Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · December 2025

Open Interest Updates

for GMX

Guardian's review of Open Interest Updates for GMX, published December 2025. The report records 5 findings, including 2 medium and 3 low.

Published
Review window
December 20 to 21, 2025
Language
Solidity
Chains
Arbitrum, Avalanche
Sector
Perpetuals
  • 0 Critical
  • 0 High
  • 2 Medium
  • 3 Low
  • 0 Informational

5 acknowledged

Findings 5

  1. M-01 Medium Funding Charged Is Not Accurate To OI In Tokens Warning Acknowledged
    Location
    MarketUtils.sol

    Description

    In the getNextFundingAmountPerSize flow the fundingUsd is calculated based on the cache.sizeOfPayingSide which is hardcoded to be the cost basis OI version instead of the open interest of positions in tokens multiplied by the current index token price.

    This means that while the fundingFactorPerSecond and the longsPayShorts value is computed based on the new open interest in tokens method, the actual resulting magnitude of funding that is charged, and the way in which it is collected and distributed from positions, is based on the old cost basis open interest method.

    This may be unexpected and can result in scenarios where positions that are very large by way of the size in tokens open interest method actually end up paying a very small amount of funding because of a much smaller cost basis open interest.

    Recommendation

    Currently this deficiency is known, be aware of it.

  2. M-02 Medium Price Impact Arbitrage Opportunities Warning Acknowledged
    Location
    Global

    Description

    The update of the open interest measurement type will have an immediate effect on the price impact calculation in all markets.

    Some markets will even switch from showing an imbalance towards one direction towards showing it towards the other direction when the measurement switches from a cost basis oriented open interest to a sizeInTokens oriented model.

    This may create arbitrage opportunities where traders may forsee that the price impact calculation method is going to change and benefit from opening a long/short when one side is favored as being under-exposed by the cost basis measurement and then closing it when their new position side is now favored as being over-exposed by the new sizeInTokens measurement.

    The price impact measurement doesn’t even necessarily have to switch sides from one side being seen as the larger side to the other for a sandwiching of opening/closing to be net profitable.

    Recommendation

    Be aware of this possible arbitrage and monitor for it. Ensure that there are no markets which would exhibit a large change in price impact measured imbalance from the open interest measurement update to limit the magnitude of arbitrage possible.

  3. L-01 Low Funding Misbehavior Warning Acknowledged
    Location
    MarketUtils.sol

    Description

    In the getNextFundingFactorPerSecond function due to the way that the dynamic funding rates are computed, with the FundingRateChangeType.Decrease using the exact fundingDecreaseFactorPerSecond value and the FundingRateChangeType.Increase using the fundingIncreaseFactorPerSecond modulated by the diffUsdToOpenInterestFactor, it is often possible depending on the active configurations and market conditions that funding would decrease slower if the balance switched from one side to another.

    For example, consider the following scenario:

    • Longs have OI 100 tokens
    • Shorts have OI 50 tokens
    • Token price is $1
    • Total OI using the OI in tokens is $150
    • The fundingExponentFactor is 1
    • diffUsdToOpenInterestFactor = $50 / $150 = 1/3
    • fundingDecreaseFactorPerSecond is 5 (arbitrary)
    • fundingIncreaseFactorPerSecond is 5 (arbitrary)
    • thresholdForStableFunding = 2/3
    • thresholdForDecreaseFunding = 1/6
    • Checkpoint A

    If a 40 token short is opened from checkpoint A:

    • Longs have OI 100 tokens
    • Shorts have OI 90 tokens
    • Total OI using the OI in tokens is $190
    • diffUsdToOpenInterestFactor = 10 / 190 = 1/19
    • We are now below the thresholdForDecreaseFunding
    • The nextSavedFundingFactorPerSecond decreases at a rate of 5 (fundingDecreaseFactorPerSecond) per second

    If a 60 token short is opened from checkpoint A:

    • Longs have OI 100 tokens
    • Shorts have OI 110 tokens
    • Total OI using the OI in tokens is $210
    • diffUsdToOpenInterestFactor = 10 / 210 = 1/21
    • We have now flipped sides and we are using the FundingRateChangeType.Increase in the other direction
    • Funding now moves in the same direction that the FundingRateChangeType.Decrease does, but at a slower rate
    • The rate is 5 * 1/21 per second

    As a result, when a more extreme funding change would typically be desired in the market, the funding rate actually moves more slowly to the new paying side and the new paying side actually continues to receive funding for a longer period, paradoxically.

    Recommendation

    Be aware of this behavior when assigning the configurations for the dynamic funding rate.

  4. L-02 Low Skip Smaller Side May Skip Larger Reserved Side Warning Acknowledged
    Location
    MarketUtils.sol

    Description

    In the getBorrowingFactorPerSecond function, when the SKIP_BORROWING_FEE_FOR_SMALLER_SIDE feature is enabled the smaller side as measured by the new USE_OPEN_INTEREST_IN_TOKENS_FOR_BALANCE receives zero borrowing fees.

    However this may not be the smaller side as measured by reserved USD, since for shorts the reserved USD as calculated by the getReservedUsd function is based on the getOpenInterest result which gives an open interest in cost basis terms.

    Recommendation

    This is not un-similar to the way the skip smaller side feature functioned before when it was based on the cost basis. Just that then it was vice-versa in line with shorts and had a descrepancy with the reservedUsd calculation for longs.

  5. L-03 Low WillPositionCollateralBeSufficient Check Still Relies On Cost Basis Warning Acknowledged
    Location
    Global

    Description

    The WillPositionCollateralBeSufficient validation still relies on the position sizeInUsd which is the cost basis form of open interest instead of the current USD value of the sizeInTokens of the position to check if the position collateral is sufficient for it’s size.

    Recommendation

    Consider if this is acceptable for this validation or if it should be updated to be based on the position size in tokens using the current index token price.

More from GMX

All 44 reports
  1. Timelock Updates

    4 findings 4 findings: 3 low, 1 informational
  2. LayerZeroProvider Routing

    1 finding 1 finding: 1 medium
  3. Updates Branch

    2 findings 2 findings: 2 low
  4. Multichain Referral Codes

    1 finding 1 finding: 1 medium

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote