{"investigation":{"slug":"ploutos-money","entity_name":"Ploutos Money","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Ploutos Money was a multi-chain DeFi lending and leveraged farming protocol, forked from Aave v3.0.2, that operated across Ethereum, Arbitrum, Hemi, Hyperliquid, Avalanche, Polygon, Base, Plasma, and Katana. On February 26, 2026, the protocol lost approximately $388,000 (187.36 ETH) after its USDC price oracle was misconfigured to reference Chainlink's BTC/USD feed instead of the correct USDC/USD feed. Immediately following the exploit, the team deleted its website, GitHub repository, and all social media accounts without issuing any warning or post-mortem, prompting on-chain security firms CertiK and BlockSec to conclude that the incident was an inside job rather than an external attack.","sections":[{"content":"Ploutos Money positioned itself as a non-custodial money market and leveraged farming platform, described in its own documentation as a refined fork of Aave v3.0.2. The protocol operated independent markets on nine chains: Ethereum, Arbitrum, Polygon, Base, Plasma, Katana, Hemi, Hyperliquid L1, and Avalanche. Users could supply supported assets to earn yield and borrow against those deposits as collateral, with algorithmic interest rates updating based on market utilization. The protocol advertised plans to evolve into a super-app natively supporting leveraged lending and leveraged farming flows. Prior to the February 2026 exploit, Ploutos Money had measurable but modest total value locked (TVL) across its deployments, with the Plasma chain market representing the largest share. The team behind the protocol operated anonymously, with no publicly identified founders or developers — a common risk factor in DeFi protocols that later exit.","heading":"Protocol Overview","sources":[{"url":"https://docs.ploutos.money","name":"docs.ploutos.money","type":"other","credibility":3},{"url":"https://defillama.com/protocol/ploutos-money","name":"defillama.com","type":"other","credibility":3},{"url":"https://app.ploutos.money/","name":"app.ploutos.money","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 26, 2026 at approximately 05:00 UTC, Ploutos Money lost 187.36 ETH (approximately $388,000) across five blockchain deployments simultaneously. The root cause was a price oracle misconfiguration: the protocol's USDC oracle was set to reference Chainlink's BTC/USD price feed rather than the correct USDC/USD feed. This caused the protocol to dramatically overvalue USDC collateral, enabling an attacker to borrow 187 ETH by posting only 8 USDC as collateral in a single transaction. BlockSec documented that the misconfiguration occurred at block 24538896, with the exploit executing at block 24538897 — one block later — netting the attacker approximately 181.7 ETH after approximately 5.6 ETH paid in builder bribes. Funds drained from the Hemi deployment were bridged to Ethereum mainnet via Stargate. Funds stolen from Arbitrum, Hyperliquid, and Avalanche were routed through Li.Fi before consolidating on Ethereum mainnet. On March 13, 2026, 182 ETH was traced moving to wallet 0x640fb638efcc086f5e95536678087e14a2e96ab, which subsequently swapped the holdings to stablecoins and dispersed them to nine or more additional wallets. Pseudonymous blockchain investigator Tanuki42 linked the Ploutos exploiter to at least four additional hacks targeting other lending protocols, including two incidents involving Moonwell that together resulted in approximately $1.8 million in bad debt through the same oracle manipulation technique.","heading":"The February 2026 Oracle Exploit","sources":[{"url":"https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"blocksec.com","type":"other","credibility":3},{"url":"https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/","name":"protos.com","type":"other","credibility":3},{"url":"https://crypto-economy.com/crypto-security-firm-certik-reports-new-oracle-based-exploit/","name":"crypto-economy.com","type":"other","credibility":3},{"url":"https://www.livebitcoinnews.com/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"livebitcoinnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Within minutes of the February 26, 2026 exploit, the Ploutos Money team deleted its website, GitHub repository, X (formerly Twitter) account, and all other publicly accessible social media presence. No incident warning was issued to users, no post-mortem was published, and no recovery or compensation measures were communicated through any official channel. An unverified message appeared in the project's Telegram channel following the incident; however, blockchain network Hemi explicitly warned users not to follow any recovery instructions from that unverified source. The immediate and total erasure of team presence without user notification is consistent with a planned exit rather than a response to an external attack. CertiK and BlockSec independently concluded that the incident bore the hallmarks of an inside job: the oracle misconfiguration — a privileged administrative action — occurred precisely one block before the exploit, which either indicates real-time monitoring by an external attacker or, more plausibly, insider coordination. The fact that the team had administrator access to oracle configuration and that all digital presence was deleted simultaneously supports the insider hypothesis advanced by both security firms. Total user deposits alleged to have been affected across all chains are estimated at approximately $1.69 million when accounting for the full scope of the oracle manipulation and minting of unbacked collateral tokens.","heading":"Exit Scam Allegations and Team Conduct","sources":[{"url":"https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://medium.com/@ellieismailidou_91686/the-ploutos-money-defi-rug-pull-how-a-ca-defi-investor-lost-300k-in-a-fake-hack-6c23d176091b","name":"medium.