Ploutos Money Hack
What happened
On 26 February 2026, Ploutos Market suffered an Ethereum lending incident estimated at about $390,000. Public technical analysis attributes it to a wrong oracle-feed assignment: a USDC collateral path used a BTC/USD Chainlink feed, producing a grossly inflated collateral valuation.
A USDC collateral valuation path used a BTC/USD oracle feed. Oracle integrations need asset/feed identity checks, decimals and quote-currency validation, bounded sanity checks, and deployment-time tests that make an incorrect feed assignment fail safely.
How it happened
- The reported configuration error mapped the USDC collateral route to a BTC/USD price feed instead of a stablecoin-appropriate feed.
- As a result, a small USDC deposit was treated as collateral worth hundreds of thousands of dollars.
- A published transaction analysis states that roughly 8.879 USDC was valued near $608,000, enabling the attacker to borrow about 187.37 WETH before the position could be liquidated under normal assumptions.
- The essential failure was not a price-feed manipulation: it was wiring the wrong feed into a lending valuation path.
- Contemporary reporting later noted that the project's site and social accounts were unavailable, but that does not establish attribution for the exploit.
Protocol details
Security review history
- CredShields View report
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.