← Radar

Incident case file

Sign in to watch

Prism — Phantom Position Fee-Layer Exploit (Uniswap V4 Hook) + Disputed Relaunch

Incident date July 14, 2026

0 views

ResolvedEthereumFee-layer exploit (Uniswap V4 hook)Cluster: PRI-SCV-2026-07

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: MISSING — @0xsolazy post-mortem cites 'bad actor' but no address disclosed. Attacker used purpose-built helper contracts (addresses not published) to create 2,500 phantom fee-earning positions routed to Uniswap V4 PoolManager and to the Prism token contract itself (both addresses excluded from Prism's internal holder accounting).

Funds moved to: ~40% of every trading fee Prism generated between early July and July 14 diverted via 2,500 phantom fee-earning positions to attacker-controlled helper contracts. No principal theft (Prism's fixed supply, holder balances, and pool reserves were never at risk — supply cannot be inflated). Absolute USD damage not disclosed by the relaunching team @0xsolazy — described as 'small only because trading volume was low.' Cash-out path from helper contracts to attacker EOA not publicly traced. PRISM
New relaunched Prism v4 hook contract (deployed July 14): 0x7341B25dAaaFF3c4723Cb28B75DDa105EB96C040. Original abandoned Prism v4 hook contract: MISSING (not cited in the @0xsolazy post-mortem — the 2,500 phantom positions are permanent inside the old pool and cannot be removed). Two addresses used as phantom position destinations: Uniswap V4 PoolManager and Prism token contract self-referential — both deliberately excluded from Prism's internal accounting set. Relaunch team account: @0xsola

Timeline: Early July 2026 ('since the start of July' per @0xsolazy): attacker begins deploying helper contracts and creating 2,500 phantom fee-earning positions in the original Prism v4 hook contract. The exploit routes fee-earning positions to addresses that were never meant to hold one — specifically the Uniswap V4 PoolManager and the Prism token contract itself. Since these addresses are excluded from Prism's internal token accounting (they should never hold positions), a position parked there becomes a 'phantom share': it keeps earning fees while sitting outside the holder set, and its cut can be siphoned out of the pool's raw balance. Total was designed to be capped at 5,000 positions; the attacker adds 2,500 more, capturing ~40% of every trading fee flow from that point forward. Until July 14: fee diversion continues silently. July 14, 2026 ~17:59 UTC: a new independent team led by @0xsolazy (self-declared, bought PRISM on open market) publishes the full post-mortem on X (23.5K views). Disclosure of the single missing guard: 'a fee-earning position could be moved onto addresses that were never meant to hold one — the pool manager itself, and the token contract.' Same day: relaunch on new contract 0x7341B25dAaaFF3c4723Cb28B75DDa105EB96C040 with fixed guard: 'A position can only ever belong to a real holder whose token balance backs it. Routing one to the pool manager, to the contract itself, or to any address outside the accounting set now simply reverts. The attack reverts on its first step.' The old contract is abandoned (phantom positions cannot be removed). PRISM price crashes ~91%. Community response: 4 of 5 top replies hostile — 'no ones falling for your final scam you fker', 'should be in jail for actions like that', 'Do you have plans to airdrop original holders with the new contract based on the snapshot?' (no answer from the team). No official Rekt News or major security firm coverage identified — the incident sits at the edge between technical exploit and potential rebrand scam. Recommend continued monitoring.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)