TMX DEX contract on Arbitrum hacked: $1.4 million lost, attacker cleverly exploits minting-staking-exchange cycle

robot
Abstract generation in progress

【Crypto World】A serious security incident has occurred on the Arbitrum network. According to CertiK's monitoring data, an unaudited contract associated with the decentralized exchange TMX was hacked, resulting in approximately $1.4 million in losses.

The hacker's tactics are not particularly complicated, but executed very cleverly. They repeatedly perform a set of actions: first mint TMX LP tokens, then stake them to exchange for USDT and other assets, then convert USDT into the USDG stablecoin, and finally unstake and sell large amounts of USDG. Through multiple cycles, the hacker successfully drained USDT, wrapped SOL, and WETH from the contract little by little.

This incident serves as a reminder of how risky unverified DeFi contracts can be. Before participating in any liquidity mining or staking projects, always ensure that the contract has undergone professional security audits.

SOL0.23%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments