logo

GMX Incident Analysis

ID: dc077d55-d320-5f65-a02c-ebbcf3692c20

STIX ID: report--dc077d55-d320-5f65-a02c-ebbcf3692c20

Feed Name: CertiK Blog

Threat Score
78/100

Date Published: 2025-07-16

Date Updated: 2026-06-11

...
...

On 9 July 2025 a reentrancy-related logic/async-update flaw in GMX V1's Vault/ShortsTracker/GlpManager interaction was exploited to inflate GLP AUM and withdraw approximately $42M; the attacker later returned most funds and received a bounty. The report provides a detailed technical root-cause analysis, step-by-step exploit trace, relevant contract and attacker addresses, key transaction links, and a breakdown of fund flows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.