CryptoReal
CASE FILE — Nov 18, 2024

Fork of Geist Lending Code Costs Polter Finance $8.7M in Oracle Exploit

Polter Finance, a lending protocol running on Fantom, lost approximately $8.7 million after an attacker manipulated the price feed used by its freshly launched BOO market. The protocol had never been independently audited, and the incident illustrates the risk of relying on a forked codebase without adapting its security assumptions.

01How the market was flagged

The first public sign of trouble came from researcher BcPaintball, who flagged unusual activity on the new BOO market shortly after it went live. Polter's own team took roughly seven hours to publicly confirm what outside observers had already noticed.

Two independent analyses followed. William Li initially suspected a rounding error tied to an "empty market," but subsequent digging pointed to a more fundamental flaw in the oracle design. Nick Franklin's write-up confirmed the root cause: classic oracle manipulation, not a rounding quirk.

02The mechanism

Polter's BOO market priced its collateral using spot values pulled directly from SpookySwap V2/V3 liquidity pools — a design that leaves the oracle exposed to any actor able to move the pool price temporarily. The attacker used a flash loan to drain BOO token reserves from the pool, distorting the spot price the lending market relied on. With the price artificially inflated, a single BOO deposit was enough to be treated as valuable collateral, letting the attacker borrow far more than the deposit was actually worth.

Exploiter address: 0x511f427Cdf0c4e463655856db382E05D79Ac44a6

Exploiter contract: 0xA21451aC32372C123191B3a4FC01deB69F91533a

Fund flow: traced on MetaSleuth

Sums referenced in this case file

03The response

Within hours of the roughly $8.7 million loss, Polter paused the platform, notified bridge operators, and said it had traced the attacker's wallet to a Binance-linked address — although on-chain data suggested the funds were already moving elsewhere by that point. The team also stated it planned to contact law enforcement.

Polter's crisis communication read: "Platform paused soon after the exploit was identified. Bridges were notified. We identified wallets involved and traced it to Binance."

The team also attempted on-chain contact with the attacker, a negotiation tactic that has become standard following DeFi exploits.

Separately, Polter is reported to have filed a police report citing $12 million in losses — a figure noticeably higher than the roughly $8.7 million tracked on-chain.

04No audit, borrowed assurance

Polter never commissioned an independent security audit. Its own audit page states: "As the smart contract used is identical to Geist, except for the removal of the flash-loan function in Lending Pool, we are providing the Geist audit report here" — leaning on a review conducted for a different, earlier protocol rather than for its own modified code.

That substitution matters: removing one function from a forked codebase changes its risk profile, and an audit written for the original contract cannot vouch for the altered version. The oracle design that enabled this exploit was apparently never reviewed by anyone outside the team.

05Takeaway

The exploit adds Polter Finance to the long list of protocols that inherited code from an established project without inheriting — or independently verifying — its security guarantees. Spot-price oracles sourced from a single DEX pool remain a well-documented attack vector, and flash-loan-funded price manipulation of exactly this kind has been demonstrated repeatedly across DeFi. The gap between the $8.7 million actually lost and the $12 million reported to authorities has also drawn scrutiny, raising questions about the accuracy of the team's public accounting following the incident.

Credit: whichghost, BcPaintball, Polter Finance, William Li, Nick Franklin

Polter Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.