Fortress Protocol hack — May 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 9, 2022 |
| Target type | Lending protocol |
| Loss | $3,000,000Price at time of incident |
| Method | Oracle or price manipulationFortress drew prices from the third-party Umbrella Network oracle, whose chain contract exposed a submit function with the caller-verification check commented out, letting any address post an arbitrary price for the FTS token. The attacker first passed a proposal through Fortress's Governor Alpha contract to raise the collateral factor on FTS, then posted an inflated FTS price and borrowed out the market's other assets against a small FTS deposit. |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
Fortress Protocol, also listed as Fortress Loans, was a Compound-fork money market deployed on BNB Chain by the Jetfuel Finance team. It was drained on 8 May 2022. CertiK timestamps the exploit transaction at 20:34 UTC and puts the loss at roughly $2.98 million, made up of 1,048.1 ETH and 400,000 DAI; Fortress and subsequent reporting rounded the figure to $3 million.
The attack chained a governance step to an oracle failure. Fortress did not run its own price feed — it read prices from the Umbrella Network oracle, whose chain contract exposed a submit function with the caller-verification requirement at line 142 commented out. Any address could therefore write an arbitrary price for the protocol's FTS token. The attacker acquired FTS on the open market first — CertiK describes roughly 400,000 FTS bought with about 11 ETH, while The Record cites a purchase of 296,193 FTS for around $8,000 — and used that voting weight to pass a proposal through the Governor Alpha contract raising the collateral factor on FTS. With FTS accepted as collateral and its price freely settable, the attacker supplied FTS, marked it up, and borrowed out the market's remaining assets, converting them to ETH and DAI.
The proceeds were moved to Ethereum over cBridge and Multichain and deposited into Tornado Cash. The attacker's contract self-destructed after execution. Fortress said publicly it had been hit with what it believed was an oracle manipulation attack draining all funds and told users to stop supplying assets; Jetfuel Finance disabled supply and borrow functions until further notice. Umbrella Network acknowledged that the exploit may have stemmed from an error in its price feed and deployed a fix, and PeckShield warned that the same flaw exposed any protocol reading the same oracle. PeckShield and BlockSec published parallel analyses. No recovery or reimbursement was announced and the market did not resume operation. No attacker has been named.
Sources
- CertiKSecondary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Fortress Protocol hack — May 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/fortress-loanshttps://itokenly.com/hacks/fortress-loansPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.