Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
    Crypto’s Biggest Hypocrite Arthur Hayes Shills Tokens Then Dumps on His Followers
    Crypto’s Biggest Hypocrite: Arthur Hayes Shills Tokens Then Dumps on His Followers
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Exclusive

Uncovering GMX Hack: What Exactly Happened in the $42M Exploit

Written By:
Shubham Sahu

Reviewed By:
Gopal Solanky

Last updated: July 12, 2025 12:28 PM
Published 2025-07-12
Share
Uncovering GMX Hack: What Exactly Happened in the $42M Exploit

There are always two sides to a coin, just like the cryptocurrency space. On one side, the market is going mainstream, with an adoption rate at its peak, as governments adopt it as a treasury asset. On the other side, cyber attacks and exploitation cases involving crypto are increasing.

On July 9, the leading decentralized perpetual exchange on Arbitrum, GMX fell victim to one of the latest hacks of this year so far, losing over $42 million. This was not a brute-force smash-and-grab but a well-planned, precision-engineered assault that revealed the weaknesses in the V1 platform of GMX. The incident revealed that as technology and security are getting advanced the hackers are getting smarter and they are continuously finding new ways to exploit platforms.

Let’s deep dive into the incident and find how exactly hackers exploited GMX and stole $42 million. 

What Actually Happened With GMX

GMX faced a major security breach on Wednesday, which led to a loss of over $42 million worth of cryptocurrency assets. Just after the theft, the attackers had already started cleaning their stolen money through the known channels. The funds were later partially transferred from Arbitum to Ethereum blockchain, with an estimated amount of about $9.6 million, and this is a typical trend, where hackers use cross-chain bridges, and then they may transfer funds through privacy protocols such as Tornado Cash.

The stolen portfolio contains wrapped Bitcoin (WBTC), wrapped Ethereum (WETH), FRAX, LINK, USDC and USDT. All the assets, excluding FRAX have been converted for 11,700 ETH which is worth around $32.33 million. 

Posting this message in hopes of connecting with the individual responsible for the GMX V1 exploit.

You've successfully executed the exploit; your abilities in doing so are evident to anyone looking into the exploit transactions.

The white-hat bug bounty of $5 million continues… https://t.co/KPf2fEtU6t

— GMX 🫐 (@GMX_IO) July 10, 2025

In reaction to the hack, the GMX developers have gone to the unconventional measure of reaching out to the hacker directly via an on-chain message, promising a 10% white-hat bounty to the hacker should they voluntarily send back the stolen funds. This would handle the event as a possible security audit as opposed to an attack.

The GMX exploit adds to an already worrying trend of cryptocurrency security breaches. Blockchain security firm CertiK estimated that investors have lost around $2.5 billion to different hacks and scams in the first half of 2025, which also reveals the weaknesses of the decentralized finance ecosystem.

GMX Hacker Agreed to Return Funds

Following the onchain discussions with the GMX team, the hacker entity agreed to return stolen funds in exchange for a 10% white-hat bounty. Under the terms, GMX will not take any legal actions against the hacker nor will it hold anything against the hacker. Meanwhile, the hacker entity would keep approximately $5 million to themselves and send remaining stolen funds to the GMX deployer address. 

How GMX Exploited

The attacker targeted the V1 protocol of GMX, its GLP pool Smart contracts. The flaw? A design flaw in the way the protocol dealt with short positions and how it computed the values of the assets. When a user opened a short position, the contract would instantly change the global average price–not waiting until the market responded. This enabled the attacker to tamper with the calculations done by the system and withdraw money at artificially low prices.

Recent attack on GMX (@GMX_IO) resulted in over $42M in losses. Here’s a summary of our analysis:

Root causes:

1️⃣GMX v1 updates globalShortAveragePrices when opening shorts but not when closing.
2️⃣It immediately increases globalShortSizes on short position creation.

These… https://t.co/H7a4ie4WmZ pic.twitter.com/vzLHpFIRBo

— SlowMist (@SlowMist_Team) July 11, 2025

The Slowmist, a blockchain security firm, disclosed that the cause of this attack was a design flaw in GMX v1. According to Slowmist the root cause was that the global short average prices would instantly be reflected in short position operations, directly affecting the calculation of Asset Under Management (AUM) and thus manipulating the pricing of the GLP token.

This design flaw was exploited by the attacker by using Keeper to activate the “timelock.enableLeverage” functionality in order execution (a precondition to opening a large number of short positions). By means of reentry attacks, the attacker managed to open a large number of short positions, control the global average price, artificially increase the price of GLP in one transaction, and earn money by redemption operations.

Final Thoughts

The GMX exploit reveals a bitter reality: the openness of DeFi, which is its great strength, is also its Achilles heel. Even after a thorough audit, smart contracts may have hidden bugs that even highly skilled attackers can take advantage of. This hack highlights the difficulty of tracking illegal funds in a decentralized system, making recovery more difficult with the use of Tornado Cash.

In the case of GMX, the way out is a thorough postmortem, which the team has promised to do, to identify the underlying cause and avoid repetition. The industry should focus on the proactive approach, frequent smart contract updates, in-time control, and standardized security procedures. DeFi platforms might work together to create best practices, which will minimize the area of attack by hackers

The GMX hack is the wake-up call of the DeFi industry. Platforms such as GMX have to ensure that they offer state of the art features with uncompromising security. To the users, the incident is a lesson to remain cautious, turn off leverage when there are vulnerabilities, and use official sources to get updates. 

Although DeFi offers financial freedom, it requires constant attention to ensure that it does not fall into the hands of individuals who will take advantage of its openness. As the crypto community awaits what GMX will do next, there is one thing that is apparent, in the race to the future of DeFi, security should be at the forefront. 

Also read: Strategy’s $42B Bet on Bitcoin Faces Major Risks Despite Huge Profit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:DeFi
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Avatar photo
By Shubham Sahu
Follow:
Shubham Sahu is a Freelance Content Writer with 7 years of experience in the financial markets and over 5 years in the crypto industry. He holds degrees in B.Tech and B.Ed, and has a strong background in market research, crypto trends, and on-chain analysis. Shubham specializes in exclusive and in-depth research articles. His investigative work, including a story on the identity of Satoshi Nakamoto, was featured in an article by TIME.com, highlighting his contribution to crypto journalism.
Gopal Solanky, Senior Reporter for Markets and Protocols at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Senior Reporter, Markets & Protocols at The Crypto Times, based in Ahmedabad. He covers institutional crypto adoption, Bitcoin treasury strategies, DeFi markets, protocol ecosystems, Ethereum network activity, Hyperliquid, on-chain trends, and broader digital asset market movements. Gopal has been active in the crypto ecosystem for more than six years. Before joining The Crypto Times full-time in 2023, he worked as a freelance crypto content writer, developing a strong understanding of blockchain infrastructure, DeFi protocols, market cycles, token mechanics, and peer-to-peer systems. His reporting focuses on explaining how protocols work, why market movements happen, and how institutional and on-chain activity affects crypto investors and builders. At The Crypto Times, Gopal regularly writes market analysis, protocol explainers, breaking news, and technical breakdowns across Bitcoin, Ethereum, DeFi, altcoins, treasury companies, and Web3 infrastructure. He also conducts on-the-record interviews with regional Web3 founders, protocol teams, and ecosystem leaders. His work has been cited by external publications, including Vulture.com, in coverage of major crypto stories such as the Hawk Tuah memecoin controversy. His reporting has also contributed to The Crypto Times’ coverage of major industry events, including FTX-related developments, institutional crypto adoption, and emerging protocol narratives. Gopal holds a Bachelor’s degree in Computer Applications, giving him a technical foundation for analyzing blockchain systems, crypto infrastructure, and market data.

Latest News

248K Affected India's ED Cracks Down on Alleged ₹500 Crore Crypto MLM
248K Affected: India’s ED Cracks Down on Alleged ₹500 Crore Crypto MLM
Why is Ethereum Price Up Today?
Why is Ethereum Price Up Today?
$4.7M Purchase Strive Adds More Bitcoin as Treasury Strategy Grows
$4.7M Purchase: Strive Adds More Bitcoin as Treasury Strategy Grows
Kraken Rolls Out CFTC-Regulated Perpetual Futures to US Clients
Kraken Rolls Out CFTC-Regulated Perpetual Futures to US Clients
Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto

Find Us on Socials

You may also like

Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans

Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans

Curve Opens a New DeFi Lending Market for LP Token Holders

Curve Opens a New DeFi Lending Market for LP Token Holders

One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit

Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure

Paradigm, Hyperliquid Sound Alarm on GENIUS Act Over Stablecoin and DeFi

Paradigm, Hyperliquid Sound Alarm on GENIUS Act Over Stablecoin and DeFi

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information