GMX V1 hack — July 2025
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $42,000,000Price at time of incident |
| Recovered | $37,000,000 |
| Method | Reentrancyre-entrancy through the ETH execution-fee refund in PositionManager.executeDecreaseOrder, which handed control to an attacker contract set as position owner while leverage was enabled via the Timelock, letting it call increasePosition directly and bypass the ShortsTracker average-short-price update, inflating GLP's assets-under-management |
| Chains | Arbitrum |
| Outcome | Settled as bug bounty |
What happened
GMX V1, the first version of the perpetual futures protocol, lost about $42 million from its GLP liquidity pool on Arbitrum on 9 July 2025. GMX V2 and the protocol's Avalanche deployment were not affected.
The attack turned on re-entrancy in PositionManager.executeDecreaseOrder. Executing a decrease order enabled leverage through the Timelock contract and refunded the execution fee to the account named in the order, and the code assumed that account was an externally owned address. Because it could be a contract, the refund handed execution control back to attacker-supplied fallback logic mid-transaction, while leverage was still enabled. Verichains describes the attacker deploying a contract as the position owner with custom fallback logic and using that window to call increasePosition directly, bypassing the validation path that updates the ShortsTracker's global average short price. With roughly $15,000 of existing short interest, repeated positions of $80,000 to $100,000 drove globalShortAveragePrices from $108,757 to $1,913, about 57 times below market. CertiK independently describes the same desynchronisation, noting the average-short-price update happens at a different level of execution from the position increase. With the average short price left artificially low, the assets-under-management calculation overstated the value of GLP, and GLP minted moments earlier could be redeemed for far more than it was worth.
GMX halted V1 trading and GLP minting and offered the attacker a bounty of 10 percent of the proceeds to return the rest. The attacker accepted. The exact returned figure is not settled: CertiK states the white-hat transferred about $37 million to GMX against a 10 percent bounty, which on a $42 million exploit implies roughly $4.2 million retained, and The Block reports the same 10 percent arrangement. Other coverage has rounded the retained amount variously between about $3.8 million and $5 million. This record uses approximately $37 million as the recovered figure, the only number stated directly by a source rather than derived.
GMX then distributed about $44 million in value to affected Arbitrum GLP holders, made up of the recovered funds plus roughly $2 million from its treasury, paid in GLV tokens — equal proportions of GLV [BTC-USDC] and GLV [WETH-USDC], amounting to about 25 percent WBTC, 25 percent ETH and 50 percent stablecoins — with a further $500,000 GLV incentive pool for holders who kept the distribution for at least three months.
Sources
- CertiKSecondary · retrieved 2026-08-01
- VerichainsSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- SherlockSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "GMX V1 hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gmx-v1https://itokenly.com/hacks/gmx-v1Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.