Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · August 2025

Reader

for GMX

Guardian's review of Reader for GMX, published August 2025. The report records 4 findings, including 1 low and 3 informational.

Published
Review window
August 13 to 18, 2025
Language
Solidity
Chains
Arbitrum, Avalanche
Sector
Perpetuals
  • 0 Critical
  • 0 High
  • 0 Medium
  • 1 Low
  • 3 Informational

4 acknowledged

Scope

Findings 4

  1. L-01 Low Unused Structs Superfluous Code Acknowledged
    Location
    contracts/reader/ReaderPricingUtils.sol#L32C1-L46C6

    Description

    The ReaderPricingUtils contract contains PositionInfo and GetPositionInfoCache structs similar to those in ReaderPositionUtils. However, the structs in ReaderPricingUtils are outdated and not used anywhere, so they can be removed.

    Recommendation

    Consider removing unused structs.

  2. I-01 Informational Function Without Logic Best Practices Acknowledged

    Description

    The getLiquidatablePositions function has no logic implemented.

    Recommendation

    Consider removing it / commenting it out or implementing the logic.

  3. I-02 Informational Inconsistent Function Parameter Names Informational Acknowledged
    Location
    contracts/reader/Reader.sol:252

    Description

    In the Reader contract, the getPnlToPoolFactor function uses marketAddress, while other functions such as getMarketInfo, getExecutionPrice, and getSwapPriceImpact use marketKey as a parameter.

    Recommendation

    Consider using marketKey in the getPnlToPoolFactor function as well for consistency.

  4. I-03 Informational Missing Params In NatSpec Best Practices Acknowledged

    Description

    There are some missing params in the NatSpec of the isPositionLiquidatable function. The same holds true for the IsPositionLiquidatableCache.

    Recommendation

    Consider adding the params to the NatSpec.

More from GMX

All 44 reports
  1. Timelock Updates

    4 findings 4 findings: 3 low, 1 informational
  2. LayerZeroProvider Routing

    1 finding 1 finding: 1 medium
  3. Open Interest Updates

    5 findings 5 findings: 2 medium, 3 low
  4. Updates Branch

    2 findings 2 findings: 2 low

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote