作者 | Asher ( @Asher_0210 ) Last night, the GMX platform , a leading DeFi protocol on the chain , suffered a major security incident. More than 40 million US dollars of 加密 assets were stolen by hackers, involving WBTC, WETH, UNI, FRAX, LINK, USDC, USDT and other mainstream tokens. After the incident, Bithumb issued an announcement announcing that the deposit and withdrawal services of GMX will be suspended until the network is stable. Affected by the theft, the GMX token fell by more than 25% in 4 hours, and the price once fell below $11, and is now at $11.8. According to DefiLlama data, GMX TVL fell from $500 million before the theft to $400 million, a short-term drop of up to 20%. Next, Odaily Planet Daily will sort out the reasons for the GMX theft, the team’s response, and the latest trends of hackers. Attacker exploits reentrancy vulnerability
The root cause of the GMX theft is a reentrancy vulnerability in the core function executeDecreaseOrder. The first parameter of the function should have been an external account (EOA), but the attacker passed in a smart contract address, which allowed the attacker to re-enter the system during the redemption process and manipulate the internal state. Ultimately, the redeemed assets far exceeded the actual value of the GLP they held.
SlowMist partner and chief information security officer 23pds posted on the X platform that in GMX V1, the establishment of a short position will immediately update the global short average price (globalShortAveragePrices), which directly affects the calculation of total assets under management (AUM), and thus affects the valuation and redemption amount of GLP tokens.
The attacker took advantage of GMXs design of enabling the timelock.enableLeverage function during order execution (a prerequisite for opening large short positions) and triggered a reentrancy vulnerability in the executeDecreaseOrder function through a contract call. Using this vulnerability, the attacker repeatedly created short positions, artificially raising the global average short price without actually changing the market price.
Since AUM relies on this price calculation, the platform mistakenly included the inflated short losses in the total assets, causing the GLP valuation to be artificially inflated. The attacker then redeemed GLP and withdrew assets far in excess of his share, realizing huge profits.
Attack transaction example: https://app.blocksec.com/explorer/tx/arbitrum/0x03182d3f0956a91c4e4c8f225bbc7975f9434fab042228c7acdc5ec9a32626ef?line=93 GMX official response: The GLP liquidity pool of GMX V1 on Arbitrum was attacked by a vulnerability, and the GMX V2 version was not affected In response to this major security incident, the GMX team has made an official response as soon as possible. It posted on the X platform that the GLP pool of GMX V1 on the Arbitrum platform was attacked by a vulnerability, and about $40 million of tokens have been transferred from the GLP pool to an unknown wallet. Security partners have participated in the investigation of this attack. Currently, the Arbitrum and Avalanche platforms have disabled transactions for GMX V1 and the minting and redemption functions of GLP to prevent any further attacks, but the vulnerability does not affect the GMX V2 version or the GMX token itself. Since GMX V1 has been attacked, users can reduce the risk by doing the following: Disable leverage: Call Vault.setIsLeverageEnabled(false) to turn it off; if Vault Timelock is used, call Timelock.setShouldToggleIsLeverageEnabled(false). Set maxUsdgAmounts of all tokens to 1: Use Vault.set代币Config or Timelock.setTokenConfig to prevent GLP from being further minted. It is worth noting that this value must be set to 1, not 0, because setting it to 0 means there is no upper limit, which will cause the vulnerability to continue to be exploited. According to the latest update, the official said that it was confirmed that the attack was only aimed at GMX V1, and the GMX V2 version of the contract did not use the same calculation mechanism. However, out of caution, GMX has updated the upper limit of GMX V2 version tokens on Arbitrum and Avalanche, so the minting of new tokens in most liquidity pools is currently restricted. Once this restriction is lifted, you will be notified as soon as possible. In addition, on-chain data shows that GMX has left a message to the hackers address, admitting that it has encountered a vulnerability in the GMX Vl version and is willing to provide a 10% white hat bounty. If the remaining 90% of the funds are returned within 48 hours, it will promise not to take further legal action.GMX has left a message to the hacker address and is willing to provide a 10% white hat bounty
Hackers have moved over $30 million to new addresses Judging from the signs on the chain, this was a long-planned action. The hackers initial funds were transferred from the privacy mixing protocol Tornado Cash a few days ago, indicating that they had already made sufficient preparations for this attack. After stealing more than $40 million in crypto assets, hackers quickly transferred more than $30 million in assets. According to on-chain data, the GMX hacker marked address (address: https://debank.com/profile/0xdf3340a436c27655ba62f8281565c9925c3a5221 ) has transferred 88 BTC (worth approximately US$9.8 million), more than 2,200 ETH (worth approximately US$5.85 million), more than 3 million USDC, and more than 1.3 million DAI to the new address 0x99cdeb84064c2bc63de0cea7c6978e272d0f2dae ; and transferred more than 4,300 ETH (worth approximately US$11 million) to the new address 0x6acc60b11217a1fd0e68b0ecaee7122d34a784c1 . In total, more than $30 million in funds have been transferred to other new addresses.Hackers stole over $40 million in assets
The remaining $10 million in funds in the current hacker address has not yet been transferred
Chain detective ZachXBT published an article on the X platform criticizing Circle for its inaction on the hacker behavior. He said that the GMX attack had occurred 1 to 2 hours ago, but Circle did not take any action against the hacker behavior. The attacker even used Circles cross-chain transfer protocol CCTP to transfer the stolen funds from Arbitrum to Ethereum. summaryThis theft not only revealed the key flaws of GMX V1 in caller permission verification, status update timing, and leverage mechanism design, but also once again sounded the alarm for the entire industry: in a system involving complex financial logic (such as leverage, dynamic pricing) and contract execution paths, any unprotected entry may evolve into the starting point of a black swan event.
