Scan to download
BTC $71,190.69 -2.64%
ETH $2,204.67 -2.51%
BNB $592.66 -2.54%
XRP $1.33 -1.52%
SOL $82.22 -3.12%
TRX $0.3219 +0.78%
DOGE $0.0910 -2.11%
ADA $0.2396 -3.98%
BCH $423.17 -3.57%
LINK $8.77 -3.55%
HYPE $41.11 -3.22%
AAVE $90.26 -3.52%
SUI $0.9084 -4.02%
XLM $0.1517 -1.96%
ZEC $367.36 -3.03%
BTC $71,190.69 -2.64%
ETH $2,204.67 -2.51%
BNB $592.66 -2.54%
XRP $1.33 -1.52%
SOL $82.22 -3.12%
TRX $0.3219 +0.78%
DOGE $0.0910 -2.11%
ADA $0.2396 -3.98%
BCH $423.17 -3.57%
LINK $8.77 -3.55%
HYPE $41.11 -3.22%
AAVE $90.26 -3.52%
SUI $0.9084 -4.02%
XLM $0.1517 -1.96%
ZEC $367.36 -3.03%
first_img

Slow Fog: GMX v1 design flaw leads to $42 million theft, attackers manipulate global average price by creating large short positions through reentrancy

2025-07-10 13:38:54
Collection

ChainCatcher message, Slow Mist Yu Xian stated on social media: "The fundamental reason for the theft of 42 million USD from GMX last night is that GMX v1 immediately updates the global short average price (globalShortAveragePrices) when handling short positions, and this global average price directly affects the calculation of total assets under management (AUM), which in turn leads to the manipulation of GLP token prices.

The attacker exploited this design flaw by using Keeper to enable the timelock.enableLeverage feature when executing orders (a necessary condition for creating large short positions), successfully creating large short positions through reentrancy to manipulate the global average price, artificially raising the GLP price in a single transaction and profiting through redemption operations.

Doing DeFi is indeed a high-risk venture. GMX is a very established decentralized perpetual trading platform, and this time it has fallen into a big pit. The 10% white hat bounty strategy is unlikely to entice the attacker…"

app_icon
ChainCatcher Building the Web3 world with innovations.