<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DeltaPrime_Arbitrum_Private_Key_Leaked</id>
	<title>DeltaPrime Arbitrum Private Key Leaked - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DeltaPrime_Arbitrum_Private_Key_Leaked"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Arbitrum_Private_Key_Leaked&amp;action=history"/>
	<updated>2026-05-30T05:23:01Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Arbitrum_Private_Key_Leaked&amp;diff=5962&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimearbitrumprivatekeyleaked.php}} {{Unattributed Sources}}  DeltaPrime Logo/HomepageDeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. Unfortunately it appears that they hired some developers who were actually from North Korea, and this may have resulted in a back door in their syste...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Arbitrum_Private_Key_Leaked&amp;diff=5962&amp;oldid=prev"/>
		<updated>2024-09-17T17:20:42Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimearbitrumprivatekeyleaked.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Deltaprime.jpg&quot; title=&quot;File:Deltaprime.jpg&quot;&gt;thumb|DeltaPrime Logo/Homepage&lt;/a&gt;DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. Unfortunately it appears that they hired some developers who were actually from North Korea, and this may have resulted in a back door in their syste...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimearbitrumprivatekeyleaked.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Deltaprime.jpg|thumb|DeltaPrime Logo/Homepage]]DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. Unfortunately it appears that they hired some developers who were actually from North Korea, and this may have resulted in a back door in their systems. This was likely later used to gain access to the private key for their Arbitrum smart contracts. The key was used to upgrade and drain the smart contracts of $5.98m worth of assets. Assets were quickly converted to Ethereum and laundered. The protocol has reported that their insurance fund will cover all losses.&amp;lt;ref name=&amp;quot;rektnews-15438&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-15439&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-15440&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-15441&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-15442&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;hackenclubtwitter-15443&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimelabsgithub-15444&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cyversalertstwitter-15445&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zachxbttwitter-15446&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zachxbttwitter-15447&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;shoucccctwitter-15448&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ruggedbyphonetwitter-15449&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprime-15051&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimedocs-15052&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About DeltaPrime ==&lt;br /&gt;
&amp;quot;Be The Whale. Your trustless, transparent, prime brokerage on Avalanche and Arbitrum. Deposit and securely earn high APYs. Borrow up to 5x your collateral, explore intuitive investment strategies and unlock your capital's full potential.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Unlock the full potential of your capital with the Prime Account: an empowered, escrow smart contract, just for you.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Traditional lending systems like banks rely on trust and credit checks to ensure loan repayment. When that trust is broken, everyone feels it.&amp;quot; &amp;quot;Trustless lending platforms like Aave / Radiant rely on locking high amounts of collateral to ensure loan repayment. This locked liquidity is trapped, harming the chain the platform is in.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Prime Brokerage solutions (read: DeltaPrime) rely on keeping access to borrowed funds to ensure loan repayment. While a borrower can use and profit from their collateral and borrowed funds to use in other DeFi platforms, funds are always accessible by an automated escrow smart contract. This ensures trustless loan repayment, without the need for credit checks.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
&amp;quot;Idk if related but they were one of the teams with the DPRK IT workers I reached out to warn (was told they were all removed)&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M.&amp;quot; &amp;quot;a total of 57 withdrawals were executed.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - DeltaPrime Arbitrum Private Key Leaked&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|August 15th, 2024 5:36:00 AM MDT&lt;br /&gt;
|ZachXBT Notes DPRK Developers&lt;br /&gt;
|ZachXBT posts a list of fake DPRK developers which have been working at different projects, including one which is drained for $1.3m from their treasury.&lt;br /&gt;
|-&lt;br /&gt;
|September 15th, 2024 10:02:46 PM MDT&lt;br /&gt;
|Gas Funding Transaction&lt;br /&gt;
|The malicious actor funs their account with 0.19 ETH to be used in the attack.&lt;br /&gt;
|-&lt;br /&gt;
|September 15th, 2024 10:14:02 PM MDT&lt;br /&gt;
|First Malicious Contract Upgrade&lt;br /&gt;
|The very first transaction happens to upgrade a smart contract.&lt;br /&gt;
|-&lt;br /&gt;
|September 15th, 2024 10:14:08 PM MDT&lt;br /&gt;
|First Malicious Withdrawal&lt;br /&gt;
|Barely seconds later, withdrawal from the first smart contract would start.&lt;br /&gt;
|-&lt;br /&gt;
|September 15th, 2024 11:41:00 PM MDT&lt;br /&gt;
|Chaofan Shou Tweet&lt;br /&gt;
|Chaofan Shou tweets, reporting that all pools are drained because the &amp;quot;admin private key leaked&amp;quot; and the loss amount is $7m so far.&lt;br /&gt;
