Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
GMX Hacker Converts Stolen Loot into 11,700 ETH

GMX Hacker Converts Stolen Loot into 11,700 ETH

CryptopotatoCryptopotato2025/07/09 16:00
By:Author: Wayne Jones

A re-entrancy exploit let the GMX hacker manipulate GLP token prices, leading to $42M in losses now mostly converted to ETH.

On July 9, the decentralized trading platform GMX suffered a major exploit, leading to the loss of $42 million in assorted cryptocurrencies.

Now, on-chain data shows that the hacker has changed most of the stolen funds into 11,700 ETH.

The GMX Hack

The Wednesday incident saw the attacker stealing over $10 million worth of legacy Frax Dollar (FRAX), $9.6 million in wrapped Bitcoin (wBTC), and about $5 million in DAI stablecoin.

Following the breach, $9.6 million of the funds were bridged to the Ethereum blockchain and exchanged into DAI and ETH, with a further $32 million remaining on Arbitrum.

GMX confirmed the theft in a post on X:

“The GLP pool of GMX V1 on Arbitrum has experienced an exploit. Approximately $40M in tokens has been transferred from the GLP pool to an unknown wallet.”

However, according to blockchain analytics platform Lookonchain, the bad actor has now exchanged all the stolen assets, except FRAX, into 11,700 ETH, which they then sent to four new wallets.

The protocol had earlier clarified that GMX V2, its markets, liquidity pools, and the GMX token were not affected. It also announced a temporary pause on GLP token minting and redemption on both Arbitrum and Avalanche to prevent further impact and secure funds. Its users were later told to disable leverage and update their settings to block further GLP minting.

Additionally, GMX sent an on-chain message to the hacker, offering a white-hat bounty worth $4.2 million. The proposal also promised there would be no legal consequences if the culprit returned the remaining 90% within 48 hours. So far, they have not responded.

A Re-Entrancy Exploit

A full postmortem report has not yet been released. However, blockchain security firm SlowMist has attributed the breach to a design flaw in GMX V1. The vulnerability enabled the exploiter to manipulate the GLP token price by interfering with the system’s calculation of total assets under management.

SlowMist explained that they used a function that enables leverage during order execution and performed a re-entrancy attack. These allow repeated calls within one function, causing a smart contract to calculate the wrong balance.

By opening large short positions in a single transaction, the criminal was able to manipulate the global price data. This action artificially inflated the GLP token price and profit through redemption.

Hacks and cybersecurity attacks remain a major challenge in the crypto industry. A recent CertiK report revealed that over $801.3 million was lost across 144 incidents in Q2 2025. Phishing was the most damaging, with $395 million stolen in 52 exploits. Code vulnerabilities followed closely, causing $235.8 million in losses across 47 cases.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Solana News Today: DeFi Dev Corp Stakes Big Bet on Solana’s Future With $77M Purchase

- DeFi Dev Corp. buys 407,247 SOL ($77M) via equity raise, boosting holdings to 1.83M tokens ($371M). - Tokens will be staked across validators, including its own infrastructure, to generate yield and expand Solana integration. - Launches DFDV UK treasury vehicle and plans five more under its global expansion strategy to drive Solana adoption. - Solana's TVL hits $11.56B amid Alpenglow upgrade, supporting long-term growth as DFDV raises $370M YTD for compounding strategy.

ainvest2025/08/30 05:33
Solana News Today: DeFi Dev Corp Stakes Big Bet on Solana’s Future With $77M Purchase

Pudgy Penguins’ Hybrid Strategy: Bridging NFTs and Physical Retail in Japan’s $15.4B Collectibles Market

- Pudgy Penguins expands into Japan's $15.4B collectibles market via QR-coded products and retail partnerships with convenience stores and Don Quijote. - The hybrid "phygital" model links physical cards/toys to NFTs, enabling digital access and revenue-sharing through OverpassIP while leveraging Japan's collectible culture. - Strategic collaborations with Suplay Inc. and Mythical Games, plus $13M+ in retail sales, demonstrate the brand's ability to merge Web3 innovation with traditional commerce for mass a

ainvest2025/08/30 05:30
Pudgy Penguins’ Hybrid Strategy: Bridging NFTs and Physical Retail in Japan’s $15.4B Collectibles Market

The SEC vs. Unicoin: A Legal and Investment Crossroads in the Evolving Crypto Landscape

- SEC sues Unicoin for $100M fraud, alleging overstated real estate collateral and misrepresentation of token risks. - Unicoin denies claims, accuses SEC of selective quoting and politicized enforcement, citing NYSE listing interference. - Case tests crypto regulation's balance between investor protection and innovation, with potential precedents for asset-backed token disclosures. - Legal experts warn outcome could reshape compliance strategies, emphasizing transparency, documented intent, and proactive r

ainvest2025/08/30 05:30
The SEC vs. Unicoin: A Legal and Investment Crossroads in the Evolving Crypto Landscape

Nukkleus Inc.'s Strategic Pivot into Defense: A High-Volatility Play in a High-Growth Sector

- Nukkleus Inc. partners with Mandragola to enter aerospace/defense via Baltic-Israeli logistics hubs and MRO services, targeting a $124B market by 2034. - The $2M-funded joint venture ties 51% ownership to $25M revenue goals, but Nukkleus' 2024 revenue fell to $6M with negative cash flow. - A 30.36% stock surge post-announcement contrasts with weak financials, raising questions about execution risks and reliance on external funding. - Strategic bets include Israeli defense tech integration and a $10M Star

ainvest2025/08/30 05:30
Nukkleus Inc.'s Strategic Pivot into Defense: A High-Volatility Play in a High-Growth Sector