Decentralized Exchange GMX Exploited for $42M, Offers Hacker 10% White Hat Bounty
Decentralized perpetual exchange GMX suffered a significant exploit, resulting in the theft of over $42 million in cryptocurrency. Blockchain security firm PeckShield identified the incident, revealing that a substantial portion of the stolen funds – approximately $9.6 million – has already been transferred to the Ethereum blockchain. This is a common tactic employed by hackers to obfuscate the trail of illicit funds, often leveraging services like Tornado Cash, a token mixing protocol known for its role in laundering cryptocurrency. The remaining $32 million currently resides on Arbitrum, the layer-2 network hosting the GMX exchange.
The stolen assets included a mix of cryptocurrencies, with a notable loss of over $10 million in legacy Frax (FRAX) stablecoin. Further analysis reveals significant losses of $9.6 million in wrapped Bitcoin (wBTC) and $5 million in Dai (DAI) stablecoin. The impact of this exploit extends beyond the immediate financial losses; it underscores the ongoing vulnerabilities within the decentralized finance (DeFi) ecosystem.
In response to the attack, GMX developers took an unusual step, publicly acknowledging the exploit and issuing an on-chain message offering a 10% white-hat bounty for the return of the stolen funds. This initiative demonstrates an attempt to incentivize the hacker – or potentially a third party – to return the assets in exchange for a significant reward. A white-hat bounty program is a standard practice within the cybersecurity field, offering financial compensation to ethical hackers who identify and report vulnerabilities before malicious actors can exploit them.
This incident highlights a larger trend within the cryptocurrency industry. A CertiK report reveals that investors lost a staggering $2.5 billion to hacks and scams during the first half of 2025 alone. This alarming figure underscores the need for enhanced security measures and robust auditing protocols within the DeFi space. The GMX exploit serves as a stark reminder of the persistent risks associated with decentralized finance and the ongoing challenge of balancing innovation with security. The GMX team’s public response and white-hat bounty offer, while unusual, suggests a proactive approach to mitigate the damage and potentially recover a portion of the lost funds. However, the long-term impact on user trust and the overall stability of the GMX exchange remains to be seen.

