{"investigation":{"slug":"deltaprime","entity_name":"DeltaPrime","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"DeltaPrime is a decentralized leveraged farming and lending protocol deployed on Arbitrum and Avalanche. The protocol suffered two major security exploits in 2024 — a $5.98 million private key compromise in September and a $4.8 million smart contract vulnerability in November — totaling over $10.7 million in losses. On-chain investigator ZachXBT alleged that DeltaPrime had previously employed North Korean IT workers with alleged ties to the DPRK-linked Lazarus Group, raising concerns about insider access as a contributing factor to the first exploit.","sections":[{"content":"DeltaPrime is a DeFi protocol offering leveraged yield farming and prime brokerage accounts, enabling users to borrow capital beyond their collateral to amplify returns across trading, liquidity provision, and farming strategies. It was founded by Piotr Duda (CEO) and Kamil Muca (CTO), both formerly associated with the Redstone oracle project. The protocol launched initially on Avalanche before expanding to Arbitrum. As of early 2026, DeltaPrime reports approximately $4.18 million in total value locked (TVL), down significantly from pre-incident levels. The protocol introduced DeltaPrime 2.0 in January 2025 and has undertaken multiple audits in an attempt to rebuild user confidence following its 2024 exploits.","heading":"Overview","sources":[{"url":"https://www.deltaprime.io/","name":"deltaprime.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/deltaprime","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.deltaprime.io/protocol/the-story-so-far","name":"docs.deltaprime.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 16, 2024, DeltaPrime's Arbitrum deployment was exploited for approximately $5.98 million in a private key compromise attack. An attacker gained unauthorized control of the admin private key for address 0x40e4ff9e018462ce71fa34abdfa27b8c5e2b1afb — the ProxyAdmin controller — and used it to upgrade five proxy contracts on Arbitrum to point to a malicious contract (0xD4CA224a176A59ed1a346FA86C3e921e01659E73). The attacker then executed 57 withdrawal transactions, draining the DPUSDC, DPARB, and DPBTCb pools of USDC, ARB, and BTC respectively. All stolen assets were swapped to approximately 2,588 ETH. Of this, 1,337 ETH was sent to Tornado Cash for obfuscation. Security firm Halborn identified the root cause as a failure to use multi-signature wallets and cold storage for the admin key. DeltaPrime's Avalanche deployment was not affected by this exploit, as it had multi-sig protection in place. The protocol acknowledged the compromise and stated that insurance coverage would address losses 'where possible/necessary.'","heading":"September 2024 Exploit: Private Key Compromise ($5.98 Million)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-september-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2024/09/16/crypto-broker-deltaprime-drained-of-over-6m-amid-apparent-private-key-leak","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/delta-prime-defi-hacked-6-m-arbitrum","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-deltaprime-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3},{"url":"https://rekt.news/deltaprime-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 11, 2024, DeltaPrime suffered a second major exploit across both its Arbitrum and Avalanche deployments, resulting in approximately $4.8 to $4.85 million in losses. This second attack was caused by a smart contract vulnerability rather than a key compromise. Specifically, the protocol's reward claiming mechanism failed to perform adequate input validation on two functions: the swapDebtParaSwap function failed to validate the _repayAmount parameter, and the claimReward function failed to validate the pair parameter. The attacker obtained a flash loan of approximately 59.958 WETH, used the malicious trading pair to convert borrowed collateral into reward tokens, and withdrew those tokens as profit, leaving bad debt in the protocol. Approximately $2 million of the stolen funds were deposited into the LFG and Stargate yield farming protocols to generate additional yield. The attacker's addresses were noted by security firm Halborn to be associated with past DeFi exploits, suggesting an experienced attacker. DeltaPrime paused all pools on both chains immediately following detection.","heading":"November 2024 Exploit: Smart Contract Vulnerability ($4.8 