Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy
BTCBTC
💲76714.08
-
2.11%
ETHETH
💲2113.46
-
3.54%
SOLSOL
💲84.25
-
3.02%
HYPEHYPE
💲45.15
+
4.18%
ZECZEC
💲508.53
+
1.53%
DOGEDOGE
💲0.1040
-
6.64%

SlowMist
SlowMist|Jul 11, 2025 03:43
Recent attack on GMX (@GMX_IO) resulted in over 42M in losses. Here’s a summary of our analysis: Root causes: 1️⃣GMX v1 updates globalShortAveragePrices when opening shorts but not when closing. 2️⃣It immediately increases globalShortSizes on short position creation. These flaws distorted the AUM calculation, manipulating GLP token prices. The attacker exploited this design flaw by leveraging the Keeper’s timelock.enableLeverage feature—which must be enabled to create large short positions—and used a reentrancy attack to successfully open large short positions. This manipulated the global average price and global short size, artificially inflating the GLP price within a single transaction and profiting through redemption. According to @MistTrack_io: 1️⃣The attacker’s initial funds came from Tornado Cash; ultimately, 11,700 ETH flowed into address: 0x6acc60b11217a1fd0e68b0ecaee7122d34a784c1. 2️⃣Current balances include: • Arbitrum: 10,494,796 Legacy Frax Dollar + 1.07 ETH (0xdf3340a436c27655ba62f8281565c9925c3a5221) • Ethereum:  - 3,000 ETH (0xa33fcbe3b84fb8393690d1e994b6a6adc256d8a3)  - 3,000 ETH (0xe9ad5a0f2697a3cf75ffa7328bda93dbaef7f7e7)  - 3,000 ETH (0x69c965e164fa60e37a851aa5cd82b13ae39c1d95)  - 2,700 ETH (0x639cd2fc24ec06be64aaf94eb89392bea98a6605) 🔗Related links: Attacker address: https://arbiscan.io/address/0xdf3340a436c27655ba62f8281565c9925c3a5221 Attack contract: https://arbiscan.io/address/0x7d3bd50336f64b7a473c51f54e7f0bd6771cc355 Vulnerable contract: https://arbiscan.io/address/0x3963ffc9dff443c2a94f21b129d429891e32ec18 Attack transaction: https://arbiscan.io/tx/0x03182d3f0956a91c4e4c8f225bbc7975f9434fab042228c7acdc5ec9a32626ef Check out our latest article for a full breakdown of the attack and fund movements.⬇️ https://slowmist.medium.com/inside-the-gmx-hack-42-million-vanishes-in-an-instant-6e42adbdead0
+5
Mentioned
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Timeline

Aug 10, 03:07【Review of Ethereum's DAO Hard Fork Event】
Aug 09, 16:49【Bank customers lose over £ 100000 due to scammers】
Aug 08, 18:05【CrediX was exploited for approximately $4.5 million in suspected exit scam】
Aug 08, 14:44【The Federal Reserve suffered losses of over 240 billion US dollars】
Aug 08, 09:56【The official X account of CrediX has been cancelled】
Aug 08, 09:37【CrediX_fi team disappears after loss event】
Aug 07, 19:46【Japan will lose nearly one million people this year】
Aug 07, 14:13【US government loses $21 billion on BTC sale】
Aug 07, 14:08【Colbert is fully owned by a large pharmaceutical company】
Aug 07, 12:41【Test network under attack】

HotFlash

|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads