GMX V1 Exploit: Re-Entrancy and GLP Price Manipulation
Summary
This account describes a July 2025 exploit of GMX V1’s GLP pool on Arbitrum. It attributes the attack to a re-entrancy flaw in the GLP token price calculation: the attacker opened large short positions in one transaction to inflate the token price, then redeemed GLP to extract value. The document reports losses of roughly $40–42 million and lists FRAX, wrapped Bitcoin, and DAI among the stolen assets. It says some funds were converted to ETH and spread across wallets.
GMX paused GLP minting and redemption on Arbitrum and Avalanche and offered a bounty for returned funds. GMX V2 and its markets are reported unaffected. The article argues for audits, real-time monitoring, and stronger pricing mechanisms, but it does not provide contract-level evidence, transaction analysis, or a completed postmortem. Its account is therefore a high-level incident summary, and its claims about the exploit and response should be checked against primary reporting.
Key ideas
- The attack targeted the GLP pool on Arbitrum and exploited a flaw in GLP price calculation.
- The described exploit used large short positions within one transaction to influence price before redemption.
- GMX paused GLP operations on Arbitrum and Avalanche in response.
- The article reports that GMX V2 and its associated markets were unaffected.
- Audits, monitoring, and manipulation-resistant pricing are presented as security priorities.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.