GMX Releases $40 Million Vulnerability Exploitation Event Recap: Further Discussion on Compensation Measures
BlockBeats News, July 11, GMX officially released a summary report on the GMX V1 approximately $40 million exploit on Arbitrum.
Event Summary:
The attacker bypassed the PositionRouter and PositionManager contracts (usually responsible for calculating the average short price) by directly calling the Vault contract's increasePosition function through reentrancy;
Through manipulation, the attacker pushed the BTC average short price down from $109,505.77 to $1,913.70;
Using a flash loan, the attacker purchased GLP at a normal price of $1.45, opening a $15 million position;
Due to the manipulated price, the GLP price was pushed above $27, allowing the attacker to redeem GLP at a high price for profit;
GMX has confirmed that V2 does not have a similar vulnerability.
Next Step Funding Situation:
Approximately $3.6 million remains in the GLP pool, reserved for unclosed positions;
The cost of V1's GLP on Arbitrum this week is around $500,000 (excluding the 30% portion allocated to GMX stakers) and will be transferred to the DAO Treasury for compensation;
Will disable GLP minting and redemption on Arbitrum (redemption disablement requires a 24-hour Timelock);
Disable GLP minting on Avalanche but retain the redemption function;
Enable the closure of V1 positions on Arbitrum and Avalanche, disable opening positions to prevent a recurrence of the vulnerability;
Cancel V1 orders on Arbitrum and Avalanche. Remaining funds in the GLP pool on Arbitrum will be allocated to the compensation pool for use by affected GLP holders.
After the above steps are completed, the GMX DAO will discuss further compensation measures. It is recommended that all GMX V1 forks take immediate action, await fixes and audits before re-enabling trading and minting of GLP-like tokens.
You may also like

Morning News | Coinbase partners with Standard Chartered Bank to expand multi-currency fiat channels; Sharplink and Forward will be included in the Russell Index; JPMorgan may issue stablecoins in the future

Morning News | Hyperliquid launches off-chain event prediction market contracts; Strategy completes $1.5 billion debt buyback; Kelp DAO announces rsETH has fully recovered

Bankless Founder: Why I Sold All My ETH

Senior Public Company Financial Audit: Taking Hashkey as an Example, Discussing Which Account to Include for Exchange Issued Platform Tokens?

How did Micron win a trillion-dollar market value while Samsung relies on technology cycles and Hynix relies on HBM?

Dialogue with AEON co-founder Leo: The real bottleneck of the Agentic Economy is not the model, but the settlement

2 years, 225 times the return? Unveiling the mysterious researcher Serenity's AI "bottleneck" investment technique

B.AI partners with BNB Chain to launch the "Billion AI Token Subsidy" celebration, fully igniting the on-chain intelligent agent ecosystem

The trillion-dollar frenzy of selling memory, profits from buying memory are halved

Who can make money in the era of Agents?

From brokerages to banks, Hong Kong intensifies efforts to clean up cross-border investment account openings

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

Morning Report | Binance launches DYOR research tool; YZi Labs launches recruitment platform YZi Talent; Vitalik states that the Ethereum Foundation will "downsize" and reduce the amount of ETH sold

Insiders betting on Musk are reaping "historic returns."

Ten Thousand Characters Breakdown of On-Chain Vaults: Eight Major Tracks, Who is Rising and Who is Declining?

Behind NEAR's Doubling: 3 Major Trends Becoming the Engine of Coin Prices

Visa and Stripe are both working on stablecoins, but their focus is not on payments

