Security
BasePump is in a guarded beta on Base. The contracts are NOT yet externally audited — we ran Slither (no high/medium findings) and 100 tests, and liquidity is permanently locked by design. Exposure is intentionally capped while we run a bug bounty.
🔎 Slither — no high/medium✅ 100 tests🔒 locked liquidity🛡️ non-custodial
Protocol owner (admin): Safe multisig 0x29522f7003cE38e82d896D5202fa52cb2929912F ↗
Bug bounty — scope
Test on Base Sepolia or a fork. Never with other people's funds.
| BasePumpFactory | 0x2b24Df333a0d7c7A0f82e6ea14989E43571220dC ↗ | |
| RewardHook | 0x1361119913F106f8a182960DfAFd274eC2D3C044 ↗ | |
| GraduationModule | 0x2B7c1B9Fa3aA4B8ba26AC1Fcb16c60123902a11E ↗ | |
| LiquidityLocker | 0x059Bd4868a728E6d36f9944191689bb11e9c3B61 ↗ | |
| Flywheel | 0xD2F57bd03150D6eA5611780245d8afa4667A8459 ↗ | |
| VolumeRewards | 0x7C9B83c5c07B293eB42a46cE87c967c2FAAF0e03 ↗ | |
Rewards
| Critical | up to 1 ETH | Funds drain, mint, reserve theft |
| High | up to 0.3 ETH | Locked funds, severe price manipulation |
| Medium | up to 0.1 ETH | Partial DoS, incorrect logic with impact |
| Low / Info | recognition | Gas, improvements |
Funded with a share of protocol fees. Rewards paid in ETH after verifying the finding.
How to report
- Email us with steps to reproduce and a PoC.
- One report per vulnerability. No public disclosure before the fix.
- Do not exploit on mainnet or touch other users' funds.
📧 security@basepump.dev · Immunefi program: coming soon
This program does NOT replace an external audit. In a pre-audit beta, funds could be lost if a bug exists. Limits reduce the damage; they do not eliminate it. Not financial advice.