$5 980 000 USD

SEPTEMBER 2024

GLOBAL

DELTAPRIME

DESCRIPTION OF EVENTS

"Be The Whale. Your trustless, transparent, prime brokerage on Avalanche and Arbitrum. Deposit and securely earn high APYs. Borrow up to 5x your collateral, explore intuitive investment strategies and unlock your capital's full potential."

 

"Unlock the full potential of your capital with the Prime Account: an empowered, escrow smart contract, just for you."

 

"Traditional lending systems like banks rely on trust and credit checks to ensure loan repayment. When that trust is broken, everyone feels it." "Trustless lending platforms like Aave / Radiant rely on locking high amounts of collateral to ensure loan repayment. This locked liquidity is trapped, harming the chain the platform is in."

 

"Prime Brokerage solutions (read: DeltaPrime) rely on keeping access to borrowed funds to ensure loan repayment. While a borrower can use and profit from their collateral and borrowed funds to use in other DeFi platforms, funds are always accessible by an automated escrow smart contract. This ensures trustless loan repayment, without the need for credit checks."

 

"Idk if related but they were one of the teams with the DPRK IT workers I reached out to warn (was told they were all removed)"

 

"In a dizzying display of greed (or thoroughness, depending on your perspective), a total of 57 withdrawals were executed.

 

The grand finale came with the attacker riding off into the sunrise with their ill-gotten gains.

 

The loot bag? A mix of USDC, WBTC, and WETH – all swiftly swapped to ETH."

 

"At 6:14 AM CET DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M."

 

"ALERT Our system has detected multiple suspicious transactions involving @DeltaPrimeDefi on $ARB chain! (Still ongoing)

 

It seems that admin has lost the private key. Suspicious address still draining the pools! Affected pools so far are the #DPUSDC, #DPARB, #DPBTCb ! Suspicious address already swapped $USDC to $ETH!

 

Total estimated loss is around $4.5M so far! however, suspicious address still draining the pools! Total loss might increase!"

 

"At 6:14 AM CET DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M. This was due to a compromised private key, the source of which is currently under investigation.

 

DeltaPrime Red (Avalanche) is not vulnerable to this attack, as the implementation here is covered solely by multisigs and cold wallets (as it should be)."

 

"The risk is contained, we're working on asset-retrieval and the insurance pool will cover any potential losses where possible / necessary. Additionally, we're looking into other ways to reduce user losses to a minimum."

 

"The risk is contained, we're working on asset-retrieval and the insurance pool will cover any potential losses where possible / necessary. Additionally, we're looking into other ways to reduce user losses to a minimum."

 

"We will keep you updated here as well as in our Discord as we move forward."

DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. Unfortunately it appears that they hired some developers who were actually from North Korea, and this may have resulted in a back door in their systems. This was likely later used to gain access to the private key for their Arbitrum smart contracts. The key was used to upgrade and drain the smart contracts of $5.98m worth of assets. Assets were quickly converted to Ethereum and laundered. The protocol has reported that their insurance fund will cover all losses.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.