Reference
Security and licenses
GAMA has not been externally audited, and it runs on testnet only.
Audit status
| Item | Status |
|---|---|
| External audit | None yet. Required before a mainnet release |
| Bug bounty | None yet. Required before a mainnet release |
| Internal review | An internal security review of the launchpad has been done. It did not cover the underlying Uniswap V4 code line by line |
| Published source code | Not yet verified on the block explorer |
Known limitations
- Owner trust. On the testnet, the protocol owner is a single key, and some of its powers could cause harm if misused. See Administration and trust.
- Buyback pricing. Buybacks rely on the operator's price checks. The contracts limit price movement but do not check prices themselves.
- Holder rewards. The reward rules stop the same-block tricks that were tested, but are not proven against every attack spread over several blocks.
- Burned supply. On the testnet, burning reduces the total supply. In the next release, burned tokens go to a dead address instead and the total supply number stays the same.
Reporting a problem
Please report security problems privately and do not share them publicly before they are fixed. A security contact has not been published yet.
Where the code comes from
GAMA builds on open-source projects, and every file keeps its original license.
| Part | Based on | License |
|---|---|---|
| Launchpad curve and token | Pons V2 | MIT, with one file under GPL-2.0-or-later |
| Trading pools | Uniswap V4 | BUSL-1.1 and MIT |
| Trading pool tools | Uniswap V4 periphery, Universal Router and Permit2 | MIT and GPL-3.0-or-later |
| Previous trading pools | Uniswap V3 | GPL-2.0-or-later |
| Shared libraries | OpenZeppelin, Solmate | MIT and AGPL-3.0-only |
GAMA's own code is MIT-licensed. The rights to use the Uniswap V4 code in production are a condition of a mainnet release and are not yet settled.