SlowMist: GMX Theft Leads to GLP Price Manipulation, Attacker Manipulates Global Average Price by Creating Large Short Positions through Reentrancy
BlockBeats News, July 10th. SlowMist Cosmos stated in a post that the fundamental reason for the $42 million theft of GMX last night was that GMX v1 would immediately update the global short average price when handling short positions. This global average price directly affects the calculation of the total asset under management (AUM), leading to the manipulation of the GLP token price.
The attacker exploited this design flaw by using a Keeper to enable the timelock.enableLeverage feature when executing orders (a necessary condition for creating large short positions), successfully creating a large short position through reentrancy to manipulate the global average price. This artificially inflated the GLP price in a single transaction and profited through redemption operations.
You may also like

New gameplay for participating in initial offerings on cryptocurrency exchanges

Why Is Bitcoin Down Today? What the Hawkish FOMC Means for SpaceX, Gold and Nasdaq

OKX Star analyzes Binance's competitive advantages: when regulation levels the playing field, competition has just begun

Full version of the debut Q&A! Federal Reserve Chairman Waller: Sticking to the 2% inflation target, establishing five special working groups, individual did not submit the dot plot

From Disruptor to Shadow Market: The Crypto Market is Becoming a Colony of Traditional Finance

Dalio's important long article: How to position in the current market environment?

DeepSeek Financing Story

Morning Report | Illinois signs the strictest digital asset tax law in the U.S.; RWA tokenization market size surpasses $43 billion, institutions accelerate the migration of on-chain assets

Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin

Cursor, why did you get on Musk's spaceship?

In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?

Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?

How to exit after asset tokenization?

The stablecoin positioning battle escalates: When compliance is just a ticket to entry, will USD1 become the biggest winner?

