Polter Finance Hack

TOTAL LOST $12.0M
High Flash Loan Attacks Fantom

What happened

On November 16, 2024, Polter Finance, a Fantom lending protocol, was exploited through its BOO price oracle. The attacker flash-borrowed BOO from SpookySwap V2 and V3 pools, depleted their BOO reserves, and caused Polter's oracle to calculate an absurdly inflated BOO price. They then deposited minimal BOO collateral and borrowed protocol assets, draining multiple lending pools.

Technical Root Cause

Polter's `AaveOracle` pricing path relied on spot reserve ratios in SpookySwap BOO pools through `ChainlinkUniV2Adapter` and `PriceFeedV2`. The purported historical-price sanity check was ineffective because `previousChainlink0Response` was also read from current manipulated reserves. That let the attacker inflate collateral value and borrow against it.

Case & protocol details

Classification Protocol Logic / Lending Oracle Manipulation
Protocol Type Lending
Official Website polter.finance/#/
Protocol Twitter/X @polterfinance

Attack Timeline

The attacker used an exploit contract to flash-borrow the BOO balances from SpookySwap V3 and V2 pools, removing almost all BOO from the pools and manipulating their reserve ratios. Polter's oracle accepted the resulting price. The attacker deposited one BOO as collateral, which the protocol valued at about $1.37 quadrillion, then repeatedly borrowed assets including wFTM from several lending pools.

The stolen assets were converted to FTM, split across wallets, bridged to Ethereum, and later routed through Tornado Cash. Polter paused operations and attempted to negotiate a return, but the reviewed sources do not establish a recovered amount.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.