GMX engaged Guardian to review the security of updates to it’s synthetic assets exchange. From the 10th of June to the 12th of June, a team of 2 auditors reviewed the source code in scope.
- Published
- Review window
- June 10 to 12, 2024
- Language
- Solidity
- Chains
- Arbitrum, Avalanche
- Sector
- Perpetuals
- 1 Critical
- 0 High
- 0 Medium
- 0 Low
- 0 Informational
Scope
Overview
GMX engaged Guardian to review the security of updates to it’s synthetic assets exchange. From the 10th of June to the 12th of June, a team of 2 auditors reviewed the source code in scope.
Findings 1
-
C-01 Critical Risk Free Trades With cancellationReceiver DoS Resolved
Description
In the
cancelOrderfunction if the order is an increase or swap order, which requires input funds, these funds are sent back to thecancellationReceiver. When the cancellationReceiver address is theOrderVaultthetransferOutfunction will revert with theSelfTransferNotSupportederror.As a result a malicious actor may create a
MarketIncreaseorder with the following properties:- The
cancellationReceiveris theOrderVault - The
swapPathincludes a market that would fail it’s reserves validation as a result of the swap
The order fails as the initial swap for the increase order cannot go through, but the order cannot be cancelled as the
cancellationReceiveris theOrderVault.Therefore the order will remain in the
OrderStoreuntil the malicious actor sees that price has moved in their favor relative to the range of prices that theirMarketIncreaseorder may be executed with. The malicious actor can then deposit into the market in theswapPathwhich was previously failing the reserve validation, such that it no longer fails the reserve validation and the order can be executed. The malicious actor then realizes a risk-free profit.If price should not move in the actor’s favor during the 5 minute max price age period after their order’s
requestExpirationtime, then the actor may update their order and attempt the risk free trade over the next period.Recommendation
Upon order creation validate that the
cancellationReceiveris not the address of theOrderVault.Resolution
GMX Team: Resolved.
- The
No findings match.
More from GMX
All 44 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
