Chibi Finance Hack
What happened
The Chibi Finance project on the Arbitrum network was hit by a rugpull, resulting in a loss of 1,052,646 $USD.
Chibi Finance is an Arbitrum-based yield farming protocol. On June 27, 2023, a malicious transaction with draining assets from three contracts took place. A scammer used a privileged function setSettings() to set a malicious contract as a Governance contract.
They then withdrew funds from three smart contracts: StrategyAave, StrategySushiSwap, and StrategyGHA in a single transaction. Several assets were stolen, including 4.2 $WBTC, 256,012 $USDC, 94.6 $WETH, 115,049 $USDT, and SLP tokens as LP tokens for ARB/WETH pool. The stolen funds were valued at 1,052,646 $USD.
All the funds were swapped for $WETH and then bridged using Multichain and Stargate. The project's website shut down and the Twitter account was deleted shortly after an incident.
Scammer Address:
https://arbiscan.io/address/0x80c1ca8f…da58e3
Deployer Address:
https://arbiscan.io/address/0xf0b6dcb0…2acd25
Malicious Transaction:
https://arbiscan.io/tx/0x3cb65210…85db95
Funds Bridging Transactions:
https://arbiscan.io/tx/0x5fad3397…782707
https://arbiscan.io/tx/0xe7a9c825…d4f73c
Malicious Contract:
https://arbiscan.io/address/0xb6122218…0fd6ee
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.