• bitcoinBitcoin (BTC) $ 116,622.00
  • ethereumEthereum (ETH) $ 3,990.89
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,228.06
  • xrpXRP (XRP) $ 2.69
  • solanaSolana (SOL) $ 206.68
  • usd-coinUSDC (USDC) $ 0.999804
  • dogecoinDogecoin (DOGE) $ 0.233116
  • staked-etherLido Staked Ether (STETH) $ 3,996.95
  • tronTRON (TRX) $ 0.330109
  • cardanoCardano (ADA) $ 0.772438
  • wrapped-stethWrapped stETH (WSTETH) $ 4,877.65
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 116,929.00
  • ethena-usdeEthena USDe (USDE) $ 0.999968
  • chainlinkChainlink (LINK) $ 20.60
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,322.59
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • suiSui (SUI) $ 3.25
  • hyperliquidHyperliquid (HYPE) $ 42.89
  • stellarStellar (XLM) $ 0.361654
  • avalanche-2Avalanche (AVAX) $ 26.57
  • bitcoin-cashBitcoin Cash (BCH) $ 564.07
  • wrapped-eethWrapped eETH (WEETH) $ 4,327.32
  • litecoinLitecoin (LTC) $ 126.40
  • wethWETH (WETH) $ 4,012.24
  • leo-tokenLEO Token (LEO) $ 9.57
  • hedera-hashgraphHedera (HBAR) $ 0.203413
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998141
  • usdsUSDS (USDS) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,898.00
  • usdt0USDT0 (USDT0) $ 1.00
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • the-open-networkToncoin (TON) $ 2.66
  • mantleMantle (MNT) $ 2.01
  • crypto-com-chainCronos (CRO) $ 0.181944
  • whitebitWhiteBIT Coin (WBT) $ 41.96
  • moneroMonero (XMR) $ 326.68
  • polkadotPolkadot (DOT) $ 3.94
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • daiDai (DAI) $ 0.999657
  • uniswapUniswap (UNI) $ 7.41
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.158700
  • okbOKB (OKB) $ 194.27
  • aaveAave (AAVE) $ 259.28
  • bitget-tokenBitget Token (BGB) $ 5.40
  • zcashZcash (ZEC) $ 231.66
  • nearNEAR Protocol (NEAR) $ 2.95
  • ethenaEthena (ENA) $ 0.509079
  • pepePepe (PEPE) $ 0.000009
  • bittensorBittensor (TAO) $ 366.74
  • memecoreMemeCore (M) $ 2.05
  • aptosAptos (APT) $ 4.80
  • jito-staked-solJito Staked SOL (JITOSOL) $ 256.26
  • aster-2Aster (ASTER) $ 1.78
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethereum-classicEthereum Classic (ETC) $ 18.31
  • usd1-wlfiUSD1 (USD1) $ 0.998936
  • ondo-financeOndo (ONDO) $ 0.829108
  • story-2Story (IP) $ 8.10
  • c1usdCurrency One USD (C1USD) $ 0.997688
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • worldcoin-wldWorldcoin (WLD) $ 1.15
  • binance-staked-solBinance Staked SOL (BNSOL) $ 222.84
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,997.89
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.225352
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.62
  • susdssUSDS (SUSDS) $ 1.08
  • internet-computerInternet Computer (ICP) $ 4.16
  • arbitrumArbitrum (ARB) $ 0.393931
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 15.16
  • gatechain-tokenGate (GT) $ 15.99
  • pi-networkPi Network (PI) $ 0.229273
  • kaspaKaspa (KAS) $ 0.070979
  • hash-2Provenance Blockchain (HASH) $ 0.037758
  • cosmosCosmos Hub (ATOM) $ 3.93
  • pump-funPump.fun (PUMP) $ 0.005171
  • algorandAlgorand (ALGO) $ 0.207005
  • usdtbUSDtb (USDTB) $ 1.00
  • vechainVeChain (VET) $ 0.020939
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,594.62
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.028049
  • bfusdBFUSD (BFUSD) $ 1.00
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 43.12
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,232.96
  • sei-networkSei (SEI) $ 0.265145
  • flare-networksFlare (FLR) $ 0.021448
  • wbnbWrapped BNB (WBNB) $ 1,228.30
  • render-tokenRender (RENDER) $ 3.01
  • filecoinFilecoin (FIL) $ 2.23
  • falcon-financeFalcon USD (USDF) $ 0.996381
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,232.95
  • skySky (SKY) $ 0.064968
  • tether-goldTether Gold (XAUT) $ 4,022.41
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,338.29
  • official-trumpOfficial Trump (TRUMP) $ 7.12
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 117,042.00
  • bonkBonk (BONK) $ 0.000017
  • chainopera-aiChainOpera AI (COAI) $ 6.74
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,252.71
  • spx6900SPX6900 (SPX) $ 1.37
  • jupiter-exchange-solanaJupiter (JUP) $ 0.403529
