{"investigation":{"slug":"prisma-fi","entity_name":"PrismaFi","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Prisma Finance was an Ethereum-based collateralized debt position (CDP) protocol that issued stablecoins (mkUSD and ULTRA) backed by liquid staking and restaking tokens (LRTs/LSTs). On March 28, 2024, a critical input validation flaw in the MigrateTroveZap contract was exploited via flash loan, resulting in the theft of approximately 3,479 ETH (~$12 million) from user vaults. Following the exploit, the core team effectively abandoned the protocol, which was subsequently shut down via DAO governance (PIP-46) and succeeded by Resupply Finance.","sections":[{"content":"Prisma Finance launched in 2023 as an Ethereum-based DeFi protocol enabling users to mint overcollateralized stablecoins — mkUSD (backed by liquid staking tokens) and ULTRA (backed by liquid restaking tokens) — by depositing LRTs and LSTs as collateral in vaults called Troves. The protocol was positioned within the Curve and Convex ecosystems, with PRISMA as its native governance token. At its peak, Prisma Finance held over $220 million in total value locked (TVL), making it a significant participant in the LRT-backed stablecoin segment of DeFi. The project operated with an anonymous and pseudonymous team; one co-founder was associated with the handle 'DgenFren' and was known for expertise in the Curve ecosystem, though publicly verified identities were not disclosed.","heading":"Protocol Overview","sources":[{"url":"https://thedefiant.io/news/defi/prisma-finance-suffers-usd12-million-exploit","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://cryptoslate.com/prisma-finances-11-6-million-exploit-leads-to-asset-value-plummet-mkusd-stablecoin-instability/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.cypherhunter.com/en/p/prisma-finance/","name":"cypherhunter.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 28, 2024, Prisma Finance was exploited by three distinct attacker addresses, resulting in the loss of approximately 3,479.24 ETH (roughly $12 million USD at the time). The root cause was a critical input validation failure in the MigrateTroveZap contract — a special-purpose contract deployed to help users migrate Trove positions during a system upgrade announced in March 2024. The contract's onFlashloan() callback function did not validate that the data it received originated from a legitimate migration call, and the flashloan() function was callable by any external user upon payment of a fee. Attackers exploited this by calling flashloan() directly, bypassing the intended migrateTrove() flow, and supplying crafted data that specified a reduced collateral amount. This caused the contract to close a victim's Trove and reopen it with lower collateral, leaving the surplus in the contract for extraction by the attacker. The primary attacker (EOA 0x7E39E3B3ff7ADef2613d5Cc49558EAB74B9a4202) stole approximately 3,257 ETH; Exploiter 2 took roughly 121 wstETH; Exploiter 3 took approximately 52 wstETH. The attack began at approximately 11:25 UTC; the community alerted the team on Discord at 11:29 UTC; the emergency multisig paused the protocol at 12:51 UTC.","heading":"March 2024 Exploit: Technical Analysis","sources":[{"url":"https://hackmd.io/@PrismaRisk/PostMortem0328","name":"hackmd.io","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/prisma-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://rekt.news/prismafi-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/prisma-finance-exploit-march-28-2024-detailed-analysis/","name":"immunebytes.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Shortly after the exploit, one of the attacker addresses posted an on-chain message stating 'this is a white hat rescue' and asked to be contacted to arrange a refund. Prisma Finance responded via on-chain message directing the attacker to negotiations@prismafinance.com. The attacker subsequently demanded a public, live apology from the development team, insisting that the team reveal their real identities and publicly acknowledge mistakes. The attacker stated 'after it happens, the amount I would keep, and the amount that I can send to you would be discussed — stay assured, most of it would be returned.' However, the sincerity of the whitehat claim was called into question when approximately 200 ETH (~$340,000) and later a further 740 ETH were sent to Tornado Cash, an OFAC-sanctioned cryptocurrency mixing service, totaling over $2.5 million moved through the mixer. Prisma Finance did not publicly respond to the apology demand. Partial fund return projections estimated $10 million might be returned, accounting for a potential 10% bounty, but no confirmed recovery figure was publicly established.","heading":"On-Chain Negotiations and Alleged Whitehat Claim","sources":[{"url":"https://www.theblock.co/post/285776/prisma-finance-hacker-defends-exploit-demands-public-apology","name":"theblock.co","type":"other","credibility":3},{"url":"https://cryptobriefing.com/prisma-finance-hacker-apology-demand/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/prisma-finance-hacker-claims-whitehat-rescue-after-11-6-million-exploit/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://coingape.com/prisma-finance-hacker-moves-funds-to-tornado-cash/","name":"coingape.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit triggered an immediate and severe market reaction. Protocol TVL fell approximately 40%, dropping from $236 million on March 27 to $143 million by March 28, with a further $110 million in withdrawals occurring in subsequent days. The mkUSD stablecoin briefly lost its $1 peg, trading at approximately $0.989 — though Prisma asserted that both mkUSD and ULTRA remained overcollateralized. The native PRISMA governance token fell over 25% immediately following news of the exploit. An estimated $540,000 in collateral remained at risk across 14 affected accounts that had not yet been able to withdraw. Secondary harm was caused by phishing campaigns launched in the immediate aftermath, with bad actors impersonating Prisma Finance and falsely directing affected users to malicious wallet revoke tools.","heading":"Immediate Market Impact","sources":[{"url":"https://cryptoslate.com/prisma-finances-11-6-million-exploit-leads-to-asset-value-plummet-mkusd-stablecoin-instability/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/news-in-crypto/thecryptotimes:prisma-finances-540k-still-at-risk-hacker-demands-apology","name":"cryptodaily.co.uk","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/prisma-finance-suffers-usd12-million-exploit","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 3, 2024, core contributor Frank Olson proposed a plan to safely restart the protocol, which received 100% approval from participating DAO members. Prisma Finance announced a resumption of operations on April 7, 2024. However, the development team subsequently abandoned the project. The protocol became what observers described as a 'ghost ship,' running without active development, maintenance, or team support. Once backed by integrations with Yearn and Convex liquid locker products, the absence of the team left the protocol in a structurally fragile state. Multiple residual bugs emerged during the shutdown process, including a TroveManager accounting flaw that prevented some users from accessing collateral and an errant line in the ULTRA stability pool code that allowed one user to improperly extract approximately 13.92 ETH. A Peg Stability Module (PSM) was introduced by the Resupply team to address stablecoin depegging caused by debt ceiling changes. The shutdown was managed externally by the Resupply team rather than the original Prisma contributors.","heading":"Protocol Restart Attempt and Subsequent Abandonment","sources":[{"url":"https://www.cryptotimes.io/2024/04/05/prisma-finance-plans-to-safely-restart-the-protocol-post-hack/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://cryptonews.com/news/prisma-finance-gains-strong-community-support-for-protocol-restart-with-dao-approval/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://wavey.info/posts/2025/decomissioning-prisma-finance/","name":"wavey.info","type":"other","credibility":3},{"url":"https://gov.prismafinance.com/t/pip-035-a-path-forward-after-the-security-incident/157","name":"gov.prismafinance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prisma Finance was formally wound down via DAO governance proposal PIP-46, which confirmed the shutdown of the protocol and introduced Resupply Finance as its successor. Resupply Finance launched in December 2024 as a stablecoin protocol issuing reUSD backed by crvUSD and frxUSD, along with a new governance token (RSUP). New PRISMA emissions ceased on January 2, 2025. By the time of the decommissioning article published in 2025, less than $80,000 in debt remained outstanding, and the mkUSD stablecoin was reported to be backed 1:1 