🚨 Primefi.xyz - Loss ~$33.4K (2026-09-16)
Network: HyperEVM
Type: Oracle Manipulation
Prime's PRFI price feed is exploitable. DataStreamConsumer.verifyReport() is permissionless and, after checking the Chainlink Data Streams signature, blindly overwrites the stored price for a feedId with no check that the report is newer/fresher than the one already stored.
The attacker pushed a favorable signed PRFI report, inflating PRFI's oracle price to ~$0.11 (vs ~$0.0021 real, ~52x). Using a Morpho flash loan they bought PRFI cheaply from the thin WHYPE/PRFI pool, deposited it as over-valued collateral into the lending pool, and borrowed ~425.5 WHYPE (~$33.4K) far exceeding the collateral's true value, draining the WHYPE reserve.
TX: https://hyperevmscan.io/tx/0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243
Attacker: https://hyperevmscan.io/address/0x19bc1c7fd4aa93f540498499b8f5b4fc3dde5a52
Victim: https://hyperevmscan.io/address/0xb339448e13e273f6f46e3390e0932ab7ff9f113f
⚡️ Detected by Defimon at 12:37:37 UTC
⏱️ Real-time alerts: @defimon_subscription_bot
Post #3309
913
Defimon Alerts 💌 Onchain message: PRIMEFI RECOVERY REQUEST | Incident tx: 0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243 | Please return 318.961630241143730359 HYPE (80% of the 398.702037801429662948 HYPE proceeds) to: | 0xF2e2A49631927108086268c68C559c63c3C8f73d…

- 🦄 5
- ❤ 1
- 😁 1