GMX engaged Guardian to review the security of its adaptive funding fee remediations. From the 18th of September to the 25th of September, a team of 2 auditors reviewed the source code in scope.
- Published
- Review window
- September 18 to 25, 2023
- Language
- Solidity
- Chains
- Arbitrum, Avalanche
- Sector
- Perpetuals
- 0 Critical
- 0 High
- 0 Medium
- 3 Low
- 0 Informational
Scope
Overview
GMX engaged Guardian to review the security of its adaptive funding fee remediations. From the 18th of September to the 25th of September, a team of 2 auditors reviewed the source code in scope.
Findings 3
-
CALC-1 Low boundMagnitude Exceeds Int256 Range Documentation Pending
Description
In the
Calc.boundMagnitudefunction, it is possible for the type casting to exceed the value range for anint256, producing a revert with theSafeCastlibrary.If the
valueparameter is the minimumint256value, the bounding will fail with aSafeCastrevert as the absolute value will not fit in anint256type.Furthermore, if the
minis greater thantype(int256).max, the resultingmagnitudewill exceedtype(int256).maxwhich results in aSafeCastrevert when castingtoInt256().Recommendation
Though currently this case will likely never be possible, consider documenting that the function will fail when
value=type(int256).minand when theminbound is outside of the range of values forint256type. -
BRTR-1 Low Redundant Validation Superfluous Code Pending
Description
The
validateReceivervalidations in thesendNativeTokenandsendWntfunctions are superfluous as thereceiveris immediately validated in theTokenUtils.sendNativeTokenandTokenUtils.depositAndSendWrappedNativeTokenfunctions.Recommendation
Remove the additional validation in the
sendNativeTokenandsendWntfunctions. -
BRTR-2 Low Missing Documentation Documentation Pending
Description
The
sendNativeTokenfunction is missing NatSpec, whilesendWntandsendTokensboth have the appropriate documentation.Recommendation
Add documentation for the
sendNativeTokenfunction.
No findings match.
Invariants 1
The review's fuzzing suite asserted 1 invariant. 1 held.
Every invariant tested
| ID | Invariant | Result |
|---|---|---|
CALC-1 | boundMagnitude successfully bounds the magnitude of the resulting value between the min and max | Held |
More from GMX
All 44 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
