Fantasm Finance Hack
What happened
The exploiter's address:
https://ftmscan.com/address/0x47091e01…07ae8d
The exploiter:
- deployed contract to trigger the exploit
https://ftmscan.com/address/0x944b58c9…749e3e
- minted XFTM by input only FSM token without entering any FTM
- collected XFTM token
- sold XFTM token to FTM
- bought more FSM and repeated the first step to get a larger amount of FTM
- sold all his FTM for ETH and bridged these ETH to Ethereum via Celer Bridge
- deposited stolen funds into Tornado Cash mixer:
https://etherscan.io/address/0x47091e01…07ae8d
That contract exploited the error in Fantasm’s Pool contract where the developer missed the condition checking for the minimum amount of input FTM when minting XFTM.
Case & protocol details
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Post-mortem medium.com
- report Report quadrigainitiative.com
- report Post-mortem medium.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference certik.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.