Polter Finance hack — November 2024
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | November 17, 2024 |
| Target type | Lending protocol |
| Loss | $8,700,000Published estimates range $7,000,000 to $12,000,000Price at time of incident |
| Method | Oracle or price manipulationPolter priced the BOO token through a ChainlinkUniV2Adapter contract that derived value from the reserve ratio of a SpookySwap Uniswap-V2-style pool, with no guard against sudden movement. The attacker flash-borrowed BOO from SpookySwap V2 and V3 pools to empty the reserves the adapter read, which made the adapter value a single BOO at roughly $1.37 trillion, then deposited one BOO as collateral and borrowed 9,134,844 wFTM against it before repaying the flash loan. |
| Chains | Fantom |
| Outcome | Project shut down |
What happened
Polter Finance, an unaudited fork of the Geist lending protocol running on Fantom, was drained on 16 November 2024, with the loss surfacing publicly early on Sunday 17 November. The protocol priced BOO, SpookySwap's token, through a ChainlinkUniV2Adapter contract that derived a value from the spot state of a SpookySwap Uniswap-V2-style pool rather than an independent feed, and had no check for sudden price movement.
The attacker flash-borrowed BOO from SpookySwap's V2 and V3 pools — 269,042 and 1,154,788 BOO respectively, by Three Sigma's account — emptying the reserves the adapter read. With the pool nearly drained, the oracle valued a single BOO at roughly $1.37 trillion. The attacker deposited one BOO as collateral, borrowed against it, and took 9,134,844 wFTM out of the lending pools before repaying the flash loan.
The dollar size of the loss is contested, but the divergence is a valuation-date artefact rather than a disagreement about what was taken: the quantity, 9,134,844 wFTM, is undisputed. Priced at the time of the attack, SolidityScan and Halborn both put the loss at approximately $8.7 million, and Decrypt reported that security firms had arrived at roughly $7 million. Three Sigma, and the founder's Singapore police report citing about S$16.1 million, both give approximately $12 million, which corresponds to a materially higher FTM price than prevailed on 16 November. This entry records the at-incident valuation of $8.7 million as the headline figure, with $7 million and $12 million as the bounds of the reported range. Decrypt separately reported the pseudonymous founder's own losses at $223,219.
Polter had not commissioned its own audit, relying instead on the audit of Geist Finance, the protocol it forked — Halborn notes the team "didn't perform a security audit of their protocol, instead providing a copy of the one from the Geist contract to its users". The team paused the protocol and made an on-chain appeal to the attacker seeking a negotiated bounty. There was no response and the funds were not recovered.
Law enforcement
Polter's founder filed a police report in Singapore stating losses of about S$16.1 million (roughly $12 million). The team worked with SEAL-ISAC to trace the attacker. No arrests or charges have been reported.
Sources
- DecryptSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Three SigmaSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Polter Finance hack — November 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/polter-financehttps://itokenly.com/hacks/polter-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.