The CTF contract is not exploited, it’s an internal address we use for ops.
POL was being sent to that address because it was in an internal refiller service that checks and refills balances every couple of seconds.
All user funds are safe and the address is being rotated.