SlowMist: GMX Theft Leads to GLP Price Manipulation, Attacker Manipulates Global Average Price by Creating Large Short Positions through Reentrancy

By: theblockbeats.news|2025/07/10 06:01:54
Share
copy

BlockBeats News, July 10th. SlowMist Cosmos stated in a post that the fundamental reason for the $42 million theft of GMX last night was that GMX v1 would immediately update the global short average price when handling short positions. This global average price directly affects the calculation of the total asset under management (AUM), leading to the manipulation of the GLP token price.

The attacker exploited this design flaw by using a Keeper to enable the timelock.enableLeverage feature when executing orders (a necessary condition for creating large short positions), successfully creating a large short position through reentrancy to manipulate the global average price. This artificially inflated the GLP price in a single transaction and profited through redemption operations.

You may also like

HashKey Secures $250M for New Crypto Fund Amid Strong Institutional Interest

Key Takeaways HashKey Capital successfully secured $250 million for the initial close of its fourth crypto fund, showcasing…

Kalshi First Research Report: When Predicting CPI, Crowd Wisdom Beats Wall Street Analysts

Kalshi’s research shows that the prediction market's judgment of CPI is significantly superior to traditional institutional consensus when unexpected inflation shocks occur

Are Those High-Raised 2021 Projects Still Alive?

Crypto's Most Rekt Leaderboard: Is Your Bag on the List?

High Fees, Can't Beat the Market Even After Paying 10x More, What Exactly Are Top Hedge Funds Selling?

Hedge funds sell not outperformance of the market, but rather scarce returns such as factor neutrality and high Sharpe ratio that cannot be easily replicated and can significantly improve portfolio efficiency.

AI Trading Risks in Crypto Markets: Who Takes Responsibility When It Fails?

AI trading is already core market infrastructure, but regulators still treat it as a tool — responsibility always stays with the humans and platforms behind it. The biggest risk in 2025 is not rogue algorithms, but mass-adopted AI strategies that move markets in sync and blur the line between tools and unlicensed advice. The next phase of AI trading is defined by accountability and transparency, not performance — compliance is now a survival requirement, not a constraint.

Twitter 上的「虚假流量」是指通过操纵关注者数量、喜欢和转发等指标来人为增加一条推文的影响力和可信度。下面是一些常见的制造虚假流量的方法: 1. <b>购买关注者:</b> 一些用户会通过购买关注者来迅速增加他们的关注者数量,从而让他们的账号看起来更受欢迎。 2. <b>使用机器人账号:</b> 制造虚假流量的另一种常见方法是使用机器人账号自动执行喜欢、转发和评论等互动操作,从而提高一条推文的互动量。 3. <b>推文交换:</b> 一些用户之间会进行推文交换,即互相喜欢、转发对方的推文...

Why Did Musk and His Tweets Have to Do This?

Popular coins

Latest Crypto News

Read more