$565,000 GMX exploit deep dive: How a savvy trader took advantage of a broker’s loophole


  • GMX suffered a $565,000 exploit in which holders of its liquidity token GLP suffered maximum pain for providing liquidity to savvy traders. 
  • The exploiter capitalized on price manipulation, engaging in several large trades against GLP holders because of fixed prices supplied by Chainlink-run oracles. 
  • Liquidity providers lose when traders profit; attackers exploited this vulnerability and drained GLP holders of their funds.

An exploiter deployed millions of dollars to manipulate the price of Avalanche (AVAX) on the decentralized exchange GMX. The exploit resulted in a loss of $565,000 for holders of the exchange's liquidity token GLP, by using a strategy that took advantage of a loophole on the liquidity pool platform. 

Also read: Luna Classic: Why crypto Twitter is pushing for 1000x gains

GMX suffered a $565K price manipulation ‘exploit’

GMX’s competitor’s founder said on September 2 that an exploit could be pulled off on the decentralized exchange, leaving GLP (liquidity provider token) holders short. Exactly 16 days later, on September 18, it happened. 

The exchange suffered a price manipulation exploit, and the attacker capitalized on GMX’s  “minimal spread” and “zero price impact” features to pull off the exploit. GLP token holders who provided liquidity in the form of Avalanche tokens to the GMX exchange suffered a loss of around $565,000 in the Avalanche AVAX/USD market.

Joshua Lim, the head of derivatives at Genesis Trading, is one of the first crypto proponents to analyze the exploit. Lim argues that offering liquidity to savvy traders is a necessary but painful part of the process. Holders of GMX’s liquidity provider token GLP lost their holdings to the exploit. 

The attacker opened large positions at zero slippage and successfully extracted profits from GMX’s AVAX/USD market. The chart presented the event as a sinusoidal pattern for over an hour as the trader orchestrating the attack switched from long to short five times. 

AVAX-USD

AVAX-USD 

The first cycle took place from 01:15 to 01:28 UTC, and the trader extracted roughly $158,000. The trader repeated it five times (with less impact each time) and extracted between $500,000 to $700,000 in profit. The net collection by the attacker was less than $700,000 since they paid spread to market-makers on other venues.  

Attack on the AVAX-USD pool

Attack on the AVAX-USD pool

Lim argues that GMX was designed in a manner to facilitate this exploit; by design, there was a loophole that the attacker exploited since Chainlink-run oracles do not factor in the impact on price of large market-moving orders. 

In contrast, on the FTX exchange, Lim explains, traders pay some slippage – the difference between the expected price of a trade and the price at which the trade is executed. This explains why the attacker chose GMX instead of FTX where perpetual contracts are available. 

Slippage comes into the picture when you buy in a large volume. When a trader purchases 200,000 units of AVAX-PERP on FTX, for example, the price would typically climb from $17.95 to $20.25. This implies a trader would suffer a loss on FTX exchange and the other avenues when moving the funds. 

GMX, however, does not reflect the true cost of liquidity; due to the Chainlink-run oracles, there is unlimited liquidity at a mid-market oracle price. 

GMX has not offered any compensation to affected GLP token holders. Traders who provide liquidity to savvy traders should be wary of similar possible exploits in the future. 


Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers. The author will not be held responsible for information that is found at the end of links posted on this page.

If not otherwise explicitly mentioned in the body of the article, at the time of writing, the author has no position in any stock mentioned in this article and no business relationship with any company mentioned. The author has not received compensation for writing this article, other than from FXStreet.

FXStreet and the author do not provide personalized recommendations. The author makes no representations as to the accuracy, completeness, or suitability of this information. FXStreet and the author will not be liable for any errors, omissions or any losses, injuries or damages arising from this information and its display or use. Errors and omissions excepted.

The author and FXStreet are not registered investment advisors and nothing in this article is intended to be investment advice.

Recommended content


Recommended Content

Editors’ Picks

VanEck sees Bitcoin reaching $61 trillion market cap, Marathon buys $100 million BTC

VanEck sees Bitcoin reaching $61 trillion market cap, Marathon buys $100 million BTC

Bitcoin declined by 1% on Thursday following asset manager VanEck's forecast that the top digital asset will reach a $61 trillion market capitalization by 2050.

More Bitcoin News

Ethereum Classic price sets for a rally following retest of key support

Ethereum Classic price sets for a rally following retest of key support

ETC edges higher by 2.3% and trades around $22.60 at the time of writing on Friday after testing a key support area the day before. On-chain data showing increased account growth suggests a bullish move ahead. Ethereum Classic price faced rejection by the daily resistance level of $25.13 earlier this week.

More Ethereum News

Celebrity meme coins lose their shine

Celebrity meme coins lose their shine

Celebrity meme coins report by Jupiter Slorg on Thursday shows that these tokens have been in deep waters since early July after experiencing heavy growth in June. In a recent analysis, Jupiter Slorg revealed that celebrity meme coins are down by an average of 94% from their all-time highs.

More Cryptocurrencies News

Ripple gains 5%, Mark Cuban says Kamala Harris’ nomination could affect SEC lawsuit

Ripple gains 5%, Mark Cuban says Kamala Harris’ nomination could affect SEC lawsuit

Ripple (XRP) made a comeback above key psychological resistance early on Wednesday. Crypto traders are optimistic after the Ethereum Exchange Traded Fund (ETF) launch. Entrepreneur and investor Mark Cuban recently shared his comments on how Kamala Harris’ nomination to the Presidential elections could influence crypto regulation. 

More Ripple News

Bitcoin: Will BTC manage to recover from recent market turmoil?

Bitcoin: Will BTC manage to recover from recent market turmoil?

Bitcoin recovers to $67,000 on Friday after finding support around $63,500 a day before. Still, BTC losses over 1.50% on the week as Mt. Gox persists in transferring Bitcoin to exchanges.

Read full analysis

BTC

ETH

XRP