Deep Dive
1. SDK v2 Subaccount & Referral Upgrades (June 2026)
Overview: This update refines the software development kit (SDK), making automated "one-click" trading more reliable and allowing developers to easily integrate referral programs. For users, it means smoother automated trading and potential rewards for referring friends.
The release (v1.6.1 to v1.6.3) focused on the SDK's v2 API. Key improvements include better state management for subaccounts (used for one-click trading), ensuring approvals refresh correctly. It also added a referralCode field to order requests, allowing the GMX API to handle referral tracking seamlessly.
What this means: This is bullish for GMX because it enhances the developer experience, encouraging more third-party apps and bots to build on GMX. For traders, it results in fewer failed transactions and a smoother, more feature-rich trading experience.
(Source)
2. New Market & Leverage Cap Support (June 2026)
Overview: This update added official support for trading the SPCX perpetual contract and enforced a safety cap on its maximum leverage. It expands the assets users can trade while managing risk.
Version 1.6.2 introduced the necessary configuration and token metadata for the SPCX/USD market on Arbitrum. Crucially, it implemented logic to cap the maximum leverage for this market at 10x directly within the SDK's utilities, which user interfaces rely on.
What this means: This is neutral for GMX, as it represents routine ecosystem expansion. It gives traders more choice but also demonstrates the protocol's commitment to implementing prudent risk controls for newer or more volatile assets.
(Source)
3. Critical V1 Security Vulnerability Patch (July 2025)
Overview: This was a major security response to a hack that exploited a design flaw in the GMX V1 smart contracts. The team patched the vulnerability, recovered most stolen funds via a bounty, and safeguarded the protocol.
The exploit, on July 9, 2025, used a re-entrancy attack in the V1 OrderBook to manipulate Bitcoin short prices and drain the GLP pool. The GMX team identified the flaw, paused V1, and offered a $5M bounty for the return of funds. Most of the ~$42M was recovered.
What this means: This was initially bearish due to the loss of funds and trust, but the effective response turned bullish. It demonstrated the team's capability in crisis management, leading to a sharp price recovery and ultimately strengthening the protocol's security posture.
(Source)
Conclusion
GMX's development trajectory balances continuous refinement of its developer toolkit with foundational lessons in security. While the major codebase event was a resolved exploit from over a year ago, recent activity focuses on enhancing the trading infrastructure. How will the upcoming GMX Account features further simplify cross-chain DeFi interactions?