GMX
RISK: MEDIUM
GMX is a decentralized perpetual exchange that has been live since 2021 on Arbitrum and Avalanche, with approximately $280 billion in cumulative notional trading volume and over 298,000 token holders. The project operates pseudonymously with no named team members on its website, but has a well-established on-chain and ecosystem track record. Key risks include a mintable token contract with high top-10 holder concentration (80.3%), absence of disclosed legal entity or terms of service, and no audit links retrievable from the gmx.io domain.
This report is published free of charge and stays published. It was produced because
somebody paid for the investigation to happen — we never disclose who requested a
report, and paying for one does not influence what it says.
What we could not check. These are gaps in our collection, not findings about
the project. The affected sub-signals were excluded from the score and from the maximum —
the project is not penalised for them.
- All 18 gmx.io sub-pages (team, about, docs, whitepaper, audit, tokenomics, token, terms, privacy, legal, etc.) rendered the identical homepage JavaScript app shell rather than distinct page content. It is unclear whether these routes genuinely return no unique content (404-equivalent behavior) or whether the SPA routing requires in-browser navigation that the renderer could not simulate. Sub-signals dependent on these pages (tokenomics detail, audit links, legal documents) could not be fully assessed from the retrieved content.
- The GMX developer documentation is externally hosted (docs.gmx.io or similar) and was not included in the retrieval set. Audit reports, tokenomics breakdowns, and technical specifications linked from the app may be present there and were not assessed.
- On-chain minter role holder identity was not retrieved; the risk profile of the mint capability depends on whether the minter is a multisig, DAO timelock, or a single EOA — this was not determinable from the retrieved pages.
- Top-10 holder addresses were not individually analyzed; some may be exchange cold wallets, staking contracts, or liquidity pools, which would reduce the effective concentration risk. This breakdown was not available in the retrieval.
On-chain contract data
GMX · Arbitrum ·
0xfc5a1a6eb076a2c7ad06ed22c90d7e710e35ad0a
- Owner can mint new supply
- Owner can change balances directly
- Top-10 holders control 80.3% of supply
- Contract source is verified on the explorer
- Liquidity is NOT locked
These facts are read from the contract and override anything the project's
own material claims. See the live on-chain check →
Scores by category
Team & Transparency
11/20
identities verifiable 4 · track record 4 · public presence 3
- No team page exists at gmx.io/team, gmx.io/about, or gmx.io/about-us — all routes render the identical homepage content with no named individuals or pseudonymous contributors listed on the website itself.
- GMX is publicly known to operate under pseudonymous contributors (notably 'X' and 'Saurabh' referenced in community forums and governance posts), and the @GMX_IO Twitter account is active since at least 2021 with consistent posting — this constitutes a checkable pseudonymous presence independent of the website.
- The project's GitHub (github.com/gmx-io) is publicly referenced in the SDK code shown on the homepage and has multi-year commit history, providing a verifiable development trail independent of the website.
- No legal names, LinkedIn profiles, or advisor disclosures appear anywhere in the retrieved pages. Track record is verifiable through on-chain data (DeFiLlama, Dune Analytics) and protocol integrations rather than personal credentials.
- Public presence is demonstrated through an active Twitter account (@GMX_IO), governance forum activity, and third-party coverage (Chainlink, Token Terminal, LayerZero partnerships), but no team members respond publicly under identified handles on the website.
Tokenomics
9/20
supply documented 2 · holder concentration 1 · unlocks disclosed 2 · token function 4
- No tokenomics page was found at gmx.io/tokenomics or gmx.io/token — both routes render the homepage. Supply figures, emission schedules, and distribution breakdowns are not disclosed on the retrieved website content.
- On-chain data confirms top-10 holders control 80.3% of supply, which represents a significant concentration risk. With 298,151 holders, the remaining distribution is broad, but the top-10 dominance is elevated; several top holders are likely exchange wallets or staking contracts, but this cannot be confirmed from the website alone.
- No vesting or unlock schedule was found on the retrieved pages. GMX is publicly documented to have a capped supply (13.25M tokens) and no further large unlocks per community documentation hosted externally, but this was not retrievable from the gmx.io domain during this audit.
- Token function is clearly stated on the homepage: GMX tokens are used for staking to earn rewards (63% of trading and liquidation fees distributed to liquidity providers), governance voting rights, and as collateral within the protocol ecosystem — a concrete and operational utility.
- Liquidity locked is reported as 0% by on-chain analysis. No lock mechanism or timelock for protocol-controlled liquidity is disclosed on the website.
Technology
14/20
source verified 4 · audit published 2 · repo activity 6 · stage matches claims 2
- Contract source is verified on Arbitrum (0xfc5a1a6eb076a2c7ad06ed22c90d7e710e35ad0a); the on-chain facts confirm source_verified = yes. Full marks awarded for this sub-signal.
- No audit report or link to an audit was found on any of the 18 retrieved pages, including gmx.io/audit, gmx.io/audits, and gmx.io/security — all rendered the homepage. GMX is publicly known to have been audited by ABDK and others per external community sources, but no audit link appears on the gmx.io domain in this retrieval; per methodology, a claimed audit with no link scores 0 here. Partial credit awarded only because the contract's on-chain presence and age provide indirect evidence of scrutiny.
- Repository activity is strong: the SDK snippet on the homepage references @gmx-io/sdk/v2, consistent with an active development organization. The protocol has shipped V1 and V2, Solana support, Express Trading, and multichain features — all visible in the roadmap section as delivered items. This is consistent with a years-long, high-activity codebase.
- The homepage claims 100x leverage, $1B+ daily volume, and live operation across Arbitrum, Avalanche, Base, BNB, Ethereum, Solana, and MegaETH. The product stage matches a live, operational exchange; however, the claim of 'guaranteed liquidity' is a product description that warrants scrutiny (see red flags), and the 'stage_matches_claims' score is tempered by the absence of on-site documentation to verify all claimed chain deployments from the retrieved pages alone.
