<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Polter_Finance_Unaudited_Contract_Price_Manipulation</id>
	<title>Polter Finance Unaudited Contract Price Manipulation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Polter_Finance_Unaudited_Contract_Price_Manipulation"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Polter_Finance_Unaudited_Contract_Price_Manipulation&amp;action=history"/>
	<updated>2026-05-30T07:19:14Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Polter_Finance_Unaudited_Contract_Price_Manipulation&amp;diff=6369&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/polterfinanceunauditedcontractpricemanipulation.php}} {{Unattributed Sources}}  Polter Finance Logo/HomepagePolter Finance is a decentralized non-custodial lending and borrowing platform. On November 16th, the team started an upgrade to their smart contract. However, the new code had not been audited. There was a price manipulation vulnerability due to ge...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Polter_Finance_Unaudited_Contract_Price_Manipulation&amp;diff=6369&amp;oldid=prev"/>
		<updated>2024-12-03T21:15:56Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/polterfinanceunauditedcontractpricemanipulation.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Polterfinance.jpg&quot; title=&quot;File:Polterfinance.jpg&quot;&gt;thumb|Polter Finance Logo/Homepage&lt;/a&gt;Polter Finance is a decentralized non-custodial lending and borrowing platform. On November 16th, the team started an upgrade to their smart contract. However, the new code had not been audited. There was a price manipulation vulnerability due to ge...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/polterfinanceunauditedcontractpricemanipulation.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Polterfinance.jpg|thumb|Polter Finance Logo/Homepage]]Polter Finance is a decentralized non-custodial lending and borrowing platform. On November 16th, the team started an upgrade to their smart contract. However, the new code had not been audited. There was a price manipulation vulnerability due to getting price data from a single oracle trading pair, which could be manipulated. The protocol lasted around 5 hours before it was exploited, and another 8 hours before the team publicly announced that there was an exploit. The team has filed a police report and reached out to the attacker. It's unclear if there is any contingency plan to assist affected users.&amp;lt;ref name=&amp;quot;rektnews-16850&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;polterfinancetwitter-16851&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;polterfinance-16852&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;polter-16853&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-16854&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;polterfinancetwitter-16855&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;polterfinancetwitter-16856&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;solidityscanblog-16857&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certik-16858&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ftmscan-16859&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Polter Finance ==&lt;br /&gt;
&amp;quot;Polter is a decentralized non-custodial lending and borrowing platform where depositors earn a percentage of the interest charged for borrowing.&lt;br /&gt;
&lt;br /&gt;
Since the cessation of the $GEIST platform on Fantom chain, there has been a demand for something similar to be available to the community. $POLTER was created to satisfy this demand using the same smart contract.&lt;br /&gt;
&lt;br /&gt;
Learning an important lesson from the previous protocol, flash-loans will be disabled on Polter. This will help to minimize risks to users of the platform.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Polter Finance Unaudited Contract Price Manipulation&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|November 16th, 2024 6:30:00 AM MST&lt;br /&gt;
|Approximate Smart Contract Deployment&lt;br /&gt;
|The approximate time of the smart contract upgrade deployment.&lt;br /&gt;
|-&lt;br /&gt;
|November 16th, 2024 11:00:00 AM MST&lt;br /&gt;
|Smart Contract Still Running&lt;br /&gt;
|The smart contract is still running at 2:00 AM local time in Singapore.&lt;br /&gt;
|-&lt;br /&gt;
|November 16th, 2024 11:00:30 AM MST&lt;br /&gt;
|Time Of Blockchain Transaction&lt;br /&gt;
|The estimated time of the blockchain transaction.&lt;br /&gt;
|-&lt;br /&gt;
|November 16th, 2024 11:30:00 AM MST&lt;br /&gt;
|Complaints From Users Start&lt;br /&gt;
