GMX Releases $40 Million Vulnerability Exploitation Event Recap: Further Discussion on Compensation Measures

By: theblockbeats.news|2025/07/11 00:42:03
0
Share
copy

BlockBeats News, July 11, GMX officially released a summary report on the GMX V1 approximately $40 million exploit on Arbitrum.

Event Summary:

The attacker bypassed the PositionRouter and PositionManager contracts (usually responsible for calculating the average short price) by directly calling the Vault contract's increasePosition function through reentrancy;

Through manipulation, the attacker pushed the BTC average short price down from $109,505.77 to $1,913.70;

Using a flash loan, the attacker purchased GLP at a normal price of $1.45, opening a $15 million position;

Due to the manipulated price, the GLP price was pushed above $27, allowing the attacker to redeem GLP at a high price for profit;

GMX has confirmed that V2 does not have a similar vulnerability.

Next Step Funding Situation:

Approximately $3.6 million remains in the GLP pool, reserved for unclosed positions;

The cost of V1's GLP on Arbitrum this week is around $500,000 (excluding the 30% portion allocated to GMX stakers) and will be transferred to the DAO Treasury for compensation;

Will disable GLP minting and redemption on Arbitrum (redemption disablement requires a 24-hour Timelock);

Disable GLP minting on Avalanche but retain the redemption function;

Enable the closure of V1 positions on Arbitrum and Avalanche, disable opening positions to prevent a recurrence of the vulnerability;

Cancel V1 orders on Arbitrum and Avalanche. Remaining funds in the GLP pool on Arbitrum will be allocated to the compensation pool for use by affected GLP holders.

After the above steps are completed, the GMX DAO will discuss further compensation measures. It is recommended that all GMX V1 forks take immediate action, await fixes and audits before re-enabling trading and minting of GLP-like tokens.

-- Price

--

You may also like

a16z founder: In the age of Agents, what truly matters has changed

The best programmers in the future may not need to write code, but they must have strong logical reasoning and system architecture thinking, because code will become a cheap commodity due to AI.

The President of Kyrgyzstan meets with Sun Yuchen, and TRON collaborates with Kyrgyzstan to build a new pattern of digital economy in Central Asia

This meeting focused on the global trends in digital financial transformation, the construction of regulatory frameworks for virtual assets, and the strategic layout of the TRON ecosystem in Central Asia, marking a substantial phase in the cooperation between TRON and Kyrgyzstan in the fields of blo...

46 minutes, $292 million stolen, DeFi faces development dilemma again

"Let's withdraw from DeFi first, it's too dangerous. This time the damage is much greater than Drift/Cowswap..." said well-known DeFi investor Dovey Wang.

How to Earn Free USDT in 2026: No High Volume Required (WEEX Poker Party Guide)

Is Joker Crypto legit in 2026 or just another memecoin? Can You Really Earn Passive Income with Joker Crypto in 2026? Learn how Joker staking rewards work, how to earn NFT bonuses, expected APY ranges, gas-fee rebates, and how to avoid crypto scams before joining.

How to Get Free USDT Welcome Bonus in 2026: Earn Up to 700 USDT on WEEX

Legit Free Welcome Bonus 2026: Learn how to earn up to 700 USDT on WEEX with Auto Earn Boost Fest. Increase your balance, activate Auto Earn, and qualify automatically.

AI Agent Payments Just Got Real: Utexo × x402 Brings 50ms USDT Transactions to Internet Scale

Utexo integrates USDT into the x402 protocol, enabling 50ms instant payments embedded natively in HTTP requests. Explore how this breakthrough is rewriting the rules for AI agent payments, API monetization, and the machine-to-machine economy.

Contents

Popular coins

Latest Crypto News

Read more