Check it, don't trust it.
Everything BOUND promises is enforced by contracts whose source you can read, and proved by tests you can run. This page lists what those contracts guarantee, who holds which keys, and every limitation we know of. If something here is wrong, the code wins.
At a glance
Verification
The contracts below are the only ones BOUND uses. Every token and curve is deployed by the factory from the verified deployer contracts, so each one runs exactly that code. Your wallet shows which contract you're calling before you sign; it should always be one of these, a BOUND token or curve, or Uniswap.
Build settings
- Solidity 0.8.26, optimizer on (200 runs), via-IR, EVM version Cancun.
- Libraries: OpenZeppelin Contracts 5, Uniswap v4-core 1.0.2.
- Uniswap v4 PoolManager on Robinhood Chain: Uniswap's own deployment, unchanged.
The BOUND pool hook's address ends in …2840. In Uniswap v4 a hook's address encodes exactly which callbacks it can run: here only before initialize, before add liquidity and after swap. It can't take fees, change swap amounts or touch anyone's balance.
Who can do what
The factory owner (a Safe multisig)
Can: change the treasury address, the curve size and whether new launches are open, for launches made after the change.
Can't: touch any launched token, its rules, its curve, its pool, its liquidity, its fees or anyone's balance. It can't mint, pause trading, block wallets or move funds. Ownership changes need two steps, so it can't be handed to a wrong address by mistake.
A token's creator
Can: pick up to five rules within fixed limits, once, at launch; claim their 15% of fees.
Can't: change the rules afterwards, mint more tokens, pull liquidity, or escape their own rules. Rule limits make honeypots impossible: whatever they pick, every holder can always sell (see Guarantees). The one deliberate exception is P2P-only, which is labelled everywhere.
The BOUND hook
Can: refuse to open a token's pool for anyone but its curve, refuse outside liquidity before graduation, and refuse a swap the token's rules refuse.
Can't: take fees, change amounts or move tokens. Its one setting, the factory link, was set once and can't change.
Traders and bots
Can: trade within the rules, including front-running and sandwiching like on any public chain.
Can't: profit from buying and selling straight back, make the curve insolvent, block graduation, or open the Uniswap pool early at a bad price. Creators can add the sniper tax and anti-bundle rules against bots; the site sets slippage limits on every trade.
The website
Can: show information and prepare transactions for your wallet to sign. It checks each trade against the contracts before your wallet opens.
Can't: sign anything for you or reach your keys. If you're ever unsure, check in your wallet that the contract you're calling is one listed above.
Guarantees
Each line is a property the contracts enforce, with the test that proves it. Fuzz tests run each check against hundreds of random inputs on every run.
- Holders can always sell. Whatever rules a creator picks, a holder can always eventually sell at least 0.05% of supply at a time, on the curve and on Uniswap.
testFuzz_HolderCanAlwaysEventuallyExittest_StrictestRulesStillLetHoldersExittest_NEW_StrictestRulesStillExitOnUniswap - Rule settings that could trap holders are refused at launch.
test_RejectsSettingsThatCouldTrapHolders - Nobody can change a launched token's rules.
test_NobodyCanChangeALaunchedTokensRules - The owner only changes future launches.
test_OnlyOwnerChangesSettings_AndOnlyForFutureLaunches - The curve always holds the ETH it owes.
testFuzz_CurveStaysSolventThroughRandomTradingtestFuzz_SolventWithFeeRules - Buying and selling straight back never makes a profit.
testFuzz_RoundTripNeverProfits - Graduation always succeeds and can't be blocked or front-run. Only the curve can open the pool or add liquidity before graduation.
testFuzz_GraduationAlwaysSucceedstest_NobodyElseCanOpenThePoolOrAddLiquidityBeforeGraduationtest_BLOCKED_1abc_NobodyButTheCurveCanInitialise - Liquidity is locked forever, and its fees can always be swept.
test_GraduatesToUniswapV4AtTheCurvePriceWithLockedLiquiditytest_LockedLiquidityFeesCanBeSwepttest_NEW_GraduationAndFeeSweepWhileMarketClosed - Fees split exactly 85 / 15.
