Skip to content
← Back to newsGMX Recovers $40M After Hacker Accepts White-Hat Bounty Deal
Security

GMX Recovers $40M After Hacker Accepts White-Hat Bounty Deal

By ToTo BugelmanNewcomer0 rep· 7/11/2025

A significant exploit rocked GMX, a decentralized exchange, leading to the theft of approximately $40 million. The attacker, however, has since returned the majority of the stolen funds after GMX offered a white-hat bounty. This incident highlights the ongoing security challenges within the DeFi space, even as it demonstrates a rare positive outcome.

 

PeckShieldAlert

 

Key Takeaways

  • Re-entrancy Vulnerability: The exploit was attributed to a re-entrancy bug in the GMX V1 OrderBook contract, a known vulnerability type in DeFi.

  • Impact on GMX V1: The GLP pool on Arbitrum was significantly affected, leading to the suspension of GLP minting and redemption on Arbitrum.

  • GMX V2 Unaffected: GMX's newer V2 infrastructure and the GMX token remained operational and secure throughout the incident.

  • Bounty Success: The GMX team's proactive offer of a white-hat bounty played a crucial role in the recovery of funds.

  • Market Reaction: The GMX token initially dropped by 28% but rebounded by approximately 14% following the news of the funds' return, indicating renewed market confidence.

GMX has stated that affected users will be allowed to close their positions and that remaining protocol funds will be allocated for reimbursements. The team is also planning a DAO discussion for further user reimbursement and long-term protocol protection, and has warned other GMX V1 forks about the vulnerability.

 

GMX Suffers Major Exploit

On Wednesday, July 9, the GMX V1 GLP pool on Arbitrum was targeted in a sophisticated re-entrancy attack. This vulnerability allowed the exploiter to manipulate the GLP token price by interfering with the system's calculation of total assets under management. By opening large short positions, the attacker artificially inflated the GLP token's value, enabling them to redeem these inflated tokens for a substantial profit.

The exploit drained over $40 million in various cryptocurrencies, including stablecoins like USDC, FRAX, and DAI, as well as wrapped Bitcoin (wBTC) and wrapped Ethereum (WETH). Following the breach, GMX promptly halted trading and minting functions on both Arbitrum and Avalanche to prevent further losses and secure remaining assets. GMX V2 operations, its markets, liquidity pools, and the GMX token itself were confirmed to be unaffected.

 

Hacker Returns Stolen Funds After Bounty Deal

In a rare turn of events for crypto exploits, the GMX exploiter began returning the stolen funds on Friday morning. This came after GMX engaged the attacker via an on-chain message, offering a 10% white-hat bounty, equivalent to over $4 million, for the return of the remaining funds within 48 hours. The protocol also promised not to pursue legal action if the offer was accepted.

  • The exploiter sent an on-chain message stating, "Ok, funds will be returned later."

  • Initial transfers included $10.5 million worth of FRAX stablecoin.

  • Subsequently, a further 10,000 Ether and other assets totaling $40.5 million were returned.

While the exploiter still retains approximately 1,700 Ether worth $5.1 million, the return of the vast majority of funds is an uncommon outcome in the DeFi space. This incident echoes the Euler Finance hack in 2023, where the exploiter also returned a significant portion of stolen funds.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

GMX Recovers $40M After Hacker Accepts White-Hat Bounty Deal | BlockzHub