• bitcoinBitcoin (BTC) $ 109,748.00
  • ethereumEthereum (ETH) $ 4,456.46
  • xrpXRP (XRP) $ 2.91
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 843.07
  • solanaSolana (SOL) $ 188.80
  • usd-coinUSDC (USDC) $ 0.999808
  • staked-etherLido Staked Ether (STETH) $ 4,448.89
  • tronTRON (TRX) $ 0.347773
  • dogecoinDogecoin (DOGE) $ 0.211399
  • cardanoCardano (ADA) $ 0.841359
  • wrapped-stethWrapped stETH (WSTETH) $ 5,410.28
  • chainlinkChainlink (LINK) $ 23.90
  • hyperliquidHyperliquid (HYPE) $ 45.44
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,841.95
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 109,692.00
  • wrapped-eethWrapped eETH (WEETH) $ 4,774.35
  • stellarStellar (XLM) $ 0.389052
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.39
  • bitcoin-cashBitcoin Cash (BCH) $ 538.59
  • hedera-hashgraphHedera (HBAR) $ 0.234371
  • wethWETH (WETH) $ 4,464.19
  • avalanche-2Avalanche (AVAX) $ 23.38
  • leo-tokenLEO Token (LEO) $ 9.61
  • litecoinLitecoin (LTC) $ 111.27
  • the-open-networkToncoin (TON) $ 3.11
  • usdsUSDS (USDS) $ 0.999497
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999541
  • crypto-com-chainCronos (CRO) $ 0.197171
  • whitebitWhiteBIT Coin (WBT) $ 42.71
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 109,558.00
  • uniswapUniswap (UNI) $ 9.67
  • polkadotPolkadot (DOT) $ 3.80
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • bitget-tokenBitget Token (BGB) $ 4.61
  • aaveAave (AAVE) $ 331.26
  • moneroMonero (XMR) $ 265.64
  • daiDai (DAI) $ 0.999720
  • pepePepe (PEPE) $ 0.000010
  • ethenaEthena (ENA) $ 0.625082
  • mantleMantle (MNT) $ 1.16
  • okbOKB (OKB) $ 169.55
  • ethereum-classicEthereum Classic (ETC) $ 21.25
  • bittensorBittensor (TAO) $ 324.20
  • nearNEAR Protocol (NEAR) $ 2.44
  • aptosAptos (APT) $ 4.30
  • ondo-financeOndo (ONDO) $ 0.907739
  • jito-staked-solJito Staked SOL (JITOSOL) $ 231.76
  • arbitrumArbitrum (ARB) $ 0.529077
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,474.90
  • pi-networkPi Network (PI) $ 0.339856
  • internet-computerInternet Computer (ICP) $ 4.96
  • usd1-wlfiUSD1 (USD1) $ 0.999806
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • kaspaKaspa (KAS) $ 0.085778
  • algorandAlgorand (ALGO) $ 0.251404
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.237169
  • vechainVeChain (VET) $ 0.024347
  • rocket-pool-ethRocket Pool ETH (RETH) $ 5,092.49
  • cosmosCosmos Hub (ATOM) $ 4.42
  • binance-staked-solBinance Staked SOL (BNSOL) $ 202.02
  • gatechain-tokenGate (GT) $ 16.71
  • fasttokenFasttoken (FTN) $ 4.54
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030536
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,698.44
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.26
  • susdssUSDS (SUSDS) $ 1.07
  • render-tokenRender (RENDER) $ 3.48
  • worldcoin-wldWorldcoin (WLD) $ 0.902925
  • sei-networkSei (SEI) $ 0.289101
  • story-2Story (IP) $ 5.71
  • bfusdBFUSD (BFUSD) $ 0.999424
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,723.68
  • official-trumpOfficial Trump (TRUMP) $ 8.27
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.632636
  • kucoin-sharesKuCoin (KCS) $ 12.72
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,822.17
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 45.33
  • flare-networksFlare (FLR) $ 0.022287
  • bonkBonk (BONK) $ 0.000021
  • filecoinFilecoin (FIL) $ 2.30
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 109,524.00
  • skySky (SKY) $ 0.062998
  • usdtbUSDtb (USDTB) $ 1.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.081330
  • jupiter-exchange-solanaJupiter (JUP) $ 0.464125
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,714.67
  • usdt0USDT0 (USDT0) $ 0.999130
  • falcon-financeFalcon USD (USDF) $ 0.999757
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,780.39
  • injective-protocolInjective (INJ) $ 13.12
  • tether-goldTether Gold (XAUT) $ 3,372.96
  • celestiaCelestia (TIA) $ 1.63
  • nexoNEXO (NEXO) $ 1.24
  • hash-2Provenance Blockchain (HASH) $ 0.025573
  • optimismOptimism (OP) $ 0.693122
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.991758
  • aerodrome-financeAerodrome Finance (AERO) $ 1.32
  • wbnbWrapped BNB (WBNB) $ 844.32