by crvUSD reserves via PSMs, achieving technical solvency. Users were required to migrate positions and claims to Resupply Finance.","heading":"Formal Shutdown and Transition to Resupply Finance","sources":[{"url":"https://gov.prismafinance.com/t/pip-46-shutdown-prisma-finance-introduce-resupply/232","name":"gov.prismafinance.com","type":"other","credibility":3},{"url":"https://mirror.xyz/0x521CB9b35514E9c8a8a929C890bf1489F63B2C84/cAkCxXs0wF0feUz29E6CvF_7v3b9ghSLgf7_EkDfmn0","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://wavey.info/posts/2025/decomissioning-prisma-finance/","name":"wavey.info","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/prisma-finance-protocol-restart-dao-vote","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prisma Finance stated it prioritized security through internal best practices, extensive testing, an independent risk team, and external auditors, with MixBytes cited as a historical security partner. The project maintains a public audits repository on GitHub. However, the MigrateTroveZap contract — the vector of the March 2024 exploit — was a newer contract deployed as part of the system upgrade announced in March 2024, and CertiK's post-exploit analysis noted no mention of prior audits or security review for that specific contract before deployment. The vulnerability was a straightforward input validation failure: a publicly callable function that accepted and acted on untrusted external data. The absence of verification that this migration-helper contract received comparable scrutiny to the core protocol represents a material oversight in the project's security process.","heading":"Security Posture and Audit History","sources":[{"url":"https://github.com/prisma-fi/audits","name":"github.com","type":"other","credibility":3},{"url":"https://docs.prismafinance.com/external-audits-and-security/audits","name":"docs.prismafinance.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/prisma-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://hackmd.io/@PrismaRisk/PostMortem0328","name":"hackmd.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The Prisma Finance founding team operated pseudonymously or anonymously throughout the protocol's existence. No verified real-world identities of core contributors were publicly disclosed prior to or following the exploit. The attacker explicitly leveraged this as a pressure point during on-chain negotiations, demanding that developers reveal their identities as a condition of fund return discussions. The team's pseudonymous structure also meant that when the core contributors departed post-exploit, there was no accountability mechanism or identified party against whom affected users could seek legal or regulatory recourse. The decommissioning of the protocol was ultimately completed by the external Resupply Finance team rather than original Prisma contributors.","heading":"Anonymous Team as Risk Factor","sources":[{"url":"https://cryptobriefing.com/prisma-finance-hacker-apology-demand/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://wavey.info/posts/2025/decomissioning-prisma-finance/","name":"wavey.info","type":"other","credibility":3},{"url":"https://www.cypherhunter.com/en/p/prisma-finance/","name":"cypherhunter.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023","event":"Prisma Finance launched on Ethereum mainnet as an LRT/LST-backed CDP stablecoin protocol, issuing mkUSD and ULTRA.","source":"","date_original":"2023-01-01"},{"date":"2024-03","event":"Prisma Finance announced a system upgrade requiring users to migrate Trove positions to new TroveManager contracts; MigrateTroveZap contract deployed.","source":"","date_original":"2024-03-01"},{"date":"2024-03-28","event":"At approximately 11:25 UTC, the primary attacker exploited a critical input validation flaw in the MigrateTroveZap contract using a flash loan, stealing approximately 3,479 ETH (~$12 million) from 25 victim wallets across three exploiter addresses.","source":""},{"date":"2024-03-28","event":"At 12:51 UTC, Prisma Finance's emergency multisig paused the protocol. TVL dropped ~40% from $236 million to $143 million. PRISMA token fell over 25%.","source":""},{"date":"2024-03-28","event":"The primary attacker posted an on-chain message claiming 'this is a white hat rescue' and requested contact information to arrange a refund.","source":""},{"date":"2024-03-28","event":"Prisma Finance directed the attacker to negotiations@prismafinance.com