It is worth noting that hackers have exchanged most of the stolen assets for cryptocurrencies that are more difficult to freeze, especially decentralized assets such as ETH and DAI, and dispersed the funds through multiple new addresses, further increasing the difficulty of tracking and recovering them. The 10% white hat bounty in exchange for exemption plan proposed by GMX also exposes the current reality of the lack of a unified legal accountability mechanism in the Web3 world.
For DeFi developers, perhaps the question they should think about more is not “how did the hacker succeed”, but whether sufficient mechanisms have been established to limit the occurrence of the most extreme attack paths when the system manages the real assets of users. Otherwise, no matter how perfect the product logic is, once there is a lack of security boundary design, it will eventually be difficult to escape the cost of systemic risk.
This article is sourced from the internet: More than $40 million stolen, GMX ambushed Related: Can the PoL mechanism be saved? Looking at the liquidity game from the new low of BERA Original author: 1912212.eth, Foresight News Recently, the price of BERA has dropped to $2.66, a new low since the TGE in February this year. BERA has been falling since March. What happened to the once popular Berachain? TVL dropped from 3.4 billion to 1.147 billion As an emerging public chain, Berachain has attracted much attention from the market for its Meme culture, liquidity mechanism, and support from well-known VCs before its mainnet launch. Its core innovation lies in its Proof of Liquidity (PoL) mechanism, which incentivizes on-chain liquidity through BGT emissions and bribes. However, the complexity of this mechanism makes it difficult to attract new users and also exposes sustainability issues. PoL relies on the continuous injection of liquidity, but when the market environment deteriorates or incentives decrease, liquidity providers… #分析# 加密# 定义# 以太坊# 交易所# 市场# 代币# web3© 版权声明文章版权归作者所有,未经允许请勿转载。 上一篇 Pump.fun finally issues coins, with a total of 1 trillion. Is the King of Meme coming? 下一篇 Written after the hacker attack: Is there any risk-free return in the DeFi world? 相关文章 The biggest airdrop in the crypto world is given by Yuanbao 6086cf14eb90bc67ca4fc62b 9,128 Conflict breaks out, does the market pay for it? A look back at the impact of previous international wars on Bitcoin 6086cf14eb90bc67ca4fc62b 29,926 2 “Black Monday” Strikes Again, Is Trump Once Again the “Flash Crash Engine”? 