BasePump

Security

BasePump is in a guarded beta on Base. The contracts are NOT yet externally audited — we ran Slither (no high/medium findings) and 100 tests, and liquidity is permanently locked by design. Exposure is intentionally capped while we run a bug bounty.

🔎 Slither — no high/medium100 tests🔒 locked liquidity🛡️ non-custodial

Protocol owner (admin): Safe multisig 0x29522f7003cE38e82d896D5202fa52cb2929912F ↗

Bug bounty — scope

Rewards

Criticalup to 1 ETHFunds drain, mint, reserve theft
Highup to 0.3 ETHLocked funds, severe price manipulation
Mediumup to 0.1 ETHPartial DoS, incorrect logic with impact
Low / InforecognitionGas, improvements

Funded with a share of protocol fees. Rewards paid in ETH after verifying the finding.

How to report

  • Email us with steps to reproduce and a PoC.
  • One report per vulnerability. No public disclosure before the fix.
  • Do not exploit on mainnet or touch other users' funds.

📧 security@basepump.dev · Immunefi program: coming soon

This program does NOT replace an external audit. In a pre-audit beta, funds could be lost if a bug exists. Limits reduce the damage; they do not eliminate it. Not financial advice.