<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DeltaPrime_Unchecked_Smart_Contract_Inputs</id>
	<title>DeltaPrime Unchecked Smart Contract Inputs - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DeltaPrime_Unchecked_Smart_Contract_Inputs"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Unchecked_Smart_Contract_Inputs&amp;action=history"/>
	<updated>2026-05-01T01:29:39Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Unchecked_Smart_Contract_Inputs&amp;diff=6342&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimeuncheckedsmartcontractinputs.php}} {{Unattributed Sources}}  DeltaPrime Logo/HomepageDeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. The project obtained multiple smart contract audits, however evidence was also present that they may have hired developers from North Korea. On N...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DeltaPrime_Unchecked_Smart_Contract_Inputs&amp;diff=6342&amp;oldid=prev"/>
		<updated>2024-11-12T22:36:51Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimeuncheckedsmartcontractinputs.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Deltaprime.jpg&quot; title=&quot;File:Deltaprime.jpg&quot;&gt;thumb|DeltaPrime Logo/Homepage&lt;/a&gt;DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. The project obtained multiple smart contract audits, however evidence was also present that they may have hired developers from North Korea. On N...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/deltaprimeuncheckedsmartcontractinputs.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Deltaprime.jpg|thumb|DeltaPrime Logo/Homepage]]DeltaPrime is a decentralized lending platform which aims to be more capital efficient, but still fully collateralized. The project obtained multiple smart contract audits, however evidence was also present that they may have hired developers from North Korea. On November 11th, an unchecked input drained separate smart contracts on both Arbitrum and Avalanche, leading to a large loss between $4.75m and $4.85m. There were allegations that the DeltaPrime team may have ignored vulnerabilities identified by PeckShield in an audit. However, DeltaPrime refutes this. DeltaPrime has a compensation program which has been underway from their September breach and has not yet announced plans of further compensation to affected users.&amp;lt;ref name=&amp;quot;rektnews-16761&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certikalerttwitter-16762&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16763&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certikalerttwitter-16764&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-16765&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprime-15051&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimedocs-15052&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;rekthqtwitter-16766&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-16767&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About DeltaPrime ==&lt;br /&gt;
&amp;quot;Be The Whale. Your trustless, transparent, prime brokerage on Avalanche and Arbitrum. Deposit and securely earn high APYs. Borrow up to 5x your collateral, explore intuitive investment strategies and unlock your capital's full potential.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Unlock the full potential of your capital with the Prime Account: an empowered, escrow smart contract, just for you.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Traditional lending systems like banks rely on trust and credit checks to ensure loan repayment. When that trust is broken, everyone feels it.&amp;quot; &amp;quot;Trustless lending platforms like Aave / Radiant rely on locking high amounts of collateral to ensure loan repayment. This locked liquidity is trapped, harming the chain the platform is in.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Prime Brokerage solutions (read: DeltaPrime) rely on keeping access to borrowed funds to ensure loan repayment. While a borrower can use and profit from their collateral and borrowed funds to use in other DeFi platforms, funds are always accessible by an automated escrow smart contract. This ensures trustless loan repayment, without the need for credit checks.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;a protocol that promises &amp;quot;Delta-grade security,&amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;an unchecked input validation flaw has cost users another $4.85 million across Arbitrum and Avalanche chains.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - DeltaPrime Unchecked Smart Contract Inputs&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|November 11th, 2024 12:41:06 AM MST&lt;br /&gt;
|Arbitrum Blockchain Exploit Transaction&lt;br /&gt;
|The exploit on the Arbitrum blockchain, worth a total of $750k.&lt;br /&gt;
|-&lt;br /&gt;
|November 11th, 2024 1:39:00 AM MST&lt;br /&gt;
|CertiK Report On Arbitrum&lt;br /&gt;
|CertiK reports a $750k loss via Arbitrum from unchecked smart contract protocol inputs. This has drained &amp;quot;[m]ultiple @DeltaPrimeDefi pools on Arbitrum&amp;quot; &amp;quot;due to vulnerability in the periphery  adaptor contract&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|November 11th, 2024 2:04:00 AM MST&lt;br /&gt;
|DeltaPrime Confirms Breach&lt;br /&gt;