test_FeesSplit85To15 - Swaps are checked even when no tokens move (Uniswap v4 claim balances).
test_HookChecksSwapsThatNeverMoveTheToken - Zero-value transfers can't be used to grief anyone.
test_ZeroValueTransfersAreNotTradestest_BLOCKED_2_ZeroValueNoLongerResetsCooldown - A price pumped for a moment can't unlock an Entangled token, and momentum faked inside one transaction can't loosen a Reactive cap.
test_Fixed_EntangledFlashUnlockRefusedtest_Fixed_ReactiveFlashMomentumDoesNothingtest_ReactiveTightenedCap_GasStarvationCantBypass - The hook only answers Uniswap, and its factory link is set once.
test_NEW_HookOnlyPoolManagertest_NEW_SetFactoryOneShot - The full lifecycle works on the real Uniswap v4 deployment on Robinhood Chain, including trades through Uniswap's Universal Router.
test_FullLifecycleOnRealUniswapV4
Known limitations
What BOUND doesn't do, or does only partly. We'd rather you read it here than find out later.
- No paid third-party audit. The reviews and tests above are thorough, but they aren't an audit by an independent firm.
- Wallet rules after graduation can be avoided inside Uniswap. Uniswap v4 lets traders keep balances inside its PoolManager instead of in a wallet. Swaps settled that way are still checked for size, market hours and the other per-trade rules, but wallet rules (max per wallet, cooldown, vesting, allowlist, holder-gated) only see tokens that actually move to a wallet.
test_STILL_4_ClaimsBypassMaxWalletAndCooldown - A second Uniswap v4 pool without the BOUND hook isn't checked per swap. Anyone can create one. Trades there that settle as Uniswap claim balances avoid per-trade rules; trades that move tokens to wallets are still checked by the token.
test_STILL_4_HooklessSecondPoolBypassesHookRules - Other exchanges look like wallet-to-wallet sends. A token can't tell a different exchange's pool from a wallet, so trades there aren't checked as buys or sells. Creators who want every trade on the official markets can turn on DEX-only, which refuses those transfers.
- Fee rules only run on the curve. Tithe, buyer rewards and the sniper tax stop at graduation, because Uniswap v4 requires exact token amounts.
- Some rules are soft limits. Per-buy caps can be split across several buys unless Anti-bundle is on. The Reactive cap moves only within the creator's floor and ceiling, from the next block.
- Entangled tokens unlock 1 to 2 hours after their Beacon first reaches the target, because the target must hold for a full hour. Their creators can't make a first buy while locked.
- P2P-only tokens can never be sold on a market. That's the point of the rule, and the only exception to "holders can always sell".
- Market hours use UTC.
- No emergency controls. There's no way to pause, fix or refund a launched token, even if its creator picked rules they regret. That's the cost of nobody being able to change them.
- The treasury's 85% waits in each curve until anyone calls
sendProtocolFees(there's a button in My vault). Creator fees wait until the creator claims them. - Charts, trades and holder lists are rebuilt from public chain data and can lag or miss events if the public RPC is slow.
Reviews and fixes
Each review tried to break the contracts the way an attacker would. Every finding was fixed, turned into a test, and redeployed before going live.
- Graduation could be blocked or hijacked by opening the token's Uniswap pool early at a bad price. Fixed: the BOUND hook only lets the token's curve open the pool or add liquidity before graduation.
- Zero-value transfers could reset other people's cooldowns or fill anti-bundle slots. Fixed: zero-value transfers are ignored.
- Locked-liquidity fees could get stuck for tokens with allowlists, holder gates or trade guards. Fixed: swept fees go to the curve and are burned, past the rules.
- Big dumps through Uniswap claim balances avoided per-sell caps. Fixed: the hook checks every swap, whether or not tokens move.
- A tithe could be pointed at a pool, the curve or the token itself instead of a real recipient. Fixed: those addresses are refused at launch.
- An Entangled token could be unlocked with a flash pump of its Beacon for about 2% in fees. Fixed: only prices that last past the end of a block count, and the target must hold for an hour.
- A Reactive cap could be loosened inside one transaction. Fixed: partners read momentum as of the previous block.