Transparent, non-custodial, yours

An audit is a document, not a guarantee

Scope, commit hash, severity counts and resolution status matter more than the auditor logo. What an audit never covers.

Check first The commit hash against the deployed, verified source
Check second Scope exclusions — often where the real risk sits
Acknowledged Means accepted, not fixed

FBT Swap

What you should know

"Audited" has become a badge rather than a claim about anything specific. A useful reading takes a few minutes and answers a different question: what exactly was examined, when, and what was found.

The answers are frequently narrower than the badge implies.

Scope and commit hash

An audit covers specific files at a specific commit. If the deployed contract differs from that commit, the audit does not describe what is live. Check the hash in the report against the deployed, verified source.

Scope exclusions matter too. Reports routinely state that economic design, oracle reliability or dependencies were out of scope, and those are often where the real risk is.

Findings and what happened to them

Count findings by severity and check the resolution status of each. Acknowledged is not fixed — it means the team read it and chose to accept it. A high-severity acknowledged finding is a decision you are now inheriting.

Zero findings on a complex protocol usually means a narrow scope rather than perfect code.

What audits never cover

Governance decisions, admin key behaviour, incentive design, oracle manipulation under extreme conditions, and every contract the audited one interacts with. Also every change made after the report date.

A report is a snapshot of one commit. Protocols ship upgrades, add collateral types and adjust parameters continuously, and none of that is covered by a document written months earlier. The useful question is what has changed since, not whether an audit exists at all.

Most large DeFi losses involved code that had been audited, because the failures were in these categories.

Better signals than an audit badge

Time in production with significant value at stake. An active bug bounty with meaningful payouts. Timelocked governance so changes are visible before they take effect. Multiple independent reviews rather than one.

FBT Swap routes through established public aggregators and does not operate its own lending or pool contracts. Protocol risk belongs to the protocol, and the app names the source of the data it displays.

At a glance

At a glance

Check first

The commit hash against the deployed, verified source

Check second

Scope exclusions — often where the real risk sits

Acknowledged

Means accepted, not fixed

Never covered

Governance, admin keys, economics, and later changes

FAQ

Frequently asked questions

Clear answers before you decide.

Does a well-known auditor mean better security?

Reputation correlates with thoroughness but does not change the fundamental limits. The scope, the commit and the resolution status tell you more than the name on the cover.

Is an unaudited protocol always unsafe?

It carries a higher unknown. Some unaudited code is simple and widely reviewed; some audited code is complex and barely understood. Audit status is one input, not a verdict.

What is a bug bounty worth as a signal?

A large, actively paid bounty is a strong signal, because it puts a continuous market price on finding flaws. A token bounty with a low cap signals the opposite.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.