WEEDSWAP

Security

Review the contracts, permissions, and known risks before depositing.

WeedSwap contracts are not independently audited.

Independent audit
Not completed
Deployment
Awaiting deployment
Role configuration
Required
Contract addresses
Awaiting deployment

Current phase

Contract code and tests exist, but open safety findings block deployment.

Contract reviews

Repository tests and static analysis are available. An independent audit has not been completed.

Administrative roles

Launch roles must be assigned to approved operational accounts before deployment.

Timelock

Sensitive production operations are designed to pass through a configured timelock.

Guardian controls

WeedChef's reward pause preserves exit access. The separate emission-controller pause has unresolved resume accounting.

Emergency withdrawals

Principal withdrawal and direct v3 NFT withdrawal remain available during reward pauses.

Known risks

Farm timer, Rewarder reconfiguration, Greenhouse recovery and rescheduling, referral eligibility and consent, emission pause, vault issuance and redemption, market, and custody risks remain.

Reporting a vulnerability

Do not disclose an exploitable issue publicly. Use the private reporting route listed in the documentation when configured.

Automated tests and static analysis are not a substitute for an independent audit.

Fifteen open source-level safety findings block farms, budget vaults, Greenhouse, referral, emission-controller, v3 vaults, rewarders, and liquidity-bootstrap deployment.

Read the security documentation