  • xdce-crowd-saleXDC Network (XDC) $ 0.070826
  • pax-goldPAX Gold (PAXG) $ 4,023.01
  • immutable-xImmutable (IMX) $ 0.633550
  • nexoNEXO (NEXO) $ 1.23
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.466030
  • optimismOptimism (OP) $ 0.667529
  • plasmaPlasma (XPL) $ 0.650231
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 116,686.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.37
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999736
  • injective-protocolInjective (INJ) $ 11.27
  • celestiaCelestia (TIA) $ 1.34
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997397
  • doublezeroDoubleZero (2Z) $ 0.304309
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 237.08
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,294.85
  • lido-daoLido DAO (LDO) $ 1.10
  • blockstackStacks (STX) $ 0.543939
  • curve-dao-tokenCurve DAO (CRV) $ 0.689798
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 116,923.00
  • sonic-3Sonic (S) $ 0.246594
  • aerodrome-financeAerodrome Finance (AERO) $ 1.00
  • clbtcclBTC (CLBTC) $ 116,765.00
  • msolMarinade Staked SOL (MSOL) $ 276.11
  • myx-financeMYX Finance (MYX) $ 4.54
  • fasttokenFasttoken (FTN) $ 1.99
  • flokiFLOKI (FLOKI) $ 0.000087
  • pyth-networkPyth Network (PYTH) $ 0.143075
  • morphoMorpho (MORPHO) $ 1.57
  • the-graphThe Graph (GRT) $ 0.077436
  • ripple-usdRipple USD (RLUSD) $ 0.999968
  • ousgOUSG (OUSG) $ 112.89
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,837.78
  • kaiaKaia (KAIA) $ 0.129923
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,009.16
  • ether-fiEther.fi (ETHFI) $ 1.47
  • solmevSolMev (SN116) $ 2,398.72
  • global-dollarGlobal Dollar (USDG) $ 0.999963
  • saros-financeSaros (SAROS) $ 0.274953
  • tbtctBTC (TBTC) $ 116,521.00
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • pendlePendle (PENDLE) $ 4.10
  • starknetStarknet (STRK) $ 0.160774
  • iotaIOTA (IOTA) $ 0.169848
  • tezosTezos (XTZ) $ 0.649524
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997011
  • aethirAethir (ATH) $ 0.054860
  • theta-tokenTheta Network (THETA) $ 0.670629
  • galaGALA (GALA) $ 0.014484
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,011.36
  • dogwifcoindogwifhat (WIF) $ 0.664627
  • newton-projectAB (AB) $ 0.008141
  • raydiumRaydium (RAY) $ 2.45
  • conflux-tokenConflux (CFX) $ 0.125204
  • ethereum-name-serviceEthereum Name Service (ENS) $ 19.42
  • dexeDeXe (DEXE) $ 11.07
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.960086
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.63
  • stader-ethxStader ETHx (ETHX) $ 4,290.72
  • the-sandboxThe Sandbox (SAND) $ 0.251736
  • gtethGTETH (GTETH) $ 4,007.92
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.45
  • usdaiUSDai (USDAI) $ 1.05
  • beldexBeldex (BDX) $ 0.080389
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.233167
  • fartcoinFartcoin (FARTCOIN) $ 0.591877
  • decentralandDecentraland (MANA) $ 0.304376
  • vaultaVaulta (A) $ 0.360978
  • jasmycoinJasmyCoin (JASMY) $ 0.011881
  • jito-governance-tokenJito (JTO) $ 1.45
  • bittorrentBitTorrent (BTT) $ 0.00000057
  • usual-usdUsual USD (USD0) $ 0.998362
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,317.98
  • dashDash (DASH) $ 44.06
  • flowFlow (FLOW) $ 0.334818
  • zero-gravity0G (0G) $ 2.54
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 116,973.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,413.27
  • swethSwell Ethereum (SWETH) $ 4,393.04
  • swissborgSwissBorg (BORG) $ 0.542143
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.997947
  • ai-companionsAI Companions (AIC) $ 0.502544
  • bitcoin-svBitcoin SV (BSV) $ 24.84
  • true-usdTrueUSD (TUSD) $ 0.998644
  • apecoinApeCoin (APE) $ 0.538838
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,318.29
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,301.42
  • sun-tokenSun Token (SUN) $ 0.025069
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 42.68
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 32.62
  • usddUSDD (USDD) $ 1.00
  • zoraZora (ZORA) $ 0.104588
  • wormholeWormhole (W) $ 0.097176
  • walrus-2Walrus (WAL) $ 0.313043
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999650
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10

