المؤلف | آشير ( @أشير_0210 ) Last night, the GMX platform , a leading DeFi protocol on the chain , suffered a major security incident. More than 40 million US dollars of تشفير assets were stolen by hackers, involving WBTC, WETH, UNI, FRAX, LINK, USDC, USDT and other mainstream tokens. After the incident, Bithumb issued an announcement announcing that the deposit and withdrawal services of GMX will be suspended until the network is stable. Affected by the theft, the GMX token fell by more than 25% in 4 hours, and the price once fell below $11, and is now at $11.8. According to DefiLlama data, GMX TVL fell from $500 million before the theft to $400 million, a short-term drop of up to 20%. Next, Odaily Planet Daily will sort out the reasons for the GMX theft, the team’s response, and the latest trends of hackers. Attacker exploits reentrancy vulnerability
The root cause of the GMX theft is a reentrancy vulnerability in the core function executeDecreaseOrder. The first parameter of the function should have been an external account (EOA), but the attacker passed in a smart contract address, which allowed the attacker to re-enter the system during the redemption process and manipulate the internal state. Ultimately, the redeemed assets far exceeded the actual value of the GLP they held.
SlowMist partner and chief information security officer 23pds posted on the X platform that in GMX V1, the establishment of a short position will immediately update the global short average price (globalShortAveragePrices), which directly affects the calculation of total assets under management (AUM), and thus affects the valuation and redemption amount of GLP tokens.
The attacker took advantage of GMXs design of enabling the timelock.enableLeverage function during order execution (a prerequisite for opening large short positions) and triggered a reentrancy vulnerability in the executeDecreaseOrder function through a contract call. Using this vulnerability, the attacker repeatedly created short positions, artificially raising the global average short price without actually changing the market price.
Since AUM relies on this price calculation, the platform mistakenly included the inflated short losses in the total assets, causing the GLP valuation to be artificially inflated. The attacker then redeemed GLP and withdrew assets far in excess of his share, realizing huge profits.
Attack transaction example: https://app.blocksec.com/explorer/tx/arbitrum/0x03182d3f0956a91c4e4c8f225bbc7975f9434fab042228c7acdc5ec9a32626ef?line=93 GMX official response: The GLP liquidity pool of GMX V1 on Arbitrum was attacked by a vulnerability, and the GMX V2 version was not affected In response to this major security incident, the GMX team has made an official response as soon as possible. It posted on the X platform that the GLP pool of GMX V1 on the Arbitrum platform was attacked by a vulnerability, and about $40 million of tokens have been transferred from the GLP pool to an unknown wallet. Security partners have participated in the investigation of this attack. Currently, the Arbitrum and Avalanche platforms have disabled transactions for GMX V1 and the minting and redemption functions of GLP to prevent any further attacks, but the vulnerability does not affect the GMX V2 version or the GMX token itself. Since GMX V1 has been attacked, users can reduce the risk by doing the following: Disable leverage: Call Vault.setIsLeverageEnabled(false) to turn it off; if Vault Timelock is used, call Timelock.setShouldToggleIsLeverageEnabled(false). Set maxUsdgAmounts of all tokens to 1: Use Vault.setرمز مميزConfig or Timelock.setTokenConfig to prevent GLP from being further minted. It is worth noting that this value must be set to 1, not 0, because setting it to 0 means there is no upper limit, which will cause the vulnerability to continue to be exploited. According to the latest update, the official said that it was confirmed that the attack was only aimed at GMX V1, and the GMX V2 version of the contract did not use the same calculation mechanism. However, out of caution, GMX has updated the upper limit of GMX V2 version tokens on Arbitrum and Avalanche, so the minting of new tokens in most liquidity pools is currently restricted. Once this restriction is lifted, you will be notified as soon as possible. In addition, on-chain data shows that GMX has left a message to the hackers address, admitting that it has encountered a vulnerability in the GMX Vl version and is willing to provide a 10% white hat bounty. If the remaining 90% of the funds are returned within 48 hours, it will promise not to take further legal action.GMX has left a message to the hacker address and is willing to provide a 10% white hat bounty
Hackers have moved over $30 million to new addresses Judging from the signs on the chain, this was a long-planned action. The hackers initial funds were transferred from the privacy mixing protocol Tornado Cash a few days ago, indicating that they had already made sufficient preparations for this attack. After stealing more than $40 million in crypto assets, hackers quickly transferred more than $30 million in assets. According to on-chain data, the GMX hacker marked address (address: https://debank.com/profile/0xdf3340a436c27655ba62f8281565c9925c3a5221 ) has transferred 88 BTC (worth approximately US$9.8 million), more than 2,200 ETH (worth approximately US$5.85 million), more than 3 million USDC, and more than 1.3 million DAI to the new address 0x99cdeb84064c2bc63de0cea7c6978e272d0f2dae ; and transferred more than 4,300 ETH (worth approximately US$11 million) to the new address 0x6acc60b11217a1fd0e68b0ecaee7122d34a784c1 . In total, more than $30 million in funds have been transferred to other new addresses.Hackers stole over $40 million in assets
The remaining $10 million in funds in the current hacker address has not yet been transferred
Chain detective ZachXBT published an article on the X platform criticizing Circle for its inaction on the hacker behavior. He said that the GMX attack had occurred 1 to 2 hours ago, but Circle did not take any action against the hacker behavior. The attacker even used Circles cross-chain transfer protocol CCTP to transfer the stolen funds from Arbitrum to Ethereum. ملخصThis theft not only revealed the key flaws of GMX V1 in caller permission verification, status update timing, and leverage mechanism design, but also once again sounded the alarm for the entire industry: in a system involving complex financial logic (such as leverage, dynamic pricing) and contract execution paths, any unprotected entry may evolve into the starting point of a black swan event.