Million)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-november-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/delta-prime-exploited-for-4-8-m-worth-of-arb-and-avax","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://threesigma.xyz/blog/exploit/deltaprime-defi-exploit-avalanche-arbitrum-hack","name":"threesigma.xyz","type":"other","credibility":3},{"url":"https://www.theblock.co/post/325498/lending-protocol-delta-prime-suffers-second-exploit-in-two-months-bringing-losses-above-10-million","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/deltaprime-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT alleged that DeltaPrime was among more than 25 Web3 projects that had unknowingly hired malicious IT workers with ties to North Korea. ZachXBT stated that he contacted DeltaPrime on August 15, 2024, warning them about the DPRK-affiliated personnel, and was told by the team that the flagged individuals had been removed. Following the September 2024 hack, ZachXBT noted in a public comment that DeltaPrime had been one of the teams he had warned, and observed that the fund laundering strategy — including bridging stolen assets across chains and depositing large sums into Tornado Cash — bore similarities to patterns associated with the Lazarus Group, a North Korean state-sponsored threat actor. Separately, reporting by CryptoNewsZ alleged that the persona 'Naoki Murano,' associated with DPRK Chinyong-related IT worker operations and the Workers' Party of Korea, had been linked to the DeltaPrime incident. However, no confirmed attribution by a government agency or court filing to North Korea exists for the DeltaPrime hack specifically. DeltaPrime has not publicly acknowledged any confirmed state-sponsored involvement. All claims of a direct North Korean link should be treated as alleged and unconfirmed.","heading":"Alleged DPRK / North Korean IT Worker Connection","sources":[{"url":"https://cryptoslate.com/deltaprime-hit-by-6m-exploit-amid-north-korea-links-allegations/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://99bitcoins.com/news/6-million-drained-from-defi-platform-zachxbt-claims-that-north-korea-hackers-may-be-involved/","name":"99bitcoins.com","type":"other","credibility":3},{"url":"https://www.cryptonewsz.com/north-korean-behind-deltaprime-attack-5-93m/","name":"cryptonewsz.com","type":"other","credibility":3},{"url":"https://beincrypto.com/deltaprime-breach-suspicious-transactions/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://rekt.news/deltaprime-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the September 2024 exploit, DeltaPrime published a reimbursement plan in October 2024 and updated it in December 2024 after the second exploit. The plan introduced Reimbursement Tokens (rTKNs), where each rTKN represents $1 of future protocol revenue owed to affected users, with a 40% compensation bonus (1.4 rTKNs issued per $1 lost). The protocol's Stability Pool contributed $1.33 million toward reimbursements, reducing the uncovered amount for the first exploit to approximately $4.65 million. The founders committed 33% of their PRIME team token allocation for sale at a discounted rate, with proceeds directed to affected users. Users who kept their savings in the protocol were offered accelerated repayment (twice as fast as those who withdrew). For the second exploit's post-mortem published December 7, 2024, 33% of all future revenue from the DegenPrime product (planned Q1 2025) was also allocated to rTKN reimbursements. DeltaPrime engaged BlockSec for an eighth protocol audit and implemented additional monitoring systems. DeltaPrime 2.0 launched in January 2025.","heading":"Reimbursement Plan and Protocol Response","sources":[{"url":"https://www.globenewswire.com/news-release/2024/10/21/2965930/0/en/DeltaPrime-Reimbursement-Plan.html","name":"globenewswire.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/press-release/2024/10/22/deltaprimes-path-to-regrowth-a-robust-plan-to-make-all-affected-users-whole-again","name":"coindesk.com","type":"other","credibility":3},{"url":"https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-reimbursement-plan-07-12-2024-2d654912715b","name":"medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/press-releases/deltaprime-reimbursement-plan","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"DeltaPrime's September 2024 exploit was directly attributed to a failure to use multi-signature wallets and cold storage for admin keys — a basic operational security control that the protocol had implemented on Avalanche but not on Arbitrum. The November 2024 exploit revealed inadequate smart contract input validation. The protocol had undergone multiple audits prior to these incidents, demonstrating that audits alone do not prevent key management failures or all classes of logical vulnerabilities. The laundering of $1,337 ETH through Tornado Cash