Regardless of layers of scrutiny, GMX’s V1 GLP pool was hacked for over $40 million in a brazen exploit. With leverage features now frozen, merchants are left questioning: How did audited contracts crack? And what does this imply for DeFi’s perpetual buying and selling future?
On July 9, on-chain perpetual and spot trade GMX confirmed that its V1 GLP pool on Arbitrum had been exploited, with over $40 million price of various tokens siphoned into an unknown pockets in a single transaction.
The assault, which seems to have manipulated the GLP vault mechanism, pressured the protocol to halt buying and selling and pause the minting and redeeming of GLP on each Arbitrum and Avalanche. GMX clarified that the breach was remoted to V1 and didn’t influence GMX V2, its token, or different related markets.
Whereas the GMX group has but to reveal the precise exploit vector, the incident exposes the fragility of even audited good contracts and raises pressing questions in regards to the sustainability of decentralized leverage markets, the place GMX has lengthy been a dominant participant.
How audits did not cease the $40 million GMX exploit
The attacker’s path to draining $40 million from GMX’s V1 GLP pool was alarmingly easy but devastatingly efficient. In keeping with blockchain analysts, the exploit concerned manipulating the protocol’s leverage mechanism to mint extreme GLP tokens with out correct collateral.
As soon as the attacker artificially inflated their place, they redeemed the fraudulently minted GLP for underlying property, leaving the pool in need of over $40 million in a matter of blocks.
The funds didn’t stay idle for lengthy. In keeping with Cyvers and Lookonchain, the attacker used a malicious contract funded via Twister Money to obscure the origin of the exploit. Roughly $9.6 million of the estimated $42 million haul was bridged from Arbitrum to Ethereum utilizing Circle’s Cross-Chain Switch Protocol, with parts swiftly transformed to DAI.
Property drained included ETH, USDC, fsGLP, DAI, UNI, FRAX, USDT, WETH, and LINK, making this a multi-asset strike spanning each native and artificial tokens.
Earlier than the hack, GMX’s V1 contracts had been reviewed by high auditing companies. Quantstamp’s pre-deployment audit assessed core dangers like reentrancy and entry controls, whereas ABDK Consulting carried out extra stress assessments. But neither audit flagged the precise leverage manipulation vector that enabled this exploit.
The oversight highlights a recurring blind spot in DeFi safety: audits are likely to deal with normal vulnerabilities however typically miss protocol-specific logic flaws. Sarcastically, GMX had proactive safeguards in place, together with a $5 million bug bounty program and energetic monitoring by companies equivalent to Guardian Audits.
This exploit doesn’t simply undermine GMX, it casts doubt on the audit-driven safety paradigm as a complete. If a protocol as mature and battle-tested as GMX can lose $40 million to a logic flaw, the implications for much less scrutinized initiatives are deeply regarding.
In the meantime, GMX’s on-chain attraction to the hacker, providing a ten% bounty for the return of funds, underscores DeFi’s harsh actuality: restoration efforts typically depend on negotiating with attackers.


