Post Mortem: Fintoch

Research Incident Analysis
Post Mortem: Fintoch

Project name: Fintoch

Project type: Token

Date of exploit: May 5th, 2023

Asset loss: ~$31.6M

Vulnerability: Rug Pull

Date of audit report publishing: Dec 15th, 2022

Conclusion: Out of audit scope

Details of the Exploit

Background

Fintoch is a SCAM token

Nature of the Vulnerability

It was a SCAM that cheated users into buying FTH tokens with BSC-USD (a stablecoin pegged at 1 USD). Finally, it dumped FTH tokens minted during deployment to drain ~31.6M BSC-USD in the pool.

CertiK Audit Overview

Screenshot 2024-01-11 at 8.59.24 PM

Conclusion

On May 5th, 2023, the Fintoch was rugpulled, leading to a loss of ~$31.6M.

CertiK Audited the pool and lending product of the Fintoch. However, the exploit was due to the vulnerability in the token product (i.e., FTH token), which is a different product from what CertiK has audited. Therefore, it is out of the audit scope.

Related Blogs

Post Mortem: Thoreum Finance

Post Mortem: Thoreum Finance

On Jan 18, 2023, Thoreum Finance's token contract v4 was exploited, leading to a loss of around 2,260 WBNB. The attacker took advantage of the flawed implementation in the token contract's transfer function and manipulated its balance.

Post Mortem:  TerraPort Finance

Post Mortem: TerraPort Finance

On April 10th, 2023, the Terraport project team was alarmed breach detected with the Terraport Liquidity wallet. The total loss is around $4M.

Post Mortem: Telcoin

Post Mortem: Telcoin

​​On Dec 26th, 2023, Telcoin experienced a loss of ~$1.25M attack. The vulnerable contract is due to a vulnerability in the proxy implementation of wallet contracts, which is a different application from what CertiK has audited.