The first three weeks
GMX Synthetics · 3 auditors
Guardian’s first GMX engagement, on the earliest V2 codebase: three auditors, three weeks, fifty-four findings, nine of them Critical. All resolved before launch.
- 9Critical
- 4High
- 11Medium
- 30Low
Guardian has reviewed every smart contract update GMX has shipped since October 2022. More than eighty engagements, thirty-eight public reports, more than a thousand findings, thirteen thousand lines of our tests living in their production repository, and an elected seat on the GMX DAO Security Committee.
GMX hosts thirty-three of our reports in a Guardian-named directory inside their production repository. Thirteen thousand lines of tests we wrote are merged into their test suite. Their bug bounty programme points hunters at our reports to explain what is already known. And Guardian’s lead auditor holds an elected seat on the GMX DAO Security Committee.
GMX engaged Guardian eight times between October 2022 and September 2023. GMX’s own summary of that period, published in their repository, reads: “a total of 88 person weeks resulted in the remediation and acknowledgement of 365 findings.”
The first engagement alone (three auditors, three weeks, before a line of V2 was live) returned nine Criticals and four Highs. Across all eight pre-launch reviews: 365 findings, of which 47 were Critical and 33 were High. Every one of those numbers is reproducible from the PDFs GMX hosts.
Guardian does not deliver findings as prose. Every issue arrives with a proof-of-concept test that demonstrates it, and those tests do not get thrown away when the engagement ends.
GMX merged them. The test/guardian/ directory in gmx-io/gmx-synthetics holds thirty files and 13,279 lines of Guardian-authored tests, running in GMX’s CI on every change, four years after the first of them was written. A separate public repository carries the original coverage suite, linked from inside the 2022 report itself.
Guardian’s Owen Thurm was elected to the GMX DAO Security Committee, and has served through Season 3 and into Season 4. The DAO’s own Season 4 proposal records that Guardian works with GMX under a separate ongoing retainer arrangement.
GMX Labs’ 2026–2027 funding proposal names Guardian among the “top-tier service providers” that have fortified the protocol. A DAO delegate’s sustainability brief lists “security firm Guardian Audits” as part of GMX’s extended workforce.
“Guardian has been an integral part of the growth of GMX and our ecosystem of protocols who also rely on them for audits. Having Guardian as a strategic partner has allowed us to move more quickly while keeping security as our highest priority.”
“We were very impressed by the quality of the audit from Guardian, they went above and beyond and exceeded our expectations, each found vulnerability was accompanied by a PoC test to demonstrate the issue, they found edge cases and wrote additional test cases which are now included in our test coverage”
Four years of continuous review, from the first pre-launch pass on V2 to the architecture records for the next release. More than eighty engagements sit behind this; what follows are the ones that changed something. The rail alongside tracks where you are.
GMX Synthetics · 3 auditors
Guardian’s first GMX engagement, on the earliest V2 codebase: three auditors, three weeks, fifty-four findings, nine of them Critical. All resolved before launch.
Eight engagements · 88 person-weeks
Over eleven months, each pass attacked the remediated codebase again, and the Critical count fell from eighteen in January to none by the end of July.
GMX’s own README records the total: 88 person-weeks and 365 findings remediated or acknowledged.
Keeper automation · 3 auditors
GMX’s keepers execute orders and liquidations, so a defect there stops the exchange rather than corrupting it. Two weeks of review found two Criticals and a High.
V1→V2 migrator · subaccounts · governance · config
With V2 live, deep passes gave way to review of every update as it was built: the V1-to-V2 migrator, the subaccount router, governance and the config contracts. Seven reports across the period.
Three concurrent update reviews
Three parallel reviews of the V2.1 update. The first alone returned three Criticals and nine Highs.
An external-call gas adjustment could deny service to liquidations, and cancel callbacks could block them outright. Either would let an attacker hold an underwater position open and push the loss onto the pool. Both closed.
GLV liquidity vaults
GLV is GMX’s vault layer over its GM markets. The review returned a Critical, two Highs, twelve Mediums and thirty-one Lows.
When pending trader PnL pushes pnlToPoolFactor above its cap, GM token value is measured slightly differently. An attacker could mint low and redeem high on that gap, repeatedly, and drain the vault. It is the kind of bug invariant fuzzing catches and a manual read passes over.
Fee buybacks · referral pro tiers · ConfigSyncer
Three engagements in autumn 2024, all published by GMX. The buyback review found three Criticals in the mechanism that moves protocol fees; Pro Tiers returned a High and two Mediums, and ConfigSyncer five Lows.