|Complaints are reported to start being received at 2:30 AM local time in Singapore.&lt;br /&gt;
|-&lt;br /&gt;
|November 16th, 2024 7:16:00 PM MST&lt;br /&gt;
|First Exploit Announcement&lt;br /&gt;
|The first exploit announcement is posted on Twitter, which goes over the pausing of the contract and reaching out to some authorities.&lt;br /&gt;
|-&lt;br /&gt;
|November 17th, 2024 6:07:00 AM MST&lt;br /&gt;
|Police Report Tweet&lt;br /&gt;
|The Polter Finance founder (whichghost) shares a tweet with a filed police report.&lt;br /&gt;
|-&lt;br /&gt;
|November 17th, 2024 7:39:00 AM MST&lt;br /&gt;
|Negotiation With Hacker&lt;br /&gt;
|The team posts an announcement that they have sent a message to negotiate with the hacker.&lt;br /&gt;
|-&lt;br /&gt;
|November 18th, 2024 7:39:00 AM MST&lt;br /&gt;
|No Specific Answers Tweet&lt;br /&gt;
|The team posts an announcement they are working with investigator teams and this includes that they will not be answering specific questions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The root cause of the exploit lies in the incorrect price validation logic within the AaveOracle contract, which Polter Finance relied on. Specifically, the ChainlinkUniV2Adapter contract used for price fetching contained a flaw in its price validation mechanism.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The protocol's critical mistake? Trusting SpookySwap V2/V3 pool prices for their BOO token oracle - about as secure as using a paper lock on a bank vault.&amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attacker initiated a flash loan of 269,042 BOO and 1,154,788 BOO tokens from Spooky V2 and Spooky V3 LPs, respectively. This left a minimal amount of BOO tokens on each liquidity pair, causing a drastic price imbalance.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Using this manipulated spot price, the attacker was able to deposit just 1 BOO token into a Polter lending pool as collateral. Due to a logic flaw in the oracle, the AaveOracle used a flawed price feed that evaluated the 1 BOO token at an inflated value of $1.37 trillion instead of its actual market value.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The ChainlinkUniV2Adapter contract was used to fetch the current price of the BOO token. However, the contract did not have any safeguards in place to check for drastic price fluctuations resulting from the flash loan. The _fetchPrice function, which retrieves the price data, fetched the manipulated, inflated price from the liquidity pools, which led to the incorrect collateral evaluation.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The getRoundData() function, used for retrieving historical price data, also failed to validate significant price changes. It relied on the _getPriceAndTimestamp() function to fetch the price, but this function did not have checks in place to detect drastic price fluctuations, such as those caused by the flash loan manipulation.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;As a result, the manipulated price was not validated before being returned. Additionally, the hardcoded answeredInRound = 2 value in the function did not account for whether the price data was accurate for the current round, further allowing the flawed price to pass unchecked.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The latestRoundData() function, which is supposed to return the most recent price data, was now returning incorrectly inflated prices due to the changes in liquidity caused by the attacker's flash loan. It lacks validation to ensure the retrieved price (answer) is accurate and hasn't been manipulated. It also uses hardcoded values for roundId and answeredInRound, bypassing any dynamic price updates or validation.&lt;br /&gt;
The getRoundData() and latestRoundData() functions were supposed to ensure that the price of BOO tokens was consistent and accurate, but they failed to validate the large price changes resulting from the flash loan. The attacker exploited this flaw by providing a small amount of collateral but receiving an inflated price feed in return.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Additionally, the previousChainlink0Response mechanism, which was supposed to detect whether the price change exceeded a set threshold, failed to do so due to the lack of proper validation. As a result, the inflated price of 1 BOO token passed the oracle's validation checks, leading to the miscalculation of collateral value.&lt;br /&gt;
