CryptoReal
CASE FILE — Mar 26, 2025

GMX-Linked Cauldron Bug Lets Attacker Walk Off With 6,260 ETH

Abracadabra Money suffered its second major exploit in just over a year on March 26, 2025, when attackers drained 6,260 ETH — worth about $13 million — from the protocol's GMX-linked lending pools by exploiting a liquidation accounting flaw.

GMX moved quickly to distance itself from the incident, stating that "no issues have been identified with GMX contracts," leaving Abracadabra to account for the shortfall on its own. The hack follows the protocol's January 2024 exploit, in which a precision/rounding bug cost roughly $6.5 million — another setback for Magic Internet Money (MIM), the platform's stablecoin.

At its core, the attack turned a failed deposit and a liquidation-tracking bug into a repeatable exploit path.

Warning signs beforehand: Hours before the exploit, pseudonymous analyst DCF God posted a general warning about founders obscuring reality when protocol debts turn bad — a post that, in retrospect, looked prescient once the $13 million vanished.

Vladimir S (Officer's Notes) was the first to publicly flag unusual activity, tagging PeckShield, which confirmed that Abracadabra's GMX-linked cauldrons were actively being drained.

The stolen 6,260 ETH did not remain in one place for long: it was bridged from Arbitrum to Ethereum and then split across three separate wallets.

As the funds moved, the two protocols involved gave differing accounts. GMX stated its core contracts were unaffected, effectively framing the issue as isolated to how Abracadabra integrated with GMX. Abracadabra acknowledged the exploit and noted that its gmCauldrons had previously been "fully audited by Guardian Audits." The team also cited its use of zeroShadow, Chainalysis for on-chain tracing, and Hexagate for incident response — tooling that did not prevent or halt the loss.

01How the exploit worked

Rekt News obtained details on the mechanism directly from Guardian Audits. Per their account, the exploit did not rely on complex cryptography but instead abused a straightforward gap in how liquidation state was tracked. The sequence broke down into four stages:

Sums referenced in this case file
  1. Setup — The attacker deposited into GMX but arranged for the deposit to fail. Instead of returning to the sender, the funds became stuck in the OrderAgent contract, pending a claim.
  2. Misdirection — The attacker borrowed funds and deliberately pushed the resulting position toward liquidation.
  3. Switch — The attacker self-liquidated the position. This cleared the position record but left the associated pending order unaddressed, so the underlying collateral remained available.
  4. Reveal — Because the system still treated the (already liquidated) position's leftover order as valid collateral, the attacker was able to borrow against it. This let 6,260 ETH be extracted while the liquidation itself absorbed attention.

In short, the root cause was a failure to reconcile a self-liquidated position with its still-open order in the OrderAgent contract, not any advanced cryptographic weakness.

Attacker address: 0xAF9e33Aa03CAaa613c3Ba4221f7EA3eE2AC38649

Exploited cauldron contract: 0x625Fe79547828b1B54467E5Ed822a9A8a074bD61

Attack transaction: 0xed17089aa6c57b7d5461209e853bdb56bc3460a91805e20d2590609a515ef0b0

The stolen 6,260 ETH was bridged from Arbitrum to Ethereum and now sits across three wallets:

Abracadabra paused all borrowing on the affected markets and offered the attacker a 20% bounty in exchange for returning the funds, but as of the time of writing the attacker had not engaged and the funds remained unmoved in the three wallets.

02Aftermath

Guardian Audits, speaking to Rekt News, acknowledged the miss directly rather than deflecting blame. The firm said that while its review had caught other issues in the same codebase, it did not identify how a failed deposit combined with self-liquidation could leave a "phantom" collateral position that remained borrowable. In response, Guardian Audits said it would expand its security team and add invariant testing to its review process.

The day after the exploit, Abracadabra published a "Path Forward" document committing to buy back 6.5 million MIM and cover half of the losses immediately, with a pledge to address the remaining shortfall "over the coming months." The protocol also said its treasury remained strong enough to support planned expansions to Berachain, Nibiru, and HyperEVM, even as it continues working with Chainalysis and contacting exchanges in hopes of tracing or recovering the stolen funds.

This is Abracadabra's second eight-figure-adjacent loss in just over a year, following the $6.5 million CauldronV4 rounding exploit in January 2024 — bringing the protocol's cumulative exploit losses to nearly $20 million. GMX's contracts were not found to be at fault, and the company kept its response focused on clarifying that distinction. Meanwhile, roughly half of the holdings in Abracadabra DAO's treasury are denominated in its own MIM and SPELL tokens, a concentration that limits how much of a buffer the treasury truly provides. Co-founder Daniele Sesta remains associated with the broader "Frog Nation" project family from the prior market cycle.

Abracadabra
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.