GMX Hacker Returns Stolen $40 Million, Accepts $5M Bounty

Less than 48 hours after siphoning about $42 million in cryptocurrencies from the decentralized trading platform GMX, the hacker responsible for the attack has begun to return the stolen loot.

According to an update from the on-chain sleuth PeckShield, the GMX exploiter has returned at least $40.5 million in crypto assets, including ether (ETH) and Legacy Frax Dollar (FRAX).

Root Cause of the Exploit

Recall that the hacker exploited GMX’s smart contracts to steal the funds on July 9. A postmortem report from the firm confirmed that it was a re-entrancy attack. The exploiter took advantage of a smart contract function that could not prevent re-entrancy issues within the same smart contract.

This design flaw on GMX V1 enabled the criminal to place multiple calls within one function and caused the contract to calculate the wrong balance. They were able to artificially inflate the price of GLP, which is the liquidity provider token for GMX.

After the breach, they stole several assets, including Wrapped bitcoin (WBTC), FRAX, and DAI. They eventually bridged the funds from Arbitrum to Ethereum and converted all, except FRAX, to 11,700 ETH.

While the hacker made these moves, GMX dropped an on-chain message, offering a 10% white hat bounty in exchange for the stolen funds. The proposal would last for 48 hours, with a promise of no legal consequences.

Hacker Returns Stolen Funds

Earlier today, the hacker responded to GMX’s 10% bounty offering, with a message that read: “Ok, funds will be returned later.” They first returned $10.49 million FRAX to the GMX Security Committee Multisig address. The remaining $32 million, which were swapped for ETH earlier, have also been returned in batches.

Notably, the $32 million ETH was worth $35 million today following the spike in ether’s price. The hacker took the $3 million profit and returned the original amount. Therefore, they took a bounty of roughly $4.5 million and returned a total of $40.5 million.

Meanwhile, GMX has confirmed that the incident did not affect its V2 protocol, as the chain does not have the vulnerability that enabled the attack on V1. The team has lifted the minting caps it placed on liquidity tokens for GMX V2 on Arbitrum and Avalanche.

GMX, the native token of the GMX platform, has also recovered from a sudden dip caused by the incident. Data from CoinMarketCap shows the asset is up over 13% today.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Mandy Williams

https://cryptopotato.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/

2025-07-11 12:22:56

bitcoin
Bitcoin (BTC) $ 121,720.00 1.81%
ethereum
Ethereum (ETH) $ 4,708.44 4.82%
xrp
XRP (XRP) $ 3.26 0.31%
tether
Tether (USDT) $ 1.00 0.02%
bnb
BNB (BNB) $ 839.52 1.29%
solana
Solana (SOL) $ 198.78 5.57%
usd-coin
USDC (USDC) $ 0.999789 0.00%
staked-ether
Lido Staked Ether (STETH) $ 4,705.05 4.95%
dogecoin
Dogecoin (DOGE) $ 0.241474 3.22%
tron
TRON (TRX) $ 0.360669 3.09%
cardano
Cardano (ADA) $ 0.872124 4.04%
wrapped-steth
Wrapped stETH (WSTETH) $ 5,719.93 5.25%
chainlink
Chainlink (LINK) $ 23.66 0.50%
hyperliquid
Hyperliquid (HYPE) $ 47.01 6.51%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 121,726.00 1.84%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 5,068.35 4.64%
stellar
Stellar (XLM) $ 0.448321 0.25%
sui
Sui (SUI) $ 3.97 2.28%
wrapped-eeth
Wrapped eETH (WEETH) $ 5,057.81 4.94%
bitcoin-cash
Bitcoin Cash (BCH) $ 612.21 1.44%
hedera-hashgraph
Hedera (HBAR) $ 0.262792 1.20%
weth
WETH (WETH) $ 4,716.40 5.10%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.01%
avalanche-2
Avalanche (AVAX) $ 25.13 2.96%
litecoin
Litecoin (LTC) $ 129.58 2.78%
the-open-network
Toncoin (TON) $ 3.50 1.95%
leo-token
LEO Token (LEO) $ 9.24 2.08%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 1.50%
usds
USDS (USDS) $ 0.999727 0.02%
uniswap
Uniswap (UNI) $ 11.94 4.99%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.01%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 121,824.00 1.80%
whitebit
WhiteBIT Coin (WBT) $ 46.49 2.13%
polkadot
Polkadot (DOT) $ 4.20 0.38%
okb
OKB (OKB) $ 104.02 125.07%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.19 0.00%
bitget-token
Bitget Token (BGB) $ 4.78 7.35%
crypto-com-chain
Cronos (CRO) $ 0.164681 1.86%
ethena
Ethena (ENA) $ 0.769831 4.61%
pepe
Pepe (PEPE) $ 0.000012 0.29%
aave
Aave (AAVE) $ 325.67 2.71%
monero
Monero (XMR) $ 255.47 0.67%
dai
Dai (DAI) $ 0.999945 0.00%
mantle
Mantle (MNT) $ 1.13 8.85%
bittensor
Bittensor (TAO) $ 388.12 0.24%
ethereum-classic
Ethereum Classic (ETC) $ 23.94 1.64%
near
NEAR Protocol (NEAR) $ 2.92 5.70%
aptos
Aptos (APT) $ 4.94 2.60%
ondo-finance
Ondo (ONDO) $ 1.06 0.36%
internet-computer
Internet Computer (ICP) $ 5.91 3.77%