$1,000,000 in security audit grants are live now, Apply here →

← Case Studies

4 years of partnership with GMX

Guardian has reviewed every smart contract update GMX has shipped since October 2022. More than eighty engagements, thirty-eight public reports, more than a thousand findings, thirteen thousand lines of our tests living in their production repository, and an elected seat on the GMX DAO Security Committee.

4 yrsContinuous engagement
80+Engagements
1,000+Findings, 173 Critical or High
13,279Lines of our tests in their repo

GMX hosts thirty-three of our reports in a Guardian-named directory inside their production repository. Thirteen thousand lines of tests we wrote are merged into their test suite. Their bug bounty programme points hunters at our reports to explain what is already known. And Guardian’s lead auditor holds an elected seat on the GMX DAO Security Committee.

Before V2 shipped

GMX engaged Guardian eight times between October 2022 and September 2023. GMX’s own summary of that period, published in their repository, reads: “a total of 88 person weeks resulted in the remediation and acknowledgement of 365 findings.”

The first engagement alone (three auditors, three weeks, before a line of V2 was live) returned nine Criticals and four Highs. Across all eight pre-launch reviews: 365 findings, of which 47 were Critical and 33 were High. Every one of those numbers is reproducible from the PDFs GMX hosts.

The tests stayed

Guardian does not deliver findings as prose. Every issue arrives with a proof-of-concept test that demonstrates it, and those tests do not get thrown away when the engagement ends.

GMX merged them. The test/guardian/ directory in gmx-io/gmx-synthetics holds thirty files and 13,279 lines of Guardian-authored tests, running in GMX’s CI on every change, four years after the first of them was written. A separate public repository carries the original coverage suite, linked from inside the 2022 report itself.

Serving on the Security Committee

Guardian’s Owen Thurm was elected to the GMX DAO Security Committee, and has served through Season 3 and into Season 4. The DAO’s own Season 4 proposal records that Guardian works with GMX under a separate ongoing retainer arrangement.

GMX Labs’ 2026–2027 funding proposal names Guardian among the “top-tier service providers” that have fortified the protocol. A DAO delegate’s sustainability brief lists “security firm Guardian Audits” as part of GMX’s extended workforce.

“Guardian has been an integral part of the growth of GMX and our ecosystem of protocols who also rely on them for audits. Having Guardian as a strategic partner has allowed us to move more quickly while keeping security as our highest priority.”
Coinflipcanada GMX
“We were very impressed by the quality of the audit from Guardian, they went above and beyond and exceeded our expectations, each found vulnerability was accompanied by a PoC test to demonstrate the issue, they found edge cases and wrote additional test cases which are now included in our test coverage”
Core contributor GMX · supplied to Guardian

The engagements

Four years of continuous review, from the first pre-launch pass on V2 to the architecture records for the next release. More than eighty engagements sit behind this; what follows are the ones that changed something. The rail alongside tracks where you are.

Oct 2022

The first three weeks

GMX Synthetics · 3 auditors

Guardian’s first GMX engagement, on the earliest V2 codebase: three auditors, three weeks, fifty-four findings, nine of them Critical. All resolved before launch.

  • 9Critical
  • 4High
  • 11Medium
  • 30Low
Read the report →
Dec 2022 – Sep 2023

Seven more passes before launch

Eight engagements · 88 person-weeks

Over eleven months, each pass attacked the remediated codebase again, and the Critical count fell from eighteen in January to none by the end of July.

GMX’s own README records the total: 88 person-weeks and 365 findings remediated or acknowledged.

  • 47Critical
  • 33High
  • 101Medium
  • 184Low
GMX’s own summary of the period →
Sep 2023

Chainlink Automations

Keeper automation · 3 auditors

GMX’s keepers execute orders and liquidations, so a defect there stops the exchange rather than corrupting it. Two weeks of review found two Criticals and a High.

  • 2Critical
  • 1High
  • 2Medium
  • 8Low
Read the report →
Sep 2023 – Jan 2024

After launch: migration, subaccounts, governance

V1→V2 migrator · subaccounts · governance · config

With V2 live, deep passes gave way to review of every update as it was built: the V1-to-V2 migrator, the subaccount router, governance and the config contracts. Seven reports across the period.

  • 1Critical
  • 4High
  • 19Medium
  • 25Low
Read the migration report → Read the governance report → Read the config report →
Jun 2024

V2.1: two ways to stop liquidations

Three concurrent update reviews

Three parallel reviews of the V2.1 update. The first alone returned three Criticals and nine Highs.

  • 6Critical
  • 10High
  • 16Medium
  • 32Low
Highlighted findings · C-01 and C-02

An external-call gas adjustment could deny service to liquidations, and cancel callbacks could block them outright. Either would let an attacker hold an underwater position open and push the loss onto the pool. Both closed.

Read the first review → Read the second review → Read the third review →
Sep 2024

GLV: the Critical that manual review would have missed

GLV liquidity vaults

GLV is GMX’s vault layer over its GM markets. The review returned a Critical, two Highs, twelve Mediums and thirty-one Lows.

  • 1Critical
  • 2High
  • 12Medium
  • 31Low
Highlighted finding · C-01

When pending trader PnL pushes pnlToPoolFactor above its cap, GM token value is measured slightly differently. An attacker could mint low and redeem high on that gap, repeatedly, and drain the vault. It is the kind of bug invariant fuzzing catches and a manual read passes over.

Read the report →
Sep – Nov 2024

Buybacks and Pro Tiers

Fee buybacks · referral pro tiers · ConfigSyncer

Three engagements in autumn 2024, all published by GMX. The buyback review found three Criticals in the mechanism that moves protocol fees; Pro Tiers returned a High and two Mediums, and ConfigSyncer five Lows.

