Prism is replacing its original Ethereum token contract after revealing that an attacker had been siphoning off almost 40% of the protocol’s trading fees for most of July. The move comes after the project concluded the flaw could not be safely fixed on the existing deployment.

The original PRISM token fell about 91% over the 24 hours through 2:13 p.m. ET on Tuesday. Over the same period, Bitcoin was up 4%.

How the exploit worked

Prism distributes a share of trading fees to token holders. According to the project, the attacker used specially built helper contracts to create 2,500 additional fee-earning positions beyond the 5,000 positions the token’s design was supposed to allow.

Those extra positions redirected just under 40% of every trading fee away from ordinary holders. Prism said the added positions effectively sat inside the pool and did not belong to any real holder, allowing the attacker to drain value from the fee mechanism without using the intended ownership structure.

Why Prism is abandoning the old contract

The team said a fix on the original contract was not viable because the phantom positions were embedded in the existing pool structure and counted as belonging to no one. Rather than patch the prior deployment, Prism opted to launch a new contract on Ethereum.

That decision effectively leaves the original PRISM token behind. It is not yet clear how holders of the old token will move to the replacement contract, and Prism has not provided final migration details in the source report.

What changes in the new deployment

Prism said the new contract is designed to close the route used in the exploit. Under the updated rules, a fee-earning position can only be assigned to a wallet whose token balance actually supports that position.

The team also said attempts to route a position to the pool manager or to the contract itself will now fail. Prism added that the total number of fee-earning positions can no longer rise above the 5,000 limit and that fees should only be distributed to legitimate holders.

Project background and impact

Prism said it did not originally create the project, but instead discovered it and purchased the token on the open market using its own funds. Despite its relatively small footprint, the token has drawn some outside development activity around its fee-sharing model. The source article notes that some tools have used Prism’s mechanism to create baskets of tokens across multiple chains.

The report said the overall damage was limited largely because Prism remained a small project. It also noted that losses could have been greater if the token had achieved wider adoption before the exploit was found.

More broadly, the episode highlights the risks in onchain fee-distribution systems that rely on hard caps and internal accounting rules. In Prism’s case, the project’s response was not to retrofit the original contract but to start over with a new one while leaving key migration questions unresolved.

Source: thedefiant.io