📈 Get daily crypto insights that make you smarter about your money

How the GMX ShortTracker Price Manipulation Exposed Fatal Flaws in DeFi Oracle Design

On July 9, 2025, the decentralized exchange GMX lost approximately $42 million not because of a simple code bug, but because of a fundamental design weakness in how DeFi protocols track and calculate internal price averages. The attack on GMX V1’s ShortTracker contract reveals a category of vulnerability that extends far beyond a single protocol — it challenges assumptions about on-chain price accounting that underpin billions of dollars in decentralized finance.

The Exploit Mechanics

The attacker targeted a specific component of GMX V1’s architecture: the globalShortAveragePrices calculation within the ShortTracker contract on Arbitrum. This value tracks the weighted average entry price of all open short positions for a given asset, and it plays a critical role in determining profit and loss calculations, GLP token redemption values, and overall protocol solvency.

The vulnerability existed because the total short position size for BTC was only about $15,000 at the time of the attack. This remarkably low baseline meant that any new position opened with a significantly larger size could dominate the weighted average calculation. The attacker exploited this by deploying a custom contract with reentrancy capabilities that allowed them to bypass normal position validation.

Through five iterative cycles of opening and closing large short BTC positions, the attacker systematically drove the globalShortAveragePrices from its legitimate value of $108,757 down through $104,766, $85,421, $40,173, $9,881, and finally to just $1,913. Each iteration compounded the manipulation because the closing of positions recalculated the average with increasingly distorted inputs.

The profit extraction came via a $7.5 million flash loan from a lending protocol. The attacker used $6 million to mint and stake GLP tokens while simultaneously opening a large short BTC position. Because the globalShortAveragePrices had been pushed to $1,913 — roughly 1.7% of Bitcoin’s actual market price of $111,326 — the system calculated that short positions were carrying enormous unrealized losses. This artificially inflated the protocol’s Assets Under Management figure, allowing the attacker to redeem GLP tokens for far more than they should have received.

Affected Systems

The exploit was confined to GMX V1 on Arbitrum. The attacker’s contract interacted with four key GMX components: the PositionManager, the Timelock, the Vault, and the ShortTracker. By exploiting the Timelock’s enableLeverage function during keeper execution, the attacker gained unauthorized direct access to the Vault’s increasePosition function, bypassing the normal validation checks that should have prevented the manipulation.

GMX V2 contracts remained secure because they had been redesigned with reentrancy guards and improved price accounting logic. The GMX governance token dropped from $14.42 to $10.30, a decline of over 20%, as the market digested the implications of the attack.

Security firms SlowMist, Verichains, BlockSec, and Halborn all published independent analyses confirming the attack vector. Crucially, the reentrancy vulnerability had been introduced by a code update in 2022 — a fix for an unrelated issue that inadvertently opened the door to cross-contract reentrancy.

The Mitigation Strategy

GMX paused all V1 contracts immediately and publicly urged users to migrate to V2. The protocol also offered a 10% white-hat bounty worth approximately $4.2 million to the attacker. In a positive turn of events, the attacker returned the majority of the stolen funds, reducing net protocol losses significantly.

For the broader ecosystem, the mitigation lesson is clear: protocols must implement sanity bounds on internal price calculations. A globalShortAveragePrices value that falls below a defined percentage of the current market price should trigger automatic circuit breakers. Additionally, protocols should require minimum liquidity thresholds before allowing new position types that influence system-wide calculations.

Lessons Learned

The GMX ShortTracker exploit demonstrates that internal price averaging mechanisms in DeFi are as critical as external oracle feeds. While the industry has invested heavily in securing price oracles like Chainlink, the GMX attack shows that protocols can be equally vulnerable to manipulation of their own derived price values.

Low-liquidity markets represent a systemic risk that is often overlooked during security audits. When the total value locked in a particular market segment — in this case, BTC shorts on V1 — drops below a critical threshold, the protocol becomes exponentially more susceptible to manipulation. Auditors and developers must model worst-case scenarios for low-utilization states, not just peak usage conditions.

The cross-contract nature of the exploit also highlights the inadequacy of per-contract security audits. The individual GMX contracts — the PositionManager, Timelock, Vault, and ShortTracker — may have each appeared secure in isolation. The vulnerability only became apparent when analyzing the full interaction surface between all four contracts under adversarial conditions.