  • paypal-usdPayPal USD (PYUSD) $ 0.999678
  • lido-daoLido DAO (LDO) $ 1.28
  • blockstackStacks (STX) $ 0.633348
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 109,580.00
  • spx6900SPX6900 (SPX) $ 1.19
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 214.30
  • curve-dao-tokenCurve DAO (CRV) $ 0.773658
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.998981
  • immutable-xImmutable (IMX) $ 0.527163
  • super-oethSuper OETH (SUPEROETH) $ 4,474.15
  • sonic-3Sonic (S) $ 0.310078
  • pump-funPump.fun (PUMP) $ 0.002801
  • pax-goldPAX Gold (PAXG) $ 3,364.36
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.12
  • the-graphThe Graph (GRT) $ 0.088178
  • flokiFLOKI (FLOKI) $ 0.000094
  • pendlePendle (PENDLE) $ 5.44
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 109,674.00
  • raydiumRaydium (RAY) $ 3.37
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.59
  • msolMarinade Staked SOL (MSOL) $ 249.22
  • conflux-tokenConflux (CFX) $ 0.172630
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,324.93
  • clbtcclBTC (CLBTC) $ 112,704.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,455.70
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,458.24
  • saros-financeSaros (SAROS) $ 0.320559
  • tezosTezos (XTZ) $ 0.785627
  • kaiaKaia (KAIA) $ 0.139823
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.87
  • dogwifcoindogwifhat (WIF) $ 0.784505
  • fartcoinFartcoin (FARTCOIN) $ 0.780054
  • theta-tokenTheta Network (THETA) $ 0.776061
  • vaultaVaulta (A) $ 0.483272
  • iotaIOTA (IOTA) $ 0.192007
  • morphoMorpho (MORPHO) $ 2.33
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.15
  • galaGALA (GALA) $ 0.016329
  • memecoreMemeCore (M) $ 0.441846
  • jasmycoinJasmyCoin (JASMY) $ 0.014993
  • ousgOUSG (OUSG) $ 112.32
  • ripple-usdRipple USD (RLUSD) $ 0.999124
  • stader-ethxStader ETHx (ETHX) $ 4,755.96
  • newton-projectAB (AB) $ 0.009201
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.996194
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,461.83
  • the-sandboxThe Sandbox (SAND) $ 0.274924
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,777.71
  • jito-governance-tokenJito (JTO) $ 1.78
  • zcashZcash (ZEC) $ 39.94
  • pyth-networkPyth Network (PYTH) $ 0.112575
  • bittorrentBitTorrent (BTT) $ 0.00000066
  • tbtctBTC (TBTC) $ 109,296.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,908.81
  • loaded-lionsLoaded Lions (LION) $ 0.020216
  • flowFlow (FLOW) $ 0.378366
  • swethSwell Ethereum (SWETH) $ 4,862.46
  • usual-usdUsual USD (USD0) $ 0.999236
  • vision-3Vision (VSN) $ 0.176043
  • walrus-2Walrus (WAL) $ 0.395918
  • build-onBUILDon (B) $ 0.558979
  • beldexBeldex (BDX) $ 0.076992
  • global-dollarGlobal Dollar (USDG) $ 0.999769
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 109,732.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.211369
  • decentralandDecentraland (MANA) $ 0.280260
  • bitcoin-svBitcoin SV (BSV) $ 26.14
  • frax-etherFrax Ether (FRXETH) $ 4,427.30
  • ether-fiEther.fi (ETHFI) $ 1.09
  • neoNEO (NEO) $ 7.00
  • true-usdTrueUSD (TUSD) $ 0.997556
  • based-brettBrett (BRETT) $ 0.049513
  • starknetStarknet (STRK) $ 0.126635
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,474.01
  • heliumHelium (HNT) $ 2.61
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 109,301.00
  • dydx-chaindYdX (DYDX) $ 0.612321
  • reserve-rights-tokenReserve Rights (RSR) $ 0.007713
  • usddUSDD (USDD) $ 0.999073
  • sun-tokenSun Token (SUN) $ 0.023945
  • apecoinApeCoin (APE) $ 0.570684
  • telcoinTelcoin (TEL) $ 0.004912
  • apenftAPENFT (NFT) $ 0.00000046
  • syrupMaple Finance (SYRUP) $ 0.400240
  • zksyncZKsync (ZK) $ 0.061747
  • coredaoorgCore (CORE) $ 0.434339
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.997578
  • savings-daiSavings Dai (SDAI) $ 1.16
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999882
  • keetaKeeta (KTA) $ 1.07
  • thorchainTHORChain (RUNE) $ 1.23
  • arweaveArweave (AR) $ 6.47
  • elrond-erd-2MultiversX (EGLD) $ 14.58
  • bio-protocolBio Protocol (BIO) $ 0.205888
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999810
  • tokenize-xchangeTokenize Xchange (TKX) $ 5.04
  • dexeDeXe (DEXE) $ 7.23

