Primefi exploited for $33.4K via oracle manipulation; attacker inflated PRFI price 52x using permissionless Chainlink Data Streams to drain WHYPE lending pool.
Security & Exploits ·
Primefi suffered an oracle manipulation exploit on the HyperEVM network resulting in approximately $33.4K in losses. The attack leveraged a permissionless function in the protocol's price feed mechanism that failed to validate whether new price reports were fresher than existing ones. An attacker submitted a favorable Chainlink Data Streams report inflating PRFI's oracle price to approximately $0.11, roughly 52 times its actual market value of $0.0021.
Using a Morpho flash loan, the attacker purchased PRFI at its depressed true price from the thin WHYPE/PRFI liquidity pool, then deposited the tokens into Primefi's lending pool where the inflated oracle price treated them as substantial collateral. Against this artificially valued position, the attacker borrowed approximately 425.5 WHYPE tokens worth around $33.4K, far exceeding what the collateral's genuine market value would have supported, draining the WHYPE reserve.
The core vulnerability lay in the DataStreamConsumer.verifyReport() function's design: after confirming a Chainlink signature, it overwrote stored prices without verifying report freshness. The transaction and attacker address remain publicly visible on chain, though it is unclear whether the protocol has deployed a patch or whether affected users will recover funds.