GMX Hacker Returns Stolen $40 Million, Accepts $5M Bounty

Less than 48 hours after siphoning about $42 million in cryptocurrencies from the decentralized trading platform GMX, the hacker responsible for the attack has begun to return the stolen loot.

According to an update from the on-chain sleuth PeckShield, the GMX exploiter has returned at least $40.5 million in crypto assets, including ether (ETH) and Legacy Frax Dollar (FRAX).

Root Cause of the Exploit

Recall that the hacker exploited GMX’s smart contracts to steal the funds on July 9. A postmortem report from the firm confirmed that it was a re-entrancy attack. The exploiter took advantage of a smart contract function that could not prevent re-entrancy issues within the same smart contract.

This design flaw on GMX V1 enabled the criminal to place multiple calls within one function and caused the contract to calculate the wrong balance. They were able to artificially inflate the price of GLP, which is the liquidity provider token for GMX.

After the breach, they stole several assets, including Wrapped bitcoin (WBTC), FRAX, and DAI. They eventually bridged the funds from Arbitrum to Ethereum and converted all, except FRAX, to 11,700 ETH.

While the hacker made these moves, GMX dropped an on-chain message, offering a 10% white hat bounty in exchange for the stolen funds. The proposal would last for 48 hours, with a promise of no legal consequences.

Hacker Returns Stolen Funds

Earlier today, the hacker responded to GMX’s 10% bounty offering, with a message that read: “Ok, funds will be returned later.” They first returned $10.49 million FRAX to the GMX Security Committee Multisig address. The remaining $32 million, which were swapped for ETH earlier, have also been returned in batches.

Notably, the $32 million ETH was worth $35 million today following the spike in ether’s price. The hacker took the $3 million profit and returned the original amount. Therefore, they took a bounty of roughly $4.5 million and returned a total of $40.5 million.

Meanwhile, GMX has confirmed that the incident did not affect its V2 protocol, as the chain does not have the vulnerability that enabled the attack on V1. The team has lifted the minting caps it placed on liquidity tokens for GMX V2 on Arbitrum and Avalanche.

GMX, the native token of the GMX platform, has also recovered from a sudden dip caused by the incident. Data from CoinMarketCap shows the asset is up over 13% today.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Mandy Williams

https://cryptopotato.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/

2025-07-11 12:22:56

bitcoin
Bitcoin (BTC) $ 112,893.00 0.69%
ethereum
Ethereum (ETH) $ 4,025.94 5.17%
tether
Tether (USDT) $ 1.00 0.05%
bnb
BNB (BNB) $ 1,287.60 12.26%
xrp
XRP (XRP) $ 2.48 0.42%
solana
Solana (SOL) $ 189.93 3.61%
usd-coin
USDC (USDC) $ 0.999856 0.00%
staked-ether
Lido Staked Ether (STETH) $ 4,020.75 5.10%
dogecoin
Dogecoin (DOGE) $ 0.203814 6.12%
tron
TRON (TRX) $ 0.321727 0.63%
cardano
Cardano (ADA) $ 0.673884 2.83%
wrapped-steth
Wrapped stETH (WSTETH) $ 4,892.94 5.17%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 113,142.00 0.99%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 4,321.27 5.57%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00 3.43%
chainlink
Chainlink (LINK) $ 18.56 3.65%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.01%
stellar
Stellar (XLM) $ 0.337734 3.00%
bitcoin-cash
Bitcoin Cash (BCH) $ 535.52 1.79%
wrapped-eeth
Wrapped eETH (WEETH) $ 4,339.89 5.22%
hyperliquid
Hyperliquid (HYPE) $ 39.11 2.92%
sui
Sui (SUI) $ 2.69 1.16%
weth
WETH (WETH) $ 4,024.70 5.25%
avalanche-2
Avalanche (AVAX) $ 22.20 2.51%
leo-token
LEO Token (LEO) $ 9.67 0.37%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.26%
usds
USDS (USDS) $ 1.00 0.04%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 112,956.00 0.76%
hedera-hashgraph
Hedera (HBAR) $ 0.179212 2.68%
litecoin
Litecoin (LTC) $ 97.66 1.45%
usdt0
USDT0 (USDT0) $ 1.00 0.00%
mantle
Mantle (MNT) $ 2.10 20.70%
shiba-inu
Shiba Inu (SHIB) $ 0.000011 1.65%
whitebit
WhiteBIT Coin (WBT) $ 42.65 1.49%
crypto-com-chain
Cronos (CRO) $ 0.167353 6.10%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20 0.07%
monero
Monero (XMR) $ 306.21 1.42%
the-open-network
Toncoin (TON) $ 2.21 0.69%
polkadot
Polkadot (DOT) $ 3.18 1.00%
dai
Dai (DAI) $ 0.999815 0.05%
zcash
Zcash (ZEC) $ 255.96 3.69%
uniswap
Uniswap (UNI) $ 6.47 6.35%
okb
OKB (OKB) $ 184.20 3.29%
aave
Aave (AAVE) $ 243.11 1.95%
memecore
MemeCore (M) $ 2.07 7.77%
bittensor
Bittensor (TAO) $ 368.10 19.34%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.126408 3.70%
bitget-token
Bitget Token (BGB) $ 4.91 0.94%
pepe
Pepe (PEPE) $ 0.000007 1.89%
near
NEAR Protocol (NEAR) $ 2.41 0.57%