T
iTokenly

DeltaPrime hack — September 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 16, 2024
Target typeLending protocol
Loss$5,980,000Published estimates range $5,980,000 to $6,050,000Price at time of incident
MethodPrivate key compromiseThe private key of an externally owned account that still held proxy-admin rights over DeltaPrime's DepositIndex contracts on Arbitrum was compromised. The team said those index contracts had never been migrated from their deployment EOAs to a multisig. The attacker upgraded the proxies to a malicious implementation, minted deposit receipt tokens (dpUSDC, dpARB, dpBTCb, dpWETH) in arbitrary quantities, and redeemed them against the savings pools.
ChainsArbitrum
OutcomeUnresolved

What happened

DeltaPrime, a lending and leveraged-trading protocol, lost close to $6 million from its Arbitrum deployment on 16 September 2024.

The attacker did not exploit a contract flaw. They obtained the private key of the externally owned account that still held admin rights over DeltaPrime's DepositIndex proxy contracts - wallets the team later said had never been moved to a multisig after deployment. Using that key they upgraded the proxies to their own implementation, which let them mint deposit receipt tokens in absurd quantities and redeem them against the savings pools. Merkle Science recorded receipt-token balances above 1.1e69 and traced the drained USDC, WBTC, WETH, ARB and DAI being swapped into 2,588 ETH, worth about $6.04 million, then split between two addresses, with 1,337 ETH bridged via Stargate and sent to Tornado Cash.

DeltaPrime's own post-mortem puts the loss at $5.98 million; Merkle Science's flow-of-funds analysis totals $6.05 million. The Avalanche deployment was unaffected because its equivalent contracts used multisig wallets and cold storage.

Attribution is unsettled. Investigator ZachXBT said DeltaPrime had previously engaged North Korean developers and that he had warned the project earlier that year, but stated the link between that and the hack was unclear; the company said it had removed those workers. No formal attribution has been made and no charges have been brought.

None of the stolen funds were recovered. DeltaPrime published a reimbursement plan allocating $1.33 million from its stability pool, leaving $4.65 million of damage, and offered affected users 40% extra in rTKN claims - raising the stated obligation to about $6.5 million - to be paid from 33% of future protocol revenue. It was the protocol's second incident in two months, following a roughly $1 million loss in July 2024.

Sources

  1. DeltaPrimePrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. Merkle ScienceSecondary · retrieved 2026-08-01
  4. CryptoSlateSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-reimbursement-plan-3e5d6086dd2e

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "DeltaPrime hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/deltaprime
https://itokenly.com/hacks/deltaprime

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.