Gasless order flow · sponsored calls · 4 auditors
Gasless execution lets someone else pay for and relay a user’s intent, which raises new questions about who can submit what on whose behalf. Five Highs on the main review, then two passes over the sponsored-call implementation.
Seven sequential reviews · up to 7 auditors · LayerZero cross-chain deposits and orders
The largest programme since pre-launch: seven rounds between February and July 2025 on GMX V2.2, which lets users deposit and trade across chains over LayerZero.
Across the seven reports, fifteen Criticals and thirty Highs, including lzCompose front-running to steal funds, token spoofing across the bridge, and two order-vault drains.
GMX market orders cannot be updated or cancelled, so a trader cannot back out once the price moves. Two Criticals broke that guarantee: one let a user drain their own order’s collateral as a “fee” to themselves, the other forced position validation to revert. Both amounted to risk-free trading against the pool.
Guardian Defender · 28 Jul – 8 Aug 2025
A $175,000 prize pool on the upgrade branch, open to public attack for two weeks. Five submissions; only Criticals were eligible, none was valid, and nothing was paid out.
JIT liquidity · 2 auditors
Just-in-time liquidity lets an LP appear for one block, collect a trade’s fees and leave, so the review is about who profits from every ordering of events. Forty-seven findings: two Highs, twelve Mediums and thirty-three Lows.
OFT integration · fee automation keepers
The OFT review returned six Mediums and nothing above; the fee automation keepers, one Medium and three Lows.
Cross-margin and market groups · plan review
GMX brought Guardian the V2.3 plan before writing it: cross-margin positions sharing collateral across markets, and the market groups underneath.
The output was the questions the design had to answer first, such as whether market groups were needed for cross-margin at all. Those are far cheaper to settle before the code exists.
Design-level assessment · dedicated fuzzing track
A week-long design review alongside the full V2 re-review, with its own fuzzing track. A design review catches the problem where every change is correct and the system they add up to is not.
Full gmx-synthetics tree · 27,805 source lines · keeper code · Chainlink CRE workflow · four follow-up rounds
A deliberate reset: instead of another diff, Guardian re-reviewed the entire GMX V2 tree, plus the keeper code, a Chainlink CRE workflow and the functions repository.
Five months and four follow-up rounds: two Criticals, seven Highs, thirty-one Mediums and twenty-one Lows. Four years in, a clean-sheet read still found two Criticals.
A reserve check that blocked decrease flows, and a factory.call() path allowing unauthorised transfers. Both resolved. The Highs include reserve checks that could block liquidations and ADLs, and a static oracle returning its minimum and maximum inverted.
Payments and referral storage timelocks · Arbitrum, Avalanche, MegaETH
Guardian reviewed GMX’s new payments and referral-storage timelocks, checking the source against what is actually deployed on Arbitrum, Avalanche and MegaETH.
Read the report →SOP-3 Market Delisting · SOP-5 Index Token Delisting
No Solidity here: Guardian reviewed the operating procedures for delisting a market and an index token. Delisting closes positions and winds down parameters in a set order, and a step in the wrong place is a vulnerability no contract audit will find.
RISK_ORACLE role · access control · market parameter updates
GMX moved from Chaos Labs’ external risk oracle to one it runs itself, adding a privileged RISK_ORACLE role that can update market parameters directly.
Guardian reviewed the new permissions and update paths under a deployment freeze, which meant confirming the change was as isolated as it claimed to be, not only that it was safe.
Architecture decision records · V2.2.1 PR review
The current work: GMX’s V2.3 architecture decision records, reviewed before implementation, alongside the V2.2.1 pull request. Four years in, the reviews happen earlier in GMX’s process than they used to.
Dolomite · Umami · Abracadabra · MUX · Jones · IVX · SNTL · Key Finance
Protocols building on GMX V2 inherit its complexity without its audit history, and many came to Guardian for that reason, at least three with GMX DAO grants earmarked for a Guardian review.
Dolomite credits Guardian in its docs and in its final report to the GMX DAO. Umami’s docs describe Guardian as a firm “which spent 11 months auditing GMX v2.”
GMX names Guardian in its documentation, hosts our reports in its repository, runs our tests in its CI, points its bug bounty at our findings, and seats us on its Security Committee. Every link below was fetched and verified.
We work closely with our partners to address their most critical security needs: every update reviewed as it ships, every deployment checked before it goes live, by a team that already knows the codebase. Tell us what you’re building and we’ll scope a long-term partnership around it.
Get a quoteWork with Guardian