Resources
Security
How to report a vulnerability, and what the contracts can and cannot do.
View as MarkdownReporting a vulnerability
If you find a bug that could put user funds at risk, report it privately through the support panel below, with enough detail to reproduce it. Please do not disclose it publicly, open a public issue, or test it against other people's funds before it is fixed.
Audits
No audit report is published for this deployment yet. When one is, it will be linked here, next to the addresses it covers.
What the contracts can and cannot do
- Deployed contracts are immutable. No one can upgrade them, pause them, or reverse a trade.
- Launch liquidity is locked in
LauncherLocker, which has no withdrawal function, for the tail band from launch and for the graduated position. - The registry's owner can whitelist or drop base assets and set curves for new launches. That changes what can be launched next, not a pool that already exists.
- Fee claims are restricted to a pool's creator or a hook operator, and a claim only ever pays the creator and the Treasury.
Bull Launch will never ask for a private key or seed phrase, and never asks you to send funds to fix, verify or unlock anything. Anyone who does is not us.
