Flash Loan Attack Drains WooFi's Arbitrum Pools for $8.5 Million
WooFi lost approximately $8.5 million on March 5th after an attacker used a flash loan to manipulate one of the protocol's price oracles on Arbitrum and drain its WooPPV2 pool contract.
Spreek, who had also been the first to report the Seneca Protocol incident the previous week, was again first to surface this attack, posting that Wootrade's WooPPV2 contract had been exploited for a total haul of $8.5 million on Arbitrum and that the contract had already been paused, meaning no further user action was required.

WooFi's team moved quickly, confirming the incident and pausing the affected pools. WooFi markets itself as a DEX spanning multiple chains, offering single-sided yield vaults, cross-chain swaps, perpetuals trading and revenue sharing.
The attack made WooFi the latest in a string of Arbitrum-based protocols hit in early 2024, following Radiant Capital, Gamma Strategies and Seneca. Analysis of the incident is credited to Spreek, PeckShield, Nick L. Franklin and WooFi's own team.
How the exploit worked
Using flash loans, the attacker distorted the price of the WOO token as reported by one of WooFi's Arbitrum oracles, enabling the borrowed funds to be repaid at an artificially reduced cost. With the price skewed, the attacker called the swap function on the WooPPV2 pool contract three separate times, extracting a combined total of roughly $8.5 million before WooFi's team caught the activity and paused the contracts - within 13 minutes of the attack starting. Despite the fast response, the attacker had already converted a significant portion of the proceeds into ETH.
On-chain details of the incident:
- Attacker's address: 0x9961190b258897bca7a12b8f37f415e689d281c4
- Attack transaction: 0x40e1b8c78083fc666cb7598efcecd0ae0af313fc41441386e4db716c2808ce07
- Attack contract: 0xD4c633C9A765bC690E1FbA566981c1F4eab52dF0
A full transaction-by-transaction breakdown of the attack flow is available via MetaSleuth. The stolen funds were routed to this Arbitrum address.
WooFi subsequently sent an on-chain message to the attacker's wallet, working on the assumption that a whitehat may have carried out the exploit, and offered a 10% bounty for the return of funds.
Root cause
In a post-mortem, WooFi explained that its v2 sPMM (synthetic proactive market maker) mechanism adjusts oracle prices in line with trade size to manage slippage and keep pools balanced. A flaw allowed a price adjustment to move beyond its intended range, and the fallback safeguard - which normally checks against Chainlink data - did not extend coverage to the WOO token itself. WooFi noted that the recent launch of a WOO lending market on Arbitrum, combined with comparatively thin liquidity for the token elsewhere on the network, made the price manipulation economically worthwhile for the attacker.
The incident is a reminder that audits and bounty programs are not guarantees of safety: WooFi's swap and oracle contracts had been reviewed by Certik as recently as October 2022, and Immunefi ran a bug bounty covering the Wooracle component through 2022-2023 - though its results were never published, and its scope reportedly did not exclude oracle manipulation or flash loan attacks. WooFi has been live on Arbitrum since November 2022.

Aftermath and broader questions
WooFi described this as the first security incident in its history, though expanding across multiple chains inherently multiplies the attack surface - a pattern becoming increasingly common as more networks interconnect. The combination of a newly introduced WOO lending market and relatively shallow liquidity for the token elsewhere appears to have created the specific conditions that made the exploit viable.
The episode also raises questions about the wisdom of running a custom, unproven oracle design rather than relying on more established, battle-tested infrastructure - a caution that applies beyond WooFi to any protocol attempting something similar. The team had publicized its sPMM design just hours before the attack took place. Whether treating Chainlink feeds as a fallback safety net - without extending that same protection to every token traded, including lower-liquidity ones like WOO - constitutes an adequate safeguard is now an open question for the protocol and others like it.
WooFi's messaging has leaned toward the theory that a whitehat was behind the attack. Regardless of the attacker's intent, the core fact remains that $8.5 million was extracted through a gap in the protocol's price-oracle safeguards.
Get new scam files the moment we publish them — usually 2–3 emails a week.