GMX suffered a hacker attack, resulting in losses of more than $40 million. The attacker exploited a reentrancy vulnerability and opened a short position while the leverage function of theGMX suffered a hacker attack, resulting in losses of more than $40 million. The attacker exploited a reentrancy vulnerability and opened a short position while the leverage function of the

Losses exceeded $40 million, GMX hacking incident analysis

2025/07/10 11:00

GMX suffered a hacker attack, resulting in losses of more than $40 million. The attacker exploited a reentrancy vulnerability and opened a short position while the leverage function of the contract was enabled.

The root of the problem lies in the incorrect use of the executeDecreaseOrder function. The first parameter of the function should have been an external account (EOA), but the attacker passed in a smart contract address. This allowed the attacker to re-enter the system during the redemption process, manipulate the internal state, and ultimately redeem assets far exceeding the actual value of the GLP they held.

GLP normal redemption mechanism

In GMX, GLP is a liquidity provider token that represents a share of treasury assets (such as USDC, ETH, WBTC). When a user calls unstakeAndRedeemGlp, the system uses the following formula to calculate the amount of assets that should be returned:

redeem_amount = (user_GLP / total_GLP_supply) * AUM

The calculation method of AUM (total assets under management) is:

AUM = Total value of all token pools + Global short unrealized losses - Global short unrealized profits - Reserved amount - Default deduction (aumDeduction)

This mechanism ensures that GLP holders receive a proportional share of the actual assets of the treasury.

Problems after leverage is enabled

When enableLeverage is turned on, users can open leveraged positions (long or short). The attacker opened a large WBTC short position before redeeming GLP.

Since the short position increases the global short size as soon as it is opened, the system assumes that the short position is losing money when the price has not changed, and this part of the unrealized loss will be counted as the "asset" of the vault, causing the AUM to artificially increase. Although the vault does not actually gain additional value, the redemption calculation will be based on this inflated AUM, allowing the attacker to obtain assets far exceeding what he deserves.

Attack Process

Attacking transactions

Losses exceeded $40 million, GMX hacking incident analysis

Losses exceeded $40 million, GMX hacking incident analysis

Written at the end

This attack exposed serious flaws in GMX's leverage mechanism and reentrancy protection design. The core problem is that the asset redemption logic places too much trust in AUM and does not conduct sufficiently prudent security checks on its components (such as unrealized losses). At the same time, key functions also lack mandatory verification of the caller's identity assumptions (EOA vs contract). This incident once again reminds developers that when it comes to sensitive operations involving funds, they must ensure that the system state cannot be manipulated, especially when introducing complex financial logic (such as leverage, derivatives), and they must strictly prevent systemic risks caused by reentrancy and state pollution.

Piyasa Fırsatı
Moonveil Logosu
Moonveil Fiyatı(MORE)
$0.002809
$0.002809$0.002809
+7.33%
USD
Moonveil (MORE) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Elon Musk’s net worth hits record $749B after legal win restores massive Tesla compensation

Elon Musk’s net worth hits record $749B after legal win restores massive Tesla compensation

The post Elon Musk’s net worth hits record $749B after legal win restores massive Tesla compensation appeared on BitcoinEthereumNews.com. Key Takeaways Elon Musk
Paylaş
BitcoinEthereumNews2025/12/21 10:13
CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Paylaş
BitcoinEthereumNews2025/09/18 00:56
Elon Musk’s Wealth Soars to $749 Billion as Delaware Supreme Court Reinstates Tesla Stock Option

Elon Musk’s Wealth Soars to $749 Billion as Delaware Supreme Court Reinstates Tesla Stock Option

The post Elon Musk’s Wealth Soars to $749 Billion as Delaware Supreme Court Reinstates Tesla Stock Option appeared on BitcoinEthereumNews.com. COINOTAG News reports
Paylaş
BitcoinEthereumNews2025/12/21 09:46