Public Oracle Function and a Rigged Vote Cost Fortress Protocol $3M
Fortress Protocol, the lending platform run under JetFuel Finance on BNB Smart Chain, lost $3 million to an attack that combined a governance takeover with price oracle manipulation, as the project itself confirmed.
The root cause was weak protection around both the protocol's oracle and its governance process, which together allowed the attacker to push through a malicious proposal and distort the price of collateral assets.

Fortress's smart contracts remain functional, but the team has taken the platform's front-end offline while a remediation proposal works its way through governance to address the damage. Whether the protocol can recover from a $3M shortfall remains an open question.
Credit: BlockSecTeam, Certik
01How the exploit worked
The core weakness sat in the price oracle: its submit() function could be called by anyone, with no access restriction in place.
The attacker paired this with a governance proposal that whitelisted FTS, Fortress's native token, as acceptable collateral, setting its collateral factor at 700000000000000000. Once that proposal passed, the attacker needed only 100 FTS — worth roughly $4.50 at pre-attack prices — to post as collateral and drain the protocol's assets entirely.
Financing for the attack came from ETH bridged onto BSC, which had itself been withdrawn from Tornado Cash on Ethereum mainnet. That ETH was then used to acquire a large quantity of FTS — enough both to push the malicious proposal past quorum and to serve as collateral for the exploit itself.
After completing the theft, the attacker routed the proceeds back through Tornado Cash: 1,048 ETH (roughly $2.6 million) along with 400,000 DAI.
Key on-chain references:
- Oracle manipulation transaction: 0x13d19809...
- Attacker's wallet, active on both BSC and Ethereum:
0xA6AF2872176320015f8ddB2ba013B38Cb35d22Ad - Attack funding transaction on BscScan
02Audits and oversight failures
Fortress's own website lists ChainLink as a "collaborator," yet nothing about the oracle design that failed here suggests ChainLink was actually involved in building it.

Two firms audited the codebase — Hash0x and EtherAuthority — both appearing for the first time on this outlet's list of auditors. Neither caught the oracle weakness that ultimately enabled the attack.
Perhaps more notably, the malicious governance proposal sat active for three full days before being acted on — ample time for anyone watching the DAO to flag it as suspicious, yet it went unchallenged.
The episode reinforces a recurring point for DeFi lending markets: governance needs active scrutiny not just from the core team but from the wider user base as well.
Whether the broader JetFuel Finance ecosystem will step in to make affected users whole remains to be seen.
Get new scam files the moment we publish them — usually 2–3 emails a week.