BusinessDrinksEntertainmentFashion

GMX Exploiter Return $40M Days After Hack, Token Zooms Higher

A significant DeFi exploit targeting GMX’s V1 contracts, resulting in the theft of over $40 million, has taken an unexpected turn. The attacker, responsible for one of the year’s largest DeFi breaches, has begun returning the stolen funds, seemingly accepting GMX’s substantial $5 million bug bounty.

The incident unfolded on Arbitrum, exploiting a re-entrancy vulnerability within the GMX OrderBook contract. This flaw allowed the attacker to manipulate short positions on Bitcoin, artificially inflating the value of GMX’s GLP pool. This manipulation enabled the attacker to redeem GLP for significantly inflated profits across various tokens, including USDC, WBTC, WETH, and FRAX. Re-entrancy, a common smart contract vulnerability, allows malicious actors to repeatedly call a protocol, tricking it into releasing assets. In this case, the attacker used the authorized smart contract address to interact with user wallets repeatedly, leading to the substantial loss.

GMX reacted swiftly by halting trading and minting on both Arbitrum and Avalanche versions of V1. A generous bug bounty, exceeding 10% of the stolen funds, was offered with a guarantee of no legal action provided the full amount was returned within 48 hours. This incentive appears to have been effective.

The return of funds began with an on-chain message from the attacker stating their intent to return the stolen assets. This was followed by the transfer of over $10.5 million in FRAX back to GMX’s deployer wallet, confirmed by PeckShield. Subsequently, Lookonchain reported the return of an additional $40 million in various tokens to the GMX Security Committee MultiSig address.

This remarkable development showcases the potential effectiveness of bug bounty programs in mitigating the risks associated with smart contract vulnerabilities. While the exploit highlights the ongoing challenges in securing decentralized finance, the attacker’s decision to return the funds demonstrates a possible path toward resolution and underscores the significant impact of substantial financial incentives in addressing such security incidents. GMX’s stock is currently trading at $13.15, having seen a 13% increase in the past 24 hours, reflecting positive market sentiment following the resolution.

Leave a Reply

Your email address will not be published. Required fields are marked *