SlowMist Cosine: GMX-related fork projects need to avoid similar security risks as GMX v1

By: odaily.com|2025/07/10 21:01:40
0
Share
copy

Odaily News Yu Xian, the founder of SlowMist, posted on the X platform that GMX-related fork projects need to pay attention to similar security risks. He said that the fundamental reason why GMX was stolen for $42 million last night was that GMX v1 would immediately update the global short average price (globalShortAveragePrices) when processing short positions, and this global average price would directly affect the calculation of the total asset size (AUM), which would lead to the manipulation of the GLP token price. The attacker took advantage of this design flaw and enabled the timelock.enableLeverage feature (a necessary condition for creating large short orders) when executing orders through Keeper. By re-entering, he successfully created a large short position to manipulate the global average price, so as to artificially raise the GLP price in a single transaction and profit through redemption operations.

You may also like

It took me a year to see the painful truth about Agent payments

Among the four major tracks of Agent purchasing, Agent API, Agent inter-payment, and Agent finance, currently only Agent finance has real users and willingness to pay. But worse than having no demand is that the real competition point has never been payment...

A Perspective on the Indian Cryptocurrency Market: Descending into Silence or Moving Towards Maturity?

The Indian cryptocurrency industry has not gone silent; it is steadily maturing towards diversification.

Morning News | Bitmine issues preferred shares to raise $300 million; Polymarket accuses Kalshi of industrial espionage

Overview of Important Market Events on June 4th

Privacy coin trust crisis! ZEC plummets over 56% in a single day

The recent increase in ZEC is nearly 3 times, and the vulnerability news may have just provided an opportunity to exit.

Who is leading the price discovery in the cryptocurrency market? Measured delays on platforms like Binance and Hyperliquid

There is a saying circulating on crypto Twitter: Hyperliquid has replaced Binance and become the center of crypto price discovery. Arrakis conducted a cross-platform test using the tick-by-tick transaction data from 29 perpetual markets, and the truth lies within milliseconds.

Anthropic launches IPO: Business miracle or valuation bubble?

Human economy is transitioning from a carbon-based drive to a dual-engine drive of carbon-based and silicon-based, which is what is truly happening behind Anthropic's IPO.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com