VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
According to CertiK Alert, a vulnerability involving a contract related to TMX on Arbitrum has been detected, with estimated losses of around $1.4 million. During the exploit loop, the attacker minted and staked TMX LP tokens using USDT, then swapped USDT for USDG, unstaked, and sold even more USDG. Attack method (per SlowMist): Contract vulnerability. Reported loss: $ 1,400,000.
Primary source
https://x.com/certikalert/status/2008360565010559045?s=46&t=DLwbX9Nw4QECiyZQ0av-fg ↗Sourced from
slowmist
Technical record
- chain
- arbitrum
- protocol
- TMX
- bug_class
- logic
- date_occurred
- 2026-01-05
- loss_usd
- $1,400,000
- source_id
- sm:tmx::2026-01-05
Related — same bug class· logic