T
iTokenly

Abracadabra Money GM cauldrons hack — March 2025

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 25, 2025
Target typeLending protocol
Loss$13,400,000Published estimates range $13,000,000 to $13,400,000Price at time of incident
MethodContract logic errorA collateral-accounting flaw in the GmxV2CauldronV4 contract. GMX V2 settles deposits in two steps (order creation, then keeper fulfilment); on liquidation the cauldron drew additional collateral from the GmxV2CauldronRouterOrder contract, but per the post-mortem 'the order is not tracked as being closed for the user in the Cauldron and the reported orderValueInCollateral is not updated.' The attacker forced a GMX deposit to fail so funds stayed in the OrderAgent contract, borrowed, self-liquidated inside the same transaction, then borrowed again against collateral that no longer existed. Halborn describes the same defect as 'state tracking errors' in the cauldrons.
ChainsArbitrum, Ethereum
Audited beforehandGuardian Audits
OutcomeUnresolved

What happened

The attack ran from 07:57:52 UTC to 09:46:22 UTC on 25 March 2025, ending when Abracadabra cut the affected borrow limits to zero. Roughly $13.4 million of Magic Internet Money (MIM) was borrowed without collateral from five "cauldrons" on Arbitrum that accepted GMX V2 liquidity tokens: gmETH, gmBTC, gmSOL, gmBTC/BTC and gmETH/ETH. The first exploit transaction, at 07:58:06 UTC, minted $44,390 of undercollateralised MIM; the last ran at 09:37:36 UTC.

According to the project's post-mortem, the flaw sat in the GmxV2CauldronV4 contract's collateral accounting. GMX V2 settles deposits in two steps — an order is created, then a keeper fills it — and on liquidation the cauldron drew extra collateral from the router-order contract without marking the user's pending order closed or updating its reported value in collateral terms. The attacker deliberately let a GMX deposit fail so the funds stayed in the OrderAgent contract, borrowed against the position, liquidated himself within the same transaction, and was then able to borrow again against collateral that no longer existed. Halborn describes the same defect as "state tracking errors" in the cauldrons, noting the attacker "could self-liquidate their position and still be able to take out a bad loan using the now non-existent collateral".

Abracadabra said no user collateral was lost and that GMX's own contracts were unaffected, a point a GMX developer confirmed publicly; the shortfall was undercollateralised MIM debt. The contracts had been audited by Guardian Audits. The DAO recovered about $260,000 from the router-order contracts, offered a 20% bounty with an email contact address, and said Chainalysis, ZeroShadow and members of Seal 911 were tracking the funds.

Within roughly 36 hours the treasury, then holding about $19 million, bought back 6.5 million MIM, covering half the loss, and said the remainder would be absorbed over the following months. MIM's peg dipped only slightly, to around $0.9946. Figures for the take vary between about $13 million and $13.4 million depending on whether the MIM borrowed or the roughly 6,260 ETH realised is counted. The ether was bridged to Ethereum; crypto.news reported that around 6,000 ETH was still sitting across three attacker addresses, with the DAO open to negotiating its return. It was not recovered.

Sources

  1. Abracadabra MoneyPrimary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. crypto.newsSecondary · retrieved 2026-08-01
  5. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://paragraph.com/@abracadabra-money/post-mortem-attack-on-gm-cauldrons-25-03-25

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Abracadabra Money GM cauldrons hack — March 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/abracadabra-gm-cauldrons
https://itokenly.com/hacks/abracadabra-gm-cauldrons

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.