CryptoReal
CASE FILE — Nov 11, 2024

DeltaPrime Breached Again as Input Validation Flaw Costs $4.85M Across Two Chains

Barely two months after a $6 million private-key compromise, DeltaPrime was hit by a second major security failure on November 11, 2024. This time, an unchecked input validation flaw drained a combined $4.85 million from the protocol's Arbitrum and Avalanche deployments.

This account draws on incident analysis from Certik and statements from DeltaPrime.

CertiK first identified the issue after several Arbitrum pools began losing funds due to a critical vulnerability in the protocol's periphery adaptor contract. Within minutes, around $750,000 had been pulled from Arbitrum.

The attacker then turned to DeltaPrime's Avalanche deployment, where roughly $4.1 million more was extracted using the same underlying weakness.

DeltaPrime moved quickly to confirm that the exploit had occurred. According to CertiK's detailed writeup, the attack combined two distinct vulnerabilities.

On Arbitrum, the attack began with a flash loan.

Attacker Address on Arbitrum: 0xb87881637b5c8e6885c51ab7d895e53fa7d7c567

A flash loan of 59.9 ETH was supplied to DeltaPrime, and 1.18 WBTC was borrowed against it and routed through a swap adapter to an attack contract.

Attack Contract on Arbitrum: 0x52ee5c0ea2e7b38d4b24c09d4d18cba6c293200e

By exploiting an arbitrary-input weakness in DeltaPrime's reward mechanism, the attacker reclaimed their ETH collateral.

First Blood on Arbitrum: 0x9efe855cd3783462207ff8a3d94dc17a74e2b2f00bf1b4c8a7e0135dae83ab5c

The stolen funds were initially routed into the same contract before being split further:

Sums referenced in this case file

0x52EE5c0eA2E7b38D4B24c09D4d18cba6C293200e

On Arbitrum, the $753K taken was divided three ways: 49.91 ETH sent to 0x56e7f67211683857EE31a1220827cac5cdaa634C, 16.62 ETH sent to 0x101723dEf8695f5bb8D5d4AA70869c10b5Ff6340, and 2.96 WBTC bridged to Ethereum via transaction 0x21032a57bb6cfed765b7b5543fe00a3831b1325dacd3c42b6e98db033da8f5da.

The attacker then shifted focus to Avalanche, where the same flaw yielded nearly six times the Arbitrum haul.

Attacker Addresses on Avalanche: 0xd5381c683191EB0999a51567274abAB73a9Df0AD and 0xd3d535141831f6bd8b7df92e2ae0463d60af2413

The same periphery adaptor contract flaw was exploited on Avalanche, resulting in another $4.1 million being extracted.

First Avalanche Strike: 0xece4efbe11e59d457cb1359ebdc4efdffdd310f0a82440be03591f2e27d2b59e

Rather than immediately cashing out, the attacker put the Avalanche proceeds to work generating yield:

  • $600K of USDC staked through Stargate
  • $518K of USDC/USDT supplied as liquidity on LFJ
  • 4,865 AVAX held
  • 49.68 WETH.e held
  • 6.34 BTC.b held

Stolen Funds on Avalanche: 0xd5381c683191EB0999a51567274abAB73a9Df0AD held 465.35 AVAX, and 0xd3d535141831F6Bd8B7DF92E2AE0463D60Af2413 held 69,401 AVAX.

Rather than the typical pattern of mixing and rapidly moving stolen assets, the attacker instead built out staking and liquidity positions with the funds, deploying them into yield-bearing protocols in public.

Notably, both vulnerabilities exploited — issues around admin key handling and input validation — had already been flagged in two separate PeckShield audits of DeltaPrime's codebase. Despite these two rounds of warnings, the protocol continued to rely on a single externally owned account for critical administrative functions rather than the multi-signature setup the audits had recommended.

Peckshield Audit 1

Peckshield Audit 2

This marks the protocol's second exploit within roughly sixty days, with the attacker's decision to farm yield on the stolen funds in public rather than immediately liquidate them standing out as an unusual feature of the case.

DeltaPrime
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.