GMX Releases $40 Million Vulnerability Exploitation Event Recap: Further Discussion on Compensation Measures
BlockBeats News, July 11, GMX officially released a summary report on the GMX V1 approximately $40 million exploit on Arbitrum.
Event Summary:
The attacker bypassed the PositionRouter and PositionManager contracts (usually responsible for calculating the average short price) by directly calling the Vault contract's increasePosition function through reentrancy;
Through manipulation, the attacker pushed the BTC average short price down from $109,505.77 to $1,913.70;
Using a flash loan, the attacker purchased GLP at a normal price of $1.45, opening a $15 million position;
Due to the manipulated price, the GLP price was pushed above $27, allowing the attacker to redeem GLP at a high price for profit;
GMX has confirmed that V2 does not have a similar vulnerability.
Next Step Funding Situation:
Approximately $3.6 million remains in the GLP pool, reserved for unclosed positions;
The cost of V1's GLP on Arbitrum this week is around $500,000 (excluding the 30% portion allocated to GMX stakers) and will be transferred to the DAO Treasury for compensation;
Will disable GLP minting and redemption on Arbitrum (redemption disablement requires a 24-hour Timelock);
Disable GLP minting on Avalanche but retain the redemption function;
Enable the closure of V1 positions on Arbitrum and Avalanche, disable opening positions to prevent a recurrence of the vulnerability;
Cancel V1 orders on Arbitrum and Avalanche. Remaining funds in the GLP pool on Arbitrum will be allocated to the compensation pool for use by affected GLP holders.
After the above steps are completed, the GMX DAO will discuss further compensation measures. It is recommended that all GMX V1 forks take immediate action, await fixes and audits before re-enabling trading and minting of GLP-like tokens.
You may also like

Why have foreign exchange stablecoins never taken off?

AIDC, computing power leasing, and cloud: The "three-part thesis" of AI transformation in cryptocurrency mining farms

Futu has had all its illegal gains confiscated, reminding cryptocurrency exchanges

Football, Web3 & Champions' Energy: A Recap of WEEX's LALIGA VIP Meetup in Barcelona
Pizza, Poker & AI Trading: A Recap of WEEX Crypto Pizza Day in Dubai

IOSG Founder: Please tell Vitalik the truth, let the OGs who have enjoyed the industry's dividends enlighten the young people

Morning Report | SpaceX reveals it holds approximately $1.45 billion in Bitcoin; Nvidia's Q1 financial report shows revenue of $81.6 billion; Manus plans to raise $1 billion for buyback business

Insiders: DeepSeek is forming a Harness team to compete with Claude Code

SpaceX officially submitted its prospectus, unveiling the largest IPO in history

The financial changes under the new SEC regulations: Opportunities and regulatory red lines behind "tokenized stocks"

Blockchain Capital Partner: The structure of on-chain dual-layer capital is still in the early stages of value discovery

Secured over $60 million in funding from Dragonfly, Sequoia, and others, learn about the on-chain derivatives protocol Variational | CryptoSeed

I tested with $10,000: zero wear and tear, annualized 8%, and can earn points (with complete tutorial + screenshots)

Eight departments take strong measures to regulate cross-border brokers, what do you think?
Cheers, Charts & AI: A Recap of WEEX Labs' Openguin Party Energy at ETHMilan 26

Morning Report | Deloitte acquires crypto infrastructure company Blocknative; stablecoin company Checker completes $8 million financing; a16z may have become the largest external institutional holder of HYPE

Interpretation of xBubble SOP: Packaging Vibe Coding for non-technical users




