Prisma Finance Incident Analysis
ID: 1ec388cd-09db-56ef-93cc-07454d54a38b
STIX ID: report--1ec388cd-09db-56ef-93cc-07454d54a38b
Feed Name: CertiK Blog
On 28 March Prisma Finance was exploited for approximately $12.3M after attackers abused a validation flaw in the MigrateTroveZap contract: by calling mkUSD.flashLoan() and spoofing the onFlashLoan() data, they forced unauthorized collateral migrations and extracted funds. The report describes the three-step attack flow, specific transaction data and crafted parameters, identifies three malicious EOAs responsible for the majority of losses, documents fund movement (including use of Tornado Cash), and notes the primary attacker has signaled intent to return funds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
