Ola Finance hack — March 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 31, 2022 |
| Target type | Lending protocol |
| Loss | $4,670,000Published estimates range $3,600,000 to $4,700,000Price at time of incident |
| Method | ReentrancyRe-entrancy through the ERC677 token-transfer callback in Ola's Compound-fork lending markets: the callback fired during a borrow transfer let the attacker move collateral out before the borrow balance was written to storage, so collateral could be redeemed while the borrowed assets were retained. |
| Chains | Other |
| Outcome | Users reimbursed |
What happened
Ola Finance supplied white-label lending-network infrastructure to other projects. The affected deployment was the Voltage Finance lending network on Fuse, an EVM-compatible chain. At about 05:00 (UTC+3) on 31 March 2022 an attacker exploited a re-entrancy flaw in the way Ola's markets handled ERC677 token transfers. ERC677 transfers invoke a callback on the receiving contract; the attacker borrowed against collateral and, inside the callback triggered during the borrow, moved the collateral out before the borrow balance was written to storage, then redeemed the collateral while keeping the borrowed assets. The first pass was seeded with a 515 WETH flash loan from the WETH-WBTC pair on Voltage, and later passes recycled the proceeds across several markets.
Ola's post-mortem itemised the loss as 216,964.18 USDC, 507,216.68 BUSD, 200,000 fUSD, 550.45 WETH, 26.25 WBTC and 1,240,000 FUSE, worth about $4.67 million, and CoinDesk reported the same itemised figure as $4.7 million on 1 April. First-day coverage on 31 March, based on PeckShield's early read, reported $3.6 million. The higher figure comes from the affected teams' own accounting published the following day and supersedes the early estimate, but both are in circulation.
Ola paused borrowing across its lending networks and temporarily disabled borrowing and lending on Fuse. It said it would publish a report confirming that the attack could not be replicated on its other lending networks, and that it would approach the attacker to negotiate a return of the funds in exchange for a bounty. No return was reported. The post-mortem lists attacker addresses on Ethereum and BNB Chain.
On 8 April 2022 Ola, Voltage and the Fuse Foundation published a joint compensation plan, paid out in proportion to each victim's share of the total loss: 250,000 USDC and 1 million FUSE distributed over a year from the Fuse Foundation, 250,000 USDC and 40 million VOLT distributed over a year from Voltage, and 400,000 of Ola's future token distributed over a year, with an option to convert immediately to USDC at one dollar per token up to a cap of $200,000. The package covered only part of the loss.
Sources
- Ola FinancePrimary · retrieved 2026-08-01
- Ola Finance / Voltage / Fuse FoundationPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
Official post-mortem: https://ola-finance.medium.com/ola-and-voltage-lending-exploit-on-fuse-post-mortem-214c13d88443
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ola Finance hack — March 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ola-financehttps://itokenly.com/hacks/ola-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.