🤯 Someone has released a dataset with over 23,000 smart contract security audit findings, free to download
Severity, proof of concepts, recommended fixes, everything is inside - it's a GOLDEN MINE. Thank you @RightNowIn - amazing contribution🔥
https://t.co/ejmuCuCkRK
DSS 2026 meets in Mumbai on 1–2 November, 10am–6pm IST each day.
Venue: Courtyard by Marriott Mumbai International Airport.
DSS at Devcon follows on 3 November as a CLS; admission is separate.
Tickets: https://t.co/RTbPxGH7zF
The Recon Extension is now fully compatible with Echidna, Medusa and Halmos.
The same code can be used to run these different powerful tools to break properties.
The extension automatically converts all broken properties to Foundry, so debugging is easyer.
So close to 300 downloads!
🛡️GMX V1 Got Exploited for ~$40M on Arbitrum (July
9, 2025)
GMX is a decentralized exchange (DEX) protocol for perpetual futures trading, operating on the Arbitrum and Avalanche blockchains. It enables users to trade leveraged positions on assets such as BTC, ETH, and others with low fees and no counterparty risk, leveraging smart contracts.
🔱Perpetual Futures
Perpetual futures are a type of derivative instrument used in both traditional and decentralized finance (DeFi). They allow traders to speculate on the price
of assets such as BTC or ETH without owning the actual asset. These contracts do not have an expiration date, so traders can hold their positions indefinitely, provided they maintain the required margin.
🔱Before we dive, the attack was on the chains of bugs
Re-entrancy -> Unauthorised Access -> Broken Invariant -> State Manipulation -> Price/PnL Distortion -> Profit Extraction.
🔱Entry Point
https://t.co/No8b9aJ0RY
1⃣OrderBook.executeDecreaseOrder()
This function reduces a trader's position and sends ETH back to the user via _transferOutETH.
However, if the recipient is a malicious contract, it can re-enter GMX contracts (e.g., Vault) while executeDecreaseOrder() is still executing. Despite being marked nonReentrant, that protection only applies to the function itself, not to external calls made during its execution (like sending ETH to untrusted receivers).
2⃣Re-entrancy → Vault.increasePosition()
globalShortAveragePrices[_indexToken] still held stale values from a valid previous position.
This bypassed invariant assumptions:
globalShortAveragePrices should be updated every time shortSize changes.
But due to re-entrancy, the attacker could manipulate global short positions without resetting the price baseline. Internally, it calls _increaseGlobalShortSize() and inflates position size, breaking the invariant in P&L calculation. Creating a fake loss, depending on which direction the attacker wants.
3⃣Broken Invariant → Price and P&L Distortion
This leads to a mismatch between the actual short position size and the average entry price, violating a key invariant used in profit/loss (PnL) calculations.
4⃣Price and P&L Distortion → Manipulated Profit Calculation
The attacker broke the P&L calculation invariant by exploiting how GMX computes unrealized gains/losses.
a. GMX uses getDelta() to calculate P&L based on:
- averagePrice (which was stale/manipulated),
- currentPrice (oracle-fed),
- and positionSize.
b. by manipulating globalShortAveragePrices and inflating globalShortSizes, the attacker made GMX think:
- Short positions were deep in loss when they were actually profitable.
=> Result:
- GMX overpaid when the attacker closed positions.
- Attacker extracted excess funds from the vault by closing at fake losses, draining real assets.
5⃣AUM Distortion
- GLP tokens are minted based on GMX’s AUM (Assets Under Management).
- AUM = Pool Value + Unrealized PnL from Shorts
- The attacker created fake short losses, which artificially inflated the AUM.
- Using a 7.538M USDC flash loan, the attacker minted 4.1M GLP - significantly more than they should have received under normal conditions.
6⃣GLP Minting → Inflated AUM via Fake Shorts Loss
- The GLP minting logic (GlpManager._addLiquidity()) uses AUM (Assets Under Management) to determine how much GLP to mint.
- AUM includes unrealized P&L from short positions.
- The manipulated fake loss in WBTC short inflated AUM dramatically.
- So when the attacker minted GLP with 6M USDC, they received way more GLP than deserved, based on fake AUM.
7⃣GLP Redemption → Extracting Real Assets
- The attacker closed short positions via executeDecreaseOrder(), and GMX overpaid due to manipulated unrealized P&L.
- This was repeated using looped re-entrancy, amplifying the fake losses and payouts.
- The attacker later burned the GLP tokens.
- Since AUM was still artificially inflated, attackers could redeem significantly more USDC/WETH than the GLP was actually worth.
- Massive profit extraction well beyond what their actual input should have entitled them to.
8⃣Flash Loan Repaid, Profit Secured
After extracting ~$42M in real assets:
- The attacker closed their large positions.
- repaid the original flash loan 7.5M USDC.
- left with clean profits and no open positions.
They distributed the funds across multiple wallets and later returned a large portion to GMX.
#Web3Security #SmartContractAuditing #DeFi #DailyVulnerabilitySeries
Introducing ZEX v0.1, a confidential peer-to-peer DEX that requires no protocol-level modifications or co-processors to operate.
Privacy assumptions impose very tight constraints, making DeFi use cases almost impossible to implement. Confidential tokens are usually very limited in functionality, enabling only encryption of balances and push-only transfers.
The ZEX v0.1 protocol aims to defy the odds. It extends the cWETH-like confidential tokens with confidential approvals and transferFrom operations, allowing confidential peer-to-peer swaps (and other protocols) to be implemented.
Although very heavy on the UX side (and gas-wise), requiring multiple ZK proofs to be verified within the same transaction, and potentially leaking confidentiality in some edge cases, ZEX shows that native confidential DeFi on Ethereum is not a dream anymore.
*ZEX is still a draft and there are security issues to consider. We will try to properly address them in the future revisions of the protocol.
A solid guide into different bridges/interop solutions: https://t.co/OwkAN4ke45.
It's written by Across, so it's biased to showcase their architecture as superior, but nonetheless, it's a solid read.
If you're assessing a bridge, always check what independent researchers have to say: https://t.co/enuVcfRToH
vyper 0.4.3 was released this week!
.. also 0.4.2 was released 3 weeks ago, but we decided to ship more features instead of tweeting about it 😅
highlights are:
- raw_create allows low level access to creation opcodes
- raw_return allows bypassing ABI encoding for proxy use cases
- pragma nonreentrancy on enables nonreentrancy by default
New competitive audit with a $200,000 prize pool, STARTS NOW!
Let’s welcome back Chainlink for an audit of a new version of Chainlink Rewards—a community engagement and rewards program designed to incentivize active participation in the Chainlink Network.
30 days to help secure @chainlink, with the biggest prizes going to the highest and rarest vulnerabilities found.
For more details on this audit, check out the audit docs below. ⤵️