トレンドトピック
#
Bonk Eco continues to show strength amid $USELESS rally
#
Pump.fun to raise $1B token sale, traders speculating on airdrop
#
Boop.Fun leading the way with a new launchpad on Solana.
この攻撃の根本的な原因は@GMX_IOショートポジション操作がグローバルショート平均価格(globalShortAveragePrices)を即座に更新するという設計上の欠陥に起因しており、運用資産残高(AUM)の計算に直接影響を与え、それによってGLPトークンの価格操作を可能にします。
攻撃者は、注文の実行中に「timelock.enableLeverage」を有効にするKeeperの能力を利用して、この設計の脆弱性を悪用しました(これは、大規模なショートポジションを作成するための前提条件です)。リエントランシー攻撃を通じて、彼らは世界平均価格を操作するための大規模なショートポジションを確立することに成功し、1回の取引でGLP価格を人為的に膨らませ、償還操作を通じて利益を得ました。


7月9日 22:35
The GLP pool of GMX V1 on Arbitrum has experienced an exploit. Approximately $40M in tokens has been transferred from the GLP pool to an unknown wallet.
Security has always been a core priority for GMX, with the GMX smart contracts undergoing numerous audits from top security specialists. So, in this hands-on-deck moment, all core contributors are investigating how the manipulation occurred, and what vulnerability may have enabled it.
Our security partners are also deeply involved, to ensure we gain a thorough understanding of the events that occurred and minimise any associated risks as quickly as possible. Our primary focus is on recovery and pinpointing the root cause of the issue.
Actions taken:
Trading on GMX V1, and the minting and redeeming of GLP, have been disabled on both Arbitrum and Avalanche to prevent any further attack vectors and protect users from additional negative impacts.
Scope of the vulnerability:
Please note that the exploit does not affect GMX V2, its markets, or liquidity pools, nor the GMX token itself.
Based on the available information, the vulnerability is limited to GMX V1 and its GLP pool.
As soon as we have more complete and validated information, a detailed incident report will follow.
120.05K
トップ
ランキング
お気に入り