Themis Protocol Hack
What happened
Themis Protocol suffered a flashloan exploit which leads to a $367,748 USD loss in various assets.
Themis Protocol, an Arbitrum-based lending protocol, fell victim to a flash loan attack. The attacker deployed a malicious contract with unverified source code which allowed them to exploit multiple pools of the Themis Protocol, including tArbWETH, tArbUSDC, tArbARB, tArbWBTC, tArbDAI, and tArbUSDT. The stolen assets were swapped to ETH, USDT, and USDC within the same transaction.
The attacker manipulated prices and gained 94.32 ETH ($178,453), 130,471 USDC, and 58,824 USDT, amassing a total of $367,748. The stolen funds were then bridged to the Ethereum Mainnet and subsequently transferred through TornadoCash.
Attacker address:
https://arbiscan.io/address/0xdb73eb48…b9ab33
Malicious contract:
https://arbiscan.io/address/0x05a1b877…964fca
Malicious transaction:
https://arbiscan.io/tx/0xff368294…7403d8
TornadoCash transfer transaction:
https://etherscan.io/tx/0x65551911…98ab3a
Case & protocol details
Security review history
- PeckShield No public report
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.