defirisk.co
rubric v1.7.0

Stale-approval exposure on deprecated router

GMX v2 (GMX Synthetics)'s assessment for RD-F-168 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

GMX v2 re-deploy model means that when routers are upgraded, old approved addresses remain active for users who approved them. GMX docs note 'contract addresses change when logic contracts are upgraded' and 'integration updates' required — acknowledging stale approval hygiene gap. No active allowance scan performed; no current count of stale approvals to deprecated router addresses. Known architectural hygiene issue in re-deploy models.

Sources #

Methodology #

Count the number of active user approvals (ERC-20 `allowance`) to deprecated router or protocol contracts.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol gmx-v2 factor RD-F-168 score yellow collected_at 2026-05-05 11:15:06