{"investigation":{"slug":"polter-finance","entity_name":"Polter Finance","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Polter Finance was a decentralized lending protocol on the Fantom blockchain that suffered a critical oracle price manipulation exploit on November 16, 2024, resulting in losses estimated between $8.7 million and $12 million. The protocol was an unaudited fork of Geist Finance that relied on spot prices from SpookySwap liquidity pools as its oracle, a fundamental design flaw that allowed an attacker using funds originating from Tornado Cash to drain nearly all protocol TVL. The platform ceased operations following the hack, with no confirmed recovery of stolen assets as of mid-2026.","sections":[{"content":"Polter Finance was a DeFi lending protocol deployed on the Fantom (FTM) blockchain. The protocol was operated by a pseudonymous founder known as 'Whichghost' and was structurally a fork of Geist Finance, itself a fork of the Aave v2 lending architecture. Rather than commissioning an independent security audit, the Polter team published Geist Finance's existing audit report on their security page, stating: 'As the smart contract used is identical to Geist, except for the removal of the flash-loan function in Lending Pool, we are providing the Geist audit report here.' The BOO token lending market, which became the attack vector, was added without any independent audit whatsoever. At the time of the exploit, the protocol held approximately $9.7 million in total value locked (TVL). Polter supported several assets including FTM, USDC, sFTMX, MIM, and the SpookySwap governance token BOO.","heading":"Background","sources":[{"url":"https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","name":"","type":"other","credibility":3},{"url":"https://rekt.news/polter-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://polter.gitbook.io/polter/security/audit","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 16, 2024, an attacker executed a classic oracle price manipulation attack against Polter Finance's BOO lending market. The root cause was the ChainlinkUniV2Adapter contract's getRoundData() function, which used a hardcoded roundId of 2 and functioned identically to latestRoundData(), meaning the protocol always read the live spot price of BOO from SpookySwap V2 and V3 liquidity pools rather than any time-weighted or validated price feed. The protocol's price change detection mechanism (_chainlinkPriceChangeAboveMax) was rendered inoperable by this bug because it could not retrieve valid historical round data to compare against.\n\nThe attacker, whose initial funds originated from Tornado Cash on Ethereum and were bridged to Fantom, executed the following sequence: First, the attacker took flash loans totaling approximately 1.42 million BOO tokens across SpookySwap V2 (269,042 BOO) and V3 (1,154,788 BOO), leaving only 1 wei of BOO in each liquidity pair. This artificial draining of reserves caused the AMM's constant-product formula (x * y = k) to reflect an extreme synthetic scarcity, causing the oracle to value a single BOO token at approximately $1,373,782,984,830,617,596 — a figure on the order of $1.37 trillion. The attacker then deposited just 1 BOO token as collateral and used the astronomically inflated valuation to borrow 9,134,844 wFTM from Polter's lending pools. The attacker systematically drained multiple pools: pMIM, pWSOL, pFTM, pSFTMX, and pLZ_WETH. Flash loans were then repaid, normalizing the BOO price, while the attacker retained the borrowed assets.\n\nSecurity researchers have characterized this exploit as a textbook oracle manipulation pattern comparable to the Euler Finance and Platypus Finance exploits, all of which involved lending protocols using spot prices from manipulable AMM pools as collateral oracles without TWAP safeguards.","heading":"The Exploit","sources":[{"url":"https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/blog/polter-finance-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-polter-finance-hack-november-2024","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/polter-finance-12m-hack-analysis","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain forensics identified the following addresses and transaction artifacts associated with the exploit.\n\nExploiter EOA: 0x511f427Cdf0c4e463655856db382E05D79Ac44a6\nExploit contract: 0xA21451aC32372C123191B3a4FC01deB69F91533a\nVulnerable price feed (ChainlinkUniV2Adapter): 0x80663EDff11e99e8E0B34cb9C3E1fF32E82A80Fe\nVulnerable PriceFeedV2: 0x875d564a6a86f6154592b88f7a107a517f00cc17\nPrimary attack transaction: 0x5118df23e81603a64c7676dd6b6e4f76a57e4267e67507d34b0b26dd9ee10eac\n\nFollowing the exploit, proceeds of approximately 10 million FTM were split across 11 wallets each receiving approximately 1 million FTM. Funds were subsequently bridged from Fantom to Ethereum via SquidRouter and Li.fi and further dispersed across 19 Ethereum wallets. At least 220 ETH were confirmed laundered through Tornado Cash. The two largest identified Ethereum receiving wallets held 358 ETH (~$1.1 million) and 220 ETH respectively. The Polter Finance team alleged they traced funds to wallets on Binance; independent analysis by CertiK and Rekt.news suggested the fund flow was more complex than a direct Binance deposit. The attacker had not responded to on-chain negotiation messages sent by the Polter team as of reporting.","heading":"On-Chain Evidence","sources":[{"url":"https://www.certik.com/blog/polter-finance-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","name":"","type":"other","credibility":3},{"url":"https://rekt.news/polter-finance-rekt","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 17, 2024, Polter Finance paused its platform and issued a public statement via X (formerly Twitter) disclosing the exploit and confirming that bridges had been notified to limit further fund movement. The pseudonymous founder 'Whichghost' filed a police report with Singaporean authorities, with identity authenticated via Singpass, Singapore's national digital identity system. The police report recorded losses of more than SGD 16.1 million (approximately USD 12 million), including SGD 223,219 in personal losses incurred by Whichghost.\n\nThe team sent an on-chain message to the exploiter offering to negotiate without legal consequences if funds were returned, a common but largely ineffective tactic in post-exploit situations. The attacker did not respond. Polter Finance subsequently announced a partnership with the Security Alliance Information Sharing and Analysis Center (SEAL-ISAC) to assist in tracking the attacker.