Swap security

Verified source code is not an audit or safety guarantee

A verified-source badge helps inspect deployed code but does not certify that the contract is safe to approve or trade.

Source verification establishes a relationship between published source and deployed bytecode. It does not mean someone reviewed the contract for vulnerabilities, assessed the token’s economics or approved its administrative powers.

Ethereum’s verification documentation explicitly distinguishes source-code verification from formal verification. An audit is another separate process with its own scope and assumptions.

What the badge helps you do

It makes the contract easier to inspect and its functions easier to decode. You can investigate permissions, transfer logic and relevant configuration using readable source rather than relying entirely on bytecode.

That usefulness depends on correctly identifying the deployed address and, for a proxy, the relevant implementation. A verified proxy shell alone may not describe all behavior reached through it.

What it does not answer

  • Whether a privileged account can change fees or block transfers.
  • Whether the implementation contains a vulnerability.
  • Whether the token can be sold at a useful price.
  • Whether the website is requesting the intended spender or recipient.

Readable malicious code can still be malicious. Comments and familiar function names do not override actual behavior.

Use it as one piece of evidence

Match the contract to official deployment information, inspect authority and look for a relevant security review. If you cannot evaluate code yourself, acknowledge that limitation rather than treating the explorer’s green badge as a substitute.

A request to approve a verified contract still deserves amount and spender review. Verification improves transparency; it does not remove the consequences of the permission you grant.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. Verifying smart contracts | ethereum.org

    Source-code correspondence differs from formal verification and security review.

    https://ethereum.org/developers/docs/smart-contracts/verifying/
  2. Proxy | OpenZeppelin Docs

    Proxy implementation upgrades and authorization boundaries.

    https://docs.openzeppelin.com/contracts/5.x/api/proxy
  3. Access Control | OpenZeppelin Docs

    Ownership, independent roles, admin roles and governance controls.

    https://docs.openzeppelin.com/contracts/5.x/access-control

Continue reading

How to read an audit claim before using an aggregator How to verify the spender before approving an aggregator