Prisma Finance (2024) — Crypto Hack
Partially RecoveredAn attacker exploited a vulnerability in Prisma Finance's migration contract to drain ~$12.4M, triggering the protocol's first major exploit since launch.
Summary
An attacker exploited a vulnerability in Prisma Finance's migration contract to drain ~$12.4M, triggering the protocol's first major exploit since launch.
How It Was Compromised — DeFi via Smart Contract Exploit / Flash Loan
On March 28, 2024, Prisma Finance, an Ethereum-based stablecoin lending protocol, was exploited for approximately $12.4M. The attacker identified a flaw in the protocol's migration contract that allowed them to manipulate the system's collateral accounting. By exploiting the migration function, the attacker was able to extract approximately 3,800 ETH from the protocol's vaults. The Prisma team paused the protocol and engaged with the attacker, who later identified themselves and returned a portion of the funds.
Fund Flow & Laundering Analysis
Stolen ETH was initially moved through multiple intermediary wallets before being partially returned. The attacker, who identified themselves as a white-hat, returned approximately $3.4M worth of ETH after negotiations. Remaining funds moved through Tornado Cash. Prisma Finance offered a 10% bounty for the return of the remaining funds.