Guardian's review of LayerZeroProvider Routing for GMX, published December 2025. The report records 1 finding, including 1 medium.
- Published
- Review window
- December 20, 2025
- Chains
- Arbitrum, Avalanche
- Sector
- Perpetuals
- 0 Critical
- 0 High
- 1 Medium
- 0 Low
- 0 Informational
Findings 1
-
M-01 Medium Messages Routed With New Data Trapped Logical Error Acknowledged
Description
The diff between the old LayerZeroProvider that has been re-enabled to rescue stuck messages and the most up-to-date LayerZeroProvider is as follows:
In the new LayerZeroProvider the
datapayload now has auint256type which is destructured from it as a second value.The data bytes are now structured like so:
(ActionType, uint256, bytes)If messages using this new
datapayload structure with theuint256as the second argument are routed to this old LayerZeroProvider contract, then the messages will be trapped forever as the provider contract is not upgradeable and the decoding of the data object as follows:(ActionType actionType, bytes memory actionData) = abi.decode(data, (ActionType, bytes));Inside the
if (srcChainId != 0 && data.length != 0) {case will revert.Recommendation
Ensure that messages using the new
dataformat withuint256as the second parameter are not routed to the old LayerZeroProvider which has now been re-enabled.
No findings match.
More from GMX
All 44 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
