Fortress Loans Hack
What happened
Fortress Loans was attacked due to oracle vulnerability. An attacker was able to manipulate the project's oracle which allowed them to borrow differrent number of tokens for the amount of ~$3m (~1k ETH and 400k DAI).
Fortress Protocol is a decentralized marketplace for Lenders and Borrowers with Borderless Stablecoins. Fortress Loans became a victim of attacker that manipulate with the price oracle, which made possible to get about $3m and launder them through the TornadoCache.
Attack flow:
Attacker created unverified smart-contract (https://bscscan.com/tx/0x4800928c…af5039) which was later used to send a series of transactions (https://bscscan.com/tx/0x13d19809…b061bf).
A series of transactions allowed them to propose Fortress Governor Alfa contract with a malicious proposal, for which they themselves voted to set the FTS extremely valuable. The attacker then borrowed a huge amount of tokens that exchanged for ETH and DAI. Then all stollen funds were transferred across the bridge to the Ethereum network and laundered via TornadoCache.
As the time of this writing information on this case is scarce. More sources will be added if the case should develop.
Attacker address on BSC: https://bscscan.com/address/0xA6AF2872…5d22Ad
Attacker address on ETH. Here all the stolen funds were laundered through TornadoCache: https://etherscan.io/address/0xA6AF2872…5d22Ad
Bridging transaction from BSC to ETH:
BSC: https://bscscan.com/tx/0x36fd458d…7e9eea
ETH: https://etherscan.io/tx/0xcf852b02…543af5
Attacker's smart-contract (BSC): https://bscscan.com/address/0xcd337b92…463a45
Attack transaction: https://bscscan.com/tx/0x13d19809…b061bf
Case & protocol details
Security review history
- Ether Authority No public report
- HashEx No public report
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-mortem rekt.news
- analysis Twitter/X Alert twitter.com
- analysis Website reference certik.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.