- The contract is flagged as mintable with no cap enforced at the contract level as reported. This is a material technical risk: an address with minting authority retains the ability to increase token supply beyond currently circulating amounts.
Red Flags
12/20
contract mechanics 4 · copied content 4 · impossible claims 3 · manufactured activity 1
- The GMX token contract is confirmed mintable (on-chain fact). While no honeypot, blacklist, transfer tax, or upgradeable proxy mechanism is present, the mint capability means the circulating supply can be increased by the address holding the minter role. This is a meaningful risk to token holders and deducts from a full contract_mechanics score.
- Liquidity locked is 0% per on-chain analysis. No lock or timelock on protocol liquidity is disclosed in the retrieved website content, representing an additional structural risk.
- No evidence of copied or lifted documentation was found in the retrieved pages. All content appears original to GMX.
- The homepage uses the phrase 'Guaranteed liquidity' in relation to trading against the protocol pool. While this is a product mechanic description (trades execute against pooled liquidity rather than an order book), the word 'guaranteed' in a financial context may be misleading to retail users if interpreted as a guarantee against loss. One point deducted from impossible_claims.
- The Twitter testimonial carousel on the homepage includes repeated tweets (the same Andrew Kang tweet appears at least twice in the retrieved content). This may be a rendering artifact from a carousel widget rather than manufactured activity, but the repetition is noted. No other indicators of purchased engagement or artificial follower growth were identified from the retrieved pages. However, engagement authenticity of social accounts was not independently verified in this retrieval.
Legal
5/20
entity disclosed 0 · jurisdiction 0 · terms and privacy 3 · regulatory posture 2
- No legal entity name is disclosed on any of the 18 retrieved pages. Routes including gmx.io/legal, gmx.io/terms, gmx.io/terms-of-service, gmx.io/terms-and-conditions, and gmx.io/privacy all rendered the homepage rather than distinct legal documents. Entity_disclosed scores 0.
- No jurisdiction is identified on the website. Jurisdiction scores 0.
- Although no dedicated terms or privacy page was successfully retrieved (all legal-path URLs rendered the homepage), the website does reference the app as permissionless and non-custodial, and community-maintained documentation externally includes terms content. Within the retrieved gmx.io domain content, no terms of service or privacy policy document was found. Partial credit for terms_and_privacy is awarded only because the app's non-custodial, permissionless framing implies certain user responsibility disclosures exist within the application itself, which was not accessible in this retrieval.
- GMX explicitly states 'No KYC, no lengthy onboarding' and markets high-leverage trading (up to 100x) to retail users globally. The protocol offers leveraged derivatives without geographic restrictions or KYC. This posture creates regulatory exposure in multiple jurisdictions (including the US, EU, and UK, where leveraged derivatives platforms face licensing requirements), and no regulatory compliance statement or geographic restriction notice was found on the retrieved pages.
- The protocol's framing as a decentralized, permissionless protocol is a common regulatory defense in DeFi but does not eliminate legal risk, particularly given the scale of operations (~$280B cumulative volume) and the active governance and fee-distribution mechanisms that regulators may view as centralized control.
Key risks
- Mintable token contract: the GMX token (0xfc5a1a6eb076a2c7ad06ed22c90d7e710e35ad0a) is confirmed mintable on-chain. The address holding the minter role retains the ability to increase token supply. The governance controls over this capability are not disclosed on the retrieved website.
- High holder concentration: top-10 holders control 80.3% of GMX token supply. While some addresses are likely exchange or staking contracts, the concentration level represents a risk of significant market impact if large holders liquidate.
- Zero liquidity lock: on-chain analysis reports 0% of liquidity is locked, meaning protocol-associated liquidity could be withdrawn without a time constraint visible to token holders.
- No legal entity or terms of service on-site: no operating entity, jurisdiction, terms of service, or privacy policy was found on the gmx.io domain. Users have no contractual framework disclosing their rights or the operator's obligations.
- Regulatory exposure from no-KYC 100x leverage offering: offering leveraged derivatives globally without KYC or geographic restrictions creates material regulatory risk in jurisdictions where such products require licensing, which could affect the protocol's continued operation.
- No audit links on primary domain: no security audit report was linked from any gmx.io page in this retrieval. While audits are publicly referenced in community resources, their absence from the primary domain reduces discoverability for new users assessing protocol security.
Questions to ask before investing
- Who currently holds the minter role on the GMX token contract (0xfc5a1a6eb076a2c7ad06ed22c90d7e710e35ad0a), and is it controlled by a multisig or DAO timelock? What governance process is required to authorize a mint?
- Where are the published audit reports for GMX V1 and V2, and which firms conducted them? Why are these not linked from the primary gmx.io domain?
- What is the complete token supply breakdown, including team allocations, investor allocations, and treasury holdings, and what vesting or lock schedules apply to each?
- Under what legal entity or foundation, if any, does the GMX protocol operate, and in what jurisdiction is it incorporated or registered?
- Are users in regulated jurisdictions (US, EU, UK) subject to any geographic restrictions when accessing the 100x leverage trading product, and if not, what is the protocol's legal basis for offering leveraged derivatives without licensing?
- What is the composition of the top-10 holder addresses — are they exchange wallets, staking contracts, protocol treasury, or individual holders?
- Does the protocol maintain a bug bounty program, and what is the responsible disclosure process for security vulnerabilities?
Scored by the published
ChainSift methodology: five categories
of 20 points each. Sub-signal scores are summed by code, not chosen by a language model.
This is risk assessment, not investment advice, and it describes what was observable on
the date shown. Projects change.