Paribus Hack

TOTAL LOST $70K
Low Reentrancy arbitrum

What happened

Paribus was exploited due to a reentrancy issue, resulting in the loss of 69,696 $USD worth of $ETH.

Paribus is a cross-chain lending and borrowing protocol. The protocol suffered an exploit on the Arbitrum layer-two chain. The root cause was a well-known reentrancy vulnerability from an old version of CompoundV2 that Paribus had forked. The attacker deployed two malicious unverified contracts and used this vulnerability to withdraw funds multiple times before updating their balance on-chain. As a result, they were able to drain 35.2 $ETH which is currently worth 69,696 $USD at the time of writing.

All stolen assets were transferred through Stargate Bridge in two transactions.

Attacker address:

https://arbiscan.io/address/0x014abff0…9e5504

Malicious transaction:

https://arbiscan.io/tx/0x0e29dcf4…2390af

Malicious contracts:

https://arbiscan.io/address/0xcd31e27f…f8c50b

https://arbiscan.io/address/0xec05281d…29dfe7

Case & protocol details

Classification Borrowing and Lending / Reentrancy
Protocol Type Lending
Affected asset / contract pUSDT
Smart Contract Language Solidity
Official Website paribus.io
Protocol Twitter/X @paribus_io

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.