Security and limits
Read this before putting real money through it.
CarefulThe router has not been audited. It is small and tested against the real contracts, but that is not an audit. Start with amounts you can afford to lose.
What you are trusting
| Component | Trust | Notes |
|---|---|---|
| The Pons curve | Full | The router calls whatever curve address you give it. Take curves from the factory's TokenLaunched event, as the demo does. A fake curve could keep your ETH. |
| The ERC-5564 announcer | Low | A shared contract that only emits events. It holds no funds. |
| secp256k1 and keccak | Standard | The same primitives as Ethereum itself, from the audited noble libraries. |
| The router | Code only | No owner, no admin, no proxy, no pause. What you read is what runs. |
| This website | Medium | The page generates your keys. Use a copy you built yourself if that matters to you. |
What the router guarantees
- It keeps no ETH or tokens between calls. Leftover ETH is returned to the caller.
- The recipient's balance change is measured, so the minimum is enforced on what really arrived.
- It is protected against re-entry.
- It cannot be changed after deployment.
What it does not protect against
- Sandwiching and price moves. A buy through the router is an ordinary buy and can be front-run like any other. Set a sensible
minTokensOut. - A malicious curve. See above.
- Launch-time tax. The curve applies its own rules, including any tax in the first seconds after a launch. The router does not change them, and the first seconds after a launch are untested.
- Fee-on-transfer tokens. The amount is measured as a balance change, so it is correct, but the announced amount reflects what arrived, not what was sent.
Key handling
| Do | Do not |
|---|---|
| Download the backup and keep it offline. | Paste your spending key into any other site. |
| Share only the meta-address, or the viewing key with a scanner you trust. | Share the spending key with anyone, ever. |
| Sign the wallet-derivation message only on the real site. | Sign it on a page that looks similar. |
The demo keeps keys in this tab's session storage, which is cleared when you close the tab. Nothing is sent to a server.
Wallet-derived keys
The "Derive from my wallet" button signs a fixed message and derives both keys from the signature. Signing the same message again gives the same keys, so you do not need a backup of the signature. Anyone who gets that signature can derive your keys, so treat it as a secret.
Known limits
- The anonymity set is the number of people using the router. It is small today.
- The privacy claim is unlinking holdings, not hiding the use of the tool. See the privacy model.
- Only Pons curves on Robinhood Chain are supported.
Reporting a problem
Send details to the project's X account. Do not publish a working exploit before the team has had time to react.