QI Quadriga Initiative

Nov 2021 - Ploutoz Finance Oracle Attack - $365k (Global)

"Ploutoz is an automated money market platform which provide 100% decentralized finance-based lending services in Binance Smart Chain." "Ploutoz allows users to efficiently lending crypto assets on the Binance Smart Chain."

"Ploutoz enables users to utilize their cryptocurrencies by as a lender, supplying collateral to the
network for supporting borrower by pledging over-collateralized asset."

"Ploutoz passed [a] smart contact audit from ThaiShield by ThaiChain."

"Ploutoz Finance, the BSC loan agreement, was attacked by a flash loan attack." On November 23rd, "Ploutoz finance was exploited and it led to the gain of ~$365K for the hacker."

"The hack was made possible due to the price oracle manipulation of DOP in Ploutoz finance." "The hacker manipulated the oracle price of DOP tokens and used the manipulated DOP as collateral to borrow other assets, including CAKE, ETH, BTCB, etc." "Specifically, the hacker leverages the manipulated DOP as collateral to borrow other assets, including CAKE, ETH, BTCB, etc."

"The attacker, who remains unknown, was able to drain the liquidity pools by way of a flash loan attack. A flash loan attack is when an attacker takes out a loan from one DeFi platform or service provider and uses the borrowed money to interact with smart contracts in a way that manipulates prices of DeFi tokens in their favor so that they can subsequently drain a project’s liquidity pool at prices favorable to them."

"The initial funds to launch the hack were withdrawn from TornadoCash. The resulting gains are swapped via paraswap and PancakeSwap, then washed via TornadoCash."

Further Analysis

Ploutoz Finance is an audited decentralized lending platform on the Binance Smart Chain. Despite their audit, the protocol's smart contract hot wallet was still vulnerable to an oracle price exploit through a flash loan. $365k of funds were taken. There is no evidence of any funds being returned.

How Could This Have Been Prevented?

More Cryptocurrency Exchange Hacks/Scams/Frauds

SnowDog DAO Liquidity Blocked > > < < Ribbon Finance Accounting Bug

Sources/Further Reading

https://blog.insurace.io/security-incidents-in-november-e4bcb39dd7f9 (Feb 1)
Ploutoz Finance Exploited Using A Price Oracle Manipulation Hack | CoinCodeCap (Feb 9)
https://www.ploutoz.finance/dashboard (Feb 10)
https://www.ploutoz.finance/publish/whitepaper-ver.1.0.pdf (Feb 10)
Ploutoz Finance Official (@ploutozfinance) | Twitter (Feb 10)
@ploutozfinance Twitter (Feb 10)
@peckshield Twitter (Feb 10)
https://bscscan.com/tx/0x7fe46c2746855dd57e18f4d33522849ff192e4e26c74835799ba8dab89099457 (Feb 10)
Ploutoz Finance 2.0( PTZ ) info, Ploutoz Finance 2.0( PTZ ) chart, market cap, and price | TheBitTimes.Com (Feb 10)
ploutoz-finance/POracle.sol at main · PTZFinance/ploutoz-finance · GitHub (Feb 10)
Ploutoz Finance Exploited using a Price Oracle Manipulation Hack : coincodecap (Feb 10)
Ploutoz Finance was attacked, hackers made a profit of 365,000 US dollars - Aliens: AI Crypto News & Markets Updates (Feb 10)
Gaurav Agrawal on LinkedIn: Ploutoz Finance Exploited using a Price Oracle Manipulation Hack (Feb 10)
DEFIYIELD - DeFi Investing & Yield Farming Platform (Feb 10)
PLOUTOZ (PLO) price, exchanges, chart - marketcap.one (Feb 10)


Join Us!

Name: Email:

t.me/QuadrigaInitiative /r/QuadrigaInitiative @QuadrigaInit info@quadrigainitiative.com

Sign-Ups: 100%

Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected User. For questions or enquiries, email info@quadrigainitiative.com.