DeFiScoreAudit shield logo
DeFiScoreAudit
Detecting DeFi Risk, Before It Breaks
← Back to DeFiScoreAudit
Rating Screen · Methodology v1.0

GMX

Derivatives · GMX · $0.5B TVL. GMX pioneered the pooled-liquidity perpetuals model that defined on-chain derivatives before order-book venues took over. Its July 2025 V1 exploit — $42M drained, roughly $40M returned by the attacker after a negotiated bounty — is the instructive counterpoint to Balancer in this screen: near-complete restitution means the framework reflects the event in the risk score without triggering a notching cap.

Screened July 27, 2026 Methodology v1.0 (screen) Caps Triggered 0
Solvency
BBB
64.8 / 100
Will it survive and pay users back?
Legitimacy
BBB
64 / 100
Is it real, credible, delivering its stated aim?
Growth
B
31.3 / 100
Adoption toward the protocol's own goal, peer-relative.
Axis I · Credit Grade

Solvency — BBB

Solvency screens at BBB. Real fee coverage (~3x) from trading volume, minimal unlock pressure on a mature token, and a 40% drawdown. The 6/10 risk score is where the exploit lives — the flaw was real and reached user funds, but recovery was substantially complete and V2 was unaffected, so the framework prices it as damage rather than as an open wound.

Solvency ScorecardBBB
MetricRawNormalizedWeightWeighted
Sustainability ratio (revenue / emissions)3x
30%24
Does it earn more than it prints? Above 1x is self-sustaining.
TVL stability (max 90-day drawdown)40%
25%10
Bank-run indicator: worst 90-day deposit flight.
Unlock pressure (next 12 months)2%
15%12.8
Incoming insider sell pressure vs circulating supply.
Risk quality (collateral, oracle, exploit posture)6 / 10
30%18
Combined collateral quality, price-feed dependence, and loss history.
FINAL DIMENSION SCORE64.8 → BBB
Axis II · Legitimacy Score

Legitimacy — BBB

Legitimacy screens at BBB. The pseudonymous team handled the incident with fast disclosure and successful recovery negotiation — creditable exploit-response quality. Audits (7/10) and delivery are adequate; governance is functional if low-participation.

Legitimacy ScorecardBBB
MetricRawNormalizedWeightWeighted
Audit coverage7 / 10
25%17.5
Code credibility: firms, recency, findings resolved.
Team & transparency7 / 10
25%17.5
Doxxed vs anonymous; track record; disclosure quality.
Delivery vs stated roadmap7 / 10
20%14
Does shipped product match the promise? The core legitimacy test.
Governance & decentralization5 / 10
30%15
Real distributed control vs theater; participation quality.
FINAL DIMENSION SCORE64 → BBB
Axis III · Adoption Trajectory

Growth — B

Growth screens at B: 7% share and 3/10 momentum as Hyperliquid absorbed the derivatives category's growth. GLP-style pooled liquidity is losing the design argument to order books.

Growth ScorecardB
MetricRawNormalizedWeightWeighted
TVL 12-month trend-40%
35%8.8
Adoption of the core product, in absolute terms.
Category market share7%
30%12
Peer-relative position: winning or losing its niche.
Momentum & users3 / 10
35%10.5
Usage trajectory and integration growth, filtered for incentives.
FINAL DIMENSION SCORE31.3 → B
Verdict

Where GMX Lands

Composite B. A protocol whose technology thesis is being outcompeted rather than one whose credit is impaired. The contrast with Balancer is the cleanest illustration in this screen of what restitution does to a rating.

Composite — Conservative (Recommended Headline)
B
31.3 / 100 · lowest of the three dimensions

"A chain is as strong as its weakest link." The conservative composite takes the weakest dimension and inherits any notching cap, so a single structural weakness cannot be diluted by strength elsewhere.

Analyst Note
Jul 2025 V1 exploit $42M with $40M returned — reflected in risk score, no cap.
Screen vs full rating. This is Methodology v1.0 applied in screening form: the same bands, weights, caps and grade scale as the full Aave workbook, reduced to the highest-signal metrics per dimension so the whole universe stays comparable in one table. Screen grades are provisional. A full rating — per-metric sourcing plus four stress scenarios — is produced when a protocol is selected for publication. Every input is an analyst estimate as of July 27, 2026, drawn from public data (DefiLlama, protocol docs, governance forums, rekt.news) and judgment, and should be verified before being relied upon.
Want the full treatment? See the complete Aave rating — per-metric sourcing, four stress scenarios, and notching-cap analysis — for what a published rating looks like. Join the waitlist to get each new full rating as it publishes.