How to read an audit claim before using an aggregator
Read the audit’s scope, version, findings and deployment relevance before treating an aggregator’s audit badge as security evidence.
Explore the reference
Check permissions, signatures and contracts before putting assets at risk.
49 guides · Page 2 of 3
Read the audit’s scope, version, findings and deployment relevance before treating an aggregator’s audit badge as security evidence.
Reduce sandwich exposure by reviewing execution bounds, route liquidity and the actual coverage of private submission.
Remove an unwanted standard token allowance and verify the onchain result without confusing revocation with recovery.
Verify the real application domain and contract request when search ads or copied swap interfaces look convincing.
Verify the exact contract receiving token permission, rather than confusing it with the token or execution router.
Triage an unfamiliar signed request by identifying whether it exposed a key, granted permission or authorized an order.
Check the scope and duration of a liquidity lock without assuming it removes token or execution risk.
Understand which authority a renounceOwnership transaction removes and which independent risks may remain.
Stop and investigate when a pasted swap recipient differs from the address you intended to use.
Compare a standard onchain token approval with an ERC-2612 signed permit and understand what each authorizes.
Separate the token allowance granted to Permit2 from the spender authorization Permit2 checks for an application.
Compare private transaction services by chain support, information sharing, fallback and execution rules rather than the word private.
Evaluate recovery claims by asking who can move the funds and rejecting fabricated unlock payments or secret requests.
Identify a token by chain and contract address instead of trusting a copied ticker, logo or wallet valuation.
Choose the right response by distinguishing stolen signing control from a malicious token permission.
An unsolicited token balance is not an obligation to claim, sell or visit the website embedded in its name.
Use account separation to limit approval exposure while understanding the limits of shared secrets and public funding links.
A verified-source badge helps inspect deployed code but does not certify that the contract is safe to approve or trade.
Use the hardware device’s trusted display to check destination details while distinguishing router and final token recipient.
Investigate a wallet’s site, token, address or transaction warning before deciding whether the requested swap is acceptable.