T
iTokenly

Prisma Finance hack — March 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 28, 2024
Target typeLending protocol
Loss$12,000,000Published estimates range $11,000,000 to $12,000,000Price at time of incident
MethodAccess control flawUnvalidated onFlashloan callback in the MigrateTroveZap helper contract let anyone act on troves that had granted it standing approvals, closing and reopening positions with the same debt but less collateral
ChainsEthereum
OutcomeUnresolved

What happened

Prisma Finance, an Ethereum collateralised-debt protocol that let users borrow its mkUSD stablecoin against liquid staking tokens, was exploited on 28 March 2024 starting around 11:25 UTC.

The flaw sat in MigrateTroveZap, a helper contract meant to move a user's position between trove managers. Its onFlashloan callback did not validate the caller or the parameters passed to it, and users had granted the contract standing token approvals. The attacker invoked the flash-loan entry point directly with crafted data, closing a victim's trove and immediately reopening it with the same debt but far less collateral, then capturing the difference. The post-mortem cites one position that went from 1,745.08 wstETH backing 1,442,100 mkUSD to 463.18 wstETH backing 1,443,398 mkUSD, cutting its collateral ratio from about 498 per cent to about 132 per cent. Only wstETH troves in the mkUSD system were affected.

Published figures differ according to what is counted. The post-mortem, compiled by Prisma with assistance from LlamaRisk, puts the total at 3,479.24 ETH, about $12 million, spread across a primary exploiter who took roughly 3,257 ETH — about $11 million — and two copycats who followed with roughly 121 and 52 wstETH. The Block reported the incident at $11 million.

Prisma paused the protocol through its emergency multisig at 12:51 UTC and told users to revoke approvals. The attacker contacted the team on-chain describing the incident as a whitehat rescue, then demanded that the pseudonymous developers hold a press conference, identify themselves and apologise publicly before returning anything. More than $2.5 million was routed through Tornado Cash while those talks continued, and no confirmed return of the bulk of the funds was documented in the reporting reviewed.

Sources

  1. Prisma Finance / PrismaRiskPrimary · retrieved 2026-08-01
  2. LlamaRiskPrimary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01

Official post-mortem: https://hackmd.io/@PrismaRisk/PostMortem0328

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Prisma Finance hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/prisma-finance
https://itokenly.com/hacks/prisma-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.