Skip to content
← Back to newsGMX Halts Trading After $40 Million Exploit, Offers Bounty
Crime

GMX Halts Trading After $40 Million Exploit, Offers Bounty

By ToTo BugelmanNewcomer0 rep· 7/10/2025

Decentralized exchange GMX has halted trading and token minting on its V1 platform following a sophisticated exploit that siphoned approximately $40 million in various tokens. The attack, which manipulated the GLP vault mechanism, prompted GMX to offer a 10% bounty for the return of the stolen funds, highlighting the ongoing security challenges in the DeFi space.

 

GMX

 

GMX V1 Suffers $40 Million Exploit

On July 9, the GMX protocol confirmed a significant exploit targeting its V1 GLP pool on the Arbitrum network. An unknown attacker drained over $40 million worth of assorted tokens, including ETH, USDC, DAI, UNI, FRAX, USDT, WETH, and LINK, in a single transaction. The attack exploited a design flaw related to the calculation of the total assets under management, allowing the manipulation of the GLP token price.

In response, GMX immediately:

  • Halted trading on GMX V1.

  • Suspended the minting and redemption of GLP tokens on both Arbitrum and Avalanche.

  • Advised users to disable leverage and adjust settings to prevent GLP minting.

 

GMX

 

The Exploit Mechanism

Blockchain security firms, including SlowMist, attributed the exploit to a flaw in GMX's pricing mechanism. The attacker manipulated the protocol's leverage mechanism to mint excessive GLP tokens without proper collateral. This allowed them to artificially inflate their position and then redeem the fraudulently minted GLP for underlying assets, rapidly draining the pool.

The attacker's methods included:

  • Funding the malicious contract through Tornado Cash to obscure the origin of the exploit.

  • Bridging approximately $9.6 million of the stolen funds from Arbitrum to Ethereum using Circle’s Cross-Chain Transfer Protocol.

  • Converting portions of the stolen funds to DAI.

 

SlowMist

 

Audits and Security Concerns

Despite GMX V1 contracts undergoing reviews by top auditing firms like Quantstamp and ABDK Consulting, the specific leverage manipulation vector that enabled this exploit was not flagged. This incident raises critical questions about the efficacy of current audit practices in identifying complex, protocol-specific logic flaws.

Key takeaways from the incident include:

  • Audits often focus on general vulnerabilities but may miss nuanced protocol-specific logic flaws.

  • The incident underscores the fragility of even audited smart contracts.

  • It highlights the ongoing challenges in securing decentralized leverage markets.

 

GMX's Response and Broader Implications

In an attempt to recover the funds, GMX publicly offered a 10% bounty to the attacker for the return of the remaining assets. The protocol clarified that the breach was isolated to V1 and did not impact GMX V2, its token, or other associated markets.

This exploit is part of a broader trend of cybersecurity breaches in the crypto industry, with significant losses reported in 2025. The incident serves as a cautionary tale, emphasizing the need for continuous innovation in security practices, including enhanced on-chain monitoring, real-time anomaly detection, and adaptive governance frameworks within the DeFi ecosystem.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.