6086cf14eb90bc67ca4fc62b 9,223 2 Metya’s payment brand Metyacard officially upgraded to MePay 6086cf14eb90bc67ca4fc62b 18,040 Bitcoin Mining Outlook 2026: Seven Trends Defining the Industry’s Future 6086cf14eb90bc67ca4fc62b 11,530 2 When Polymarket Enters the Dow Jones, Prediction Markets Are Becoming Part of Serious Journalism 6086cf14eb90bc67ca4fc62b 9,797 无评论 您必须登录后才能发表评论! 立即登录 没有评论... Bee.com 全球最大的 Web3 门户网站 合作伙伴 硬币卡 Binance CoinMarketCap CoinGecko Coinlive 装甲 下载蜜蜂网络APP,开始web3之旅 白皮书 角色 常见问题 © 2021-2026.保留所有权利。. 隐私政策 | 服务条款 下载蜜蜂网络 APP 并开始 web3 之旅 全球最大的 Web3 门户网站 合作伙伴 CoinCarp Binance CoinMarketCap CoinGecko Coinlive Armors 白皮书 角色 常见问题 © 2021-2026.保留所有权利。. 隐私政策 | 服务条款 搜索 搜索InSite链上社会新闻 热门推荐: 空投猎人 数据分析 加密货币名人 陷阱探测器 简体中文 English 繁體中文 日本語 Tiếng Việt العربية 한국어 Bahasa Indonesia हिन्दी اردو Русский 简体中文智能索引记录
-
2026-03-02 10:04:02
游戏娱乐
成功
标题:火影忍者ol最强输出忍者是谁? 阿修罗+终焉之战斑_欢乐园游戏
简介:火影忍者ol最新版本里哪个输出忍者最强?这是很多玩家搭配阵容都需要考虑的,对于目前版本来说,条件充足的话,小编认为阿修罗
-
2026-03-02 17:02:00
游戏娱乐
成功
标题:战神5pc版画面设置怎么样比较好-诸神黄昏画面设置推荐_3DM单机
简介:《战神:诸神黄昏》这款游戏刚刚上线PC,游戏想要流畅游玩难度非常大,配置不算高的话需要画面设置才能做到,而画面设置首先是
-
2026-03-02 18:57:56
综合导航
成功
标题:Double Whammy: Yen Exchange Rate Volatility + Potential Government Shutdown, Where is the Bottom of the Crypto Market? Bee Network
简介:Author Ethan (@ethanzhang_web3)
-
2026-03-02 12:40:20
综合导航
成功
标题:阿里云奥运之旅
简介:阿里云以AI驱动的云计算技术,全面支撑巴黎奥运会!
-
2026-03-02 16:34:37
教育培训
成功
标题:公园游记作文【精选4篇】
简介:在平平淡淡的学习、工作、生活中,大家都写过作文,肯定对各类作文都很熟悉吧,作文可分为小学作文、中学作文、大学作文(论文)
-
2026-03-02 18:04:11
视频影音
成功
标题:消逝的光芒2纵断器武器图纸位置视频攻略-消逝的光芒2纵断器武器图纸位置视频流程_3DM单机
简介:消逝的光芒2“屠戮本能“新版本纵断器图纸收集地点是很多粉丝想知道的,消逝的光芒2游戏内容自由度非常高,还有非常爽快的跑酷
-
2026-03-02 18:01:16
游戏娱乐
成功
标题:禁闭求生2_Grounded2下载,MOD,攻略,修改器,汉化补丁
简介:《禁闭求生2》是一款探索沙盒冒险游戏,这款游戏由Obsidian Entertainment制作,属于动作类型。为了让玩
-
2026-03-02 14:49:13
综合导航
成功
标题:ç®æçæ¼é³_ç®æçææ_ç®æçç¹ä½_è¯ç»ç½
简介:è¯ç»ç½ç®æé¢é,ä»ç»ç®æ,ç®æçæ¼é³,ç®ææ¯
-
2026-03-02 19:03:14
游戏娱乐
成功
标题:芭比美容水疗,芭比美容水疗小游戏,4399小游戏 www.4399.com
简介:芭比美容水疗在线玩,芭比美容水疗下载, 芭比美容水疗攻略秘籍.更多芭比美容水疗游戏尽在4399小游戏,好玩记得告诉你的朋
-
2026-03-02 16:36:50
游戏娱乐
成功
标题:动漫王国守卫战完整版,动漫王国守卫战完整版小游戏,4399小游戏 www.4399.com
简介:动漫王国守卫战完整版在线玩,动漫王国守卫战完整版下载, 动漫王国守卫战完整版攻略秘籍.更多动漫王国守卫战完整版游戏尽在4
-
2026-03-02 15:50:17
综合导航
成功
标题:How Can Organic Workspaces Support a Modern Hybrid Workplace? Inspiring Workspaces by BOS