It is worth noting that hackers have exchanged most of the stolen assets for cryptocurrencies that are more difficult to freeze, especially decentralized assets such as ETH and DAI, and dispersed the funds through multiple new addresses, further increasing the difficulty of tracking and recovering them. The 10% white hat bounty in exchange for exemption plan proposed by GMX also exposes the current reality of the lack of a unified legal accountability mechanism in the Web3 world.
For DeFi developers, perhaps the question they should think about more is not “how did the hacker succeed”, but whether sufficient mechanisms have been established to limit the occurrence of the most extreme attack paths when the system manages the real assets of users. Otherwise, no matter how perfect the product logic is, once there is a lack of security boundary design, it will eventually be difficult to escape the cost of systemic risk.
This article is sourced from the internet: More than $40 million stolen, GMX ambushed Related: Can the PoL mechanism be saved? Looking at the liquidity game from the new low of BERA Original author: 1912212.eth, Foresight News Recently, the price of BERA has dropped to $2.66, a new low since the TGE in February this year. BERA has been falling since March. What happened to the once popular Berachain? TVL dropped from 3.4 billion to 1.147 billion As an emerging public chain, Berachain has attracted much attention from the market for its Meme culture, liquidity mechanism, and support from well-known VCs before its mainnet launch. Its core innovation lies in its Proof of Liquidity (PoL) mechanism, which incentivizes on-chain liquidity through BGT emissions and bribes. However, the complexity of this mechanism makes it difficult to attract new users and also exposes sustainability issues. PoL relies on the continuous injection of liquidity, but when the market environment deteriorates or incentives decrease, liquidity providers… تحليل #عملة # المشفرة# ديفي# ايثريومتبادل ## السوقرمز ## ويب 3© 版权声明المصفوفة 上一篇 Pump.fun finally issues coins, with a total of 1 trillion. Is the King of Meme coming? 下一篇 كُتبت بعد هجوم القراصنة هل هناك أي عائد خالٍ من المخاطر في عالم DeFi؟ 相关文章 لماذا يجب أن تتجه معايير إطار عمل الذكاء الاصطناعي نحو التسلسل؟ 6086cf14eb90bc67ca4fc62b 37٬739 1 جديدBitMart Launches AMM Automated Market Making Tool, Introducing New Liquidity Yield Method 6086cf14eb90bc67ca4fc62b 2٬912 The AI Industry Welcomes a Deep-Pocketed Tether 6086cf14eb90bc67ca4fc62b 11٬332 Pakistan, from “Iron Brother” to “Iron Chain”? 6086cf14eb90bc67ca4fc62b 20٬899 1 Hardcore teardown: The X402 wanted to fix the “payment gap” in the internet, but fell into the same old pitfall again.Re 6086cf14eb90bc67ca4fc62b 17٬070 BitMart Launches Pre-Market Trading, with Monad (MON) as the First Project Launched 6086cf14eb90bc67ca4fc62b 17٬002 1 بدون تعليقات يجب عليك تسجيل الدخول لتترك تعليق! تسجيل الدخول على الفور بدون تعليقات... أحدث المقالات Did Jane Street “Manipulate” BTC? Decoding the AP System, Understanding the Power Struggle