Live Wire

Delta Prime Attacker Steals $6M by Massively Minting Tokens

Delta Prime DeFi Protocol Attacked: $6 Million Stolen by Minting Tokens

Massive Token Minting Exploit in Delta Prime

In a recent breach, a hacker exploited the decentralized finance protocol Delta Prime, stealing over $6 million. The attack was executed by minting an enormous number of deposit receipt tokens. Specifically, the hacker minted over 115 duovigintillion Delta Prime USD (DPUSDC) tokens, a figure so large it’s represented as 1.1*10^69 in scientific notation. These tokens are supposed to be redeemable at a 1:1 ratio for USDC stablecoins held at Delta Prime.

The Mechanics of the Attack

Despite creating an astronomical number of tokens, the attacker only burned 2.4 million of them, converting this fraction into $2.4 million in USDC stablecoins. The hacker repeated this process across various deposit receipt tokens, including Delta Prime Wrapped Bitcoin (DPBTCb), Delta Prime Wrapped Ether (DPWETH), and Delta Prime Arbitrum (DPARB). By redeeming small portions of these minted tokens, the attacker managed to accumulate over $1 million in Bitcoin, Ether, and other cryptocurrencies.

Security Breach and Exploitation

Blockchain security expert Chaofan Shou confirmed that the hacker has siphoned off approximately $6 million in total. The method involved gaining control of an admin account, possibly by stealing the developer’s private key. With this access, the attacker executed an “upgrade” function on the protocol’s liquidity pool contracts. Normally intended for software updates, these functions can change the code by redirecting a proxy to a new implementation address.

However, in this case, the attacker redirected each proxy to a malicious contract they had created. This malicious contract allowed the hacker to mint an unlimited number of deposit receipts, effectively draining all the funds from each pool.

Delta Prime’s Response

Delta Prime acknowledged the incident in a public post, stating that the attack occurred at 6:14 AM CET and resulted in a loss of $5.98 million. The protocol assured users that the Avalanche version of Delta Prime is not susceptible to this type of attack. Additionally, they mentioned that their insurance would cover any potential losses, where feasible.

Risks of Upgradeable Contracts in DeFi

This attack highlights the vulnerabilities associated with DeFi protocols that use upgradeable contracts. The Web3 ecosystem is designed to prevent private key hacks from compromising entire protocols. Ideally, an attacker would need to steal the private keys of every user to drain the protocol. However, upgradeable contracts introduce a centralization risk, potentially allowing a single point of failure to jeopardize the entire user base’s funds.

Despite these risks, some protocols argue that the ability to upgrade contracts is essential for fixing bugs discovered post-deployment. The debate continues among Web3 developers on when it is appropriate to allow upgrades in protocols.

Ongoing Threats in the Web3 Space

Smart contract exploits remain a significant threat to Web3 users.

  • Earlier in September, an attacker drained over $1.4 million from a CUT token liquidity pool by exploiting an unverified function in a separate contract.
  • Another incident in the same month saw over $27 million stolen from the Penpie protocol, where an attacker registered a malicious contract as a token market.

Conclusion

The Delta Prime attack serves as a stark reminder of the risks involved in decentralized finance, especially concerning upgradeable contracts. While these features are designed to provide flexibility and allow for necessary updates, they also introduce significant vulnerabilities that can be exploited by malicious actors. As the Web3 ecosystem evolves, finding the balance between security and adaptability will be crucial in protecting user funds and maintaining trust in decentralized platforms.

Author

Leave a Reply

Discover more from CRYPTO CASINO NEWS

Subscribe now to keep reading and get access to the full archive.

Continue reading