SlowMist Cosine: GMX-related fork projects need to avoid similar security risks as GMX v1

By: odaily.com|2025/07/10 21:01:40
0
Share
copy

Odaily News Yu Xian, the founder of SlowMist, posted on the X platform that GMX-related fork projects need to pay attention to similar security risks. He said that the fundamental reason why GMX was stolen for $42 million last night was that GMX v1 would immediately update the global short average price (globalShortAveragePrices) when processing short positions, and this global average price would directly affect the calculation of the total asset size (AUM), which would lead to the manipulation of the GLP token price. The attacker took advantage of this design flaw and enabled the timelock.enableLeverage feature (a necessary condition for creating large short orders) when executing orders through Keeper. By re-entering, he successfully created a large short position to manipulate the global average price, so as to artificially raise the GLP price in a single transaction and profit through redemption operations.

-- Price

--

You may also like

Crypto Market Update: BTC Holds $76K as Fear Index Signals Opportunity — What Is Futures Trading & Spot Trading Explained

Bitcoin (BTC) is holding above $76,000, supported by strong institutional buyingThe Fear & Greed Index at 33 indicates continued market caution despite price strengthCrypto ETPs saw $1.4B in inflows, marking three consecutive weeks of capital growthEthereum (ETH) is consolidating around $2,300, with resistance near $2,360Understanding what is futures trading vs what is spot trading is key in volatile marketsTraders are increasingly combining spot accumulation with futures trading strategies

DeFi is trapped in the most dangerous prisoner's dilemma in history

This incident has returned to the classic dilemma of cryptography: pragmatic security vs completely decentralized security.

Exclusive Interview with Jeff Hoffman: How Web3 and AI are Reshaping the Trillion-Dollar Social Travel Market

The most valuable platforms will not only be aggregators of suppliers, but they will also have relational networks around payments, loyalty, and communities.

After the KelpDAO hack, AAVE's situation is worse than you think

October 10 is the CEX-driven collapse, an epic failure in DeFi risk mitigation.

Atkins Marks One-Year Anniversary at SEC: Crypto Regulation Shifts from ‘Enforcement Heavy’ to ‘Rulemaking Mode’

Before the bill is passed, the SEC's cryptocurrency regulatory framework remains in a transition state of "administrative guidance + enforcement actions."

Under Political Pressure, Is the Federal Reserve Still Independent?

Powell believes that political pressure is not a threat, and what truly determines the Fed's independence is the Fed itself.

Contents

Popular coins

Latest Crypto News

Read more