User Action Required

Any users still holding positions in GMX V1 contracts should immediately migrate to V2. Traders using other DeFi protocols that calculate internal price averages based on position data should evaluate whether those systems have adequate safeguards against manipulation in low-liquidity scenarios. If a protocol does not publish clear documentation about how its internal price accounting works and what circuit breakers are in place, that opacity itself should be considered a risk factor.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before engaging with DeFi protocols.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “How the GMX ShortTracker Price Manipulation Exposed Fatal Flaws in DeFi Oracle Design”

  1. GLP_bagholder_

    42M loss because the BTC short position was only 15k. you can manipulate a weighted average with pocket change if the baseline is that low

    1. oracle_slippage_

      GLP_bagholder_ exactly. the real bug was allowing position sizes that could dominate the global average. basic concentration risk that nobody flagged

  2. this is why Synthetix moved to a dual-oracle model. single price sources are sitting ducks for anyone willing to spend gas

  3. short_squeeze_calc_

    15K in short open interest and the weighted average was manipulable with a single large position. thats not a hack thats a design flaw on a napkin

  4. short_squeeze_calc_ exactly. anyone who read the ShortTracker contract could see the UTB scaling issue. the audit probably flagged it and got marked low severity

    1. reentrancy_hunter

      alt_season_ liquid staking derivatives are important but the GMX exploit shows that legacy contracts with low liquidity are ticking time bombs. V1 should have been sunset months ago

      1. reentrancy_hunter V1 should have been sunset the moment V2 launched. leaving legacy contracts with thin liquidity live is just asking for exploits

      2. five iterations to push the average from $108K to $1.9K. each cycle compounded because closing positions recalculated with distorted inputs. classic feedback loop exploit

        1. gmx_bagholder_

          $15K total BTC short position on GMX V1 is insane. the protocol had millions in TVL but the short order book was basically empty. minimum position sizes would have prevented this entirely

          1. gmx_bagholder_ $15K total BTC short position on a protocol with millions in TVL is wild. minimum position size of even $5K would have made manipulation cost-prohibitive

        2. feedback_loop_

          five iterations to push average from 108K to 1.9K and nobody at GMX thought to add a circuit breaker. legacy contracts with thin liquidity are just waiting to be exploited

          1. circuit_break_missing

            feedback_loop_ five iterations and no circuit breaker. GMX V1 was a sitting duck with $15K in short liquidity and zero guards on the average price calc

        3. oracle_audit_ the feedback loop was the real vulnerability. each close recalculated with distorted inputs so the next open compounded the manipulation. elegant exploit honestly

          1. Yuki S is right about the feedback loop vulnerability. Each close operation with distorted inputs compounded the manipulation. Genius exploit actually.

          2. Yuki S is right about the feedback loop vulnerability. Each close operation with distorted inputs compounded the manipulation. Genius exploit actually.

  5. Dmitri Petrov

    total short position of 15K on BTC is the real scandal. GMX V1 was running with near zero short liquidity and nobody flagged it. the weighted average was trivially manipulable

    1. Dmitri Petrov the $15K short position on a protocol with millions in TVL is the part nobody talks about. minimum position sizes would have saved them

    2. short_squeeze_

      Dmitri Petrov $15K total short position on BTC is comically thin. GMX should have delisted the pair or set minimum position sizes

  6. The $15K total BTC short position shows how legacy DeFi contracts can have fatal design flaws. Circuit breakers should be mandatory for low-liquidity pairs.

  7. The $15K total BTC short position shows how legacy DeFi contracts can have fatal design flaws. Circuit breakers should be mandatory for low-liquidity pairs.

    1. Wei Zhang circuit breakers are standard in Tradfi since 1987. DeFi still hasnt learned that unguarded price oracles with thin liquidity are just flash loan targets

  8. median_oracle_

    5 iterations to push the average from $108K to $1.9K. the attacker turned a $42M profit on a $15K short position because nobody at GMX flagged the ratio

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,360.00-0.3%ETH$2,474.57-0.6%SOL$101.89-1.1%BNB$724.19-3.3%XRP$1.39-1.4%ADA$0.2131-1.8%DOGE$0.0861-3.9%DOT$1.11-7.8%AVAX$7.80-1.9%LINK$11.85-4.6%UNI$6.06-10.5%ATOM$1.88+4.2%LTC$52.94-1.8%ARB$0.1505-9.1%NEAR$2.51+10.2%FIL$0.8155-2.2%SUI$0.7700-4.7%BTC$78,360.00-0.3%ETH$2,474.57-0.6%SOL$101.89-1.1%BNB$724.19-3.3%XRP$1.39-1.4%ADA$0.2131-1.8%DOGE$0.0861-3.9%DOT$1.11-7.8%AVAX$7.80-1.9%LINK$11.85-4.6%UNI$6.06-10.5%ATOM$1.88+4.2%LTC$52.94-1.8%ARB$0.1505-9.1%NEAR$2.51+10.2%FIL$0.8155-2.2%SUI$0.7700-4.7%
Scroll to Top