DeltaPrime hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $1,000,000Price at time of incident |
| Recovered | $900,000 |
| Method | Access control flawTwo initialisation paths in the DiamondBeaconProxy architecture each read the _initialized flag from a different storage slot, so a live Prime Account still appeared uninitialised to one of them. Calling init() (selector 0xe1c7392a) re-ran initialisation and let the caller install themselves as owner. |
| Chains | Arbitrum |
| Outcome | Users reimbursed |
What happened
On 23 July 2024 an attacker took over thirteen DeltaPrime Prime Accounts on Arbitrum and emptied them. DeltaPrime, a lending protocol whose users borrow against collateral held in per-user Prime Account contracts, put the loss at $1,000,000, or about 290.3 ETH. Its post-mortem, which uses UTC+2 throughout, records the attacker changing the ownership of several accounts between 17:23 and 19:33, the first victim's account being drained of collateral between 22:15 and 22:33, and the thirteenth and last account being drained at 00:09 on 24 July.
The post-mortem traced the failure to a storage-slot mismatch created by the protocol's DiamondBeaconProxy architecture. Two separate initialisation routines each checked an _initialized flag, but read that flag from different storage slots, so an account that had already been set up still looked uninitialised to one of them. Calling the init() function, selector 0xe1c7392a, on a live Prime Account therefore re-ran initialisation and allowed the caller to write themselves in as owner. Holding ownership, the attacker repaid each account's outstanding loan and withdrew the collateral standing behind it.
DeltaPrime paused Prime Accounts at 00:10 on 24 July, contacted law enforcement across several jurisdictions at 05:45, and had the code re-audited the same day by AstraSec and PeckShield, who found and resolved two further attack vectors of the same kind. The timelocks passed and the fixes went live at 20:30 on 25 July; affected accounts were reimbursed at 21:06. The attacker returned $900,000 and DeltaPrime covered the remaining $100,000 from its stability pool. The team said it passed the leads it had gathered to law enforcement; no attribution has been published.
Out of that review AstraSec disclosed a related ownership-hijacking flaw in DeltaPrime's contracts, which DL News reported could have exposed roughly $64 million in deposits; DeltaPrime paid a $65,000 bounty for the disclosure. A larger, separate exploit hit DeltaPrime in September 2024.
Sources
- DeltaPrimePrimary · retrieved 2026-08-01
- DL NewsSecondary · retrieved 2026-08-01
- OlympixSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-report-752bd60a25e6
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DeltaPrime hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/deltaprime-july-2024https://itokenly.com/hacks/deltaprime-july-2024Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.