An attack against two small Arbitrum projects took out $1.5M. The exploit shows even obscure protocols are watched as a potential target.An attack against two small Arbitrum projects took out $1.5M. The exploit shows even obscure protocols are watched as a potential target.

Losses reach $1.5M as attackers access two DeFi smart contracts on Arbitrum

2026/01/05 20:17
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

On-chain research noted outflows from two Arbitrum-based projects. An attacker managed to gain access to two projects, launching a malicious smart contract. 

Two Arbitrum projects launched by the same deployer suffered unauthorized withdrawals for an estimated $1.5M. The attacker managed to gain admin access, replacing smart contracts with malicious versions. 

Cyvers Alert noted multiple suspicious transactions on Arbitrum, still one of the most active Ethereum-compatible L2 networks. 

Preliminary research showed the deployer of USDGambit and TLP projects may have lost access to their account. This allowed the attacker to launch a new contract with ProxyAdmin permissions, controlling both DeFi projects. The stolen funds were bridged back to Ethereum and mixed. 

Arbitrum attack follows similar small-scale smart contract exploits

The recent attack extends the trend of relatively sophisticated and targeted attacks against smaller protocols. Crypto hacks slowed down in the past year, but DeFi and individual wallets, as well as smart contracts, remain one of the main targets. 

The attack follows the recent Unleash Protocol theft, again managing to gain access to a governance process and deploy a malicious smart contract. As with previous attacks, the funds were almost immediately mixed. 

Even after last year’s outflows, Arbitrum remains one of the main venues for DeFi activity, still carrying over $3B in liquidity. 

Recent attacks targeted relatively obscure projects

Recent attacks affected relatively obscure projects, with smaller hauls. The recent attack follows a model that has been linked to DPRK hackers, which mostly use the Ethereum network and Tornado Cash to launder funds. 

In this case, the attacker chose a project with residual liquidity. USD Gambit points to a singular exchange, which will be phased out in the coming weeks. The project has been around since 2023, but it did not benefit from the recovery of DeFi and perpetual futures trading. The recent attack shows that all Web3 projects remain at risk of draining available liquidity. 

In the last quarter of 2025, Tornado Cash also showed a spike in deposits. The mixer holds record value locked, from both new hacks and older exploits. The mixer contains more than 338K ETH, surpassing even the 2021 peak. 

Arbitrum projects lose $1.5M in smart contract access attacksTornado Cash holds record ETH liquidity after deposits picked up in late 2025. | Source: Dune Analytics

Even the Railgun mixer, which requires more monitoring, has achieved peak activity at the end of 2025.

New exploiters move fast to avoid address blacklisting. However, most Web3 projects allow trading without blacklisting exploit addresses. Unlike older hacks, new exploiters tend to swap and mix their funds almost immediately, relying on a wider Web3 infrastructure.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Market Opportunity
DeFi Logo
DeFi Price(DEFI)
$0.00036
$0.00036$0.00036
+13.20%
USD
DeFi (DEFI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

The post Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO appeared on BitcoinEthereumNews.com. Aave DAO is gearing up for a significant overhaul by shutting down over 50% of underperforming L2 instances. It is also restructuring its governance framework and deploying over $100 million to boost GHO. This could be a pivotal moment that propels Aave back to the forefront of on-chain lending or sparks unprecedented controversy within the DeFi community. Sponsored Sponsored ACI Proposes Shutting Down 50% of L2s The “State of the Union” report by the Aave Chan Initiative (ACI) paints a candid picture. After a turbulent period in the DeFi market and internal challenges, Aave (AAVE) now leads in key metrics: TVL, revenue, market share, and borrowing volume. Aave’s annual revenue of $130 million surpasses the combined cash reserves of its competitors. Tokenomics improvements and the AAVE token buyback program have also contributed to the ecosystem’s growth. Aave global metrics. Source: Aave However, the ACI’s report also highlights several pain points. First, regarding the Layer-2 (L2) strategy. While Aave’s L2 strategy was once a key driver of success, it is no longer fit for purpose. Over half of Aave’s instances on L2s and alt-L1s are not economically viable. Based on year-to-date data, over 86.6% of Aave’s revenue comes from the mainnet, indicating that everything else is a side quest. On this basis, ACI proposes closing underperforming networks. The DAO should invest in key networks with significant differentiators. Second, ACI is pushing for a complete overhaul of the “friendly fork” framework, as most have been unimpressive regarding TVL and revenue. In some cases, attackers have exploited them to Aave’s detriment, as seen with Spark. Sponsored Sponsored “The friendly fork model had a good intention but bad execution where the DAO was too friendly towards these forks, allowing the DAO only little upside,” the report states. Third, the instance model, once a smart…
Share
BitcoinEthereumNews2025/09/18 02:28
Trump erupts at Fox News reporter during  roundtable: 'What a stupid question'

Trump erupts at Fox News reporter during  roundtable: 'What a stupid question'

An agitated President Donald Trump lashed out at two reporters during his White House “Saving College Sports” roundtable, complaining that the journalists failed
Share
Rawstory2026/03/07 07:19
Lyn Alden Tips Bitcoin Outperforming Gold Through to 2029

Lyn Alden Tips Bitcoin Outperforming Gold Through to 2029

The post Lyn Alden Tips Bitcoin Outperforming Gold Through to 2029 appeared on BitcoinEthereumNews.com. Bitcoin is likely to outperform gold on price performance
Share
BitcoinEthereumNews2026/03/07 07:22