following the September exploit complicates any potential recovery of user funds. As of early 2026, the protocol's TVL remains at approximately $4.18 million — a fraction of its pre-exploit levels — indicating diminished user confidence. The alleged involvement of DPRK-affiliated personnel represents an ongoing reputational and potential legal risk, though it has not resulted in confirmed regulatory action against DeltaPrime.","heading":"Security Posture and Risk Factors","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-september-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-november-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/deltaprime","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-deltaprime-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of May 2026, no public record of SEC, CFTC, DOJ, or other regulatory enforcement action specifically targeting DeltaPrime has been identified. There are no known court filings related to the exploits or the alleged DPRK IT worker connection. The broader North Korean IT worker scheme involving multiple DeFi protocols has attracted U.S. government attention: in related actions, the U.S. government seized $7.74 million in crypto tied to North Korea's fake IT worker network, though DeltaPrime was not named as a direct subject of that seizure. The absence of regulatory action should not be interpreted as a clean regulatory record, given the nascent state of DeFi enforcement and the ongoing nature of investigations into DPRK-linked cyber operations.","heading":"Regulatory and Legal Status","sources":[{"url":"https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html","name":"thehackernews.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/deltaprime-hit-by-6m-exploit-amid-north-korea-links-allegations/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-08-15","event":"ZachXBT contacts DeltaPrime and more than 25 other Web3 projects warning them about unknowingly hired DPRK-affiliated IT workers. DeltaPrime reportedly tells ZachXBT the flagged individuals have been removed.","source":""},{"date":"2024-09-16","event":"DeltaPrime's Arbitrum deployment is exploited for approximately $5.98 million via a compromised admin private key. The attacker upgrades proxy contracts to malicious versions and drains DPUSDC, DPARB, and DPBTCb pools. 1,337 ETH is sent to Tornado Cash.","source":""},{"date":"2024-09-16","event":"ZachXBT publicly comments that DeltaPrime was one of the teams warned about DPRK IT workers, and observes laundering patterns similar to the Lazarus Group.","source":""},{"date":"2024-10-21","event":"DeltaPrime publishes its initial reimbursement plan introducing rTKN tokens, with a 1.4x compensation ratio for affected users and a $1.33 million Stability Pool contribution.","source":""},{"date":"2024-11-11","event":"DeltaPrime suffers a second exploit affecting both Arbitrum and Avalanche, losing approximately $4.8 million due to insufficient input validation in the reward claiming smart contract. Total 2024 losses exceed $10.7 million. Protocol pauses all pools.","source":""},{"date":"2024-12-07","event":"DeltaPrime publishes updated post-mortem and reimbursement plan for the second exploit, allocating 33% of future DegenPrime revenue to rTKN reimbursements.","source":""},{"date":"2025","event":"DeltaPrime 2.0 launches with enhanced security features including a new audit by BlockSec (the protocol's eighth audit).","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://www.deltaprime.io/","name":"deltaprime.io","type":"other","archive_url":"http://web.archive.org/web/20260608111215/https://www.deltaprime.io/","credibility":3,"archive_timestamp":"2026-06-08T11:12:15+00:00"},{"url":"https://defillama.com/protocol/deltaprime","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20260828195811/https://defillama.com/protocol/deltaprime","credibility":3,"archive_timestamp":"2026-08-28T19:58:11+00:00"},{"url":"https://docs.deltaprime.io/protocol/the-story-so-far","name":"docs.deltaprime.io","type":"other","archive_url":"http://web.archive.org/web/20260520040049/https://docs.deltaprime.io/protocol/the-story-so-far","credibility":3,"archive_timestamp":"2026-05-20T04:00:49+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-september-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260315170422/https://www.halborn.com/blog/post/explained-the-deltaprime-hack-september-2024","credibility":3,"archive_timestamp":"2026-03-15T17:04:22+00:00"},{"url":"https://www.coindesk.com/markets/2024/09/16/crypto-broker-deltaprime-drained-of-over-6m-amid-apparent-private-key-leak","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260303181324/https://www.coindesk.com/markets/2024/09/16/crypto-broker-deltaprime-drained-of-over-6m-amid-apparent-private-key-leak","credibility":3,"archive_timestamp":"2026-03-03T18:13:24+00:00"},{"url":"https://cointelegraph.com/news/delta-prime-defi-hacked-6-m-arbitrum","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260720145532/https://cointelegraph.com/news/delta-prime-defi-hacked-6-m-arbitrum","credibility":3,"archive_timestamp":"2026-07-20T14:55:32+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-deltaprime-flow-of-funds-analysis","name":"merklescience.com","type":"other","archive_url":"http://web.archive.org/web/20260511062117/https://www.merklescience.com/blog/hack-track-deltaprime-flow-of-funds-analysis","credibility":3,"archive_timestamp":"2026-05-11T06:21:17+00:00"},{"url":"https://rekt.news/deltaprime-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513164257/https://rekt.news/deltaprime-rekt","credibility":3,"archive_timestamp":"2026-05-13T16:42:57+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-deltaprime-hack-november-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414114037/https://www.halborn.com/blog/post/explained-the-deltaprime-hack-november-2024","credibility":3,"archive_timestamp":"2026-04-14T11:40:37+00:00"},{"url":"https://cointelegraph.com/news/delta-prime-exploited-for-4-8-m-worth-of-arb-and-avax","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260209205613/https://cointelegraph.com/news/delta-prime-exploited-for-4-8-m-worth-of-arb-and-avax","credibility":3,"archive_timestamp":"2026-02-09T20:56:13+00:00"},{"url":"https://threesigma.xyz/blog/exploit/deltaprime-defi-exploit-avalanche-arbitrum-hack","name":"threesigma.xyz","type":"other","archive_url":"http://web.archive.org/web/20260415064318/https://threesigma.xyz/blog/exploit/deltaprime-defi-exploit-avalanche-arbitrum-hack","credibility":3,"archive_timestamp":"2026-04-15T06:43:18+00:00"},{"url":"https://www.theblock.co/post/325498/lending-protocol-delta-prime-suffers-second-exploit-in-two-months-bringing-losses-above-10-million","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.certik.com/resources/blog/deltaprime-incident-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20251016161120/https://www.certik.com/resources/blog/deltaprime-incident-analysis","credibility":3,"archive_timestamp":"2025-10-16T16:11:20+00:00"},{"url":"https://cryptoslate.com/deltaprime-hit-by-6m-exploit-amid-north-korea-links-allegations/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260419121350/https://cryptoslate.com/deltaprime-hit-by-6m-exploit-amid-north-korea-links-allegations/","credibility":3,"archive_timestamp":"2026-04-19T12:13:50+00:00"},{"url":"https://99bitcoins.com/news/6-million-drained-from-defi-platform-zachxbt-claims-that-north-korea-hackers-may-be-involved/","name":"99bitcoins.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.cryptonewsz.com/north-korean-behind-deltaprime-attack-5-93m/","name":"cryptonewsz.com","type":"other","archive_url":"https://web.archive.org/web/20260830004848/https://www.cryptonewsz.com/","credibility":3,"archive_timestamp":"2026-08-30T00:48:48+00:00"},{"url":"https://beincrypto.com/deltaprime-breach-suspicious-transactions/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20251122005855/https://beincrypto.com/deltaprime-breach-suspicious-transactions/","credibility":3,"archive_timestamp":"2025-11-22T00:58:55+00:00"},{"url":"https://www.globenewswire.com/news-release/2024/10/21/2965930/0/en/DeltaPrime-Reimbursement-Plan.html","name":"globenewswire.com","type":"other","archive_url":"https://web.archive.org/web/20260830005310/https://www.globenewswire.com/news-release/2024/10/21/2965930/0/en/DeltaPrime-Reimbursement-Plan.html","credibility":3,"archive_timestamp":"2026-08-30T00:53:10+00:00"},{"url":"https://www.coindesk.com/press-release/2024/10/22/deltaprimes-path-to-regrowth-a-robust-plan-to-make-all-affected-users-whole-again","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-reimbursement-plan-07-12-2024-2d654912715b","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20250923155425/https://medium.com/@DeltaPrimeDefi/deltaprime-post-mortem-reimbursement-plan-07-12-2024-2d654912715b","credibility":3,"archive_timestamp":"2025-09-23T15:54:25+00:00"},{"url":"https://cointelegraph.com/press-releases/deltaprime-reimbursement-plan","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html","name":"thehackernews.com","type":"other","archive_url":"http://web.archive.org/web/20260607022105/https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html","credibility":3,"archive_timestamp":"2026-06-07T02:21:05+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:30.597828+00:00","updated_at":"2026-08-30T01:16:26.114376+00:00"}}