GMX has publicly acknowledged the $42 million exploit on its V1 platform and is offering the attacker a 10% white-hat bounty—approximately $4.2 million—if the stolen funds are returned within 48 hours.

GMX has publicly acknowledged the $42 million exploit on its V1 platform and is offering the attacker a 10% white-hat bounty—approximately $4.2 million—if the stolen funds are returned within 48 hours.
DL News
Revision history

17 recorded changes

Want your article here?

Promote with Leviathan News

Decentralised derivatives exchange GMX has confirmed that its GMX V1 GLP pool on Arbitrum was exploited on 9 July 2025 for around $42 million in crypto assets, and is now publicly offering the attacker a 10% “white‑hat” bounty – roughly $4.2 million – if 90% of the funds are returned within 48 hours. The team halted all trading and GLP minting/redemption on GMX V1 across Arbitrum and Avalanche as an immediate response and stressed that GMX V2, the GMX token, and other liquidity pools were not affected. Security analyses attribute the incident to a re‑entrancy vulnerability and flawed internal accounting logic in GMX V1’s PositionManager.executeDecreaseOrder function and GLP pricing/AUM calculations. The attacker used a malicious contract to gain re‑entrant access during refund handling, artificially manipulated assets under management and GLP prices, then cycled GLP minting and redemption to drain value from the vault, ultimately extracting more than $42 million in ETH, WBTC, USDC and other assets. This exploit, introduced by earlier contract changes, highlights ongoing smart‑contract risk in DeFi and underscores the need for robust re‑entrancy protections and accounting design. GMX is working with security firms and auditors on a full post‑mortem and recovery plan, with the bounty offer aimed at maximising fund recovery while avoiding a protracted legal and investigative process.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on GMX

Comments