onlyOwner 0 · delegatecall 0 · selfdestruct opcode 0 (1 mention, in a comment) · public immutable 11What this page is about
When you swap on BullBearSwap, the site finds the route and a single contract executes it: every hop in one transaction, the minimum output you signed checked at the end, the result sent to you. That contract is the only code your tokens ever touch, so it is the thing worth reading.
It is verified on Etherscan and on the PulseChain explorer, so anyone can read the exact code that runs. It has no owner, no admin functions and no upgrade path: every setting is fixed at deployment and cannot be changed. It only pulls the exact amount of your swap from the wallet that calls it, and the site approves that exact amount rather than unlimited, so nothing stays approved afterwards. It cannot touch anyone else's tokens.
There is no third-party audit yet; that is the next step. Until then the source is the audit: read it before you swap. What follows is everything we checked ourselves, how, and what the tools said, with nothing filtered out.
Ethereum 0x128716EaAb226A68299d3c0198a38c1e90C52356
PulseChain 0xc74de6B549D5A667ABc3867c8904D1d00420825C
Settlement contract · security review · 8 Sep 2026
Five questions to ask before signing, each answered from the verified source. Nothing here is a promise. Every tile names the thing in the code you can check.
onlyOwner 0 · delegatecall 0 · selfdestruct opcode 0 (1 mention, in a comment) · public immutable 11sweep(), returns stuck tokens to the caller and is blocked mid-swapHow it was analysed
Check it yourself
The two chains run different builds of the same contract. The Ethereum build adds relayed execution and is compiled through the IR pipeline. What matters is that the source we analysed is the code your transaction hits, so each build is recompiled and compared with the bytes on chain.
BullBearSettlement.sol at HEAD, 2,108 lines, one contract, no imports9d4c0a8, 2 Sep 2026, no relayed entry pointsTools: Slither 0.11.6 and Aderyn 0.6.8, one run per build. Explorer pages list four solc 0.8.30 compiler bugs; none applies here: the contract uses no transient storage (and targets Shanghai, where it does not exist), has no mutually recursive functions, inherits from nothing, and has no storage arrays. The next deployment compiles with 0.8.36 or later, which retires the notices.
Every finding, sorted by what it could do to you
Scanners rank patterns; a swapper cares about outcomes. So the 740 scanner lines plus a line-by-line manual review are grouped here by the worst thing each one could actually cause, with the reason it cannot cause more.
Reported privately, credited
Separate from the contract scanner lines above: issues researchers reported to us privately — fixed ones, and one under active remediation — listed here so they are known. A duplicate report of a listed issue is credited, not re-rewarded; the finding belongs to whoever reported it first. The full technical write-up of a remediation-in-progress finding publishes here once its fix ships.
RouteNotAttested otherwise), the relayer address is part of the signed order, and a fork replay of the original report reverts. Live in the current Ethereum deployment (contract 0x917a31bB: runtime bytecode identical in size to the build from this source, 24,311 bytes, carrying the check). First reported privately by ibnu76 (2026-09-09); High, rewarded. A duplicate of this known issue was independently reported by Galih (2026-09-09); credited, not re-rewarded./status) was reachable on the public host without authentication, exposing operational and telemetry data intended only for the operator. It is now gated behind operator authentication — an unauthenticated request receives a 404. The same researcher also reported an error response on the public API that could reveal internal service addresses; that detail is now suppressed for unauthenticated callers as well. No user funds, private keys, or personal data were ever exposed, and no user-facing behaviour changed. Credit: Gwei (@highestgwei). Low, credited.computeFee. Credit: Aliyaan Blaike. Low, credited.X-Frame-Options: DENY and Content-Security-Policy: frame-ancestors 'none', so the app refuses to render inside any third-party frame. No user funds were ever at risk — every swap requires the wallet's own confirmation prompt, which a framing page cannot see or control. Credit: Fawwaz (@AkasakaID); the missing-headers gap was independently flagged by Galih. Low, credited.What changes, and what does not
Verified source. Ownerless and immutable. Exact approvals. Automated analysis published. No third-party audit yet.
Found something?
Scope, rules and rewards in full: the security policy. Out of scope: the venues the contract routes through, wallets, RPC providers, and anything needing a compromised device or key.