GMX Exploit Reveals Design Flaw, $42M Lost
GMX v1 exploited by hackers due to design flaw, causing $42M loss. SlowMist identifies vulnerability, with GMX pausing trading and offering bounty.

- GMX lost approximately $42 million due to a design flaw.
- SlowMist identified the vulnerability in GMX v1.
- Trading paused, a bounty offered for fund return.

GMX v1 on Arbitrum suffered a $42 million exploit on July 10, 2025, due to a design flaw, identified by security firm SlowMist, prompting immediate protocol suspensions.
The exploit exposes potential vulnerabilities and underscores the challenges in ensuring DeFi security, swiftly impacting market confidence.
The security breach at GMX revealed vulnerabilities in their v1 design. Users suffered significant losses when hackers exploited this flaw to manipulate GLP token prices, draining funds from the liquidity pool.
Key players include SlowMist, who identified the vulnerability, and the GMX Core Team, who took prompt action by suspending trading activities and offering a 10% bounty for the return of stolen assets.
Financial markets saw immediate repercussions. The value of GMX’s governance token fell sharply. The exploit resulted in a loss of public trust, underlining the need for robust security measures in DeFi platforms.
“The vulnerability arises from the immediate update of the global average price when handling short positions. This price directly affects the calculation of the total asset under management (AUM), leading to potential manipulation of the GLP token price.” – @im23pds, CISO, SlowMist
The loss affected major stablecoins like USDC and pressured DeFi protocols to tighten security defenses. It highlighted vulnerabilities in decentralized mechanics, impacting their usability and trustworthiness among users.
Historically, design flaws and reentrancy vulnerabilities have plagued the DeFi sector. This incident accentuates the importance of continual security audits and improvements, aiming for safer crypto ecosystems. The event forecasts heightened scrutiny and innovation in crypto security.
More From Crypto News
SlowMist: Aave V3 Loop Safe Module Exploited, 114.09 ETH Stolen
Aave v3 is one of the largest decentralized lending protocols by total value locked . A module-level exploit differs from a core protocol breach, but it still c...
Ripple reveals XRPL privacy and AI-agent upgrades in Seoul
Ripple used a Seoul event to outline two new development directions for the XRP Ledger: privacy upgrades and AI-agent capabilities.
Fed Bank Reserves Fall $88.236B as Weekly Average Rises
Federal Reserve bank reserves dropped $88. 236 billion between the September 23 and September 30 Wednesday snapshots, even as the weekly average for the same pe...
Crypto Hacks Totaled $766M in September, Led by Bitget and Liquid Losses
Crypto hacks and exploits drained a reported $766 million in September, with losses tied to Bitget and Liquid exchange incidents leading the monthly tally, maki...
US Banking Group Sues OCC Over Crypto Trust Bank Approvals
A US banking industry group has filed a lawsuit against the Office of the Comptroller of the Currency, challenging the federal regulator’s decisions to approve...
20,000 ETH Moved From Bitfinex to Aave: What It Means
On-chain monitoring service Whale Alert flagged a transfer of 20,000 ETH from Bitfinex to an address attributed to Aave on Oct. 3, 2026 at 14:06:47 UTC, valuing...