|DeltaPrime posts on X to confirm that they have been breached and provide a total loss estimate of $4.75m. At this time, they have paused both smart contracts and &amp;quot;the risk is contained&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|November 11th, 2024 2:21:00 AM MST&lt;br /&gt;
|CertiK Loss Update Avalanche&lt;br /&gt;
|CertiK responds to update the total loss to $4.75m and report the additional losses via exploiting the Avalanche smart contracts.&lt;br /&gt;
|-&lt;br /&gt;
|November 11th, 2024 3:36:00 PM MST&lt;br /&gt;
|Rekt Investigation Published&lt;br /&gt;
|Rekt publishes an investigation of the exploit, in which they claim that DeltaPrime ignored suggestions to improve the smart contract further.&lt;br /&gt;
|-&lt;br /&gt;
|November 12th, 2024 7:30:00 AM MST&lt;br /&gt;
|DeltaPrime Provides An Update&lt;br /&gt;
|DeltaPrime provides an update on the situation. In this update, they claim that Rekt has misstated them ignoring audit advice, and ask for clarification.&lt;br /&gt;
|-&lt;br /&gt;
|November 12th, 2024 7:46:00 AM MST&lt;br /&gt;
|DeltaPrime Follow Up To Rekt&lt;br /&gt;
|DeltaPrime puts a comment on the Rekt post asking for them to &amp;quot;review [their] statements on this and rectify the article and tweet&amp;quot;.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;Here's a few words on what happened from a non-dev. I'll try to keep it as simple as possible so it's understandable for everyone. This does mean I will have to oversimplify elements. The full post mortem will dive into all details:&lt;br /&gt;
&lt;br /&gt;
• Attacker flashloaned a Lot of WAVAX (and WETH), which was provided as collateral to his Prime Account&lt;br /&gt;
&lt;br /&gt;
• This was used to create large loans, which subsequently were converted to more WAVAX&lt;br /&gt;
&lt;br /&gt;
• A malicious contract was created that mimicked a TJ pair so that when our contracts tried to get the TJ rewarder address for the pair, it actually returned the attacker's malicious contract address&lt;br /&gt;
&lt;br /&gt;
• The ClaimRewards() function was triggered. This function has no solvency check as rewards do not add to solvency of an account (and the check makes transactions significantly more expensive).&lt;br /&gt;
&lt;br /&gt;
• This function took the malicious contract as an argument, allowing the malicious code to be executed mid-transaction&lt;br /&gt;
&lt;br /&gt;
• The malicious code allowed wrapping all AVAX into WAVAX in the middle of the claim() method execution, tricking the PA into believing it was a part of the reward that should be paid out&lt;br /&gt;
&lt;br /&gt;
• All WAVAX was taken out of the PA, leaving the pools with a deficit equal to the max borrowable amount (the loss)&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;Multiple @DeltaPrimeDefi pools on Arbitrum were drained, likely due to vulnerability in the periphery  adaptor contract, resulting a loss of about $750K.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Within minutes, the attacker had drained $750K from Arbitrum – but they were just getting warmed up.&lt;br /&gt;
&lt;br /&gt;
Their next target? The protocol's Avalanche deployment, where another $4.1M would soon vanish. Different chain, same painful lesson.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $4,850,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;DeltaPrime was just exploited on Avalanche and Arbitrum for a total of (initial estimate) $4.75mm.&lt;br /&gt;
&lt;br /&gt;
With the protocol being paused on both chains, the risk is contained. We will provide updates asap.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;There are three elements that must be finished before reopening:&lt;br /&gt;
&lt;br /&gt;
1) Fixing the bug&lt;br /&gt;
2) Resetting interest rates (paused PAs don't pay interest)&lt;br /&gt;
3) preventing first-come-first-serve on the pools&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-16761&amp;quot;&amp;gt;[https://rekt.news/deltaprime-rekt2/ Rekt - DeltaPrime - Rekt II] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certikalerttwitter-16762&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1855893120040497278 @CertiKAlert Twitter] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16763&amp;quot;&amp;gt;[https://arbiscan.io/address/0x56e7f67211683857ee31a1220827cac5cdaa634c https://arbiscan.io/address/0x56e7f67211683857ee31a1220827cac5cdaa634c] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certikalerttwitter-16764&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1855903698259456424 @CertiKAlert Twitter] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-16765&amp;quot;&amp;gt;[https://twitter.com/DeltaPrimeDefi/status/1855899502944903195 @DeltaPrimeDefi Twitter] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprime-15051&amp;quot;&amp;gt;[https://deltaprime.io/ DeltaPrime] (Accessed Aug 20, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimedocs-15052&amp;quot;&amp;gt;[https://docs.deltaprime.io/ Unlock the Blockchain | DeltaPrime] (Accessed Aug 20, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;rekthqtwitter-16766&amp;quot;&amp;gt;[https://twitter.com/RektHQ/status/1856103654467445153 @RektHQ Twitter] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;deltaprimedefitwitter-16767&amp;quot;&amp;gt;[https://twitter.com/DeltaPrimeDefi/status/1856347726407205092 @DeltaPrimeDefi Twitter] (Accessed Nov 12, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>