GoCheckMyCrypto.com
Crypto Cronkite And that's the way it is.
Verifiednewssecuritybitcoinethereum

Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees

A flaw in Prism, a Uniswap v4 fee-sharing token, allowed an attacker to create 2,500 unauthorized positions that siphoned nearly 40% of trading fees. The original PRISM token collapsed 91% in 24 hours. A pseudonymous team now relaunching the project on a patched contract.

An attacker exploited a single missing code check in Prism, a Uniswap v4 fee-sharing token, to create 2,500 unauthorized positions that siphoned nearly 40% of all trading fees away from ordinary holders. The original PRISM token collapsed approximately 91% in 24 hours through Tuesday afternoon, according to The Defiant, dropping from a high of roughly $1,145 on June 3 to near $16, for a market value of about $82,000 on $288,000 of 24-hour volume. The same Bitcoin index ticked up 4% over the window.

Prism is built as a Uniswap v4 hook, a piece of code that allows a token to function as its own liquidity pool, so that holding it earns a cut of trading fees without manual staking. The flaw allowed a fee-earning position to be transferred to addresses never meant to hold one, including the pool manager and the token contract itself, creating phantom positions that collected fees while counting as no one's property. The attacker spent most of July siphoning fees before the flaw was discovered, according to the team's account, though the absolute dollar loss remained limited only because Prism never took off and trading volume was low.

A patch on the original deployment would not work because the phantom positions sit inside the pool and cannot be removed. A team identifying themselves only through pseudonymous account @0xsolazy announced the relaunch, stating they did not create Prism but found it and bought the token on the open market with their own money. This account has not been independently verified. In the new contract, a position can belong only to a wallet whose token balance backs it, and any attempt to route one to the pool manager or contract itself now fails outright.

Spectrum, a tool for launching baskets of tokens, uses Prism and has deployed baskets across Ethereum, Base, and Robinhood's chain. Prism promoted several baskets including one holding Sky, Aave, Maple, Curve, Spark, Ondo, and Ethena tokens, according to The Defiant's reporting.

The team offered no independent security review of either the exploit or the fix. The attacker's extended access to the fee stream, spanning most of July, underscores the time lag between deployment and discovery. Migration mechanics from the old token to the new contract remain unspecified, and no compensation framework or exchange rate has been announced. The same structural flaw in a protocol with higher trading volume could have produced substantially greater losses, the team acknowledged.

The key fact

The original PRISM token declined 91% in 24 hours after an attacker exploited a code flaw to create phantom fee-earning positions, diverting nearly 40% of all trading fees.

The Bottom Line

Watch for the announcement of migration mechanics and whether the team pursues a third-party security audit before the new contract begins trading. If migration terms prove unfavorable or the relaunch stalls, it will signal whether recovery from such flaws is viable in pseudonymous-team protocols.

And that's the way it is.

Crypto Cronkite The Crypto Cronkite Desk · automated newsroom Passed our automated editorial review: ranked, source-checked, and verified by the desk's independent review pass.

Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.