GMX releases $40 million attack summary report: GMX DAO will discuss compensation measures
Odaily News GMX published a report on the X platform to summarize the reasons and follow-up measures for the attack of about $40 million on the Arbitrum chain on July 9 on GMX V1. It pointed out that after analysis by the security team, the attack originated from the reentrancy vulnerability of the OrderBook contract. Hackers used this vulnerability to manipulate the average short price of BTC, thereby significantly raising the price of GLP and arbitrage. The official has suspended transactions related to the Avalanche chain, confirmed that the V2 version is not affected, and will take measures such as disabling GLP casting and redemption and setting up a compensation pool. GMX reminds V1 fork projects to promptly repair similar risks.
Next step: Funding situation: There is about $3.6 million left in the GLP pool, which is reserved for open positions. The GLP fee for V1 on Arbitrum this week is about $500,000 (minus the 30% allocated to GMX stakers), which will be transferred to the DAO treasury for compensation. GLP minting and redemption on Arbitrum will be disabled (redemption disablement requires a 24-hour timelock). GLP minting on Avalanche is disabled, but the redemption function is retained. Enable V1 position closing on Arbitrum and Avalanche, and disable opening to prevent the vulnerability from recurring. Cancel V1 orders on Arbitrum and Avalanche. The remaining GLP funds on Arbitrum will be allocated to the compensation pool for use by affected GLP holders.
GMX DAO will discuss further compensation measures. It is recommended that all GMX V1 forks take immediate action and enable trading and minting of GLP-like tokens only after repairs and audits.
You may also like

DWF Deep Report: AI in DeFi Outperforms Humans in Yield Optimization, but Complex Trades Still Lag Behind by 5 Times

The Risk Management Core Team has just been ousted, and Aave is now facing a $200 million default.

The $293 million bug wasn't in the code; so, what's the deal with the "DVN Configuration Bug," which led to the largest hack of 2026?

a16z on Recruitment: How to Choose Between Crypto-Native and Traditional Talent?

The biggest DeFi heist of 2026, hackers easily took advantage of Aave

Will Robots Replace Humans? He Says No!

Binance Coin's Price Skyrockets 15x to All-Time High, Saved by Three Bull Market Lifelines

The organization has accessed the prediction market, but is stuck at the third stage

Head of crypto VC collective shrinks: a16z crypto fund management scale plummets by 40%, Multicoin cut in half

Arthur Hayes New Post: It's "No Trade" Time Now

Claude Opus 4.7 Review: Is It Worthy of the Title of Strongest Model?

DWF In-Depth Report: AI Outperforms Humans in Yield Farming Optimization in DeFi, But Complex Transactions Still Lag Behind 5x

The financial tricks of the crypto giant Kraken

When proactive market makers start to take initiative

Massive Whale Movement: Unstaking $84.96 Million in HYPE Tokens
Key Takeaways A crypto whale, known as TechnoRevenant, has unstaked approximately $84.96 million in HYPE tokens. The tokens…

ListaDAO Addresses Third-Party Contract Vulnerability Concerns
Key Takeaways GoPlus Security revealed a vulnerability in a contract resembling those of ListaDAO. ListaDAO confirmed that their…

Security Risks of Fake Ledger Nano S+ Devices Emerging Through Chinese E-Commerce
Key Takeaways Counterfeit Ledger Nano S+ devices are being sold on Chinese e-commerce platforms, posing significant risks to…

Wave of Cyber Attacks Hits DeFi Protocols Post-Drift Hack
Key Takeaways A significant $280 million attack on Drift Protocol set off a chain of security breaches across…






