Refreshed 1h ago· updates every 6h

Prisma Finance (2024) — Crypto Hack

Partially Recovered
Mar 28, 2024·
Ethereum
Amount Stolen
$12.4M
~3,800 ETH
Recovered
$3.4M
27% of stolen funds

An attacker exploited a vulnerability in Prisma Finance's migration contract to drain ~$12.4M, triggering the protocol's first major exploit since launch.

Summary

An attacker exploited a vulnerability in Prisma Finance's migration contract to drain ~$12.4M, triggering the protocol's first major exploit since launch.

How It Was Compromised — DeFi via Smart Contract Exploit / Flash Loan

DeFiSmart Contract Exploit / Flash Loan

On March 28, 2024, Prisma Finance, an Ethereum-based stablecoin lending protocol, was exploited for approximately $12.4M. The attacker identified a flaw in the protocol's migration contract that allowed them to manipulate the system's collateral accounting. By exploiting the migration function, the attacker was able to extract approximately 3,800 ETH from the protocol's vaults. The Prisma team paused the protocol and engaged with the attacker, who later identified themselves and returned a portion of the funds.

Fund Flow & Laundering Analysis

Stolen ETH was initially moved through multiple intermediary wallets before being partially returned. The attacker, who identified themselves as a white-hat, returned approximately $3.4M worth of ETH after negotiations. Remaining funds moved through Tornado Cash. Prisma Finance offered a 10% bounty for the return of the remaining funds.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.