Findings · public surfaces only · a source on every claim
Read as holders, not critics: we hold esGMX, we have real forum history, and we applied in the 2026 CEO search. Every finding below is verifiable from public surfaces, one is already fixed and live on our infrastructure, and the rest come with what "fixed" looks like. All of it is GMX's to keep.
The door AI agents knock on is not open yet. GMX's own docs tell agents the MCP server "is not yet available," so the integration agents ask for first is a promise, not an endpoint. We built that integration and put it live, free.
The official SDK fails a standard security check on install. Anyone whose build pipeline runs npm audit, a normal, sane default, sees 7 HIGH findings the moment they install GMX's own package. The fix is a one-dependency swap, written out below.
Machines quoting GMX today can get the economics wrong. The March 2026 staking change lives in blog posts, not in the API, so an agent can still tell its user "fees go to stakers" when, right now, they don't.
The ground truth the findings sit on, from public trackers and GMX's own releases. Real revenue, real audits, one dominant chain, and a hard year in a market that moved fast.
Ordered by how much each one costs GMX with the people already trying to build on it. Nothing here required anything beyond public pages, public repos, and one clean npm install.
"The MCP server is under development and not yet available."GMX AI Agents documentation, verbatim · docs.gmx.io ↗
The same recon that found the gaps found these, and they are why the gaps are worth closing.
July 2025: a ~$40M V1 exploit, a fast $5M white-hat negotiation returning ~90%+ of funds, then a completed ~$44M holder compensation program. An uncommonly clean record for an exploit of that size.
Per-market, risk-isolated GM pools directly retired the shared-pool exposure class the V1 exploit lived in. LPs choose their markets; one market's trouble stays in that market.
Eight Guardian engagements (88 person-weeks, 365 findings worked), plus ABDK, Certora, Dedaub, and Sherlock reviews, plus a $5M-max ImmuneFi bounty still current as of January 2026.
Coding-agent skills for 11 frameworks, llms.txt doc bundles, and a two-phase MCP plan whose shape is exactly right. The groundwork is real; the last mile is what this engagement provisions.