Themis Protocol Hack

TOTAL LOST $370K
Low Flash Loan Attacks arbitrum

What happened

Themis Protocol suffered a flashloan exploit which leads to a $367,748 USD loss in various assets.

Themis Protocol, an Arbitrum-based lending protocol, fell victim to a flash loan attack. The attacker deployed a malicious contract with unverified source code which allowed them to exploit multiple pools of the Themis Protocol, including tArbWETH, tArbUSDC, tArbARB, tArbWBTC, tArbDAI, and tArbUSDT. The stolen assets were swapped to ETH, USDT, and USDC within the same transaction.

The attacker manipulated prices and gained 94.32 ETH ($178,453), 130,471 USDC, and 58,824 USDT, amassing a total of $367,748. The stolen funds were then bridged to the Ethereum Mainnet and subsequently transferred through TornadoCash.

Attacker address:

https://arbiscan.io/address/0xdb73eb48…b9ab33

Malicious contract:

https://arbiscan.io/address/0x05a1b877…964fca

Malicious transaction:

https://arbiscan.io/tx/0xff368294…7403d8

TornadoCash transfer transaction:

https://etherscan.io/tx/0x65551911…98ab3a

Case & protocol details

Classification Ecosystem / Borrowing and Lending / Oracle Manipulation
Protocol Type Lending
Smart Contract Language Solidity
Official Website themis.exchange/
Protocol Twitter/X @ThemisProtocol

Security review history

  • PeckShield 2022-01-11 No public report

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.