GMX Hacker Goes White-Hat, Returns $40 Million—Sends Rest to Tornado Cash

0 26

GMX Hacker Goes White-Hat, Returns $40 Million—Sends Rest to Tornado Cash

Some say crime doesn’t pay—but blockchain data suggests that an attacker who exploited a flaw in a GMX’s codebase earlier this week is walking away with a $5 million bounty.

“Ok, funds will be returned later,” the individual said in an on-chain message on Friday, days after they absconded with over $40 million worth of crypto from the decentralized exchange.

GMX, which specializes in perpetual futures trading on Avalanche and the Ethereum layer-2 scaling network Arbitrum, was later sent $10 million worth of stablecoin Frax, which swiftly disappeared from the GMX’s GLP pool on Wednesday, blockchain data show.



In total, it appeared the exploiter had returned $40.5 million worth of cryptocurrency, including 10,000 Ethereum, with funds being held in a digital wallet operated by GMX’s security committee, blockchain security and analytics firm PeckShield said on X.

Although the attacker initially stole $40 million worth of crypto from GMX, that sum inflated as Bitcoin hit a new all-time high and Ethereum cracked $3,000 for the first time in five months.

In an on-chain message, GMX had offered the attack “a 10% white-hat bounty” on Wednesday, promising not to pursue further legal action if the bulk of stolen funds were returned.

GMX’s token was recently changing hands around $12.24, a 16% jump over the past day, according to crypto data provider CoinGecko. It had still fallen 6% on the week, however.

Most attackers will consider how easy it is to cover their tracks, or how motivated the affected party is to recover funds, before returning stolen crypto, Marcin Kaźmierczak, co-founder of COO of modular blockchain oracle Redstone, told Decrypt.

“Forensics tools have been becoming more and more sophisticated,” he noted. “We’ve seen more and more cases of just accepting the bounty and returning the vast majority of the funds.”

In a post-mortem published on Thursday, GMX said on X that the attacker used a re-rentrancy attack to manipulate the exchange’s GLP pool on Arbitrum, where funds are pooled together  from the sale of GLP tokens, which reward holders with fees from GMX users’ activity.

The attacker was able to withdraw millions of dollars from GMX’s GLP pool by redeeming GLP tokens for digital assets like Bitcoin and Ethereum at an inflated price. The price of GLP tokens became inflated as the attacker messed with the logic for calculating short positions for Bitcoin on GMX, the decentralized exchange said.

“This wasn’t a smash-and-grab,” Suhail Kakar, who leads developer relations for crypto network TAX, said on X on Wednesday. “It was a long-planned, precision hit.”

In 2016, the DAO hack on Ethereum resulted in $55 million in losses, making it one of the most prominent examples. Since then, security experts say that re-entrancy attacks have become an all-too-common flaw affecting myriad projects over the years, despite education and solutions.

On Friday morning, funds kept by the attacker bounced from wallet to wallet until they reached Tornado Cash, the Ethereum coin mixer, blockchain data shows. In total, 1,700 Ethereum was sent to the tool U.S. authorities have flagged as a way for criminals to mask the flow of funds.

Source

Leave A Reply

Your email address will not be published.