Behind ETF Creation and Redemption Pricing منذ 22 ساعة 669 Stop Comparing Bitcoin to Gold—It’s Now a High-Volatility Software Stock منذ 22 ساعة 711 Matrixport Research: $25 Billion Gamma Unwinding Imminent, Liquidity Yet to Return Behind the Rebound منذ 22 ساعة 665 ERC-5564: Ethereum’s Stealth Era Has Arrived, Receiving Addresses No Longer ‘Exposed’ منذ 22 ساعة 555 Hong Kong Regulatory Green Light: Asseto Enables DL Holdings to Achieve Compliance for Two RWA Business Implementations منذ 22 ساعة 648 المواقع الشعبيةTempoLighterGAIBطائرة شراعيةبلانكرايلزبوكر BCPokerفوي Bee.com أكبر بوابة Web3 في العالم الشركاء كوين كارب بينانس CoinMarketCap كوين جيكو كوين لايف الدروع قم بتنزيل تطبيق Bee Network وابدأ رحلة web3 ورق ابيض الأدوار التعليمات © 2021-2026. جميع الحقوق محفوظة. سياسة الخصوصية | شروط الخدمة تحميل تطبيق Bee Network وابدأ رحلة web3 أكبر بوابة Web3 في العالم الشركاء CoinCarp Binance CoinMarketCap CoinGecko Coinlive Armors ورق ابيض الأدوار التعليمات © 2021-2026. جميع الحقوق محفوظة. سياسة الخصوصية | شروط الخدمة يبحث يبحثفي الموقععلى تشيناجتماعيأخبار العنوان: صيادو الإنزال الجوي تحليل البيانات مشاهير التشفير كاشف الفخ العربية English 繁體中文 简体中文 日本語 Tiếng Việt 한국어 Bahasa Indonesia हिन्दी اردو Русский العربية智能索引记录
-
2026-03-02 22:33:40
电商商城
成功
标题:饰水琉年预订订购价格 - 京东
简介:京东是国内专业的饰水琉年网上购物商城,本频道提供饰水琉年商品预订订购价格,饰水琉年哪款好信息,为您选购饰水琉年提供全方位
-
2026-03-02 21:45:43
综合导航
成功
标题:BitMEX Alpha: Weekly Trader Report (November 2 – November 8) Bee Network
简介:Original author: BitMEX Brief Overview Memecoins have bee
-
2026-03-02 06:31:57
综合导航
成功
标题:GREEN LANTERN #60 DC
简介:BRIGHTEST DAY continues as the truth about the Indigo Tribe
-
2026-03-02 22:53:35
综合导航
成功
标题:我是丰饶孽物?扑火的飞萤最新章节_我是丰饶孽物?扑火的飞萤全文免费阅读_恋上你看书网
简介:我是丰饶孽物?扑火的飞萤是由作者:佚名所著,恋上你看书网免费提供我是丰饶孽物?扑火的飞萤全文在线阅读。<br />三秒记
-
2026-03-02 20:56:10
综合导航
成功
标题:Cyberpunk 2077 PS5 With Alternate Cover Spotted Online - PlayStation Universe
简介:Cyberpunk 2077 PS5 has been listed with an alternate cover o
-
2026-03-02 22:27:34
教育培训
成功
标题:不出国ACCA有必要考吗?了解大学生职业发展-高顿
简介:在全球化经济环境下,ACCA作为国际财会专业资格认证价值凸显。其证书全球认可度高,国内多个城市将其纳入高端人才引进计划。
-
2026-03-02 14:17:58
图片素材
成功
标题:一年级想象作文700字 一年级700字想象作文大全-作文网
简介:作文网优秀一年级想象700字作文大全,包含一年级想象700字作文素材,一年级想象700字作文题目、美文范文,作文网原创名
-
2026-03-02 20:21:16
综合导航
成功
标题:è½æçæ¼é³_è½æçææ_è½æçç¹ä½_è¯ç»ç½
简介:è¯ç»ç½è½æé¢é,ä»ç»è½æ,è½æçæ¼é³,è½ææ¯
-
2026-03-02 15:25:50
综合导航
成功
标题:NVE Corp- ADL125-14E: 1 mT, 3V, 30 Hz Duty-Cycled GMR Switch, DFN4 -
简介:This is ADL125-14E: 1 mT, 3V, 30 Hz Duty-Cycled GMR Switch,
-
2026-03-02 20:24:59
综合导航
成功
标题:UID I UX-Agentur für Innovation, Design & Strategie - UID
简介:UID ist eure UX-Agentur für die gesamte Produktentwicklung:
-
2026-03-02 20:40:25
综合导航
成功
标题:WEDNESDAY COMICS #9 DC
简介:WEDNESDAY COMICS, DC
-
2026-03-02 17:08:37
综合导航
成功
标题:笔趣阁-书友最值得收藏的网络小说阅读网
简介:看小说到笔趣阁,笔趣阁,笔趣阁,为您提供免费热门小说txt阅读
-
2026-03-02 23:03:17
综合导航
成功
标题:Customer Data Provides Incrementality, Segmentation Opportunities and Cost Savings
简介:RaceTrac, Kwik Trip and Yesway executives talk tech in C-Sto
-
2026-03-02 20:39:04
综合导航
成功
标题:NVE Corp - Gear-Tooth Sensors
简介:This is Gear-Tooth Sensors.
