SlowMist: The core reason for the GMX attack is that the global short average price of GMX v1 can be manipulated, causing the GLP price to be maliciously inflated for arbitrage.
BlockBeats News, July 10th, Slowmist CISO @im23pds tweeted that "The root cause of the GMX attack is that GMX v1 immediately updates the global short position average price when handling short positions. This global average price directly affects the calculation of the total asset under management (AUM), leading to the manipulation of the GLP token price.
The attacker exploited this design flaw by using a Keeper to enable the timelock.enableLeverage feature when executing orders (a necessary condition to create a large short position). Through reentrancy, they successfully created a large short position to manipulate the global average price, artificially raising the GLP price in a single transaction and profiting through redemption.
You may also like
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.

How to Trade Cryptocurrency Without App Store: Instant Browser Crypto Trading on WEEX
Trade crypto instantly without downloading an app. Use WEEX H5 to access spot and futures trading directly in your browser with fast execution, real-time risk control, and seamless experience across mobile, tablet, and desktop. Supports Bitcoin, Ethereum, and more.

From OKX to Bybit, exchanges are changing tires on the highway at high speed

A Brief History and Future of Perpetual Contracts

AI Agent Gets ID and Wallet on the Same Day | Rewire News Morning Brief

IOSG: Power Flexibility Paradigm Shift: From Macro Assets to Distributed Intelligence Layer

Murata 35% Price Increase Explained: A Capacitor that Gives AI Empire a Cold

MiniMax: A Henan County Youth and His 300 Billion

From Abandoned Project to Sky-High Target, Mastercorp Acquires BVNK for $1.8 Billion

Is Polymarket's Pricing Accurate? I Simulated a Crisis with 200 Agents to Find Out

A Decade of Regulation Finally Clarified, Victory for Crypto-Native Logic

The United States Establishes the "Five Categories Law" for Cryptographic Assets: A Summary to Understand the New Regulatory Framework

Morning Report | Mastercard plans to acquire BVNK for up to $1.8 billion; Solana Foundation launches aggregator Tokens on Solana; Bitcoin sees its first 8 consecutive rises in four years

Aster Chain officially launches: defining a new era of on-chain privacy and transparency

Stargate Debut Illustrated: The 1.4 Trillion Computing Power Empire Dream, Awakened

A Billion-Dollar Life Buy Threat Triggered by an Iranian Missile

BlackRock Launches ETHB: Ethereum ETF Enters 'Interest-Bearing Age'

Nvidia Starts Putting Chips in the Road | Rewire News Evening Update
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.
How to Trade Cryptocurrency Without App Store: Instant Browser Crypto Trading on WEEX
Trade crypto instantly without downloading an app. Use WEEX H5 to access spot and futures trading directly in your browser with fast execution, real-time risk control, and seamless experience across mobile, tablet, and desktop. Supports Bitcoin, Ethereum, and more.