The decentralized derivatives exchange GMX has secured an agreement from the attacker behind its roughly $40–42 million July 2025 exploit to return the stolen funds in exchange for a substantial bounty, after the hacker signaled their intent via an onchain message flagged by security firm PeckShield. The episode is becoming a textbook example of how DeFi protocols increasingly use “white hat” bounty deals and public, onchain negotiation to resolve large-scale thefts. GMX v1, deployed on Arbitrum, was drained of about $40–42 million in assets when an attacker exploited a vulnerability tied to its GLP liquidity design and related smart contract logic. Analyses describe two related issues: a design flaw that allowed manipulation of GLP token value via a targeted liquidity pool attack, and a deeper reentrancy vulnerability in the executeDecreaseOrder flow that let the attacker repeatedly interact with contracts and distort internal accounting to redeem more value than they should have been entitled to. The haul included large amounts of ETH and FRAX, among other assets. Following discovery of the exploit, the GMX team publicly posted onchain messages offering the exploiter a 10% / $5 million “white hat” bounty and promising not to pursue legal action if at least 90% of funds were returned within 48 hours, while warning of legal consequences if the demand was ignored. In response, the attacker sent an onchain message stating “ok, funds will be returned later,” which PeckShield and others highlighted as an acceptance of the bounty terms. Transfers back to GMX-controlled addresses then began in multimillion-dollar tranches, including large repayments in ETH and FRAX, bringing the total returned to roughly $40.5 million and leaving the attacker with the agreed bounty and a realized profit due in part to ETH price appreciation between the theft and the return. GMX subsequently published a technical post‑mortem, patched the exploited vulnerabilities, and used the incident to emphasize the need for exhaustive audits and careful handling of complex state dependencies in DeFi protocol design. The case is significant for the broader sector because it illustrates both the risks of composable, high‑leverage derivatives architectures and the growing practice of treating successful exploiters as de facto security researchers when they agree to return funds under structured bounty deals. "entities":["GMX","GMX v1","GLP","PeckShield","PeckShieldAlert","FRAX","ETH (Ether)","Arbitrum","GMX Exploiter / GMX hacker","Halborn"]}'}]}

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on GMX

Comments