connecting to the API…
Measured On-Chain · 2026-09-30

QUSD Liquidity Pool — Measured Findings

Every figure below was read from chain at build time. Reserve accounting is clean on all pools. Depth is $5.33 in total, and at that depth a $10 trade moves spot price by 718%.

Reserves Reconcile Depth $5.33 2 Pools Monitored

This replaces an earlier draft that cited a Hashlock audit of FiatTokenV1, FiatTokenV2_3 and Whitelistable. Those are Circle’s USDC contract names. QUSD is not that contract — verified against the live contract, where currency(), masterMinter(), pauser(), updateBlacklister() and updateRescuer() are all absent. No third-party audit of QUSD is claimed here. What follows is measurement, which anyone can repeat.

What Is Verifiable Today

Measured
Contract
Canonical QUSD 0xb57bf3c5… carries identical 19,338-byte bytecode on all five chains — BNB Smart Chain, Polygon, Base, Arbitrum and QVTX 42000. One coin, five ledgers.
Oracle
QUSDOracleCore returns exactly 1.00000000 on every chain. It is independent of pool spot price, which at this depth is the only safe design.
  • Reserve accounting is clean. Cached getReserves() matches the balance each pair actually holds on every leg of every pool. Delta is exactly zero — no donation attack, no fee-on-transfer breakage.
  • No audit rating is asserted. A contract rating requires an auditor who has reviewed these contracts. That engagement has not happened.

Pool-by-Pool, Measured

Live
QuickSwap · chain 137
0x763aff9d01fa6412ea762659d8c8896515434ce5
Reserves 1.39118881 QUSD / 1.39397000 USDC. Reserve vs balance delta zero on both legs. k = 1.93927547, spot 1.001999 USDC per QUSD, fee 30 bps. Last trade 13.1 days ago.
PancakeSwap · chain 56
0xe848f417b7b91e381ccfedeba27ff2f6c4a1fa8c
Reserves 4.09946280 QUSD / 3.93704503 USDT. Reserve vs balance delta zero on both legs. k = 16.13976962, spot 0.960381 USDT per QUSD, fee 25 bps. Last trade 6.3 days ago.

This pool quotes the superseded QUSD contract 0x63c4664ceb3e93ef22d1e56826395fb1c927c118, not the canonical one. A buyer here receives the deprecated token.
  • QuickSwap — $10 moves spot +718%, $100 moves it +7174%, $1,000 moves it +71738%.
  • PancakeSwap — $10 moves spot +254%, $100 moves it +2540%, $1,000 moves it +25400%.
!Flash-loan manipulation is normally rated medium because it needs capital. At this depth it needs none — ordinary retail size moves spot by hundreds of percent. This is precisely why pool spot must never be an oracle input, and it is not one.

Method

Scope
  • Reads, not claims. getReserves(), balanceOf(), token0/1(), decimals(), symbol(), eth_getCode against public RPCs on each chain.
  • Invariant and impact computed with the AMM’s own formula on live reserves. No transaction was built, signed or sent.
  • Not in scope: line-by-line contract review, formal verification, and anything requiring an auditor. Absence of a finding here is not evidence of absence of a bug.

Recommendations — Status

5 of 5 Built
1
Bug bounty program — OPEN
Scope, SLA, safe harbour and the out-of-scope list are built and read from chain (below). The four reward tiers are set and published below. Reports go to the published channel.
2
On-chain monitoring — IMPLEMENTED
Reserves against real balances, per pool, on demand. Currently reports zero delta everywhere.
3
Transparency reports — IMPLEMENTED
This page. Depth is reported as the stable side only — a DEX aggregator’s reserve_in_usd counts our own QUSD as dollars and roughly doubles the figure.
4
Stress testing — IMPLEMENTED
Invariant and price impact at size, from live reserves.
5
Community education — IMPLEMENTED
Six plain-language sections below, each with the command that reproduces it. Depth is $5.33 and one pool quotes a superseded contract — those are the two that matter.

