 Ola Finance exploit have been identified in available Tier 1 or Tier 2 sources. The use of Tornado Cash for initial funding and fund obfuscation is consistent with techniques employed to prevent on-chain attribution. Voltage Finance's requests to Circle and centralized exchanges to freeze attacker addresses were not confirmed as successful in any subsequent reporting. The 10% bounty offer made on-chain on March 31, 2022 received no public response. PeckShield tracked approximately $3.6 million in net proceeds to wallets on Ethereum and BNB Chain, but no public report of fund recovery has been identified.","heading":"Attacker Identity and Law Enforcement","sources":[{"url":"https://ola-finance.medium.com/ola-voltage-exploit-on-fuse-network-transparency-report-compensation-plan-and-future-steps-98d858b9e5a3","name":"ola-finance.medium.com","type":"other","credibility":3},{"url":"https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","name":"therecord.media","type":"other","credibility":3},{"url":"https://beincrypto.com/ola-finance-loses-4-6m-in-latest-defi-exploit/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Ola Finance exploit occurred days after the Ronin Network hack, in which over $600 million was stolen — the largest DeFi hack at the time. The reentrancy attack class targeting Compound forks with callback-enabled tokens had precedent: Cream Finance lost approximately $29 million to a reentrancy attack in 2021, and Revest Finance lost approximately $2 million in a similar exploit in early 2022. Ola Finance's case is notable because the vulnerability was introduced not in Ola's own core contracts but in the interaction between a third-party deployment (Voltage Finance on Fuse) and the ERC677 token standard — a design risk inherent to the lending-as-a-service model where Ola provides infrastructure to external operators who may integrate incompatible token types.","heading":"DeFi Ecosystem Context","sources":[{"url":"https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/03/31/ola-finance-exploited-for-36m-in-re-entrancy-attack","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-05-26","event":"Fuse Lending Network powered by Ola Finance goes live on Fuse Network, initially supporting FUSE, WETH, WBTC, and USDC.","source":""},{"date":"2022-03-31","event":"Ola Finance's Fuse Network deployment exploited via ERC677 reentrancy vulnerability. Approximately $4.67 million stolen across USDC, BUSD, fUSD, WETH, WBTC, and FUSE. Attacker's seed capital sourced via Tornado Cash; stolen funds bridged to Ethereum and BNB Chain.","source":""},{"date":"2022-03-31","event":"Ola Finance and Voltage Finance pause all borrowing on affected networks, set borrower interest rates to 0% APY, and disable RainMaker rewards. Teams send on-chain message to attacker offering 10% (~$467,000) bounty.","source":""},{"date":"2022-04","event":"CoinDesk reports revised loss figure of $4.67 million following full accounting. PeckShield confirms reentrancy vulnerability diagnosis. Voltage Finance requests Circle, Etherscan, and CEX teams blacklist attacker addresses.","source":"","date_original":"2022-04-01"},{"date":"2022-04","event":"Ola Finance publishes initial post-mortem on Medium detailing attack mechanism and immediate mitigations. Protocol estimates 1-2 months for remediation and relaunch.","source":"","date_original":"2022-04-01"},{"date":"2022-04","event":"Ola Finance publishes Transparency Report and compensation plan: Fuse Foundation (250K USDC + 1M FUSE over 1 year), Voltage Finance (250K USDC + 40M VOLT over 1 year), Ola Finance (400K OLA tokens + up to $200K USDC option for sign-ups by June 30, 2022).","source":"","date_original":"2022-04-01"},{"date":"2022-06-30","event":"Deadline for affected users to sign up for Ola Finance's USDC compensation option at $1 per future OLA token.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/tech/2022/04/01/ola-finance-says-attackers-stole-47m-in-re-entrancy-exploit","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","name":"ola-finance.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250910225857/https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443","credibility":3,"archive_timestamp":"2025-09-10T22:58:57+00:00"},{"url":"https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","name":"therecord.media","type":"other","archive_url":"http://web.archive.org/web/20251109134215/https://therecord.media/ola-finance-defi-platform-hacked-nearly-5-million-stolen","credibility":3,"archive_timestamp":"2025-11-09T13:42:15+00:00"},{"url":"https://medium.com/coinmonks/ola-finance-hack-a-post-mortem-analysis-7bf498f73a54","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/ola-finance-loses-4-6m-in-latest-defi-exploit/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://ola-finance.medium.com/ola-voltage-exploit-on-fuse-network-transparency-report-compensation-plan-and-future-steps-98d858b9e5a3","name":"ola-finance.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.theblock.co/post/140012/ola-finance-on-fuse-network-suffers-3-6-million-hack","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260429184112/https://www.theblock.co/post/140012/ola-finance-on-fuse-network-suffers-3-6-million-hack","credibility":3,"archive_timestamp":"2026-04-29T18:41:12+00:00"},{"url":"https://ola-finance.medium.com/ola-finance-upgrades-oracles-to-include-chainlink-price-feeds-on-fantom-142a27811f5c","name":"ola-finance.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://olafinances.gitbook.io/ola-finance","name":"olafinances.gitbook.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/fusenet/lending-powered-by-ola-finance-a-new-paradigm-in-defi-on-fuse-230cd407125c","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://spiritswap.medium.com/spiritswap-leveraging-chainlink-price-feeds-through-ola-finance-to-power-fantom-lending-services-3a48cd6a07b0","name":"spiritswap.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/tech/2022/03/31/ola-finance-exploited-for-36m-in-re-entrancy-attack","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260322055934/https://www.coindesk.com/tech/2022/03/31/ola-finance-exploited-for-36m-in-re-entrancy-attack","credibility":3,"archive_timestamp":"2026-03-22T05:59:34+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:50.289806+00:00","updated_at":"2026-08-30T01:16:34.236221+00:00"}}