Over $6 million in various tokens from wallets belonging to on-chain DeFi platform, DeltaPrime were drained earlier today (Monday 16 September) after an apparent private key leak – and now cyber sleuth has stirred the pot alleging North Korea Lazarus Group involvement.

The DeltaPrime hack only affects the Arbitrum side of the platform. Web3 security experts on X have said that the exploit involved a hacker gaining control over an admin proxy, redirecting it to a malicious contract, and allowing the bad actors to drain over $6 million from DeltaPrime wallets.

DeltaPrime Hack First Picked Up On Social Media By Web3 Security Expert

It was first picked up by an X user named ‘Chaofan Shou‘. Shou is the co-founder of Web3 Security Analyst firm, Fuzzland. He posted earlier today, warning that DeltaPrime’s admin private keys were leaked, telling users to withdraw funds immediately. Initially, Shou claimed that $7 million had been drained before clarifying that it was actually $4 million. His last update showed that over $6 million had been stolen.

Chaofan posted details on the hack, saying a hacker had gained control of 0xx40e4ff9e018462ce71fa34abdfa27b8c5e2b1afb, the admin of proxies. Then, the hacker upgraded the proxies to point to malicious contract 0xD4CA224a176A59ed1a346FA86C3e921e01659E73.

Following the $6 million exploit, ZachXBT says he was told by DeltaPrime that all North Korean IT workers had been removed

(@zachxbt)

ZachXBT has recently published a huge expose on North Korea’s Lazarus group. Lazarus is a hacker group made up of an unknown number of individuals. It is alleged to be run by the government of North Korea. While little is known about the Lazarus Group, researchers have attributed many cyberattacks to them since 2010.

In his expose from August 15, Zach said that he had reached out to 25+ Web3 projects that had unknowingly hired malicious IT workers with links to North Korea. In relation to the DeltaPrime hack, Zach commented on Chaofan Shou’s post, saying Idk (I don’t know) if it related, but they were one of the teams with the DPRK IT workers I reached out to warn (I was told they were all removed).

RELATED: Crypto Firms On High Alert As FBI Issues A PSA Warning Of Alarming Rise In ‘Complex’ Scams Carried Out By North Korea

DeltaPrime Acknowledged The Hack, Saying The Risk Is Contained And Is ‘Focused On Asset Retrieval’

Over an hour ago, DeltaPrime posted to its X account, acknowledging the exploit. In the post, the team confirmed that only the Arbitrum arm is affected and that the Avalanche side of the platform ‘is not vulnerable.’

There have been no further updates from the team since that post at 9:55 a.m. BST. As per CoinGecko data, PRIME, the native token for the DeltaPrime platform, has reacted negatively to the news. It is down 6% in the past 24 hours. However, PRIME looks to be holding steady at around $0.997 following the team’s announcement that the risk is contained.

Following the $6 million exploit, ZachXBT says he was told by DeltaPrime that all North Korean IT workers had been removed

(COINGECKO)

DISCOVER: First Restaking Protocol On TON Raises $100 Million In Institutional Backing And Is Using The Success Of EigenLayer As Inspiration

Disclaimer: Crypto is a high-risk asset class. This article is provided for informational purposes and does not constitute investment advice. You could lose all of your capital.

Why you can trust 99Bitcoins

10+ Years

Established in 2013, 99Bitcoin’s team members have been crypto experts since Bitcoin’s Early days.

90hr+

Weekly Research

100k+

Monthly readers

50+

Expert contributors

2000+

Crypto Projects Reviewed

Google News Icon
Follow 99Bitcoins on your Google News Feed
Get the latest updates, trends, and insights delivered straight to your fingertips. Subscribe now!
Subscribe now
Alex Ioannou
Alex Ioannou
On-Chain Journalist

Chasing dreams under the Cypriot sun, Alex is an up-and-coming writer focusing on the more degen side of the crypto market. Always on the lookout for the next hot narrative, meme coin pump, or meta trend. Alex has been actively... Read More

Free Bitcoin Crash Course

  • Enjoyed by over 100,000 students.
  • One email a day, 7 days in a row.
  • Short and educational, guaranteed!
Back to top