$1.5M Stolen in Arbitrum DeFi Attack: How Hackers Struck

USDGambit and TLP on Arbitrum lost $1.5 million after an attacker gained admin access, deployed malicious contracts, and funneled funds through Tornado Cash, highlighting ongoing DeFi security risks.

Two Arbitrum-based projects, USDGambit and TLP, suffered a coordinated exploit resulting in the unauthorized withdrawal of approximately $1.5 million. The attacker gained administrative access after the deployer lost control of a privileged account, allowing the deployment of malicious contracts via ProxyAdmin permissions. This enabled the attacker to drain funds from both protocols. The stolen assets were swiftly bridged to Ethereum and funneled through Tornado Cash, complicating tracking and recovery efforts. The incident highlights persistent vulnerabilities in Layer-2 and DeFi ecosystems, particularly regarding privileged account security and proxy contract governance. Analysts note that such attacks are increasingly targeting smaller protocols by exploiting governance or admin roles, following patterns seen in previous high-profile exploits. The event underscores the urgent need for robust security and monitoring solutions, even for less prominent projects, as attackers continue to exploit weaknesses in decentralized finance infrastructure.

Related Tokens

Related News