Summary
DeltaPrime is a decentralized leveraged farming and lending protocol deployed on Arbitrum and Avalanche. The protocol suffered two major security exploits in 2024 — a $5.98 million private key compromise in September and a $4.8 million smart contract vulnerability in November — totaling over $10.7 million in losses. On-chain investigator ZachXBT alleged that DeltaPrime had previously employed North Korean IT workers with alleged ties to the DPRK-linked Lazarus Group, raising concerns about insider access as a contributing factor to the first exploit.
Connected Entities
1 entitiesTimeline(7 events)
2024-08-15
ZachXBT contacts DeltaPrime and more than 25 other Web3 projects warning them about unknowingly hired DPRK-affiliated IT workers. DeltaPrime reportedly tells ZachXBT the flagged individuals have been removed.
2024-09-16
DeltaPrime's Arbitrum deployment is exploited for approximately $5.98 million via a compromised admin private key. The attacker upgrades proxy contracts to malicious versions and drains DPUSDC, DPARB, and DPBTCb pools. 1,337 ETH is sent to Tornado Cash.
2024-09-16
ZachXBT publicly comments that DeltaPrime was one of the teams warned about DPRK IT workers, and observes laundering patterns similar to the Lazarus Group.
2024-10-21
DeltaPrime publishes its initial reimbursement plan introducing rTKN tokens, with a 1.4x compensation ratio for affected users and a $1.33 million Stability Pool contribution.
2024-11-11
DeltaPrime suffers a second exploit affecting both Arbitrum and Avalanche, losing approximately $4.8 million due to insufficient input validation in the reward claiming smart contract. Total 2024 losses exceed $10.7 million. Protocol pauses all pools.
2024-12-07
DeltaPrime publishes updated post-mortem and reimbursement plan for the second exploit, allocating 33% of future DegenPrime revenue to rTKN reimbursements.
2025-01-01
DeltaPrime 2.0 launches with enhanced security features including a new audit by BlockSec (the protocol's eighth audit).
Decision Log
- hash: GHyweNCQQcpNHs5SD4613VCDXJ4RmAfVtRmGMiFnvYDx
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:30 AM
last updated: 5/28/2026, 3:34:46 AM
avoid.net — verified advice for a post-truth world