Disclosure Programme — Scope

Recommendation 1

Scope is not a list somebody typed. It is every chain the canonical contract actually answers on, the oracle, and the QUSD side of each pool — read at build time, the same way every other figure on this page is read.

  • BNB Smart Chain chain 56 — canonical QUSD 0xb57bf3c50f20096723b46645f741f632aef220fa, 19,338 bytes, identical to the others
  • Polygon chain 137 — canonical QUSD 0xb57bf3c50f20096723b46645f741f632aef220fa, 19,338 bytes, identical to the others
  • Base chain 8453 — canonical QUSD 0xb57bf3c50f20096723b46645f741f632aef220fa, 19,338 bytes, identical to the others
  • QVTX 42000 chain 42000 — canonical QUSD 0xb57bf3c50f20096723b46645f741f632aef220fa, 19,338 bytes, identical to the others
  • Arbitrum One chain 42161 — canonical QUSD 0xb57bf3c50f20096723b46645f741f632aef220fa, 19,338 bytes, identical to the others
  • Oracle 0xc234af77d0884ffb31a1a604f212bd5d6c75a4e5 on Polygon — 2,076 bytes deployed
  • QuickSwap pool 0x763aff9d01fa6412ea762659d8c8896515434ce5 — the QUSD side only. The AMM’s own factory, router and pair code belongs to its programme, not ours.
  • PancakeSwap pool 0xe848f417b7b91e381ccfedeba27ff2f6c4a1fa8c — the QUSD side only. The AMM’s own factory, router and pair code belongs to its programme, not ours.
Wallet integrations
  • The QVTX/QUSD Chrome wallet extension, id eimfajgaonhebooepmjccgakcdccpphk v1.6.8 (non-custodial; it holds keys, so key handling, signing and approval flows are the interesting surface)
  • https://wallet.quantvestrix.io
  • https://qusd.quantvestrix.io/redeem - the burn-to-redeem flow
  • Not in scope: MetaMask, Ledger, Xaman and any other third-party wallet - report those to their own programmes.
APIs and dashboards
  • The QUSD Integration API on api-direct.quantvestrix.io and marov.quantvestrix.io (/api/pools, /api/transparency/, /api/audits/, /api/risk/, /api/health)
  • https://qusd.quantvestrix.io/api/* - the mint and redeem APIs behind the membrane
  • https://explorer.quantvestrix.io
  • https://oracle.quantvestrix.io
  • https://qusd.quantvestrix.io/audit - the published pool audit page (also on the .com twin), and /api/transparency/summary on the integration API
  • Not in scope: Public RPC providers and third-party block explorers; Blockscout's own upstream code behind explorer.quantvestrix.io - the deployment and its configuration are ours, the project is not; rate-limit and load testing of any kind.
Out of scope
  • Third-party AMM contracts (QuickSwap, PancakeSwap factory/router/pair code) — report those to their own programmes
  • Public RPC providers and block explorers
  • The known depth of the pools, which is published, and anything that follows from it (price impact, spot movability, oracle manipulation via spot)
  • The known ERC-165 defect (supportsInterface(0x80ac58cd) returns true), which is published and open
  • The superseded contract 0x63c4664ceb3e93ef22d1e56826395fb1c927c118 being quoted on PancakeSwap, which is published and open

These are published, so they earn no reward: total pool depth is a few dollars; retail-size trades move spot by hundreds of percent; one live pool quotes the superseded QUSD contract; the contract answers TRUE to the ERC-721 interface id.