|-&lt;br /&gt;
|September 16th, 2024 12:15:00 AM MDT&lt;br /&gt;
|ZachXBT Notes DPRK Involvement&lt;br /&gt;
|ZachXBT notes that the DeltaPrime project was on his list of projects which had hired fake DPRK workers.&lt;br /&gt;
|-&lt;br /&gt;
|September 16th, 2024 12:32:56 AM MDT&lt;br /&gt;
|Proxy Admin Change Over&lt;br /&gt;
|The Proxy Admin is changed for all smart contract involved, removing the ability for further modifications to be made.&lt;br /&gt;
|-&lt;br /&gt;
|September 16th, 2024 12:36:00 AM MDT&lt;br /&gt;
|Cyvers Alert Posted&lt;br /&gt;
|The Cyvers team posts an alert of the DeltaPrime smart contracts, correctly noting the incident is caused by a leaked private key. Total losses at this point are announced to be $4.5m, and the Cyvers team notes the potential for this total to increase.&lt;br /&gt;
|-&lt;br /&gt;
|September 16th, 2024 2:55:00 AM MDT&lt;br /&gt;
|Announcement Of Breach&lt;br /&gt;
|An announcement is posted on Twitter to highlight the breached private key. Accordingly, the Arbitrum version of the smart contract was drainged for $5.98m, while the Avalanche version was not.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;In a dizzying display of greed (or thoroughness, depending on your perspective), a total of 57 withdrawals were executed.&lt;br /&gt;
&lt;br /&gt;
The grand finale came with the attacker riding off into the sunrise with their ill-gotten gains.&lt;br /&gt;
&lt;br /&gt;
The loot bag? A mix of USDC, WBTC, and WETH – all swiftly swapped to ETH.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;At 6:14 AM CET DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $5,980,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&lt;br /&gt;
&amp;quot;ALERT Our system has detected multiple suspicious transactions involving @DeltaPrimeDefi on $ARB chain! (Still ongoing)&lt;br /&gt;
&lt;br /&gt;
It seems that admin has lost the private key. Suspicious address still draining the pools! Affected pools so far are the #DPUSDC, #DPARB, #DPBTCb ! Suspicious address already swapped $USDC to $ETH!&lt;br /&gt;
&lt;br /&gt;
Total estimated loss is around $4.5M so far! however, suspicious address still draining the pools! Total loss might increase!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;At 6:14 AM CET DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M. This was due to a compromised private key, the source of which is currently under investigation. &lt;br /&gt;
&lt;br /&gt;
DeltaPrime Red (Avalanche) is not vulnerable to this attack, as the implementation here is covered solely by multisigs and cold wallets (as it should be).&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;The risk is contained, we're working on asset-retrieval and the insurance pool will cover any potential losses where possible / necessary. Additionally, we're looking into other ways to reduce user losses to a minimum.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
&amp;quot;The risk is contained, we're working on asset-retrieval and the insurance pool will cover any potential losses where possible / necessary. Additionally, we're looking into other ways to reduce user losses to a minimum.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
&amp;quot;We will keep you updated here as well as in our Discord as we move forward.&amp;quot;&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-15438&amp;quot;&amp;gt;[https://rekt.news/deltaprime-rekt/ Rekt - DeltaPrime - Rekt] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-15439&amp;quot;&amp;gt;[https://twitter.com/DeltaPrimeDefi/status/1835603279369125893 @DeltaPrimeDefi Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-15440&amp;quot;&amp;gt;[https://arbiscan.io/tx/0xeb034ecfa6b1eaa95bc659883eff8a106fd5d7262da54848525f656597f55d3f Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-15441&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x2e6748e92e4f833d3ea3c2aa7d11e74aa502e2cfcab8398dc2056a83a1b7caae Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-15442&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x28a9b62fbfc375ebb3f5321d80baac9c2a225a6ec2f140cbfae5bff95fc80b1e Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;hackenclubtwitter-15443&amp;quot;&amp;gt;[https://twitter.com/hackenclub/status/1835582831952597270 @hackenclub Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimelabsgithub-15444&amp;quot;&amp;gt;[https://github.com/DeltaPrimeLabs/deltaprime-primeloans/tree/dev/main/audits deltaprime-primeloans/audits at dev/main · DeltaPrimeLabs/deltaprime-primeloans · GitHub] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cyversalertstwitter-15445&amp;quot;&amp;gt;[https://twitter.com/CyversAlerts/status/1835568466901766208 @CyversAlerts Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zachxbttwitter-15446&amp;quot;&amp;gt;[https://twitter.com/zachxbt/status/1824047425822310580 @zachxbt Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zachxbttwitter-15447&amp;quot;&amp;gt;[https://twitter.com/zachxbt/status/1835563015694917831 @zachxbt Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;shoucccctwitter-15448&amp;quot;&amp;gt;[https://twitter.com/shoucccc/status/1835554652777336975 @shoucccc Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ruggedbyphonetwitter-15449&amp;quot;&amp;gt;[https://twitter.com/RuggedByPhone/status/1835647703910343057 @RuggedByPhone Twitter] (Accessed Sep 17, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprime-15051&amp;quot;&amp;gt;[https://deltaprime.io/ DeltaPrime] (Accessed Aug 20, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimedocs-15052&amp;quot;&amp;gt;[https://docs.deltaprime.io/ Unlock the Blockchain | DeltaPrime] (Accessed Aug 20, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>