Transparent, non-custodial, yours

A scanner catches known patterns, not novel logic

Scanners match code against known risky patterns in seconds. What they reliably catch, what they miss, and why a clean result proves little.

Detects Mint, blacklist, pause, fee-change and upgrade patterns
Misses Novel logic, economic exploits, off-chain dependencies
A flag Strong evidence of risk

FBT Swap

What you should know

Automated contract analysis reads verified source or bytecode and checks it against a library of patterns associated with risk. It takes seconds and costs nothing, which makes it a genuinely good first screen.

It is also not an audit, and the gap between the two is where most losses happen.

What scanners reliably detect

Unrestricted mint functions, blacklist and whitelist mechanisms, transfer-blocking logic, owner-only functions that change fees or pause transfers, proxy upgradeability, and hard-coded privileged addresses.

These are structural and visible in the code, which is why detection is accurate when the source is verified.

What they miss

Novel logic that does not match a known pattern. Economic exploits where every function is individually correct but the combination is not. Off-chain dependencies such as an oracle or an admin key. And anything in an unverified contract, where only bytecode is available.

Most large protocol losses have come from this category, not from patterns a scanner would flag.

Why a clean result is weak evidence

It means no known pattern matched. Given that the most damaging exploits were novel at the time, absence of known patterns is a weak statement about safety.

The asymmetry matters: a flag is strong evidence of risk, a clean result is weak evidence of safety. Treat the two very differently.

False positives cut the other way. Scanners flag patterns that are legitimate in context, such as a pause function in a protocol with a published emergency process, so a flag is a prompt to read rather than a verdict. Understanding what was flagged beats counting how many flags there were.

Using it sensibly

As a cheap filter to eliminate obvious problems before spending attention. Then look at the things a scanner cannot see: who holds admin keys, whether the contract is upgradeable, how long it has held value, and whether a named firm audited it.

FBT Swap does not audit arbitrary imported token contracts and does not claim to. It shows the route, price impact and fee before you sign; verification of a token you selected by address remains yours.

At a glance

At a glance

Detects

Mint, blacklist, pause, fee-change and upgrade patterns

Misses

Novel logic, economic exploits, off-chain dependencies

A flag

Strong evidence of risk

A clean result

Weak evidence of safety — only that nothing known matched

FAQ

Frequently asked questions

Clear answers before you decide.

Is a scanner as good as an audit?

No. An audit involves humans reasoning about intent, economics and composition over weeks. A scanner matches patterns in seconds. They answer different questions at vastly different depth.

What if the contract is unverified?

Then source is unavailable and only bytecode analysis is possible, which is far less reliable. For a token asking for your money, unverified source is itself a reason to decline.

Does a clean scan mean I can buy safely?

No. It means no known risky pattern was found. Liquidity can still be pulled, admin keys can still exist, and novel logic is exactly what scanners do not catch.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.