Security
Audit status
Deployed on mainnet without an external audit
zk-pad is deployed on BSC mainnet (chain 56) and has not been externally audited. The admin contracts are owned by a single EOA, not a multisig or timelock. Use it at your own risk and do not use it with funds you cannot afford to lose.
| Item | Status |
|---|---|
| External audit | Not yet. Auditor and scope to be announced. |
| Mainnet deployment | Live on BSC mainnet since 2026-10-05, deployed from main at ef6614c (with the round-4 review fixes) through the release gate; every contract verified on BscScan. It supersedes a 2026-10-04 deployment whose factory is deprecated on-chain (no coins were launched on it). See addresses and deployment. |
| Administration | Single EOA owner of FeeVault, ZkPadFactory, QuoteRegistry and RailgunShieldAdapter; separate EOA guardian. No multisig or timelock yet. See trust assumptions. |
| Social-account escrows | Coming soon. Binds are disabled: no attestors are registered (attestorThreshold = 0). Fees to escrows stay in the vault but cannot be claimed yet; an escrow with a fallback recipient can be swept to it after its fallback delay (at least 180 days) passes without a bind. |
| Fork tests | Green against BSC mainnet state on 2026-10-04 (feeds, V3 routes, Railgun, sanctions oracle). Fork tests are not an audit. |
| Internal adversarial review | Four rounds (security, economics and privacy-leak reviewers). Each finding was verified, then fixed with a regression test or documented as an accepted risk in docs/THREAT_MODEL.md. An internal review is not an audit. |
| Upstream code | Clanker v4 (MIT) was audited by Cantina and Macro. zk-pad's port carries over the relevant fixes; deviations are listed in contracts/PORTING.md. A port is new code and needs its own audit. |
| Railgun | Independently audited upstream; zk-pad does not modify it. |
| Bug bounty | To be announced. See disclosure. |
Audit reports will be linked here when available.
Security properties
| Property | Enforced by |
|---|---|
| Fixed supply, no mint, no tax, no blacklist | ZkPadToken |
| Liquidity can never be removed | ZkPadLpLocker has no remove path; positions are not transferable |
| Only the locker adds liquidity | Hook beforeAddLiquidity |
| Nobody can pre-initialize a launch pool | Hook beforeInitialize; only the hook (for the factory) initializes |
| F ∈ [1%, 5%], lowering-only | Hook MIN_FEE, MAX_FEE, lowerFees |
| Anti-sniper fee ≤ 80% for ≤ 2 minutes | Hook MAX_MEV_FEE, MAX_MEV_MODULE_DELAY |
| 25 / 75 split | Hook protocol fee = 1/3 of the LP fee the positions receive; buys measured on the gross input, sells at the execution value with 75% of the excess over the post-swap value rebated and a protocol top-up at conversion; locker sends 100% of LP fees to the vault |
| Beneficiary balances can only leave the account through the owner key, the fallback sweep after inactivity, or (social escrows only) a new owner after a timelocked, vetoable attestor rebind. A launch creator can only swap its own launch's credit into USDT inside the same account and shield it to the beneficiary's own templates | FeeVault |
| A relayer cannot alter a claim | EIP-712 over every field, adapter payload by hash |
| Admins cannot take beneficiary funds | No such function; recoverSurplus is limited to the excess over totalBalance. The owner does control the attestor set, the guardian and consolidation configuration; see trust assumptions |
| Trading never blocks on fee plumbing | Fee payouts and collections are try/catch with failure events |