Cryptocurrency [loss] $8M+

"Jimbos Protocol exploited for $7.5 million three days after V2 launch"

2023-05-28 [vendor] Jimbos Protocol [chain] ethereum
Primary Source ↗
Financial Loss $7.5M (7,500,000 USD)
Blockchain(s) Ethereum

Incident Details

Three days after the launch of its v2 protocol, the Arbitrum-based Jimbos Protocol was exploited for 4,090 ETH (~$7.5 million). The project had not properly controlled for slippage, which enabled an attacker to use a flash loan to manipulate the trading pairs on the project. The attacker then bridged the stolen funds to the Ethereum chain.After the attack, Jimbos Protocol tweeted “We are aware of the exploit regarding our protocol and are actively in contact with law enforcement and security professionals. We will release further information when possible.” They also sent an on-chain message to the exploiter, offering to stop all investigations if the hacker returns 90% of the stolen funds.

Total loss estimated at $7,500,000.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
Jimbos Protocol

Timeline

  1. 2023-05-28 Breach occurred
  2. 2023-05-28 Publicly disclosed