GMX-logo

GMX

GMX is a decentralized spot and perpetual exchange that supports low swap fees and zero price impact trades.

Arbitrum
Avalanche
Defi
AMM
DEX
JavaScript
Solidity
Typescript
Maximum Bounty
$5,000,000
Live Since
20 October 2021
Last Updated
08 April 2024
  • Triaged by Immunefi

  • PoC required

Resources & Documentation

All smart contracts of GMX can be found at https://github.com/gmx-io/gmx-contracts and http://github.com/gmx-io/gmx-synthetics. However, only those in the Assets in Scope table are considered as in-scope of the bug bounty program.

If an impact can be caused to any other asset managed by GMX that isn’t on this table but for which the impact is in the Impacts in Scope section, you are encouraged to submit it for the consideration of the project.

Detection of malicious Timelock transactions will be eligible for a bounty if it is submitted 1 hour after the malicious transaction was sent, this is to allow time for the GMX team to self-report based on their own monitoring. An exception to this would be if the Timelock transaction is able to cause losses in less than an hour’s time due to any misconfiguration of the Timelock, in which case it would be preferred that the report be submitted as early as possible.