{"investigation":{"slug":"themis-protocol","entity_name":"Themis Protocol","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Themis Protocol is a DeFi lending and borrowing platform deployed on Arbitrum that allows users to collateralize Uniswap v3 LP positions and Balancer LP tokens to borrow stablecoins and blue-chip assets. On June 27, 2023, approximately eleven days after its beta launch, the protocol suffered a flash loan oracle manipulation exploit resulting in approximately $370,000 in losses. The attacker laundered the stolen funds via Tornado Cash, the protocol was suspended indefinitely, and TVL effectively dropped to near zero following the incident.","sections":[{"content":"Themis Protocol is a decentralized, multi-chain supported peer-to-pool lending and borrowing platform founded in 2021 and headquartered in Singapore. The protocol was designed to allow liquidity providers to collateralize their Uniswap v3 LP positions and Balancer LP tokens in order to borrow stablecoins and blue-chip digital assets, enabling leveraged capital to remain in liquidity pools while unlocking additional liquidity for the holder. The project raised $2 million in a November 2021 seed round with backers including DAO Maker, NFX, LD Capital, and Ghaf Capital. Themis publicly promoted security as a core priority, citing multiple audits from PeckShield in its documentation. The protocol was deployed on Arbitrum One as its primary chain. Prior to the exploit, the protocol had grown to approximately $1 million in total value locked (TVL) within days of its June 16, 2023 beta launch.","heading":"Protocol Overview","sources":[{"url":"https://blog.themis.exchange/themis-the-first-defi-nft-lending-protocol-raises-2m-with-multiple-backers-including-dao-maker-4554fb9f578f","name":"blog.themis.exchange","type":"other","credibility":3},{"url":"https://defillama.com/protocol/themis-protocol","name":"defillama.com","type":"other","credibility":3},{"url":"https://github.com/Themis-protocol/Introduction","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 27, 2023, Themis Protocol was exploited on the Arbitrum One network via a flash loan attack that took advantage of a flawed Balancer LP token price oracle. The attack occurred approximately eleven days after the protocol's beta launch on June 16, 2023. The attacker, identified by the on-chain address 0xdb73eb484e7dea3785520d750eabef50a9b9ab33, initiated the exploit by obtaining approximately 40,000 WETH through flash loans sourced from Aave v3 and two Uniswap v3 pools. The attacker deposited 220 WETH as collateral to borrow DAI, USDC, USDT, ARB, and WBTC from Themis. The attacker then supplied 55 WETH to a Balancer pool containing wstETH and WETH, receiving approximately 54.665 BLP tokens. These BLP tokens were deposited into Themis as collateral. The attacker proceeded to swap 39,725 WETH into approximately 2,423 wstETH, artificially inflating the BLP token price, and used the manipulated collateral value to borrow 317.62 WETH from the protocol. The attacker reversed the swap, repaid all flash loans, and extracted profits. The drained amount totaled approximately 220 wrapped ETH, nominally worth around $417,000, though due to liquidity constraints only approximately 94 ETH (~$178,000) and approximately $190,000 in stablecoins were successfully converted, yielding a total haul of approximately $368,000–$370,000. Stolen funds were subsequently cross-chained via Stargate Finance into ETH, and approximately 191 ETH were laundered through Tornado Cash.","heading":"Flash Loan Oracle Manipulation Exploit (June 2023)","sources":[{"url":"https://neptunemutual.medium.com/how-was-themis-protocol-exploited-79844ff4f97b","name":"neptunemutual.medium.com","type":"other","credibility":3},{"url":"https://smartcontract.tips/articoli/flash-loan-attack-themis-en/","name":"smartcontract.tips","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/themis-protocol-hack-analysis-7241f6470b2e","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://arbiscan.io/address/0xdb73eb484e7dea3785520d750eabef50a9b9ab33","name":"arbiscan.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The root cause of the exploit was an inaccurate and manipulation-susceptible price oracle for Balancer LP (BLP) tokens. The protocol calculated LP token prices by multiplying individual token prices by their respective pool quantities, summing the results, and dividing by the total LP token supply. This approach was vulnerable because an attacker could temporarily inflate the ratio of tokens within the pool via a large swap, causing the oracle to return an inflated price for BLP tokens. The protocol did not employ time-weighted average prices (TWAP) or any other manipulation-resistant pricing mechanism, making the oracle trivially exploitable via flash loans within a single transaction block. A related vulnerability had been publicly documented even earlier: a GitHub issue filed in the Themis-protocol/Solidity-Open-Source repository on March 28, 2022, flagged that the Uniswap v3 LP pricing formula used by the protocol relied on spot price from the pool's slot0 rather than a TWAP, which is a well-known vector for price manipulation. This issue, labeled High Risk and associated with Immunefi, was assigned internally and closed, but the underlying class of vulnerability — spot-price-based LP oracle — persisted in the Balancer LP integration that was exploited in June 2023. Security analysts noted that the vulnerable contract was at address 0x75f805 on Arbitrum One.","heading":"Root Cause: Oracle Design Vulnerability","sources":[{"url":"https://neptunemutual.medium.com/how-was-themis-protocol-exploited-79844ff4f97b","name":"neptunemutual.medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/themis-protocol-hack-analysis-7241f6470b2e","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://github.com/Themis-protocol/Solidity-Open-Source/issues/1","name":"github.com","type":"other","credibility":3},{"url":"https://smartcontract.tips/articoli/flash-loan-attack-themis-en/","name":"smartcontract.tips","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit on June 27, 2023, the Themis team suspended borrowing functions and issued a public acknowledgment of the incident. The team stated it had temporarily paused the protocol and was conducting an emergency investigation. In public communications, the team committed to 'working on plans to retrieve funds from the hacker as a win-win for everyone involved,' and stated that if the attacker did not cooperate, the team would pursue legal authorities. The team also indicated a compensation plan for affected users was being prepared. No publicly verifiable evidence of fund recovery or completion of a compensation scheme has been identified in available sources as of the time of this investigation. Following the exploit, the protocol's TVL effectively collapsed to near zero. DeFiLlama data shows a current TVL of approximately $2.16, indicating the protocol has not been meaningfully reactivated.","heading":"Team Response and Compensation Claims","sources":[{"url":"https://cryptorank.io/news/feed/1ea76-198354-themis-protocol-370000-damage-due-to-flashloan-attack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/21237749/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/themis-protocol","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Themis Protocol's documentation cited multiple audits by PeckShield as evidence of its security commitment. However, the exploited oracle vulnerability — a Balancer LP token price manipulation vector — was not caught or remediated prior to the protocol's beta launch. Additionally, a separate oracle manipulation vulnerability in the Uniswap v3 LP pricing formula had been documented in a public GitHub issue as early as March 2022, labeled High Risk, and was reportedly closed without resolving the underlying class of flaw. This sequence of events — a publicly disclosed oracle vulnerability class, claimed audits, and then a successful oracle manipulation exploit within days of launch — suggests a material gap between the protocol's stated security posture and its implemented controls. Security researchers have recommended that protocols of this type employ TWAP oracles, aggregate multiple price sources, and implement circuit-breaker mechanisms capable of detecting abnormal collateral price movements. The attack transaction hash is documented as 0xff3682 on Arbitrum One.","heading":"Security Audit Record and Pre-Launch Risk Signals","sources":[{"url":"https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://github.com/Themis-protocol/Solidity-Open-Source/issues/1","name":"github.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/themis-protocol-hack-analysis-7241f6470b2e","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://neptunemutual.medium.com/how-was-themis-protocol-exploited-79844ff4f97b","name":"neptunemutual.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain records on Arbitrum One identify the exploiter wallet as 0xdb73eb484e7dea3785520d750eabef50a9b9ab33. Following the exploit, the attacker bridged stolen assets cross-chain via Stargate Finance. Neptune Mutual's post-mortem analysis confirmed that approximately 191 ETH were subsequently deposited into Tornado Cash, a sanctioned cryptocurrency mixing service, in an effort to obscure the transaction trail. The U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash in August 2022, making its use for laundering by the attacker a further aggravating factor. The Arbiscan explorer page for the attacker address provides a public record of the exploit transactions. No documented address attribution to any known threat actor group or individual has been identified in publicly available sources.","heading":"On-Chain Evidence and Fund Flow","sources":[{"url":"https://arbiscan.io/address/0xdb73eb484e7dea3785520d750eabef50a9b9ab33","name":"arbiscan.io","type":"other","credibility":3},{"url":"https://neptunemutual.medium.com/how-was-themis-protocol-exploited-79844ff4f97b","name":"neptunemutual.medium.com","type":"other","credibility":3},{"url":"https://smartcontract.tips/articoli/flash-loan-attack-themis-en/","name":"smartcontract.tips","type":"other","credibility":3}],"severity":"medium"},{"content":"As of the time of this investigation, Themis Protocol's TVL on DeFiLlama stands at approximately $2.16, indicating the protocol is effectively dormant following the June 2023 