CryptoReal
CASE FILE — Sep 16, 2024

Compromised Admin Key Costs DeltaPrime's Arbitrum Deployment $5.98 Million

DeltaPrime Blue's Arbitrum deployment lost $5.98 million on September 16, 2024, after an attacker gained control of the protocol's contract-administration key.

Speculation began circulating quickly that the exploit carried the fingerprints of a nation-state operation, with commentary pointing toward North Korea's Lazarus Group as a possible source — a theory given added weight by remarks from blockchain investigator ZachXBT.

This account draws on analysis from Chaofan Shou, statements from DeltaPrime, a breakdown from Hacken, and observations from ZachXBT.

Per Chaofan Shou, who was among the first to identify the incident, a compromised admin address on Arbitrum was used to upgrade DeltaPrime's proxy contracts to a malicious implementation.

Compromised Admin Address: 0x40E4172e595Fb5B3076dC6d0A1a24d885b881Afb

DeltaPrime's Compromised Proxy Admin Address: 0xd550cfeA0BFFDC81B2dEe7B6d915D9D9e31d83A2

That upgrade let the attacker artificially inflate their own recorded deposit balances across every pool in the protocol. DeltaPrime subsequently acknowledged the loss, confirming that a private key compromise was the root cause.

Hacken's breakdown fills in the sequence: the attacker first obtained 0.19 ETH for gas, routed through Across Protocol.

Funding Transaction: 0xeb034ecfa6b1eaa95bc659883eff8a106fd5d7262da54848525f656597f55d3f

A malicious proxy contract was then deployed.

Malicious Proxy Contract: 0xD4CA224a176A59ed1a346FA86C3e921e01659E73

Within a span of just eight confirmed blocks, five separate proxy contracts were upgraded to point to malicious code.

First Upgrade Transaction: 0x2e6748e92e4f833d3ea3c2aa7d11e74aa502e2cfcab8398dc2056a83a1b7caae

Seconds after those upgrades landed, 2.44 million USDC was withdrawn.

First Withdrawal Transaction: 0x28a9b62fbfc375ebb3f5321d80baac9c2a225a6ec2f140cbfae5bff95fc80b1e

Several DeltaPrime contracts were affected in the process:

DeltaPrimeWrappedETH: 0x0bebeb5679115f143772cfd97359bbcc393d46b3

USDCPoolTUP: 0x8FE3842e0B7472a57f2A2D56cF6bCe08517A1De0

DeltaPrimeArbitrum: 0x2B8C610F3fC6F883817637d15514293565C3d08A

DeltaPrimeBitcoin: 0x5CdE36c23f0909960BA4D6E8713257C6191f8C35

DaiPoolTUP: 0xd5E8f691756c3d7b86FD8A89A06497D38D362540

In total, 57 separate withdrawals were carried out. The proceeds — a mix of USDC, WBTC, and WETH — were entirely converted into ETH. As a final step, the attacker changed the proxy admin on every affected contract.

DeltaPrime maintains that its Avalanche deployment was unaffected, citing protection from multisig wallets and cold storage on that chain — a distinction that offers little consolation to Arbitrum users. The team has said its insurance pool will cover losses "where possible/necessary."

The protocol has undergone multiple audits, though none of that scrutiny could have prevented a leaked private key — a category of failure that sits outside what code audits are designed to catch.

As of this report, the attacker's $5.98 million in proceeds remained untouched.

Adding a further wrinkle, ZachXBT noted: "Idk if related but they were one of the teams with the DPRK IT workers I reached out to warn (was told they were all removed)." Whether this points to Lazarus Group involvement, or another North Korea-linked operation, remains an open question — one that fits into a broader pattern of state-sponsored actors probing DeFi protocols for weak points in key management.

DeltaPrime
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.