-
2026-03-02 23:38:49
综合导航
成功
标题:FS: Sunroof Mk1 Factory Front Strut Bar
简介:Up for sale is the factory strut bar for sunroof equipped Mk
-
2026-03-02 23:07:14
综合导航
成功
标题:Ant Smash - Play The Free Mobile Game Online
简介:Ant Smash - click to play online. These ants are everywhere!
-
2026-03-02 17:51:08
综合导航
成功
标题:Robert Fitzroy (1805-1865). The Reader's Biographical Encyclopaedia. 1922
简介:Robert Fitzroy (1805-1865). The Reader
-
2026-03-02 23:37:49
教育培训
成功
标题:高一物理B1 第3期暑假补习补课辅导班-上海新王牌培优
简介:新王牌培优是上海好的初高中辅导培训机构,创立于2005年,采用分层授课,小班化教学的辅导补课方式 ,是一家致力于初高中辅
-
2026-03-02 18:04:22
综合导航
成功
标题:Fraction Greater than One: Definition and Example EDU.COM
简介:Learn about fractions greater than 1, including improper fra
-
2026-03-02 20:16:56
电商商城
成功
标题:hollywood提拉紧致预订订购价格 - 京东
简介:京东是国内专业的hollywood提拉紧致网上购物商城,本频道提供hollywood提拉紧致商品预订订购价格,holly
-
2026-03-02 15:22:23
综合导航
成功
标题:注册安全工程师如何才能审核为高级安全工程师-中级注册安全工程师-233网校
简介:关于注册安全工程师如何审核为高级安全工程师,目前河南省发布了《河南省安全工程专业高级职称申报评审条件(试行)》通知、,持
-
2026-03-02 21:57:15
综合导航
成功
标题:è¡ççæ¼é³_è¡ççææ_è¡ççç¹ä½_è¯ç»ç½
简介:è¯ç»ç½è¡çé¢é,ä»ç»è¡ç,è¡ççæ¼é³,è¡çæ¯
-
2026-03-02 22:40:33
综合导航
成功
标题:Ozzy Fan&Memorial
简介:Celebrating the life, music, and heritage of the Prince of D
-
2026-03-02 17:51:17
综合导航
成功
标题:Let’s get back to the basics: Don’t confuse memecoin with shitcoin Bee Network
简介:Original author: Mannay Compiled by Odaily Planet Daily ( @
-
2026-03-02 21:57:58
综合导航
成功
标题:WTB mk1 [Archive] - Toyota MR2 Message Board
简介:I
-
2026-03-02 20:36:25
数码科技
成功
标题:特别的qq网名昵称女生,会让别人刮目一新-免费起名_免费取名_宝宝起名_起名软件_名字测试打分解名(缇帕电子科技)-起点起名网
简介:有什么样的网名昵称是特别的又适合女生,而且不常见的呢,女生们是不是都在想该怎么起一个特别的qq网名昵称呢?大家肯定都不想
-
2026-03-02 06:28:55
教育培训
成功
标题:家庭风波作文600字7篇
简介:在日常学习、工作和生活中,大家都经常接触到作文吧,作文要求篇章结构完整,一定要避免无结尾作文的出现。一篇什么样的作文才能
-
2026-03-02 23:16:35
游戏娱乐
成功
标题:10_勇者斗恶龙7重制版通关怎么玩-全流程通关攻略分享_3DM单机
简介:《勇者斗恶龙7:重制版》这款游戏的流程是比较长的,想要快速通关也比较难,游戏的故事也很独特,故事从住在孤岛上的一群少年少
-
2026-03-02 15:46:02
综合导航
成功
标题:玄幻小说_恋上你看书网_书友最值得收藏的网络小说阅读网
简介:恋上你看书网
-
2026-03-02 22:38:04
电商商城
成功
标题:冬季毛绒帽子女包邮怎么样 - 京东
简介:京东是专业的冬季毛绒帽子女包邮网上购物商城,为您提供冬季毛绒帽子女包邮价格图片信息、冬季毛绒帽子女包邮怎么样的用户评论、