The exploiter who removed approximately $40 million from GMX V1 began returning assets on July 11, 2025, converting a major decentralized-finance loss into an unusual negotiated recovery.
Contemporaneous blockchain analysis ultimately valued the returned cryptocurrency at approximately $40.5 million, including 10,000 ether and more than 10 million FRAX. That valuation was an event-day estimate rather than a fixed cash amount: ether traded continuously, FRAX could deviate from one dollar, and the cited analysts did not publish a single comprehensive valuation timestamp or audited reconciliation.
The recovery followed GMX’s offer of a $5 million white-hat bounty. It materially reduced the protocol’s apparent loss, but it did not immediately restore affected liquidity-provider balances or reopen every disabled GMX V1 function.
The first returns are visible on Arbitrum
Two primary Arbitrum records document the opening stage of the return. At 08:04:34 UTC on July 11, the address identified by Arbiscan as “GMX Exploiter 1” transferred 5,494,796.166294325551571952 FRAX to the GMX deployer address. At 08:08:27 UTC, the same address sent another 5,000,000 FRAX.
Together, those transactions returned 10,494,796.166294325551571952 FRAX. That calculation uses token quantities recorded by the two successful transactions; it does not assume that each FRAX was worth exactly one dollar at execution.
Contemporaneous reporting subsequently tracked multiple ether transfers to an address operated by GMX’s Security Committee. Decrypt, citing PeckShield’s blockchain analysis, reported that the combined returns had reached an estimated $40.5 million by later on July 11. CoinDesk separately reported more than $40 million returned after initially observing approximately $37.5 million in 9,000 ether and 10.5 million FRAX. The changing totals reflected transfers arriving in stages and asset prices moving during the measurement period.
A legacy contract failure
The original exploit occurred on July 9, 2025, against GMX V1’s GLP liquidity system on Arbitrum. GMX’s incident account attributed it to reentrancy through the V1 OrderBook contract. The exploiter could call into the Vault through an unintended path, bypass normal short-price accounting, distort GLP’s calculated value and redeem liquidity at an inflated price.
GMX halted affected V1 activity and said its V2 system was not affected. The distinction mattered because the incident concerned legacy contracts rather than every version of the exchange. It nevertheless demonstrated how separate protections in modular smart contracts could fail when one contract re-entered another whose accounting assumptions depended on the expected call path.
A bounty agreement also did not retroactively make the withdrawals authorized. On July 11, the verified facts were that assets had left through an exploited vulnerability, GMX had negotiated for their return, and substantial transfers were arriving at protocol-controlled addresses. The ultimate legal characterization and final reimbursement process were not established by the transactions themselves.
Recovery was not the same as reimbursement
Returned assets still had to be secured, reconciled and allocated among affected GLP holders. GLP balances and the pool’s composition had changed during the incident, while other protocols held GLP on behalf of their own users. Simply placing the assets back into the original vault risked treating economically different positions as equivalent.
The July 11 recovery therefore mattered as containment, not final resolution. It reduced the immediate financial shortfall and demonstrated that public blockchain tracing and negotiated bounties could influence an exploiter’s choices. It did not prove that the V1 design was safe again or that every affected user could withdraw an equivalent value on July 11.
Later context
On July 16, GMX said the affected funds had been fully recovered, confirmed payment of a $5 million bounty and reported that the assets were held under Security Committee oversight pending a DAO-approved distribution plan. That later statement corroborated the recovery but was not available for the event-day assessment on July 11.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