  • 3Critical
  • 2High
  • 3Medium
  • 24Low
Read the buybacks report →
Feb – Jul 2025

Cross-chain V2.2: seven reports over five months

Seven sequential reviews · up to 7 auditors · LayerZero cross-chain deposits and orders

The largest programme since pre-launch: seven rounds between February and July 2025 on GMX V2.2, which lets users deposit and trade across chains over LayerZero.

Across the seven reports, fifteen Criticals and thirty Highs, including lzCompose front-running to steal funds, token spoofing across the bridge, and two order-vault drains.

  • 15Critical
  • 30High
  • 58Medium
  • 156Low
Highlighted findings · risk-free trading

GMX market orders cannot be updated or cancelled, so a trader cannot back out once the price moves. Two Criticals broke that guarantee: one let a user drain their own order’s collateral as a “fee” to themselves, the other forced position validation to revert. Both amounted to risk-free trading against the pool.

Read the seven reports →
Jul – Aug 2025

A $175,000 contest on the V2.2 branch

Guardian Defender · 28 Jul – 8 Aug 2025

A $175,000 prize pool on the upgrade branch, open to public attack for two weeks. Five submissions; only Criticals were eligible, none was valid, and nothing was paid out.

Aug – Sep 2025

Just-in-time liquidity

JIT liquidity · 2 auditors

Just-in-time liquidity lets an LP appear for one block, collect a trade’s fees and leave, so the review is about who profits from every ordering of events. Forty-seven findings: two Highs, twelve Mediums and thirty-three Lows.

  • 0Critical
  • 2High
  • 12Medium
  • 33Low
Aug – Nov 2025

OFT and fee automation

OFT integration · fee automation keepers

The OFT review returned six Mediums and nothing above; the fee automation keepers, one Medium and three Lows.

  • 0Critical
  • 0High
  • 7Medium
  • 3Low
Nov 2025

V2.3: reviewing the plan before the code existed

Cross-margin and market groups · plan review

GMX brought Guardian the V2.3 plan before writing it: cross-margin positions sharing collateral across markets, and the market groups underneath.

The output was the questions the design had to answer first, such as whether market groups were needed for cross-margin at all. Those are far cheaper to settle before the code exists.

Mar 2026

Design review

Design-level assessment · dedicated fuzzing track

A week-long design review alongside the full V2 re-review, with its own fuzzing track. A design review catches the problem where every change is correct and the system they add up to is not.

Jan – Jun 2026

The full V2 re-review: 27,800 source lines, five months

Full gmx-synthetics tree · 27,805 source lines · keeper code · Chainlink CRE workflow · four follow-up rounds

A deliberate reset: instead of another diff, Guardian re-reviewed the entire GMX V2 tree, plus the keeper code, a Chainlink CRE workflow and the functions repository.

Five months and four follow-up rounds: two Criticals, seven Highs, thirty-one Mediums and twenty-one Lows. Four years in, a clean-sheet read still found two Criticals.

  • 2Critical
  • 7High
  • 31Medium
  • 21Low
Highlighted findings · C-01 and C-02

A reserve check that blocked decrease flows, and a factory.call() path allowing unauthorised transfers. Both resolved. The Highs include reserve checks that could block liquidations and ADLs, and a static oracle returning its minimum and maximum inverted.

Read the report →
Apr 2026

New timelocks, three chains

Payments and referral storage timelocks · Arbitrum, Avalanche, MegaETH

Guardian reviewed GMX’s new payments and referral-storage timelocks, checking the source against what is actually deployed on Arbitrum, Avalanche and MegaETH.

Read the report →
May 2026

Token delisting: auditing a procedure, not a contract

SOP-3 Market Delisting · SOP-5 Index Token Delisting

No Solidity here: Guardian reviewed the operating procedures for delisting a market and an index token. Delisting closes positions and winds down parameters in a set order, and a step in the wrong place is a vulnerability no contract audit will find.

May 2026

Risk oracle: taking risk parameters in-house

RISK_ORACLE role · access control · market parameter updates

GMX moved from Chaos Labs’ external risk oracle to one it runs itself, adding a privileged RISK_ORACLE role that can update market parameters directly.

Guardian reviewed the new permissions and update paths under a deployment freeze, which meant confirming the change was as isolated as it claimed to be, not only that it was safe.

Jul – Aug 2026

V2.3 pre-review, and the road to the next release

Architecture decision records · V2.2.1 PR review

The current work: GMX’s V2.3 architecture decision records, reviewed before implementation, alongside the V2.2.1 pull request. Four years in, the reviews happen earlier in GMX’s process than they used to.

2023 – 2026

And everyone building on top

Dolomite · Umami · Abracadabra · MUX · Jones · IVX · SNTL · Key Finance

Protocols building on GMX V2 inherit its complexity without its audit history, and many came to Guardian for that reason, at least three with GMX DAO grants earmarked for a Guardian review.

Dolomite credits Guardian in its docs and in its final report to the GMX DAO. Umami’s docs describe Guardian as a firm “which spent 11 months auditing GMX v2.”

Third-party resources

GMX names Guardian in its documentation, hosts our reports in its repository, runs our tests in its CI, points its bug bounty at our findings, and seats us on its Security Committee. Every link below was fetched and verified.

Looking for a partnership like this?

We work closely with our partners to address their most critical security needs: every update reviewed as it ships, every deployment checked before it goes live, by a team that already knows the codebase. Tell us what you’re building and we’ll scope a long-term partnership around it.

Get a quote