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"bitcoinethereumnews.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"blocksec.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CertiK, a major blockchain security auditor, documented in real time that Ploutos Money's USDC oracle was incorrectly configured to reference Chainlink's BTC/USD feed, and subsequently confirmed that 'the Ploutos website and social media accounts have been deleted' immediately following the exploit. CertiK's reporting characterized the incident as suspicious, given the timing and the team's complete disappearance. BlockSec, another respected blockchain security firm, provided detailed technical analysis: the misconfiguration occurred at block 24538896 and the exploit fired at block 24538897, consistent with either real-time on-chain monitoring or inside knowledge of the configuration change. BlockSec recommended that 'sensitive operations like oracle configuration should be protected by multisig wallets or timelock' as a mitigation standard to prevent such rapid exploitation windows. Both firms' findings were independent, and their agreement on the insider-job characterization carries significant credibility weight. Pseudonymous on-chain investigator Tanuki42 separately linked the Ploutos exploiter's wallet addresses to at least four prior hacks totaling approximately $3.5 million in aggregate, suggesting the actor — whether insider or external — was a repeat offender. Hemi Network issued an official statement confirming the exploit was isolated to Ploutos deployments, that the core Hemi protocol remained unaffected, and published a list of twelve contract addresses that users should revoke permissions for immediately.","heading":"Security Firm Findings","sources":[{"url":"https://crypto-economy.com/crypto-security-firm-certik-reports-new-oracle-based-exploit/","name":"crypto-economy.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"blocksec.com","type":"other","credibility":3},{"url":"https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.livebitcoinnews.com/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"livebitcoinnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Individual user losses from the February 2026 incident have been documented in public reporting. One identified victim, a software engineer referred to as Michael Chen by pseudonym, reported losing approximately $300,000 in the incident. According to a post-incident account, AYRLP, a blockchain forensics firm, recovered approximately $210,000 (approximately 70% of the loss) by tracing fund flows through FixedFloat exchange, which cooperated with the investigation. FBI Internet Crime Complaint Center (IC3) and Federal Trade Commission complaints were filed in connection with the loss. The total protocol drain across all affected users has been estimated at approximately $1.69 million by forensic analysis, significantly exceeding the 187.36 ETH figure cited by CertiK and BlockSec, which reflects only the primary ETH-denominated drain. As of the date of this investigation, the protocol's remaining TVL across all nine chains stands at approximately $483, with the vast majority locked in negligible residual amounts on the Plasma chain, indicating the protocol is effectively defunct.","heading":"User Impact and Reported Losses","sources":[{"url":"https://medium.com/@ellieismailidou_91686/the-ploutos-money-defi-rug-pull-how-a-ca-defi-investor-lost-300k-in-a-fake-hack-6c23d176091b","name":"medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/ploutos-money","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Several structural red flags were present in Ploutos Money's design and operation prior to the February 2026 incident. First, the team operated entirely anonymously, with no publicly identified founders, developers, or officers — meaning that no individual faced reputational or legal accountability. Second, the protocol was a fork of Aave v3.0.2 with modified risk configurations, but there is no publicly available independent security audit of those modifications, including the oracle configuration that ultimately led to the exploit. Third, oracle configuration — a highly privileged and security-critical operation — was not protected by multisig governance or timelock delays, meaning a single administrative action could immediately alter pricing across all deployed markets. Fourth, the protocol operated across nine blockchains simultaneously, a scope that compounds operational risk and audit surface area. Fifth, the one-block gap between oracle misconfiguration and exploit execution, combined with the team's total disappearance, is consistent with the exit scam pattern identified by CertiK and BlockSec. Sixth, an unverified post-incident Telegram message resembles the social engineering recovery scam pattern frequently used to extract additional funds from victims after a primary exploit. ZachXBT, the pseudonymous blockchain investigator known for flagging exit scams and insider fraud, flagged this entity.","heading":"Risk Indicators and Red Flags","sources":[{"url":"https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"blocksec.