GMX Incident Analysis
ID: dc077d55-d320-5f65-a02c-ebbcf3692c20
STIX ID: report--dc077d55-d320-5f65-a02c-ebbcf3692c20
Feed Name: CertiK Blog
Threat Score
On 9 July 2025 a reentrancy-related logic/async-update flaw in GMX V1's Vault/ShortsTracker/GlpManager interaction was exploited to inflate GLP AUM and withdraw approximately $42M; the attacker later returned most funds and received a bounty. The report provides a detailed technical root-cause analysis, step-by-step exploit trace, relevant contract and attacker addresses, key transaction links, and a breakdown of fund flows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
