SwaptoX is a non-custodial, permissionless execution-based swap aggregator. It does not validate token implementations and relies on atomic execution guarantees.
Core features:
msg.sender.
amountOut ≥ amountMinOut.
nonReentrant.
Description:
Impact:
Mitigation:
Description:
Executor may execute arbitrary logic or consume excessive gas.Impact:
Mitigation:
Description:
Users can provide arbitrary permit parameters (within allowed selectors).Impact:
Conclusion:
This is a user-controlled execution surface, not a protocol vulnerability.
Description:
Potential unauthorized token transfers.Analysis:
safetyTransferInmsg.senderConclusion:
Unauthorized fund extraction is impossible.
Description:
External calls via ETH transfer or executor.Mitigation:
nonReentrantConclusion:
No reentrancy attack path exists.
Description:
Tokens may behave unexpectedly (fake balances, transfer anomalies).Impact:
Conclusion:
Protocol does not enforce token validity.
Description:
Users can farm referral tiers via multiple addresses.Impact:
Conclusion:
Accepted business tradeoff.
Description:
Rewards are skipped for fee amounts < 100 units.Impact:
SwaptoX guarantees:
SwaptoX does NOT guarantee:
Overall Classification:
Permissionless Execution Aggregator