DeltaPrime Hack

REPORTED LOSS $6.0M
Medium Private Key Compromised (Unknown Method) arbitrum

What happened

DeltaPrime Blue's September 2024 exploit drained approximately $6 million from its Arbitrum deployment after an attacker obtained a key controlling contract upgrades. The attacker installed malicious implementations and withdrew deposited assets.

Technical Root Cause

The compromise of a privileged upgrade key let the attacker replace trusted contract logic. The malicious implementations inherited access to assets held by the affected proxies.

Case & protocol details

Classification Protocol Logic / Yield Aggregator / Key Compromise
Protocol Type Leveraged Farming
Implementation language Solidity
Official Website deltaprime.io/
Protocol Twitter/X @DeltaPrimeDefi

How it happened

  1. The attacker obtained access to the private key controlling the proxy upgrade administrator.
  2. They replaced contract implementations with malicious code.
  3. The replacement code executed with the existing contracts' access to deposited assets, allowing the attacker to drain them.
  4. The stolen assets were swapped to ETH.

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.