DeltaPrime Hack
What happened
DeltaPrime Blue's September 2024 exploit drained approximately $6 million from its Arbitrum deployment after an attacker obtained a key controlling contract upgrades. The attacker installed malicious implementations and withdrew deposited assets.
The compromise of a privileged upgrade key let the attacker replace trusted contract logic. The malicious implementations inherited access to assets held by the affected proxies.
Case & protocol details
How it happened
- The attacker obtained access to the private key controlling the proxy upgrade administrator.
- They replaced contract implementations with malicious code.
- The replacement code executed with the existing contracts' access to deposited assets, allowing the attacker to drain them.
- The stolen assets were swapped to ETH.
Security review history
- PeckShield Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference cointelegraph.com
- analysis Explained: The DeltaPrime Hack (September 2024) halborn.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.