DeltaPrime Incident Analysis
ID: cb605672-7112-575d-8b52-56d22afccd85
STIX ID: report--cb605672-7112-575d-8b52-56d22afccd85
Feed Name: CertiK Blog
## Executive summary On 11 November 2024 Delta Prime was exploited across Arbitrum and Avalanche for roughly $4.8M by chaining two smart-contract vulnerabilities: an unchecked input enabling transfer of borrowed tokens to an attacker-controlled address and an arbitrary-address input in the reward claim mechanism that allowed the attacker to manipulate balances and withdraw collateral. The report includes transaction links, attacker and aggregator addresses, step-by-step attack flow (flash loan, borrow WBTC, swap adapter transfer, claimReward callback triggering wrapNative), and a fund-flow breakdown showing aggregation, staking, and bridged assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
