Ploutos Money Hack

Reported loss $390K
Ethereum
Wrong Oracle Feed Assignment

What happened

On 26 February 2026, Ploutos Market suffered an Ethereum lending incident estimated at about $390,000. Public technical analysis attributes it to a wrong oracle-feed assignment: a USDC collateral path used a BTC/USD Chainlink feed, producing a grossly inflated collateral valuation.

Technical root cause

A USDC collateral valuation path used a BTC/USD oracle feed. Oracle integrations need asset/feed identity checks, decimals and quote-currency validation, bounded sanity checks, and deployment-time tests that make an incorrect feed assignment fail safely.

How it happened

  1. The reported configuration error mapped the USDC collateral route to a BTC/USD price feed instead of a stablecoin-appropriate feed.
  2. As a result, a small USDC deposit was treated as collateral worth hundreds of thousands of dollars.
  3. A published transaction analysis states that roughly 8.879 USDC was valued near $608,000, enabling the attacker to borrow about 187.37 WETH before the position could be liquidated under normal assumptions.
  4. The essential failure was not a price-feed manipulation: it was wiring the wrong feed into a lending valuation path.
  5. Contemporary reporting later noted that the project's site and social accounts were unavailable, but that does not establish attribution for the exploit.

Protocol details

Classification Oracle Misconfiguration / Protocol Logic
Protocol Type Lending
Implementation language Solidity
Protocol links @ploutos_money

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.