GMX Releases $40 Million Vulnerability Exploitation Event Recap: Further Discussion on Compensation Measures
BlockBeats News, July 11, GMX officially released a summary report on the GMX V1 approximately $40 million exploit on Arbitrum.
Event Summary:
The attacker bypassed the PositionRouter and PositionManager contracts (usually responsible for calculating the average short price) by directly calling the Vault contract's increasePosition function through reentrancy;
Through manipulation, the attacker pushed the BTC average short price down from $109,505.77 to $1,913.70;
Using a flash loan, the attacker purchased GLP at a normal price of $1.45, opening a $15 million position;
Due to the manipulated price, the GLP price was pushed above $27, allowing the attacker to redeem GLP at a high price for profit;
GMX has confirmed that V2 does not have a similar vulnerability.
Next Step Funding Situation:
Approximately $3.6 million remains in the GLP pool, reserved for unclosed positions;
The cost of V1's GLP on Arbitrum this week is around $500,000 (excluding the 30% portion allocated to GMX stakers) and will be transferred to the DAO Treasury for compensation;
Will disable GLP minting and redemption on Arbitrum (redemption disablement requires a 24-hour Timelock);
Disable GLP minting on Avalanche but retain the redemption function;
Enable the closure of V1 positions on Arbitrum and Avalanche, disable opening positions to prevent a recurrence of the vulnerability;
Cancel V1 orders on Arbitrum and Avalanche. Remaining funds in the GLP pool on Arbitrum will be allocated to the compensation pool for use by affected GLP holders.
After the above steps are completed, the GMX DAO will discuss further compensation measures. It is recommended that all GMX V1 forks take immediate action, await fixes and audits before re-enabling trading and minting of GLP-like tokens.
You may also like

Slow Down, That's the Answer to the Age of the Agent

From Cash to Cryptocurrency: Moving Towards a Unified Regulatory Path for Illegal Payments

Who will own the most Bitcoin in 2026

A private feud lasting 10 years, if not for OpenAI's "hypocrisy," would not have led to the world's strongest AI company, Anthropic

"Crypto Tsar" steps down: 130 days of political performance come to an end, how much of Trump's crypto promise remains?

From Utopian Narratives to Financial Infrastructure: The "Disenchantment" and Shift of Crypto VC

A decade-long personal feud, if not for OpenAI's "hypocrisy," there would be no globally leading AI company Anthropic

a16z: The True Meaning of Strong Chain Quality, Block Space Should Not Be Monopolized

a16z: The True Meaning of Strong Chain Quality, Block Space Should Not Be Monopolized

2% user contribution, 90% trading volume: The real picture of Polymarket

Trump Can't Take It Anymore, 5 Signals of the US-Iran Ceasefire

Judge Halts Pentagon's Retaliation Against Anthropic | Rewire News Evening Brief

Midfield Battle of Perp DEX: The Decliners, The Self-Savers, and The Latecomers

Iran War Stalemate: What Signal Should the Market Follow?

Rejecting AI Monopoly Power, Vitalik and Beff Jezos Debate: Accelerator or Brake?

Insider Trading Alert! Will Trump Call a Truce by End of April?

After establishing itself as the top tokenized stock, does Ondo have any new highlights?

