DeltaPrime (November 2024) hack — November 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 11, 2024 |
| Target type | Lending protocol |
| Loss | $4,750,000Published estimates range $4,750,000 to $4,850,000Price at time of incident |
| Method | Contract logic errorMissing input validation in DeltaPrime's Prime Account logic. Per the protocol's own post-mortem, the claimRewards path did not verify that the pair contract passed to it was a genuine Trader Joe Liquidity Book pair. The attacker flash-loaned about 14,230 WAVAX, deposited it as collateral, borrowed 56,923 WAVAX inside the same account so the position still appeared solvent, then supplied a fake LB pair and rewarder whose claim method wrapped native tokens into WAVAX. The accounting logic read the resulting balance increase as reward income and paid the attacker their own borrowed collateral. Three Sigma's analysis describes a second unvalidated parameter in swapDebtParaSwap, where an unchecked repay amount allowed borrowed assets to be routed to an attacker-controlled contract without settling the debt. |
| Chains | Avalanche, Arbitrum |
| Outcome | Unresolved |
What happened
DeltaPrime is a leveraged borrowing protocol whose Prime Accounts let users borrow against deposited collateral. On 11 November 2024 an attacker drained funds from its Avalanche and Arbitrum deployments. It was the protocol's second incident in two months, following a loss of roughly $6 million in September 2024.
DeltaPrime's own post-mortem attributes the November exploit to missing validation in the claimRewards path. The attacker flash-loaned about 14,230 WAVAX, deposited it as collateral, then borrowed 56,923 WAVAX inside the same account, which kept the position within solvency limits. They deployed a fake Trader Joe Liquidity Book pair and rewarder and called claimRewards with it. The fake rewarder simply wrapped native tokens back into WAVAX; the protocol measured the balance difference before and after the call, treated the borrowed and collateral funds as reward income, and sent them to the attacker, who then repaid the flash loan. Three Sigma's independent analysis describes a second unvalidated parameter, an unchecked repay amount in swapDebtParaSwap, used to move borrowed assets out without settling the debt.
Figures differ. DeltaPrime's post-mortem states $4.75 million, Three Sigma calculates about $4.85 million and Halborn reports about $4.8 million.
The attacker moved proceeds into Trader Joe and Stargate pools on Avalanche within minutes and bridged part to Ethereum the same morning. On 18 November they claimed to be a white hat but returned nothing. DeltaPrime paused the protocol, added a 24-hour withdrawal queue and a solvency check on every Prime Account interaction, commissioned a BlockSec review, and proposed reimbursement tokens redeemable against a third of future protocol revenue.
Law enforcement
DeltaPrime's post-mortem says investigations were continuing with security partners and law enforcement; no public case, charge or seizure has been identified.
Sources
- DeltaPrimePrimary · retrieved 2026-08-01
- Three SigmaSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-reimbursement-plan-07-12-2024-2d654912715b
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DeltaPrime (November 2024) hack — November 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/deltaprime-november-2024https://itokenly.com/hacks/deltaprime-november-2024Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.