GMX engaged Guardian to review the security of their GMX Crosschain architecture. From the 21st of July to the 25th of July, a team of 2 auditors reviewed the source code in scope.
- Published
- Review window
- July 21 to 25, 2025
- Language
- Solidity
- Chains
- Arbitrum, Avalanche
- Sector
- Perpetuals
- 0 Critical
- 1 High
- 0 Medium
- 8 Low
- 0 Informational
Scope
Overview
GMX engaged Guardian to review the security of their GMX Crosschain architecture. From the 21st of July to the 25th of July, a team of 2 auditors reviewed the source code in scope.
Findings 9
-
H-01 High Secondary Amount Is Not Bridged Out Logical Error Resolved
Description
In the
bridgeOutFromControllerfunction for tokens andsecondaryTokensthe_bridgeOutParams.amountis assigned as only theparams.amountin the first case, ignoring thesecondaryAmountentirely.This misses the secondary token amount that should be bridged out in the event that both output tokens are the same token.
Recommendation
Assign the
_bridgeOutParams.amountasparams.amount + params.secondaryAmountin the first case.Resolution
GMX Team: Resolved.
-
L-01 Low Some Tokens Incompatible With Edge Oracle Warning Acknowledged
Description
Depending on the token decimals and corresponding edge oracle decimals there may be some tokens which cannot be used with the edge oracle due to the token decimals multiplier calculations.
For example:
- Token has 18 decimals
- Expo is -14
floatMultiplier= 30 - 18 - 14 = -2
A resulting negative multiplier reverts with the
InvalidEdgeDataStreamExpoerror.Recommendation
Consider if tokens which have a net negative float multiplier due to high decimals or a high exponent should be supported by using a division of
10^(-floatMultiplier). Otherwise be aware of this incompatibility for exotic tokens.Resolution
GMX Team: Acknowledged.
-
L-02 Low Max Data List Length Warning Configuration Acknowledged
Description
With the addition of the minimum output amount configuration for the user, the maximum datalist length should be increased as necessary to be able to include a minimum amount out value for both the primary output token and secondary output token if there is one for the action.
Recommendation
Be sure that the largest required data list length can be supported by the validation.
Resolution
GMX Team: Acknowledged.
-
L-03 Low Lacking From And To Validations Validation Resolved
Description
In the
transferClaimfunction there is no validation preventing the from and to addresses from being the same account. This may lead to unexpected issues and should be explicitly prevented to avoid mistakes.Recommendation
Consider adding validation to ensure that the from and to addresses of each
TransferClaimParamare unique.Resolution
GMX Team: Resolved.
-
L-04 Low Misleading Account Emitted Events Resolved
Description
In the
emitClaimFundsClaimedinvocation in theclaimFundsfunction the receiver is emitted as the account, however themsg.senderis the account that claimed funds.This may be misleading to consumers of the
emitClaimFundsClaimedemission.Recommendation
Consider using the
msg.senderas the account field for theemitClaimFundsClaimedinvocation.Resolution
GMX Team: Resolved.
-
L-05 Low Terms Should Be Set Before Depositing Warning Acknowledged
Description
The
setTermsfunction should be called for a givendistributionIdthat requires terms before thedepositFundsfunction is used for thatdistributionId.This is because it is possible for an actor to withdraw their distribution immediately after the
depositFundsfunction is used, without signing any terms if they are not configured at that point.Recommendation
Be sure to call the
setTermsfunction before thedepositFundsfunction for any distributions which require terms.Resolution
GMX Team: Acknowledged.
-
L-06 Low Lacking Signature Deadline Or Nonce Validation Acknowledged
Description
The
validateTermsSignaturevalidation does not include any deadline for when the signature made by the user should become invalid, or Nonce which makes signature uses unique.This may be unexpected especially if a user makes an initial claim for a
distributionIdbefore their allocation for thatdistributionIdis increased and they are able to claim again.Recommendation
Consider adding mechanisms that more strictly define the use of a user’s signature such as a nonce and deadline.
Resolution
GMX Team: Acknowledged.
-
L-07 Low Lacking Domain Separator Best Practices Resolved
Description
There is no domain separator included in the
validateTermsSignaturesignature validation. This means a signature of terms could be potentially used across multiple contracts or even on other chains if aClaimHandlerwere to be deployed on multiple networks.Recommendation
Consider adding a domain separator to make signatures specific to the context in which they are meant to be used.
Resolution
GMX Team: Resolved.
-
L-08 Low Min Amount Is Altered Unexpected Behaviour Acknowledged
Description
In the
prepareSendfunction thesendParam.minAmountLDis re-assigned toreceipt.amountReceivedLD.Therefore if for any reason the amount received by the user on the
stargate.sendinvocation would be less than thereceipt.amountReceivedLDbut more than thesendParam.minAmountLDthen the send would fail even though the minimum amount specified by the user could have been met.Recommendation
This case should not be possible since the
quoteOFTcall should always return the exact result of the send.However consider if the
minAmountLDshould be left as the user’s specifiedsendParam.minAmountLDso that this case cannot arise with any underlying stargate pool or OFT implementation.Resolution
GMX Team: Acknowledged.
No findings match.
More from GMX
All 44 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
