Jimbos Protocol hack — May 2023
Incident facts
| Date of incident | |
|---|---|
| Target type | Token contract |
| Loss | $7,500,000Price at time of incident |
| Method | Flash loan attackThe attacker used a flash loan to buy JIMBO and push its price up inside the protocol's Trader Joe Liquidity Book pool, then called the JimboController contract's shift() function, which redeployed protocol-owned liquidity around the manipulated price. PeckShield identified the defect as a lack of slippage control on the liquidity-shifting operation; Numen Cyber added that shift() carried no access control, so any address could trigger arbitrary liquidity additions and removals. The attacker sold back into the newly placed liquidity, repaid the loan and kept the difference. |
| Chains | Arbitrum |
| Outcome | Unresolved |
What happened
Jimbos Protocol, an Arbitrum token project that managed its own liquidity through a JimboController contract built on Trader Joe's Liquidity Book, lost 4,090 ETH, about $7.5 million, on 28 May 2023, three days after its V2 contracts launched.
The attacker funded the operation with a flash loan, bought JIMBO to push its price up inside the pool, then called the controller's shift() function, which rebalanced protocol-owned liquidity. PeckShield, whose analysis was cited by The Register and The Block, identified the defect as a lack of slippage control on the liquidity-shifting operation. Numen Cyber's write-up adds that shift() carried no access control, so any address could trigger arbitrary liquidity additions and removals. With the pool price distorted, the redeployed liquidity sat at rates far from the real market, and the attacker sold back into it, converted the proceeds to ETH, repaid the flash loan and left with the difference.
The protocol's contracts had not been audited, a fact the project disclosed on its own website beforehand, warning that the mechanisms were experimental and that funds could be lost.
The team offered the attacker a 10 percent bounty, roughly $800,000, for return of the rest, then said it had opened a case with the New York office of the U.S. Department of Homeland Security and extended the bounty to the public for information leading to an arrest. Nothing was returned and no arrest has been reported. In September 2023 PeckShield said the full proceeds had been moved through Tornado Cash. The team subsequently rebranded to Baseline Protocol and said a future version would include a repayment structure for those affected.
Law enforcement
Jimbos Protocol said it opened a case with the New York office of the U.S. Department of Homeland Security and extended a bounty to the public for information leading to an arrest. No arrests have been reported.
Sources
- The RegisterSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- Numen Cyber LabsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Jimbos Protocol hack — May 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/jimbos-protocolhttps://itokenly.com/hacks/jimbos-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.