Binswap
Security

Found a hole in the bin?

Report it privately

If you find a vulnerability in a Binswap program, the SDK or this app, send the details privately to the Binswap team through the contact the team publishes. Please do not open a public issue or post about it until a fix is live.

Include what is affected, the steps or a transaction that reproduces it, and what an attacker could do with it.

Play fair

Prove the issue with the smallest amounts you can, on a local validator where possible. Do not take funds that are not yours, and do not degrade the service for other people.

Not audited

Binswap's programs have not been audited. The AMM is a fork of Raydium's open-source raydium-cp-swap: its trading logic is upstream's (audited upstream by MadShield, Q1 2024), but that audit does not cover this fork's changes. Every program is built with Anchor.

On chain