TMX Hack

TOTAL LOST $1.4M
Medium Other

What happened

On January 6, 2026, TMX decentralized exchange on Arbitrum suffered a $1.4 million exploit through an unverified contract when an attacker repeatedly executed a loop involving minting and staking TMX LP with USDT, swapping for USDG, unstaking, and selling to drain USDT, wrapped SOL, and WETH from the contract.

CertiK's monitoring systems detected the attack on an unverified smart contract associated with TMX deployed on Arbitrum, flagging the unusual transaction patterns that led to the $1.4 million loss. The attacker discovered they could execute a profitable loop that involved minting and staking TMX LP tokens using USDT, then swapping the USDT for USDG tokens, unstaking their position, and selling the acquired USDG. According to CertiK's analysis, this process was repeated numerous times in succession, with each iteration draining additional value from the contract's liquidity pools.

The vulnerability likely stemmed from improper validation of staking and minting ratios or inadequate checks on the swap pricing mechanism, allowing the attacker to extract more value than they deposited with each cycle. The repeated execution of this loop systematically drained the contract's holdings of USDT, wrapped SOL, and WETH until approximately $1.4 million worth of assets had been extracted. The use of an unverified contract suggests the exploit may have gone undetected longer due to lack of public code auditing.

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Official Website tge.tribe-dex.com/
Protocol Twitter/X @TMXTribe

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.