Arbix Finance Hack
What happened
Arbitrum (ARBX) contract exploited due to onlyOwner function, leading to the minting and dumping of 10M ARBX tokens.
The ARBX contract contained a mint() function with onlyOwner, which was exploited to mint 10M ARBX tokens to 8 different addresses. Approximately 4.5M ARBX were minted in a single transaction and subsequently dumped by the recipient. The users' assets were drained from several pools, with the stolen funds being bridged to Ethereum.
The addresses involved in the exploit:
https://bscscan.com/address/0x4714a26e…61a2c4
https://bscscan.com/address/0x161262d1…2c183d
The transaction of 4.5M ARBX minting:
https://bscscan.com/tx/0x4707d30a…c3db6f
The transaction of asset draining:
https://bscscan.com/tx/0xfbba507c…f825b9
The Ethereum address where stolen funds were bridged:
https://etherscan.io/address/0xdc85c1eb…5a7a9f
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- analysis Web Archive web.archive.org
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.