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"bitcoinethereumnews.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025","event":"Ploutos Money launches as a multi-chain Aave v3.0.2 fork across Plasma, Arbitrum, Polygon, Base, and Katana, advertising leveraged lending and farming features.","source":"","date_original":"2025-01-01"},{"date":"2026-02","event":"Arbitrum integration with Ploutos announced, expanding the protocol's multi-chain footprint per TradingView/Coindar announcement.","source":"","date_original":"2026-02-01"},{"date":"2026-02-26","event":"At approximately 05:00 UTC, the USDC oracle on Ploutos Money is misconfigured to reference Chainlink's BTC/USD feed instead of the USDC/USD feed (block 24538896). One block later (block 24538897), an attacker borrows 187.36 ETH using only 8 USDC as collateral. $388,000 is drained across Hemi, Ethereum, Arbitrum, Hyperliquid, and Avalanche deployments.","source":""},{"date":"2026-02-26","event":"Immediately following the exploit, the Ploutos Money website, GitHub repository, X account, and all social media are deleted. No incident notice or post-mortem is issued.","source":""},{"date":"2026-02-26","event":"CertiK and BlockSec flag the oracle misconfiguration and subsequent exploit in real time. Both firms document that the protocol's website and social accounts have been deleted.","source":""},{"date":"2026-02-27","event":"Hemi Network issues an official statement confirming the exploit, stating its core protocol is unaffected, warning users against following unverified Telegram recovery instructions, and publishing 12 contract addresses requiring permission revocation.","source":""},{"date":"2026-02-27","event":"Pseudonymous investigator Tanuki42 links the Ploutos exploiter wallet to at least four additional hacks, including two Moonwell incidents totaling approximately $1.8 million in bad debt.","source":""},{"date":"2026-03","event":"BlockSec includes the Ploutos Money exploit in its weekly Web3 security incident roundup for February 23 to March 1, 2026, providing detailed block-level technical analysis.","source":"","date_original":"2026-03-01"},{"date":"2026-03-13","event":"On-chain trackers observe 182 ETH moving to wallet 0x640fb638efcc086f5e95536678087e14a2e96ab, which then swaps holdings to stablecoins and disperses to nine or more additional wallets.","source":""},{"date":"2026-03-21","event":"A victim account published on Medium documents a $300,000 individual loss and partial recovery of approximately $210,000 via blockchain forensics firm AYRLP, with FBI IC3 and FTC complaints filed.","source":""}],"sources_used":[{"url":"https://docs.ploutos.money","name":"docs.ploutos.money","type":"other","archive_url":"http://web.archive.org/web/20251031020600/https://docs.ploutos.money/","credibility":3,"archive_timestamp":"2025-10-31T02:06:00+00:00"},{"url":"https://defillama.com/protocol/ploutos-money","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20251007173903/https://defillama.com/protocol/ploutos-money","credibility":3,"archive_timestamp":"2025-10-07T17:39:03+00:00"},{"url":"https://app.ploutos.money/","name":"app.ploutos.money","type":"other","archive_url":"http://web.archive.org/web/20260215092243/https://app.ploutos.money/","credibility":3,"archive_timestamp":"2026-02-15T09:22:43+00:00"},{"url":"https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260830034705/https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/","credibility":3,"archive_timestamp":"2026-08-30T03:47:05+00:00"},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"blocksec.com","type":"other","archive_url":"http://web.archive.org/web/20260315202530/https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","credibility":3,"archive_timestamp":"2026-03-15T20:25:30+00:00"},{"url":"https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260730190608/https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/","credibility":3,"archive_timestamp":"2026-07-30T19:06:08+00:00"},{"url":"https://crypto-economy.com/crypto-security-firm-certik-reports-new-oracle-based-exploit/","name":"crypto-economy.com","type":"other","archive_url":"http://web.archive.org/web/20260315180810/https://crypto-economy.com/crypto-security-firm-certik-reports-new-oracle-based-exploit/","credibility":3,"archive_timestamp":"2026-03-15T18:08:10+00:00"},{"url":"https://www.livebitcoinnews.com/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"livebitcoinnews.com","type":"other","archive_url":"https://web.archive.org/web/20260829050639/https://www.livebitcoinnews.com/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","credibility":3,"archive_timestamp":"2026-08-29T05:06:39+00:00"},{"url":"https://medium.com/@ellieismailidou_91686/the-ploutos-money-defi-rug-pull-how-a-ca-defi-investor-lost-300k-in-a-fake-hack-6c23d176091b","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bitcoinethereumnews.com/tech/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","name":"bitcoinethereumnews.com","type":"other","archive_url":"http://web.archive.org/web/20260829023917/https://bitcoinethereumnews.com/tech/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/","credibility":3,"archive_timestamp":"2026-08-29T02:39:17+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:13.380378+00:00","updated_at":"2026-08-30T03:54:57.298479+00:00"}}