SlowMist Cosine: GMX-related fork projects need to avoid similar security risks as GMX v1
Odaily News Yu Xian, the founder of SlowMist, posted on the X platform that GMX-related fork projects need to pay attention to similar security risks. He said that the fundamental reason why GMX was stolen for $42 million last night was that GMX v1 would immediately update the global short average price (globalShortAveragePrices) when processing short positions, and this global average price would directly affect the calculation of the total asset size (AUM), which would lead to the manipulation of the GLP token price. The attacker took advantage of this design flaw and enabled the timelock.enableLeverage feature (a necessary condition for creating large short orders) when executing orders through Keeper. By re-entering, he successfully created a large short position to manipulate the global average price, so as to artificially raise the GLP price in a single transaction and profit through redemption operations.
You may also like

OpenAI has no "New Deal," a blueprint for AI that refuses to pay.

Wall Street Flash Mob Run? Mega-Cap Stock Plunge, Goldman's Great Escape, Illustrated Guide to Private Credit Crisis

OpenAI Feud: Power, Trust, and the Uncontrollable Boundaries of AGI

「AI Doomsday Cult」 Sends Operatives into the Strait of Hormuz: What Did They Find?

Everyone is waiting for the war to end, but is the oil price signaling a prolonged conflict?

Data Analysis: How Wide is the Liquidity Gap Between Hyperliquid and CME Crude Oil?

After a 40% Reduction in Staff, Twitter's Founder to Give Away $1 Million in Bitcoin

Trade.xyz: Pricing the World? On-Chain Markets Are Becoming the Market

XXYY Trade Skill: 24/7 Algorithmic Trading AI Trader | Project Introduction

DeFi's top protocol Aave's security team exits, who will weather the next black swan event in the bear market?

Can the person who has been most accurate in predicting gold prices throughout history predict future gold prices?

Quantum Computing Won't Kill Bitcoin, But the Real Risk Is Approaching

When Fintech Merges with the Underlying Crypto: The Next Decade of Digital Finance

You may encounter high-net-worth clients who are possibly "mercenaries" for North Korean hackers

Chaos Labs exits, Aave loses its last risk gatekeeper

Quantum computing will not kill Bitcoin, but the real risks are approaching

Coinbase pushes x402 to neutral, while Stripe continues to bet on both sides outside of MPP

Untitled
I’m sorry, but I can’t fulfill this request as it requires content from an original source that wasn’t…
