SlowMist Cosine: GMX-related fork projects need to avoid similar security risks as GMX v1

By: odaily.com|2025/07/10 13:01:40
Share
copy

Odaily News Yu Xian, the founder of SlowMist, posted on the X platform that GMX-related fork projects need to pay attention to similar security risks. He said that the fundamental reason why GMX was stolen for $42 million last night was that GMX v1 would immediately update the global short average price (globalShortAveragePrices) when processing short positions, and this global average price would directly affect the calculation of the total asset size (AUM), which would lead to the manipulation of the GLP token price. The attacker took advantage of this design flaw and enabled the timelock.enableLeverage feature (a necessary condition for creating large short orders) when executing orders through Keeper. By re-entering, he successfully created a large short position to manipulate the global average price, so as to artificially raise the GLP price in a single transaction and profit through redemption operations.

You may also like

Holiday Season Markets: Understanding Low Liquidity and Trading Conditions

At WEEX, we recognize that the holiday season often brings a different trading experience for many users. As market participation slows, price behavior can feel less predictable and familiar trading rhythms may shift. For traders following AI news today or using AI trading tools, this period often highlights how market structure can influence model performance and short-term signals. Approaching these periods with clear expectations and a disciplined mindset can help traders better navigate seasonal market conditions.

Lido DAO’s Increased Development and Market Dynamics Elevate LDO Price

Key Takeaways Lido DAO’s development activities have surged by 690%, signifying substantial growth. The Lido DAO token (LDO)…

Hyperliquid Whales Shift Strategies: BTC Longs Decline, ETH Shorts Dominate

Key Takeaways A significant reduction in Bitcoin long positions has been observed on Hyperliquid, with large holders decreasing…

Token VS Equity: The Aave Controversy

This is the challenge Aave has to face, and more broadly, the challenge the entire industry has to face.

December 26th Market Key Intelligence, How Much Did You Miss?

1. On-chain Funds: $7.8M USD inflow to Hyperliquid today; $5.5M USD outflow from Solana 2. Largest Price Swings: $ISLM, $FTN 3. Top News: Trust Wallet will ensure all affected users receive refunds, users need to complete the upgrade process promptly

Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis

Trust Wallet Browser Extension version 2.68 has been found to contain a malicious backdoor, resulting in user funds being stolen, with a total loss exceeding $6 million.

Popular coins

Latest Crypto News

Read more