The attacker continued to borrow wFTM tokens against the inflated collateral. As long as the manipulated price was maintained, they could repeat the borrowing process and drain the liquidity pools without limits. The oracle contract failed to detect these repeat borrowings because the price validation was not functioning properly.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attacker borrowed 9,134,844 wFTM by using the inflated price of the BOO token as collateral, ultimately draining approximately $8.7 million from the Polter Finance lending pools.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $8,700,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;On 19/01/2024, | created a cryptocurrency investing lending platform named “Polter Finance” as well as&lt;br /&gt;
anew cryptocurrency with the same name. This platform links up lender and borrower for them to stake&lt;br /&gt;
the above-mentioned coin for interest. | did not register this company under any countries.&lt;br /&gt;
&lt;br /&gt;
On 16/11/2024, at about 2130hrs, my team and | deployed a smart contract to allow people to borrow an&lt;br /&gt;
existing token. The token name is &amp;quot;Boo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
On 17/11/2024, at about 0200hrs, | made a check on the backend of the website, | saw that there is still&lt;br /&gt;
having an amount of around $16124400.00/- worth of cryptocurrency in the staking pool.&lt;br /&gt;
&lt;br /&gt;
On 17/11/2024, at about 0230hrs, | saw that some of the community members from Discord commented&lt;br /&gt;
that the interest for borrowing money from the platform had spike hence they are unable to borrow any&lt;br /&gt;
cryptocurrency from my platform. This is when | found out that something was amiss.&lt;br /&gt;
&lt;br /&gt;
On 17/11/2024, at about 0300hrs, | checked the transactions of the platform and made a check on the&lt;br /&gt;
account balance. | saw that there's multiple unauthorized transactions being made to various places.&lt;br /&gt;
One of it is to Binance.&lt;br /&gt;
&lt;br /&gt;
Total monetary loss is about $16124400.00/- worth of cryptocurrencies. Most of the cryptocurrencies&lt;br /&gt;
belongs to the lenders of the platform.&lt;br /&gt;
&lt;br /&gt;
My personal monetary loss from the transaction is about $300000/- worth of cryptocurrencies.&lt;br /&gt;
&lt;br /&gt;
| wish to state that I did not provide anyone my login details (private keys) and | believed that my&lt;br /&gt;
platform's newly deployed smart contract has been exploited, hence causing the unauthorized&lt;br /&gt;
transactions.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;We are actively working with @cryptogle @_SEAL_Org @MatchSystems to find resolution to the $POLTER exploit.&lt;br /&gt;
&lt;br /&gt;
Please understand we cannot answer specific questions right now, but will give another announcement as soon as we are able to.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-16850&amp;quot;&amp;gt;[https://rekt.news/polter-finance-rekt/ Rekt - Polter Finance] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;polterfinancetwitter-16851&amp;quot;&amp;gt;[https://twitter.com/polterfinance/status/1858142820785439192 @polterfinance Twitter] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;polterfinance-16852&amp;quot;&amp;gt;[https://polter.finance/ Polter Finance] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;polter-16853&amp;quot;&amp;gt;[https://polter.gitbook.io/polter Overview | Polter] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coingecko-16854&amp;quot;&amp;gt;[https://www.coingecko.com/en/coins/polter-finance https://www.coingecko.com/en/coins/polter-finance] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;polterfinancetwitter-16855&amp;quot;&amp;gt;[https://twitter.com/polterfinance/status/1858520465649840149 @polterfinance Twitter] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;polterfinancetwitter-16856&amp;quot;&amp;gt;[https://twitter.com/polterfinance/status/1858158065264324769 @polterfinance Twitter] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;solidityscanblog-16857&amp;quot;&amp;gt;[https://blog.solidityscan.com/polter-finance-hack-analysis-c5eaa6dcfd40 Polter Finance Hack Analysis. Overview: | by Shashank | Nov, 2024 | SolidityScan] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certik-16858&amp;quot;&amp;gt;[https://www.certik.com/resources/blog/2Y6ZeCCClVIhkBlS4GWKEv-polter-finance-incident-analysis https://www.certik.com/resources/blog/2Y6ZeCCClVIhkBlS4GWKEv-polter-finance-incident-analysis] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ftmscan-16859&amp;quot;&amp;gt;[https://ftmscan.com/tx/0x5118df23e81603a64c7676dd6b6e4f76a57e4267e67507d34b0b26dd9ee10eac Fantom Transaction Hash (Txhash) Details | FTMScan] (Accessed Nov 21, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>