cryptonews
2025-08-14 14:04:52

Hacked Perp DEX GMX to Repay $44M to Arbitrum GLP Holders After Exploit

Decentralized perpetuals exchange GMX said Wednesday that users hit by last month’s security breach can now claim compensation through its dApp. Key Takeaways: GMX is distributing $44M to fully compensate Arbitrum GLP holders impacted by last month’s $42M exploit. The breach stemmed from a reentrancy vulnerability in GMX V1’s contract structure. Compensation will be in GLV tokens with extra rewards for users who hold them for at least three months. “About $44 million in value is being distributed, making all impacted Arbitrum GLP holders whole and marking a favorable resolution to the security challenge GMX faced,” the project said . The payout combines recovered funds with $2 million from GMX’s treasury. GMX V1 Exploit Drains $42M via AUM Manipulation Vulnerability The incident occurred on July 9, when GMX V1’s GLP pool on Arbitrum was exploited for $42 million. At the time, blockchain security firm PeckShield attributed the loss to a reentrancy vulnerability that let the attacker manipulate the protocol’s assets-under-management (AUM) calculations, enabling them to withdraw more than their deposits. #GMXDeveloper msg pic.twitter.com/miTaxE6OEj — PeckShieldAlert (@PeckShieldAlert) July 9, 2025 GMX also confirmed that the $42 million exploit was caused by a re-entrancy vulnerability within its V1 contracts. Although the affected function was protected by a nonReentrant modifier, it only applied within the same contract, allowing the attacker to bypass this safeguard and manipulate the BTC average short price through the Vault contract. By exploiting this loophole, the attacker artificially drove the GLP price up and profited by redeeming inflated GLP tokens after opening a large position using a flash loan. The vulnerability was tied to how GMX V1 handled pricing calculations across separate contracts, a structure that has been revised in GMX V2, where calculations and executions now occur within the same contract to avoid such risks. In response, GMX paused trading on Avalanche, engaged with security partners and major infrastructure providers, and initiated direct on-chain communication with the exploiter. Hours after the breach, GMX sent an on-chain message offering a 10% white-hat bounty if 90% of the stolen funds were returned, an offer the attacker accepted. Compensation will be issued in GLV, GMX’s upgraded liquidity vault product for V2. Eligible claimants will receive equal portions of GLV [BTC-USDC] and GLV [WETH-USDC], reflecting roughly 25% Bitcoin, 25% Ether, and 50% stablecoins, mirroring the original GLP asset mix. In addition, GMX has launched a $500,000 GLV incentive pool for users who hold their distributed GLV for at least three months without selling or transferring, offering pro-rata rewards to long-term holders. Crypto Hacks, Scams Cost Investors $2.2B in H1 2025: CertiK Crypto investors lost over $2.2 billion to hacks , scams, and breaches in the first half of 2025, driven largely by wallet compromises and phishing attacks, according to CertiK’s latest security report. Wallet breaches alone caused $1.7 billion in losses across just 34 incidents, while phishing scams accounted for over $410 million across 132 attacks. Two major incidents, including Bybit’s $1.5 billion hack in February and Cetus Protocol’s $225 million exploit in May, skewed the year’s losses upward, together accounting for nearly $1.78 billion. Without these, losses align more closely with previous years at around $690 million. Ethereum remained the primary target, suffering over $1.6 billion in losses across 175 events. The report also pointed to rising sophistication of phishing schemes and ongoing risks from social engineering, urging crypto users to verify links, avoid suspicious sites, and use hardware wallets. The post Hacked Perp DEX GMX to Repay $44M to Arbitrum GLP Holders After Exploit appeared first on Cryptonews .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.