Paribus Hack
What happened
Paribus was exploited due to a reentrancy issue, resulting in the loss of 69,696 $USD worth of $ETH.
Paribus is a cross-chain lending and borrowing protocol. The protocol suffered an exploit on the Arbitrum layer-two chain. The root cause was a well-known reentrancy vulnerability from an old version of CompoundV2 that Paribus had forked. The attacker deployed two malicious unverified contracts and used this vulnerability to withdraw funds multiple times before updating their balance on-chain. As a result, they were able to drain 35.2 $ETH which is currently worth 69,696 $USD at the time of writing.
All stolen assets were transferred through Stargate Bridge in two transactions.
Attacker address:
https://arbiscan.io/address/0x014abff0…9e5504
Malicious transaction:
https://arbiscan.io/tx/0x0e29dcf4…2390af
Malicious contracts:
https://arbiscan.io/address/0xcd31e27f…f8c50b
https://arbiscan.io/address/0xec05281d…29dfe7
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.