Security and limits
The honest version, including the parts that are not done.
StatusThe Yoke contract address is not published yet. No independent audit has been published yet. The contracts are tested on a fork of the real chain by their author. Judge the risk accordingly: only use funds you can afford to lose.
What is tested
- 21 Foundry tests on a fork of Robinhood Chain, against the real Uniswap V3 factory and real tokens: graduation with USDG (6 decimals), ETH, an NVDA stock token, the ORBIO memecoin, and a Yoke coin as pair; both token address orderings; fees and claims; the 1% round-trip cost; refunds; slippage; refused pairs; pools created in advance, with and without liquidity.
- 7 groups of JavaScript tests that reproduce the contract's printed numbers exactly and check the invariant over up to 6,000 random trades.
What is not done yet
- Fuzz and invariant tests on the Solidity side (solvency over random sequences). The JavaScript engine has this check; the contract does not yet.
- An independent audit report (see the status above).
- A formal bound on the opening-price rounding for extreme decimals.
What you have to trust
| Who | Can | Cannot |
|---|---|---|
| The owner | Change the address that receives protocol fees, transfer ownership | Touch a curve, a balance, a pool, a coin, or pause anything. There is no upgrade path. |
| A coin's creator | Hand over their fee seat, buy first with firstBuy | Mint, change the curve, remove liquidity |
| Anyone | Trade, graduate a full curve, collect pool fees | Do any of the above on someone else's behalf in a harmful way: graduation and fee collection are permissionless but only do what the rules say |
Built-in protections
- A reentrancy lock on trading, graduation, fee collection and claims.
- Exact-amount check on every pair transfer in, so fee-on-transfer tokens are refused.
- Slippage limits on every buy and sell.
- Rounding always in the curve's favour; a solvency check in the engine tests.
- Liquidity amounts rounded down so the pool never over-asks; no leftover can leave through a function.
Known limits and risks
- Pair risk. Pausable, blacklistable, upgradeable, depegging or illiquid pairs are allowed and can hurt you. See Pairs.
- Sandwiching. Like any AMM, a trade can be sandwiched. Use
minOut. - No anti-snipe. There is no launch-time tax or per-wallet limit. The creator can buy first with
firstBuy; others can buy right after creation. - Poisoned pools. Handled in most cases, but a determined attacker who adds real liquidity in several fee tiers can delay graduation; the curve stays full and trading on the curve stays closed until a tier is free.
- Metadata. The token has a name and a symbol and nothing else on chain: no logo, no description.
- The site is a static page that reads the chain and asks your wallet to sign transactions. It never holds funds or keys. Always compare the contract address in your wallet's confirmation with the one in the footer and on the Contracts page.
Reporting a problem
Write to the project on X (the handle is in the page footer). Please do not publish a vulnerability before the team has had time to answer.