Prisma Finance, a decentralized finance protocol for stablecoin loans against liquid staking tokens, suffered a major exploit on March 28, 2024, resulting in losses of roughly $11.5–12.3 million in crypto assets. The primary attacker and at least two copycat addresses abused a vulnerability in the MigrateTroveZap contract, which failed to properly validate data passed in flash loan operations, allowing them to spoof migration data and steal users’ collateral during a migration process. Security firms including CertiK and PeckShield estimated that the main exploiter stole about 3,257 ETH (~$11.5M), while two additional attackers extracted roughly $600–700k more. Prisma Finance quickly paused the protocol and began an investigation, as total value locked and the PRISMA governance token price dropped sharply following the incident. Several hours after the initial transactions, an address linked to the main exploiter sent an on-chain message from the attack wallet (including address 0x2d4…7507a) claiming the operation was a “whitehat rescue” and asking whom to contact to refund the funds. Prisma Finance replied on-chain, providing a negotiations email and opening a dialogue over potential return of assets. However, subsequent on-chain behavior and messaging have been mixed: the attacker began swapping stolen assets to ETH and sending portions to Tornado Cash, an OFAC‑sanctioned mixer, raising doubts about a full restitution. In later messages, the attacker criticized Prisma’s security practices and communications, demanded that the team identify themselves and publicly apologize, and insisted on recognition for the “whitehat” effort. As of reporting from incident analyses, the episode sits in a gray area between conventional exploit and claimed whitehat intervention, highlighting ongoing tensions in DeFi between protocol security failures, opportunistic attackers, and self-described ethical hackers who sometimes seek leverage or public concessions in exchange for returning user funds.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Hacks

Comments