exploit. The protocol's GitHub repositories remain publicly accessible but show no evidence of active remediation commits or a relaunched smart contract. The Themis Protocol Medium blog and official social channels have not published verified post-exploit updates in publicly indexed sources. ZachXBT, the pseudonymous on-chain investigator known for flagging DeFi exploits and scam projects, is noted as having flagged this entity; however, no specific public ZachXBT post regarding Themis Protocol was independently located and verified in available search results at the time of this investigation. The CryptoRank and Web3 Is Going Great databases both classify the incident as a confirmed hack. No regulatory filings, law enforcement actions, or fund recovery announcements have been identified.","heading":"Current Protocol Status","sources":[{"url":"https://defillama.com/protocol/themis-protocol","name":"defillama.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/1ea76-198354-themis-protocol-370000-damage-due-to-flashloan-attack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11","event":"Themis Protocol announces $2 million seed round with backers including DAO Maker, NFX, LD Capital, and Ghaf Capital.","source":"","date_original":"2021-11-01"},{"date":"2022-03-28","event":"A High Risk vulnerability in the Uniswap v3 LP pricing formula is filed in Themis Protocol's public GitHub repository, noting that use of spot price (slot0) rather than TWAP makes LP token collateral exploitable via price manipulation.","source":""},{"date":"2023-06-16","event":"Themis Protocol launches in beta on Arbitrum One. TVL grows to approximately $1 million within days.","source":""},{"date":"2023-06-27","event":"Themis Protocol is exploited via a flash loan oracle manipulation attack on Arbitrum One. Approximately $370,000 is stolen by manipulating the Balancer LP token price oracle. Attacker address: 0xdb73eb484e7dea3785520d750eabef50a9b9ab33.","source":""},{"date":"2023-06-27","event":"Themis team suspends borrowing functions and announces an emergency investigation. Team states it is preparing a compensation plan and pursuing fund recovery from the attacker.","source":""},{"date":"2023-06-28","event":"Attacker cross-chains stolen funds via Stargate Finance and begins laundering approximately 191 ETH through Tornado Cash.","source":""},{"date":"2023-06-28","event":"Multiple security firms including Neptune Mutual and SolidityScan publish post-mortem analyses of the Themis Protocol exploit.","source":""}],"sources_used":[{"url":"https://blog.themis.exchange/themis-the-first-defi-nft-lending-protocol-raises-2m-with-multiple-backers-including-dao-maker-4554fb9f578f","name":"blog.themis.exchange","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/themis-protocol","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913042030/https://defillama.com/protocol/themis-protocol","credibility":3,"archive_timestamp":"2025-09-13T04:20:30+00:00"},{"url":"https://github.com/Themis-protocol/Introduction","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829134016/https://github.com/Themis-protocol/Introduction","credibility":3,"archive_timestamp":"2026-08-29T13:40:16+00:00"},{"url":"https://neptunemutual.medium.com/how-was-themis-protocol-exploited-79844ff4f97b","name":"neptunemutual.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://smartcontract.tips/articoli/flash-loan-attack-themis-en/","name":"smartcontract.tips","type":"other","archive_url":"http://web.archive.org/web/20260113081646/https://smartcontract.tips/articoli/flash-loan-attack-themis-en/","credibility":3,"archive_timestamp":"2026-01-13T08:16:46+00:00"},{"url":"https://blog.solidityscan.com/themis-protocol-hack-analysis-7241f6470b2e","name":"blog.solidityscan.com","type":"other","archive_url":"https://web.archive.org/web/20260829124737/https://blog.solidityscan.com/themis-protocol-hack-analysis-7241f6470b2e/","credibility":3,"archive_timestamp":"2026-08-29T12:47:37+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260413104210/https://www.web3isgoinggreat.com/?id=themis-protocol-hacked-shortly-after-going-live","credibility":3,"archive_timestamp":"2026-04-13T10:42:10+00:00"},{"url":"https://arbiscan.io/address/0xdb73eb484e7dea3785520d750eabef50a9b9ab33","name":"arbiscan.io","type":"other","archive_url":"http://web.archive.org/web/20251012120854/https://arbiscan.io/address/0xdb73eb484e7dea3785520d750eabef50a9b9ab33","credibility":3,"archive_timestamp":"2025-10-12T12:08:54+00:00"},{"url":"https://github.com/Themis-protocol/Solidity-Open-Source/issues/1","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829134029/https://github.com/Themis-protocol/Solidity-Open-Source/issues/1","credibility":3,"archive_timestamp":"2026-08-29T13:40:29+00:00"},{"url":"https://cryptorank.io/news/feed/1ea76-198354-themis-protocol-370000-damage-due-to-flashloan-attack","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260830041820/https://cryptorank.io/news","credibility":3,"archive_timestamp":"2026-08-30T04:18:20+00:00"},{"url":"https://cryptonews.net/news/security/21237749/","name":"cryptonews.net","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:40.834919+00:00","updated_at":"2026-08-30T05:14:10.893769+00:00"}}