简介:Many employers are transitioning from traditional offices to
-
2026-03-02 14:11:21
综合导航
成功
标题:AI智能索引 - AI智能索引
简介:AI智能索引 - 提供全网公开链接智能索引服务,快速访问目标内容,支持分类筛选和智能导航
-
2026-03-02 18:53:54
综合导航
成功
标题:给咸鱼文女主当庶妹笔趣阁最新章节_51 第五十一章 桂榜 城独发第1页_给咸鱼文女主当庶妹笔趣阁免费阅读_恋上你看书网
简介:51 第五十一章 桂榜 城独发第1页_给咸鱼文女主当庶妹笔趣阁_将月去_恋上你看书网
-
2026-03-02 19:09:32
综合导航
成功
标题:Gabriel Hanotaux (1853-1944). The Reader's Biographical Encyclopaedia. 1922
简介:Gabriel Hanotaux (1853-1944). The Reader
-
2026-03-02 18:53:59
综合导航
成功
标题:写轮眼是真实的吗最新章节_004 来自天才结社的邀请第1页_写轮眼是真实的吗免费阅读_恋上你看书网
简介:004 来自天才结社的邀请第1页_写轮眼是真实的吗_山下竹狸_恋上你看书网
-
2026-03-02 10:01:34
图片素材
成功
标题:暑期实践的作文300字 描写暑期实践的作文 关于暑期实践的作文-作文网
简介:作文网精选关于暑期实践的300字作文,包含暑期实践的作文素材,关于暑期实践的作文题目,以暑期实践为话题的300字作文大全
-
2026-03-02 17:00:38
综合导航
成功
标题:ä¸»äººçæ¼é³_ä¸»äººçææ_主人çç¹ä½_è¯ç»ç½
简介:è¯ç»ç½ä¸»äººé¢é,ä»ç»ä¸»äºº,ä¸»äººçæ¼é³,主人æ¯
-
2026-03-02 15:18:43
图片素材
成功
标题:新编的作文20字 描写新编的作文 关于新编的作文-作文网
简介:作文网精选关于新编的20字作文,包含新编的作文素材,关于新编的作文题目,以新编为话题的20字作文大全,作文网原创名师点评
-
2026-03-02 09:51:40
综合导航
成功
标题:GQR Innovative Talent Solutions for Strategic Growth · GQR
简介:Discover GQR
-
2026-03-02 14:00:06
教育培训
成功
标题:实用的关爱的作文600字
简介:无论在学习、工作或是生活中,大家都不可避免地要接触到作文吧,根据写作命题的特点,作文可以分为命题作文和非命题作文。那么你
-
2026-03-02 18:07:18
综合导航
成功
标题:Sandra/Sandy ?
简介:Hallo Miteinander, in der Börse inseriert eine Dame die s
-
2026-03-02 13:06:41
教育培训
成功
标题:平安作文600字(通用3篇)
简介:在平凡的学习、工作、生活中,大家或多或少都会接触过作文吧,作文是人们以书面形式表情达意的言语活动。那么问题来了,到底应如
-
2026-03-02 12:34:16
综合导航
成功
标题:1985 Toyota MR2 - Price Not Listed [Archive] - Toyota MR2 Message Board
简介:Up for sale is an original condition red 1985 MR2. There is
-
2026-03-02 16:50:33
综合导航
成功
标题:Princess with Mirror and Chandelier - Free Princess Coloring Pages EDU.COM
简介:Free printable princess coloring page for 4th and 5th grade.
-
2026-03-02 13:20:24
综合导航
成功
标题:说明文不无聊_450字_作文网
简介:有人说,说明文很枯燥,一点趣味都没有。相反,我认为有选择性地阅读一些好的说明文,可以收获许多有趣的知识,扩大视野,开阔眼
-
2026-03-02 17:55:42
综合导航
成功
标题:For Sale: Clean 1986 MR2 and extras For Sale - $2500 [Archive] - Toyota MR2 Message Board
简介:For Sale in Madison Wisconsin (Mc Farland ) for $2500 198
-
2026-03-02 16:55:34
教育培训
成功
标题:特别的礼物的作文3篇[推荐]
简介:在平日的学习、工作和生活里,大家总少不了接触作文吧,借助作文人们可以实现文化交流的目的。你知道作文怎样写才规范吗?下面是
-
2026-03-02 12:59:48
综合导航
成功
标题:é¼ççæ¼é³_é¼ççææ_é¼ççç¹ä½_è¯ç»ç½
简介:è¯ç»ç½é¼çé¢é,ä»ç»é¼ç,é¼ççæ¼é³,é¼çæ¯
-
2026-03-02 14:08:01
综合导航
成功
标题:FTIR Gas Analyzer
简介:MultiGas FTIR Spectroscopy gas analyzers are capable of ppb
-
2026-03-02 18:54:30
综合导航
成功
标题:周易 第51页 - 吉吉算命网
简介:周易 第51页_吉吉算命网