{"id":79449,"date":"2023-05-28T16:08:27","date_gmt":"2023-05-28T13:08:27","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=79449"},"modified":"2025-09-11T11:06:59","modified_gmt":"2025-09-11T08:06:59","slug":"hackers-siphoned-more-than-7-5-million-from-defi-project-jimbos-protocol","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/hackers-siphoned-more-than-7-5-million-from-defi-project-jimbos-protocol\/","title":{"rendered":"Hackers siphoned more than $7.5 million from DeFi project Jimbos Protocol"},"content":{"rendered":"<p>The Arbitrum-based project Jimbos Protocol was attacked, with unknown actors withdrawing 4,090 ETH (more than $7.5 million at the time of writing). PeckShield analysts reported.<\/p>\n<p>The project team <a href=\"https:\/\/twitter.com\/jimbosprotocol\/status\/1662711995072909312?s=20\">confirmed<\/a> the exploit. The developers said they are actively contacting law enforcement and security experts.<\/p>\n<p>They also <a href=\"https:\/\/etherscan.io\/tx\/0xa77e60f93a350588211275c20d6e05b3b134b3e0de9d15f9cbd77c9e8782912b\">published<\/a> in the Ethereum blockchain a message in which they offered the hackers to return the stolen assets for a 10% reward and drop the pursuit. As of writing, no funds had been sent to the address specified by the team.<\/p>\n<p>PeckShield noted that the exploit was linked to a \u201cslippage control deficiency\u201d in relation to tokens under the protocol&#8217;s management. According to the analysts, the stolen funds were routed through the Stargate infrastructure and <a href=\"https:\/\/u1f987.com\/en\/news\/what-are-cross-chain-bridges\">Celer Network<\/a>.<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p lang=\"en\" dir=\"ltr\">Here comes the flow of stolen funds. <a href=\"https:\/\/twitter.com\/jimbosprotocol?ref_src=twsrc%5Etfw\">@jimbosprotocol<\/a> <a href=\"https:\/\/t.co\/HkUtTFZILv\">pic.twitter.com\/HkUtTFZILv<\/a><\/p>\n<p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1662651234254299136?ref_src=twsrc%5Etfw\">May 28, 2023<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Numen Cyber said that for the attack the attackers initiated <a href=\"https:\/\/u1f987.com\/en\/news\/what-are-flash-loans\">flash loan<\/a> of 10,000 ETH. These assets were used to manipulate the price of the JIMBO token, followed by draining liquidity pools.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">? The attacker initiated a <a href=\"https:\/\/u1f987.com\/en\/news\/what-are-flash-loans\">flash loan<\/a> of 10,000 <a href=\"https:\/\/twitter.com\/search?q=%24ETH&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$ETH<\/a> as initial capital<\/p>\n<p>? Then the <a href=\"https:\/\/twitter.com\/search?q=%24ETH&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$ETH<\/a> was swapped for a significant amount of <a href=\"https:\/\/twitter.com\/search?q=%24Jimbo&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$Jimbo<\/a> in the [ETH-Jimbo] causing a surge in the price of <a href=\"https:\/\/twitter.com\/search?q=%24Jimbo&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$Jimbo<\/a> <a href=\"https:\/\/t.co\/7BauCRLqA0\">pic.twitter.com\/7BauCRLqA0<\/a><\/p>\n<p>\u2014 Numen Cyber (@numencyber) <a href=\"https:\/\/twitter.com\/numencyber\/status\/1662748403972071429?ref_src=twsrc%5Etfw\">May 28, 2023<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Jimbos Protocol originally launched on May 16. Shortly after launch, the team abandoned the first version of the protocol due to a critical bug in the smart contracts and unveiled a second iteration of the app.<\/p>\n<p>According to <a href=\"https:\/\/dexscreener.com\/arbitrum\/0x16a5d28b20a3fddecdcaf02df4b3935734df1a1f\">DEX Screener<\/a>, amid news of the hack, the JIMBO token price fell by 25%. As of writing, the asset trades near $0.18.<\/p>\n<p>Earlier in May 2023, unknown <a href=\"https:\/\/u1f987.com\/en\/news\/deus-finance-defi-protocol-hacked-for-6-million\">withdrew assets worth $6 million<\/a> from the Deus Finance DeFi protocol.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Arbitrum-based project Jimbos Protocol was attacked, with unknown actors withdrawing 4,090 ETH (more than $7.5 million at the time of writing).<\/p>\n","protected":false},"author":1,"featured_media":79450,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1335,44,1093],"class_list":["post-79449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-arbitrum-arb","tag-cybercrime","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"12","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=79449"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79449\/revisions"}],"predecessor-version":[{"id":79451,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79449\/revisions\/79451"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/79450"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=79449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=79449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=79449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}