Security and licences
GAMA runs on a test network only. This page sets out what has been reviewed, the limits of the design that you should know about, how to report a problem, and the open-source code GAMA is built on.
Review status
| Item | Status |
|---|---|
| Bug bounty | None yet. Required before any mainnet release |
| Internal reviews | Adversarial reviews of the launchpad contracts (24 September 2026) and of the whole service, from the app to the operators (1 October 2026), and a review of how orders could be sandwiched, which led to the current order design (decided 3 October 2026) |
| Source code on Gamascan | Not verified. Every contract of the current release is recorded as not submitted |
The internal reviews found no way for an ordinary user to drain funds in the code they covered. That is evidence, not a guarantee, and it did not cover the Uniswap V4 code line by line.
Known limits
- One owner key. On the testnet the protocol owner is a single key, and some of its powers could cause harm if it were misused or stolen. It cannot take fees, rewards or earnings already credited. See Administration and trust.
- Fee-exempt addresses. An address the owner exempts from fees pays nothing on either side of a trade, so it can trade around other people's trades or a buyback round at a profit.
- Buy limits are per address. One person with several wallets can buy up to the limits with each of them. See Buy limits.
- Trading ahead of large orders. The order books stop a fill from being timed or priced by an attacker, but a large DCA order in a thin market still moves the price as it buys, and anyone already holding the token gains from that. A live test on 3 October measured about 2% on one such trade. See Price impact and sandwiches.
- Buyback pricing. Each buyback round refuses to start above a price bound the operator sets just before sending it, plus a small buffer. A price pushed up within that buffer makes the round pay at most the buffer plus its own 1% more. See Buyback and burn.
- Holder rewards. The reward rules stop the same-block tricks that were tested, but are not proven against every attack spread over several blocks. In reward mode, early holders, including the creator's opening buy, receive most holder rewards while the token is on its curve. See Holder rewards.
- Automatic services. Automatic payouts, order fills and buybacks depend on GAMA's operators. If one stops, balances stay claimable at no charge, and the order books still let you pause, change, cancel or fill your own orders without a keeper.
- Burned supply. Burned tokens go to the dead address. The token's total supply number does not change; the app counts them as burned.
Reporting a problem
If you find a security problem, report it privately and do not share it before it is fixed. Write to contact@gama.win. GAMA will never ask for your seed phrase or private key, including in reply to a report.
Where the code comes from
GAMA builds on open-source projects, and every file keeps its original licence and notices.
| Part | Based on | Licence |
|---|---|---|
| Launchpad curve and token | Pons V2 | MIT, with one file under GPL-2.0-or-later |
| GAMA DEX pools | Uniswap V4 core | BUSL-1.1 and MIT, per file |
| GAMA DEX tools | Uniswap V4 periphery, Universal Router 2.2.0, Permit2 | MIT and GPL-3.0-or-later |
| Earlier GAMA DEX | Uniswap V3 | GPL-2.0-or-later |
| Shared libraries | OpenZeppelin 5.0.2, Solmate | MIT, and AGPL-3.0-only and MIT per file |
GAMA's own contracts are under the MIT licence. GAMA DEX runs Uniswap V4's pool code unchanged; GAMA's changes are the names, the NFT branding and the protocol fee controller. The rights to use the Uniswap V4 code in production are a condition of any mainnet release and are not settled yet.
