Fantasm Finance Hack

TOTAL LOST $2.6M
Medium Missing Condition Check fantom

What happened

The exploiter's address:

https://ftmscan.com/address/0x47091e01…07ae8d

The exploiter:

- deployed contract to trigger the exploit

https://ftmscan.com/address/0x944b58c9…749e3e

- minted XFTM by input only FSM token without entering any FTM

- collected XFTM token

- sold XFTM token to FTM

- bought more FSM and repeated the first step to get a larger amount of FTM

- sold all his FTM for ETH and bridged these ETH to Ethereum via Celer Bridge

- deposited stolen funds into Tornado Cash mixer:

https://etherscan.io/address/0x47091e01…07ae8d

That contract exploited the error in Fantasm’s Pool contract where the developer missed the condition checking for the minimum amount of input FTM when minting XFTM.

Case & protocol details

Classification Protocol Logic / Other / Input Validation
Protocol Type Exploit/Other
Affected asset / contract XFTM
Smart Contract Language Solidity
Official Website fantasm.finance/
Protocol Twitter/X @fantasm_finance

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.