SlowMist: GMX Theft Leads to GLP Price Manipulation, Attacker Manipulates Global Average Price by Creating Large Short Positions through Reentrancy

By: theblockbeats.news|2025/07/10 14:01:54
0
Share
copy

BlockBeats News, July 10th. SlowMist Cosmos stated in a post that the fundamental reason for the $42 million theft of GMX last night was that GMX v1 would immediately update the global short average price when handling short positions. This global average price directly affects the calculation of the total asset under management (AUM), leading to the manipulation of the GLP token price.

The attacker exploited this design flaw by using a Keeper to enable the timelock.enableLeverage feature when executing orders (a necessary condition for creating large short positions), successfully creating a large short position through reentrancy to manipulate the global average price. This artificially inflated the GLP price in a single transaction and profited through redemption operations.

-- Price

--

You may also like

a16z Crypto: What We See Behind the $2.2 Billion New Fund

After the noise subsides, what remains is often more useful than it appeared at its peak and more enduring than it seemed at its lowest point.

Web3 is dead, Web2+3 should rise

We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.

Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market

In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.

The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets

Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android

To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance

Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com