QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$4 850 000 USD
NOVEMBER 2024
GLOBAL
DELTAPRIME
DESCRIPTION OF EVENTS
"Be The Whale. Your trustless, transparent, prime brokerage on Avalanche and Arbitrum. Deposit and securely earn high APYs. Borrow up to 5x your collateral, explore intuitive investment strategies and unlock your capital's full potential."
"Unlock the full potential of your capital with the Prime Account: an empowered, escrow smart contract, just for you."
"Traditional lending systems like banks rely on trust and credit checks to ensure loan repayment. When that trust is broken, everyone feels it." "Trustless lending platforms like Aave / Radiant rely on locking high amounts of collateral to ensure loan repayment. This locked liquidity is trapped, harming the chain the platform is in."
"Prime Brokerage solutions (read: DeltaPrime) rely on keeping access to borrowed funds to ensure loan repayment. While a borrower can use and profit from their collateral and borrowed funds to use in other DeFi platforms, funds are always accessible by an automated escrow smart contract. This ensures trustless loan repayment, without the need for credit checks."
"a protocol that promises "Delta-grade security,""
"Here's a few words on what happened from a non-dev. I'll try to keep it as simple as possible so it's understandable for everyone. This does mean I will have to oversimplify elements. The full post mortem will dive into all details:
• Attacker flashloaned a Lot of WAVAX (and WETH), which was provided as collateral to his Prime Account
• This was used to create large loans, which subsequently were converted to more WAVAX
• A malicious contract was created that mimicked a TJ pair so that when our contracts tried to get the TJ rewarder address for the pair, it actually returned the attacker's malicious contract address
• The ClaimRewards() function was triggered. This function has no solvency check as rewards do not add to solvency of an account (and the check makes transactions significantly more expensive).
• This function took the malicious contract as an argument, allowing the malicious code to be executed mid-transaction
• The malicious code allowed wrapping all AVAX into WAVAX in the middle of the claim() method execution, tricking the PA into believing it was a part of the reward that should be paid out
• All WAVAX was taken out of the PA, leaving the pools with a deficit equal to the max borrowable amount (the loss)"
"Multiple @DeltaPrimeDefi pools on Arbitrum were drained, likely due to vulnerability in the periphery adaptor contract, resulting a loss of about $750K."
"Within minutes, the attacker had drained $750K from Arbitrum – but they were just getting warmed up.
Their next target? The protocol's Avalanche deployment, where another $4.1M would soon vanish. Different chain, same painful lesson."
"DeltaPrime was just exploited on Avalanche and Arbitrum for a total of (initial estimate) $4.75mm.
With the protocol being paused on both chains, the risk is contained. We will provide updates asap."
"There are three elements that must be finished before reopening:
1) Fixing the bug 2) Resetting interest rates (paused PAs don't pay interest) 3) preventing first-come-first-serve on the pools"
DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. The project obtained multiple smart contract audits, however evidence was also present that they may have hired developers from North Korea. On November 11th, an unchecked input drained separate smart contracts on both Arbitrum and Avalanche, leading to a large loss between $4.75m and $4.85m. There were allegations that the DeltaPrime team may have ignored vulnerabilities identified by PeckShield in an audit. However, DeltaPrime refutes this. DeltaPrime has a compensation program which has been underway from their September breach and has not yet announced plans of further compensation to affected users.
Rekt - DeltaPrime - Rekt II (Nov 12)
@CertiKAlert Twitter (Nov 12)
https://arbiscan.io/address/0x56e7f67211683857ee31a1220827cac5cdaa634c (Nov 12)
@CertiKAlert Twitter (Nov 12)
@DeltaPrimeDefi Twitter (Nov 12)
DeltaPrime (Aug 20)
Unlock the Blockchain | DeltaPrime (Aug 20)
@RektHQ Twitter (Nov 12)
@DeltaPrimeDefi Twitter (Nov 12)