GMX Hacker Goes White-Hat, Returns $40 Million—Sends Rest to Tornado Cash

0 13

GMX Hacker Goes White-Hat, Returns $40 Million—Sends Rest to Tornado Cash

Some say crime doesn’t pay—but blockchain data suggests that an attacker who exploited a flaw in a GMX’s codebase earlier this week is walking away with a $5 million bounty.

“Ok, funds will be returned later,” the individual said in an on-chain message on Friday, days after they absconded with over $40 million worth of crypto from the decentralized exchange.

GMX, which specializes in perpetual futures trading on Avalanche and the Ethereum layer-2 scaling network Arbitrum, was later sent $10 million worth of stablecoin Frax, which swiftly disappeared from the GMX’s GLP pool on Wednesday, blockchain data show.



In total, it appeared the exploiter had returned $40.5 million worth of cryptocurrency, including 10,000 Ethereum, with funds being held in a digital wallet operated by GMX’s security committee, blockchain security and analytics firm PeckShield said on X.

Although the attacker initially stole $40 million worth of crypto from GMX, that sum inflated as Bitcoin hit a new all-time high and Ethereum cracked $3,000 for the first time in five months.

In an on-chain message, GMX had offered the attack “a 10% white-hat bounty” on Wednesday, promising not to pursue further legal action if the bulk of stolen funds were returned.

GMX’s token was recently changing hands around $12.24, a 16% jump over the past day, according to crypto data provider CoinGecko. It had still fallen 6% on the week, however.

Most attackers will consider how easy it is to cover their tracks, or how motivated the affected party is to recover funds, before returning stolen crypto, Marcin Kaźmierczak, co-founder of COO of modular blockchain oracle Redstone, told Decrypt.

“Forensics tools have been becoming more and more sophisticated,” he noted. “We’ve seen more and more cases of just accepting the bounty and returning the vast majority of the funds.”

In a post-mortem published on Thursday, GMX said on X that the attacker used a re-rentrancy attack to manipulate the exchange’s GLP pool on Arbitrum, where funds are pooled together  from the sale of GLP tokens, which reward holders with fees from GMX users’ activity.

The attacker was able to withdraw millions of dollars from GMX’s GLP pool by redeeming GLP tokens for digital assets like Bitcoin and Ethereum at an inflated price. The price of GLP tokens became inflated as the attacker messed with the logic for calculating short positions for Bitcoin on GMX, the decentralized exchange said.

“This wasn’t a smash-and-grab,” Suhail Kakar, who leads developer relations for crypto network TAX, said on X on Wednesday. “It was a long-planned, precision hit.”

In 2016, the DAO hack on Ethereum resulted in $55 million in losses, making it one of the most prominent examples. Since then, security experts say that re-entrancy attacks have become an all-too-common flaw affecting myriad projects over the years, despite education and solutions.

On Friday morning, funds kept by the attacker bounced from wallet to wallet until they reached Tornado Cash, the Ethereum coin mixer, blockchain data shows. In total, 1,700 Ethereum was sent to the tool U.S. authorities have flagged as a way for criminals to mask the flow of funds.

Source

Leave A Reply

Your email address will not be published.