Flash Loan Drains $7.5M From Jimbo's Protocol Days After Arbitrum Relaunch
Arbitrum's run of exploits continued into the weekend. Jimbo's Protocol was hit by a flash loan attack in the early hours of Sunday, with losses totaling $7.5 million.
Jimbo's Protocol sets out to build a semi-stablecoin through a rebalancing mechanism — a design that draws obvious comparisons to OHM. The exploit landed just after the project relaunched its v2 build, an attempt to correct course following a flawed v1 launch that had collapsed earlier the same month.

Trader UltraXBT summed up the skepticism circulating beforehand:
Kinda sus $JIMBO v1 failed because it was way too complicated and now 1 week later they have decided to launch a v2 with even more complexity by adding leverage
Very dope if they succeed and rooting for them but this is a lot of moving parts for a defi protocol
Those concerns proved warranted: just three days after v2 went live, warnings started circulating that something was wrong. The team itself didn't confirm the incident until roughly six hours after the alarm had already been raised on Twitter.
This is the sixth Arbitrum-based incident covered this year, following losses at dForce Network, Dexible, Hope Finance, Deus DAO (its third appearance), and Swaprum — a pace that echoes the wave of BSC exploits seen in spring 2021.
01The mechanism
Analysis credited to Peckshield and Numen Cyber pinned the root cause on missing slippage protection inside the shift() function of the JimboController contract.
The attacker borrowed 10,000 ETH via flash loan and used it to aggressively buy JIMBO, pushing its price sharply upward. By then depositing a portion of that now-overvalued JIMBO back into the JimboController, the attacker triggered a rebalance through shift(), which moved the contract's WETH holdings back into the liquidity pool. With WETH now sitting in the pool, the attacker sold the remaining JIMBO holdings into it, draining the pool's WETH liquidity entirely and crashing the JIMBO price in the process.
Key on-chain details:
- Attacker's address: 0x102be4bccc2696c35fd5f5bfe54c1dfba416a741
- Destination of the stolen ETH: 0x5f3591e2921d5c9291f5b224e909ab978a22ba7e
- Attack transaction: 0x3c6e053f…
Over 4000k ETH (roughly $7.5 million) was subsequently bridged back to Ethereum mainnet, where it remains held at the address above.

02Negotiating with the attacker
The Jimbo's Protocol team has since reached out on-chain to the attacker, proposing a 10% bounty in exchange for returning the funds. To apply pressure, they issued a public ultimatum:
We are already working with multiple security researchers and on-chain analysts who helped with both the Euler Finance and Sentiment exploits.
We will start working with law enforcement agencies tomorrow by 4PM UTC if this isn't sorted out by then.
As of now, the attacker has not responded, leaving Jimbo's Protocol — and the $7.5 million — in limbo, with no indication yet of whether a v3 attempt lies ahead.
Get new scam files the moment we publish them — usually 2–3 emails a week.