Deri Protocol Hack
Incident Overview
Deri Protocol's trading pool on Arbitrum was exploited resulting in a loss of 143,532 $USD.
On October 28th, 2022, an attack took place on Deri Protocol’s trading pool on Arbitrum. The attacker used two associated accounts to execute the exploit. The attacker added margin to these two accounts and gradually established large opposite positions for option BTCUSD-40000-C for both accounts by trading relatively small volumes for each turn. Due to the low margin requirement for far OTM options on Deri Protocol, the attacker repeated this process hundreds of times until they opened a huge long position for account A (notional=100,192 BTC) and a huge short position for account B (notional=-96,940 BTC). With everlasting options’ funding mechanism, Account A continuously paid funding fees to B which pushed up the positive net volume causing higher funding rates making it likely that Account A would get liquidated unless BTC price kept going up. At UTC time 10/28/2022 17:51 when BTC price went down and brought Account A under maintenance margin it got liquidated causing massive sell notional=100,192.4024 $BTC which dragged mark price below zero leading to a loss of around $144k USD but only lost original balance as opposed to full loss due bound by margin balance.
Immediately after liquidation of A; the attacker closed out short position in B resulting in large profits for 144,532 $USDC.
The pool ended up with a net loss since although theoretically B’s profit came from A’s loss but since losses were bound by margin balances and could not be fully realized thus resulted in negative PnL.
Attacker addresses:
https://arbiscan.io/address/0x09ca8053…1e228d
https://arbiscan.io/address/0x2443506117e03136727E394F85B5b0797A3E0477_
Malicious Transaction:
https://arbiscan.io/tx/0xc31ade49…7bc93d
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Deri Protocol, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next Deri Protocol
The Deri Protocol hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.