ArbTomb Hack
What happened
ArbTomb project was rugged by the $xToken deployer, resulting in the loss of 114,646 $USD worth of ETH.
On the day of its genesis launch, ArbTomb project experienced a rugpull on the Arbitrum layer-two chain. The attack affected ParbRewardPool contract which had $xToken as one of its assets. The attacker exploited their privilege over contracts by minting 1,000,000,000,000,000 $xTokens and transferring them into the pool since they were also deployers for this token's contract.
The exploit involved unverified source code for $xToken which allowed malicious actors to drain funds from the pool such as $WETH, $USDC, $ARB, and $SUSHI tokens. After gaining access to these funds the scammer swapped all stolen assets for 54.75 $ETH before bridging it onto Ethereum mainnet.
After that point, they used TornadoCash mixer service to move around some part (52 $ETH)of stolen funds before sending the rest (2.43$ ETH) directly to Binance hot wallet address.
Scammer address:
https://arbiscan.io/address/0x2b899942…ec81ef
Stolen funds holder address:
https://arbiscan.io/address/0x2781d100…A212E6
Malicious transaction:
https://arbiscan.io/tx/0xa54485cf…258f26
Bridging transaction:
https://arbiscan.io/tx/0x3809350b…f2782b
Malicious contract:
https://arbiscan.io/address/0x38f26758…8c5c8b
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.