\n\nThe protocol formally ceased operations following the exploit. No compensation mechanism for affected users was announced. No stolen funds were recovered as of mid-2026. The exploit ranked as the third-largest price manipulation exploit of 2024 according to CertiK, behind UwULend ($19 million) and WooFi ($19 million).","heading":"Team Response","sources":[{"url":"https://decrypt.co/292080/crypto-lender-polter-finance-hack-drains-funds","name":"","type":"other","credibility":3},{"url":"https://crypto.news/polter-finance-kicks-off-recovery-efforts-following-12m-flash-loan-attack/","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/blog/polter-finance-incident-analysis","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Polter Finance presents a critical risk profile across multiple dimensions. The protocol is no longer operational, having shut down following the November 2024 exploit. Users who held funds in the protocol at the time of the hack sustained total losses with no recovery path announced.\n\nThe fundamental security failures were systemic rather than incidental. Deploying a forked lending protocol without independent audit, relying exclusively on the parent protocol's audit report, and launching a new collateral market (BOO) with no security review of any kind are all practices that expose users to catastrophic risk. The oracle design — using raw AMM spot prices with no TWAP safeguard and a non-functional price-change detection mechanism — was a textbook vulnerability that security researchers have documented repeatedly in the context of Aave-derived forks.\n\nFund recovery is unlikely. The attacker routed proceeds through Tornado Cash and across multiple chains, a laundering pattern that has historically defeated attribution efforts. The on-chain negotiation produced no response. Law enforcement engagement through Singapore authorities may provide some investigative avenue given Whichghost's KYC via Singpass, though cross-jurisdictional crypto enforcement outcomes remain unpredictable.\n\nAny future relaunch of Polter Finance or affiliated products by the same team should be treated with extreme caution absent fully transparent, independent security audits and verifiably sound oracle architecture.","heading":"Risk Assessment","sources":[{"url":"https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-polter-finance-hack-november-2024","name":"","type":"other","credibility":3},{"url":"https://rekt.news/polter-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://www.auditone.io/blog-posts/the-12m-polter-finance-hack-a-comprehensive-analysis","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-11-16","event":"Attacker, using funds sourced from Tornado Cash on Ethereum bridged to Fantom, exploits the BOO lending market oracle via flash loan price manipulation, draining an estimated $8.7M–$12M from Polter Finance.","source":""},{"date":"2024-11-17","event":"Polter Finance pauses platform, issues public disclosure on X, notifies bridge operators, and traces alleged fund movement to Binance wallets.","source":""},{"date":"2024-11-17","event":"Pseudonymous founder Whichghost files a police report with Singapore authorities via Singpass, recording losses of SGD 16.1M (~$12M USD).","source":""},{"date":"2024-11-17","event":"Polter Finance sends on-chain message to exploiter offering no-prosecution negotiation; attacker does not respond.","source":""},{"date":"2024-11-18","event":"Polter Finance announces partnership with SEAL-ISAC to assist in attacker identification and fund tracing.","source":""},{"date":"2024-11-18","event":"On-chain forensics confirm attacker split ~10M FTM across 11 wallets, bridged to Ethereum via SquidRouter/Li.fi, and laundered at least 220 ETH through Tornado Cash.","source":""},{"date":"2024-11-20","event":"Polter Finance ceases operations. No user compensation mechanism is announced. Protocol remains offline.","source":""}],"sources_used":[{"url":"https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","name":"","type":"other","archive_url":"http://web.archive.org/web/20260415073640/https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss","credibility":3,"archive_timestamp":"2026-04-15T07:36:40+00:00"},{"url":"https://rekt.news/polter-finance-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260608195541/https://rekt.news/polter-finance-rekt","credibility":3,"archive_timestamp":"2026-06-08T19:55:41+00:00"},{"url":"https://polter.gitbook.io/polter/security/audit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260219073517/https://polter.gitbook.io/polter/security/audit","credibility":3,"archive_timestamp":"2026-02-19T07:35:17+00:00"},{"url":"https://www.certik.com/blog/polter-finance-incident-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20260724211527/https://www.certik.com/blog/polter-finance-incident-analysis","credibility":3,"archive_timestamp":"2026-07-24T21:15:27+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-polter-finance-hack-november-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609205321/https://www.halborn.com/blog/post/explained-the-polter-finance-hack-november-2024","credibility":3,"archive_timestamp":"2026-06-09T20:53:21+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/polter-finance-12m-hack-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20260417051911/https://www.quillaudits.com/blog/hack-analysis/polter-finance-12m-hack-analysis","credibility":3,"archive_timestamp":"2026-04-17T05:19:11+00:00"},{"url":"https://decrypt.co/292080/crypto-lender-polter-finance-hack-drains-funds","name":"","type":"other","archive_url":"http://web.archive.org/web/20260608145536/https://decrypt.co/292080/crypto-lender-polter-finance-hack-drains-funds","credibility":3,"archive_timestamp":"2026-06-08T14:55:36+00:00"},{"url":"https://crypto.news/polter-finance-kicks-off-recovery-efforts-following-12m-flash-loan-attack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251006020955/https://crypto.news/polter-finance-kicks-off-recovery-efforts-following-12m-flash-loan-attack/","credibility":3,"archive_timestamp":"2025-10-06T02:09:55+00:00"},{"url":"https://www.auditone.io/blog-posts/the-12m-polter-finance-hack-a-comprehensive-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511085443/https://www.auditone.io/blog-posts/the-12m-polter-finance-hack-a-comprehensive-analysis","credibility":3,"archive_timestamp":"2026-05-11T08:54:43+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.543758+00:00","updated_at":"2026-08-29T09:21:05.766787+00:00"}}