Terms
  • Acknowledge within 48 hours, triage within 5 days, fix or explain within 30 days. Disclosure is coordinated, after fix or 90 days, whichever is first.
  • Permitted: reading any public chain state, at any rate; testing against a local fork of any chain listed in scope; reporting a finding privately before disclosing it.
  • Not permitted: any transaction against a live pool intended to demonstrate impact; social engineering of QVTX people, partners or bank counterparties; denial of service against any RPC, front end or API; accessing or exfiltrating data belonging to any holder.
  • Depth is a few dollars. A live demonstration against these pools destroys real funds and forfeits safe harbour. A local fork proves the same thing.
Rewards
  • Critical — $5,000. Exploits that compromise reserves, mint/burn logic, or user funds
  • High — $2,500. Vulnerabilities affecting liquidity pools, trustline setup, or transaction routing
  • Medium — $1,000. Issues impacting UI/UX, noncritical smart contract logic, or minor compliance gaps
  • Low — $250. Cosmetic bugs, documentation errors, or minor inefficiencies
Paying, and what a report must carry
  • Paid in QUSD or USDC, within 30 days of validation.
  • Where several reports describe the same bug, the first valid submission is the one rewarded.
  • Severity is classified by the QUSD security team.
  • Responsible disclosure only - rewards are paid for it and for nothing else.
  • An exploit must not be used to harm users or drain liquidity.
  • A report must include reproducible steps and a proof of concept.
!Open. Rewards are set and payable and reports reach security@quantvestrix.com. Both live in ~/.qvtx/policy/pool_bounty.json; this page changes with that file.

For Holders — Plain Language

Recommendation 5
  • How deep the pools are. $5.33 in total, counting the stable side only. If you see roughly double that on a DEX aggregator, it is counting our own QUSD as dollars. Reproduce with getReserves() on each pair.
  • What that means if you trade. QuickSwap: a $10 buy moves spot +718%; PancakeSwap: a $10 buy moves spot +254%. A pool this shallow is a listing, not an exit. Redemption at par runs through qusd.quantvestrix.io/redeem, not through these pools.
  • The price you see is not the peg. The oracle returns exactly 1.00000000 and never reads pool spot. At this depth spot is whatever the last trader left behind. Backing is 1:1 and lives in the ByteID, not in a pool.
  • Check the address, not the ticker. Canonical QUSD is 0xb57bf3c50f20096723b46645f741f632aef220fa with identical 19,338-byte code on 5 chains. PancakeSwap pairs against 0x63c4664ceb3e93ef22d1e56826395fb1c927c118, which is superseded — a buyer there receives the deprecated token.
  • Why your explorer may show nothing. The contract answers TRUE to supportsInterface(0x80ac58cd), so some explorers file QUSD as an NFT collection and hide price and holders. That is our defect and it is open — add the token by contract address and the balance appears.
  • Found a bug? Reading chain state and testing on a local fork are explicitly permitted. A live trade to demonstrate impact destroys real funds and is not. Report privately to security@quantvestrix.com first.

Risks to Watch

Rated From Measurement
  • High A live pool quotes a superseded contract. PancakeSwap pairs against 0x63c4664ceb3e93ef22d1e56826395fb1c927c118. The report’s “unverified tokens” risk, except the confusing token is our own deprecated one.
  • High Depth is $5.33 in total. Any trade of meaningful size fails or executes at a price nothing like par.
  • High Spot is trivially movable. $10 shifts it by hundreds of percent, so no system may consume pool spot as truth.
  • Medium Pools are quiet. Last trades were 13.1 days and 6.3 days. Stale reserves mean the cached values drift further from any external price.
  • Medium An explorer defect suppresses listings. The contract answers TRUE to supportsInterface(0x80ac58cd), so explorers file QUSD as an NFT collection and hide price and holders. Open.

Sources

Reproducible
On-chain readsPublic RPCs: polygon-bor-rpc.publicnode.com and bsc-dataseed1.binance.org. Every number on this page can be reproduced from a terminal without asking QVTX for anything.
SmartContractAudit — DeFi Liquidity Pool Security (AMM Guide)Reference for the AMM risk taxonomy: invariant violations, oracle manipulation, fee-on-transfer tokens and donation attacks. A general reference, not an audit of QUSD.View
pool_audit.pyThe tool that produced this page. Adding a pool to its POOLS list puts it in every section above.
✓No audit rating is claimed, because no auditor has reviewed these contracts. What is claimed is measured, and stated at the size it actually is.