via on-chain message.","source":""},{"date":"2024-03-29","event":"The attacker publicly demanded a live public apology from the development team and insisted developers reveal their real identities as conditions for fund return discussions.","source":""},{"date":"2024-03-29","event":"Blockchain security firm Cyvers observed the attacker beginning to swap stolen funds to ETH; PeckShield reported approximately 200 ETH transferred to OFAC-sanctioned mixer Tornado Cash.","source":""},{"date":"2024-03-29","event":"A further 740 ETH reportedly transferred to a Tornado Cash-associated address, bringing total funds sent to mixers to over $2.5 million.","source":""},{"date":"2024-04-03","event":"Core contributor Frank Olson published a proposal (later PIP-035) to safely restart the Prisma protocol, including re-enabling LST/LRT deposits and stablecoin borrowing.","source":""},{"date":"2024-04-05","event":"The DAO voted 100% in favor of the protocol restart proposal.","source":""},{"date":"2024-04-07","event":"Prisma Finance announced resumption of operations with limited functionality restored.","source":""},{"date":"2024-12","event":"Resupply Finance launched as the successor protocol, issuing reUSD backed by crvUSD and frxUSD, with RSUP as its governance token.","source":"","date_original":"2024-12-01"},{"date":"2025-01-02","event":"New PRISMA token emissions ceased. DAO proposal PIP-46 formally confirmed the shutdown of Prisma Finance and transition to Resupply Finance.","source":""},{"date":"2025","event":"Decommissioning of Prisma Finance completed by the Resupply team; less than $80,000 in debt remained, with mkUSD backed 1:1 by crvUSD via Peg Stability Modules.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://thedefiant.io/news/defi/prisma-finance-suffers-usd12-million-exploit","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://cryptoslate.com/prisma-finances-11-6-million-exploit-leads-to-asset-value-plummet-mkusd-stablecoin-instability/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.cypherhunter.com/en/p/prisma-finance/","name":"cypherhunter.com","type":"other","credibility":3},{"url":"https://hackmd.io/@PrismaRisk/PostMortem0328","name":"hackmd.io","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/prisma-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://rekt.news/prismafi-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/prisma-finance-exploit-march-28-2024-detailed-analysis/","name":"immunebytes.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/285776/prisma-finance-hacker-defends-exploit-demands-public-apology","name":"theblock.co","type":"other","credibility":3},{"url":"https://cryptobriefing.com/prisma-finance-hacker-apology-demand/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/prisma-finance-hacker-claims-whitehat-rescue-after-11-6-million-exploit/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://coingape.com/prisma-finance-hacker-moves-funds-to-tornado-cash/","name":"coingape.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/news-in-crypto/thecryptotimes:prisma-finances-540k-still-at-risk-hacker-demands-apology","name":"cryptodaily.co.uk","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/04/05/prisma-finance-plans-to-safely-restart-the-protocol-post-hack/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://cryptonews.com/news/prisma-finance-gains-strong-community-support-for-protocol-restart-with-dao-approval/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://wavey.info/posts/2025/decomissioning-prisma-finance/","name":"wavey.info","type":"other","credibility":3},{"url":"https://gov.prismafinance.com/t/pip-035-a-path-forward-after-the-security-incident/157","name":"gov.prismafinance.com","type":"other","credibility":3},{"url":"https://gov.prismafinance.com/t/pip-46-shutdown-prisma-finance-introduce-resupply/232","name":"gov.prismafinance.com","type":"other","credibility":3},{"url":"https://mirror.xyz/0x521CB9b35514E9c8a8a929C890bf1489F63B2C84/cAkCxXs0wF0feUz29E6CvF_7v3b9ghSLgf7_EkDfmn0","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/prisma-finance-protocol-restart-dao-vote","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://github.com/prisma-fi/audits","name":"github.com","type":"other","credibility":3},{"url":"https://docs.prismafinance.com/external-audits-and-security/audits","name":"docs.prismafinance.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:33:15.509179+00:00","updated_at":"2026-08-29T01:33:58.254+00:00"}}