• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

GMX Hit by Hack: $40 Million Stolen

user avatar

by Giorgi Kostiuk

4 hours ago


As a result of an attack on the GMX V1 GLP pool, over $40 million was stolen, once again questioning the security of decentralized finance protocols. The protocol halted trading after the incident.

Overview of the GMX V1 GLP Attack

On July 9, 2023, GMX confirmed an attack on its V1 GLP pool on the Arbitrum platform, resulting in over $40 million worth of tokens stolen in a single transaction. The attacker manipulated the GLP vault mechanism, causing the protocol to halt trading and pause the minting and redeeming of GLP on both Arbitrum and Avalanche.

Exploitation Mechanism and Consequences

Experts believe that the attack was carried out by manipulating the leverage mechanism to mint excessive GLP tokens without proper collateral. By inflating their position, the attacker exchanged the fraudulently minted GLP for underlying assets, leaving the pool short over $40 million. The funds were swiftly moved using a malicious contract funded through Tornado Cash, with approximately $9.6 million bridged from Arbitrum to Ethereum and converted to DAI.

Security Issues in DeFi

GMX's contracts were audited by top firms like Quantstamp and ABDK Consulting, but no audits identified the vulnerability that allowed the leverage exploitation. This raises questions about the reliability of existing security measures in DeFi. Despite having a $5 million bug bounty program, the attack on GMX highlights that even the most secure protocols can be vulnerable to specific logical flaws.

The attack on GMX V1 GLP casts doubt on the effectiveness of audits in the DeFi space. This incident serves as a reminder of the risks faced by decentralized finance protocols and the need for improved security systems.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

FOMC Considers Rate Adjustment Amid Economic Uncertainty

chest

FOMC evaluates monetary policy adjustments considering economic risks and inflation.

user avatarGiorgi Kostiuk

5,071 ETH Transfer from Consensys to SharpLink Gaming — A New Step in Cryptocurrency World

chest

The transfer of over 5,000 ETH from Consensys to SharpLink Gaming highlights the growing collaboration between traditional finance and the crypto ecosystem.

user avatarGiorgi Kostiuk

USDC on Hedera Shows Growth, HBAR ETF Still Likely

chest

Hedera recorded a 1200% increase in USDC issuance and awaits the SEC decision on HBAR ETF.

user avatarGiorgi Kostiuk

Bitcoin Achieves Historic High: Reasons Behind the Surge

chest

Bitcoin reaches a new all-time high of $112,000, updating its record amid increased investor interest and market conditions.

user avatarGiorgi Kostiuk

Bitget and xStock Introduce Continuous Tokenized Equities Trading

chest

Bitget and xStock have launched six tokenized stocks, including TSLAx and AAPLx, allowing 24/7 trading for users.

user avatarGiorgi Kostiuk

World Liberty Financial's Vote: $WLFI Token May Become Tradable

chest

World Liberty Financial is holding a vote to determine the potential trading of its token $WLFI on secondary markets.

user avatarGiorgi Kostiuk
dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.