Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · September 2023

Adaptive Funding Fee Remediations

for GMX

GMX engaged Guardian to review the security of its adaptive funding fee remediations. From the 18th of September to the 25th of September, a team of 2 auditors reviewed the source code in scope.

Published
Review window
September 18 to 25, 2023
Language
Solidity
Chains
Arbitrum, Avalanche
Sector
Perpetuals
  • 0 Critical
  • 0 High
  • 0 Medium
  • 3 Low
  • 0 Informational

3 pending

Scope

Overview

GMX engaged Guardian to review the security of its adaptive funding fee remediations. From the 18th of September to the 25th of September, a team of 2 auditors reviewed the source code in scope.

Findings 3

  1. CALC-1 Low boundMagnitude Exceeds Int256 Range Documentation Pending
    Location
    Calc.sol: 28-30

    Description

    In the Calc.boundMagnitude function, it is possible for the type casting to exceed the value range for an int256, producing a revert with the SafeCast library.

    If the value parameter is the minimum int256 value, the bounding will fail with a SafeCast revert as the absolute value will not fit in an int256 type.

    Furthermore, if the min is greater than type(int256).max, the resulting magnitude will exceed type(int256).max which results in a SafeCast revert when casting toInt256().

    Recommendation

    Though currently this case will likely never be possible, consider documenting that the function will fail when value=type(int256).min and when the min bound is outside of the range of values for int256 type.

  2. BRTR-1 Low Redundant Validation Superfluous Code Pending
    Location
    BaseRouter.sol: 38, 50

    Description

    The validateReceiver validations in the sendNativeToken and sendWnt functions are superfluous as the receiver is immediately validated in the TokenUtils.sendNativeToken and TokenUtils.depositAndSendWrappedNativeToken functions.

    Recommendation

    Remove the additional validation in the sendNativeToken and sendWnt functions.

  3. BRTR-2 Low Missing Documentation Documentation Pending
    Location
    BaseRouter.sol: 49

    Description

    The sendNativeToken function is missing NatSpec, while sendWnt and sendTokens both have the appropriate documentation.

    Recommendation

    Add documentation for the sendNativeToken function.

Invariants 1

The review's fuzzing suite asserted 1 invariant. 1 held.

Every invariant tested
IDInvariantResult
CALC-1boundMagnitude successfully bounds the magnitude of the resulting value between the min and maxHeld

More from GMX

All 44 reports
  1. Timelock Updates

    4 findings 4 findings: 3 low, 1 informational
  2. LayerZeroProvider Routing

    1 finding 1 finding: 1 medium
  3. Open Interest Updates

    5 findings 5 findings: 2 medium, 3 low
  4. Updates Branch

    2 findings 2 findings: 2 low

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote