GMX Hacker Returns Stolen $40 Million, Accepts $5M Bounty

Less than 48 hours after siphoning about $42 million in cryptocurrencies from the decentralized trading platform GMX, the hacker responsible for the attack has begun to return the stolen loot.

According to an update from the on-chain sleuth PeckShield, the GMX exploiter has returned at least $40.5 million in crypto assets, including ether (ETH) and Legacy Frax Dollar (FRAX).

Root Cause of the Exploit

Recall that the hacker exploited GMX’s smart contracts to steal the funds on July 9. A postmortem report from the firm confirmed that it was a re-entrancy attack. The exploiter took advantage of a smart contract function that could not prevent re-entrancy issues within the same smart contract.

This design flaw on GMX V1 enabled the criminal to place multiple calls within one function and caused the contract to calculate the wrong balance. They were able to artificially inflate the price of GLP, which is the liquidity provider token for GMX.

After the breach, they stole several assets, including Wrapped bitcoin (WBTC), FRAX, and DAI. They eventually bridged the funds from Arbitrum to Ethereum and converted all, except FRAX, to 11,700 ETH.

While the hacker made these moves, GMX dropped an on-chain message, offering a 10% white hat bounty in exchange for the stolen funds. The proposal would last for 48 hours, with a promise of no legal consequences.

Hacker Returns Stolen Funds

Earlier today, the hacker responded to GMX’s 10% bounty offering, with a message that read: “Ok, funds will be returned later.” They first returned $10.49 million FRAX to the GMX Security Committee Multisig address. The remaining $32 million, which were swapped for ETH earlier, have also been returned in batches.

Notably, the $32 million ETH was worth $35 million today following the spike in ether’s price. The hacker took the $3 million profit and returned the original amount. Therefore, they took a bounty of roughly $4.5 million and returned a total of $40.5 million.

Meanwhile, GMX has confirmed that the incident did not affect its V2 protocol, as the chain does not have the vulnerability that enabled the attack on V1. The team has lifted the minting caps it placed on liquidity tokens for GMX V2 on Arbitrum and Avalanche.

GMX, the native token of the GMX platform, has also recovered from a sudden dip caused by the incident. Data from CoinMarketCap shows the asset is up over 13% today.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Mandy Williams

https://cryptopotato.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/

2025-07-11 12:22:56

bitcoin
Bitcoin (BTC) $ 91,590.00 7.80%
ethereum
Ethereum (ETH) $ 3,019.24 10.17%
tether
Tether (USDT) $ 1.00 0.03%
xrp
XRP (XRP) $ 2.17 8.70%
bnb
BNB (BNB) $ 877.30 7.83%
usd-coin
USDC (USDC) $ 0.999807 0.01%
tron
TRON (TRX) $ 0.282356 1.52%
staked-ether
Lido Staked Ether (STETH) $ 3,019.08 9.93%
dogecoin
Dogecoin (DOGE) $ 0.146478 10.05%
cardano
Cardano (ADA) $ 0.429849 14.55%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 0.79%
whitebit
WhiteBIT Coin (WBT) $ 61.78 7.54%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,686.47 9.99%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 91,383.00 7.76%
bitcoin-cash
Bitcoin Cash (BCH) $ 547.41 6.56%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,271.59 10.01%
usds
USDS (USDS) $ 1.00 0.01%
chainlink
Chainlink (LINK) $ 13.34 12.50%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999819 0.04%
hyperliquid
Hyperliquid (HYPE) $ 32.84 10.46%
leo-token
LEO Token (LEO) $ 9.43 4.18%
weth
WETH (WETH) $ 3,019.79 10.12%
stellar
Stellar (XLM) $ 0.253974 11.68%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,268.79 10.09%
monero
Monero (XMR) $ 399.98 2.09%
ethena-usde
Ethena USDe (USDE) $ 0.999369 0.12%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 91,603.00 7.67%
litecoin
Litecoin (LTC) $ 82.40 8.71%
hedera-hashgraph
Hedera (HBAR) $ 0.143198 9.05%
sui
Sui (SUI) $ 1.59 21.14%
avalanche-2
Avalanche (AVAX) $ 13.64 7.33%
zcash
Zcash (ZEC) $ 344.73 0.10%
shiba-inu
Shiba Inu (SHIB) $ 0.000009 7.83%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.16094 4.53%
dai
Dai (DAI) $ 0.999404 0.00%
susds
sUSDS (SUSDS) $ 1.08 0.27%
crypto-com-chain
Cronos (CRO) $ 0.110025 10.27%
the-open-network
Toncoin (TON) $ 1.58 7.64%
paypal-usd
PayPal USD (PYUSD) $ 0.999294 0.08%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.08%
uniswap
Uniswap (UNI) $ 5.96 7.97%
usdt0
USDT0 (USDT0) $ 1.00 0.06%
polkadot
Polkadot (DOT) $ 2.25 13.27%
mantle
Mantle (MNT) $ 1.04 7.44%
aave
Aave (AAVE) $ 186.30 13.23%
canton-network
Canton (CC) $ 0.078112 1.95%
bittensor
Bittensor (TAO) $ 284.85 10.71%
usd1-wlfi
USD1 (USD1) $ 0.999398 0.02%
bitget-token
Bitget Token (BGB) $ 3.57 4.28%
memecore
MemeCore (M) $ 1.38 0.06%