Appearance
Security
Status
Hanok is unaudited testnet software. Treat every contract as experimental until audits are published here.
What the design protects against
| Threat | Mitigation |
|---|---|
| Rug pull by removing liquidity | Graduated liquidity is owned by a contract with no withdraw path. |
| Creator pre-mine or hidden allocation | The full supply mints to the curve; the first buy is capped at 10% and visible on-chain. |
| Sniping bots | 99% → 0 decaying tax over the first 10 seconds, snapshotted per launch. |
| Griefing the final buy | Oversized buys are clamped and refunded instead of reverted. |
| Fee-on-transfer or reentrant quote assets | Balance-delta accounting and reentrancy guards on every entry point; graduation closes the curve before moving funds. |
| Blocking payouts | Pull-payment escrow; no push transfers to arbitrary recipients. |
| Admin overreach | Hard-coded ceilings on every setting; platform fee is a constant; term pinning on launch. |
| Stuck graduation | Permissionless retry; sells reopen after 7 days. |
Known limitations
- The hook, locker and escrow are shared singletons; a bug in one affects every graduated pool.
- Buyback execution depends on a protocol-run fee operator; if it is offline, buybacks queue but creator and protocol payouts continue.
- The testnet
PoolManageris a Hanok-deployed instance, not Uniswap's canonical deployment.
Reporting
Report vulnerabilities privately before disclosing them publicly. A contact address will be published with the mainnet release.