defirisk.co
rubric v1.7.0

Solc version used (known-bug versions flagged)

GMX v2 (GMX Synthetics)'s assessment for RD-F-170 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Hardhat config specifies Solidity 0.8.29, released 2025-03-12. The known LostStorageArrayWriteOnSlotOverflow bug was introduced in 0.1.0 and fixed in 0.8.32 - meaning 0.8.29 carries this unfixed bug. Severity is officially rated low (affects storage array operations straddling 2^256-slot boundary - extremely unlikely in practice). Not red because practical exploitability is negligible; yellow because 0.8.29 technically carries an unfixed known compiler bug per the Solidity bug list.

Sources #

Methodology #

Identify the Solidity compiler version used for deployed bytecode and flag if it appears on the known-bug list (solc bugs.json or Vyper 0.2.15–0.3.0 range).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol gmx-v2 factor RD-F-170 score yellow collected_at 2026-05-05 11:15:06