Skip to content

CADINU Non-Custodial Exchange: Architecture, Asset Control & Smart Contract Transparency

This page is the technical reference for how the CADINU Non-Custodial DEX and CADINU MultiSwap handle your assets. Every statement on it is based on the published contract code, the public state of BNB Smart Chain, or the code of the CADINU web interface. Section 14 shows how you can check the on-chain facts yourself.

1. What “non-custodial” means at CADINU

Section titled “1. What “non-custodial” means at CADINU”

At CADINU, a non-custodial swap means all of the following:

  • Your tokens stay in a wallet you control. CADINU runs no deposit accounts, keeps no internal balances for swaps and has no wallet that holds user funds.
  • You sign every approval and every swap yourself, in your own wallet.
  • Settlement is atomic and on-chain. A swap settles on BNB Smart Chain inside the one transaction you sign. Either you receive the output in that transaction, or the whole transaction reverts.
  • No CADINU key, server or contract function can move tokens out of your wallet or spend an approval you gave.

This is what makes the CADINU DEX a self-custody DEX and a non-custodial crypto exchange in the technical sense used on this page. The model also has limits, which this page states openly: the contracts are administered by a single owner key (section 10), and you rely on the web interface to build the transaction you sign (section 12).

  • You connect your own wallet. Without a connected wallet, the swap screen offers only “Connect Wallet”.
  • Your identity is your wallet address. There are no CADINU accounts, deposits, withdrawals or balances for swaps.
  • Approvals. To sell a token other than BNB, your wallet first approves a router to use that token. By default the interface asks for an unlimited approval. It falls back to the exact amount for tokens that do not accept unlimited approvals. An approval stays in place after the swap, and you can review or revoke it at any time in your wallet or with a token-approval tool.
  • Who can use an approval. The CADINU Smart Router pulls tokens only from the address that sends the transaction. An approval you give it can therefore be used only in a transaction you send yourself. The owner key has no function that can use it.
Route Your wallet approves
CADINU DEX CADINU Smart Router
PancakeSwap V2 (MultiSwap) PancakeSwap Router02
PancakeSwap V3 (MultiSwap) PancakeSwap V3 SwapRouter
Market-maker path (see section 7) CadinuSwapMMPool

CADINU MultiSwap is a route comparison inside the CADINU interface, live on apps.cadinu.io/swap. It replaced the embedded swap pages of PancakeSwap, Uniswap and Biswap. It works on BNB Smart Chain only and compares two exchanges: the CADINU DEX and PancakeSwap.

  1. Quote, in your browser. The interface reads live pool state from BNB Smart Chain nodes and builds two quotes:
    • a CADINU DEX quote from CADINU V2 and V3 pools;
    • a PancakeSwap quote from PancakeSwap’s own on-chain contracts (Router02 for V2 paths, QuoterV2 for V3 paths). PancakeSwap’s hosted routing service is not used.
  2. Compare, in your browser. The interface compares the quotes and selects the better route that can actually be executed. A quote that has expired cannot be signed. A valid route is never blocked: when the price impact is high, the button reads “Price impact too high … Swap anyway” and asks you to confirm. No CADINU server and no smart contract chooses the route.
  3. Simulate. Before you sign, the interface simulates the exact transaction from your address.
  4. Sign. Your wallet shows you a transaction addressed to the selected router. The confirmation screen also shows the router address.
  5. Settle. The router executes the route in one transaction and pays the output to your address.
  6. Record, after the fact. Once you have sent the transaction, the interface reports its hash to a CADINU server, which checks it against the chain and records it for trade statistics. The record contains your wallet address, the tokens and the amounts. It holds no funds and cannot change the transaction.

Tokens that charge a fee on transfer are not compared. For those, the interface uses the standard CADINU DEX swap. MultiSwap is crypto to crypto only and contains no fiat logic.

CADINU DEX route PancakeSwap route (MultiSwap)
Your wallet sends the transaction to CADINU Smart Router PancakeSwap Router02 (V2) or PancakeSwap V3 SwapRouter (V3)
Liquidity CADINU V2 and V3 pools PancakeSwap pools
CADINU contracts in the path CADINU Smart Router and CADINU pools None
Approval spender CADINU Smart Router The PancakeSwap router used
Output paid to Your address Your address

For a PancakeSwap route, your wallet calls PancakeSwap’s router directly. No CADINU contract sits between you and PancakeSwap, and no CADINU contract ever calls a PancakeSwap router. CADINU’s role in a PancakeSwap route is limited to the web interface: it finds the quote and builds the transaction that your wallet then shows you to sign, and it records the transaction hash afterwards for statistics (step 6 above).

PancakeSwap’s routers are third-party contracts. CADINU has no administrative control over them.

  • Every swap is a transaction from your wallet, signed in your wallet. The interface passes the transaction to your wallet. It does not sign anything itself.
  • The CADINU backend cannot execute a swap for you. No CADINU server holds a key that can sign swaps or approvals, and no relayer or meta-transaction service exists for swaps. The interface does not use permit or Permit2 signatures for swaps. The router’s permit helper functions only take effect inside a transaction that you send.
  • The router executes exactly what you sign. The route, the minimum amount you accept and the deadline are all encoded in the transaction. No contract changes the route after you sign.
  • Your protections travel with the transaction. The minimum amount out (your slippage setting) and the deadline are enforced by the contract.

A swap is one BNB Smart Chain transaction. If any step fails (a pool rejects the trade, the output would be below your minimum, or the deadline has passed), the entire transaction reverts and your tokens stay in your wallet. You pay only the network fee for the failed attempt.

  • CADINU Smart Router: a multi-step swap reverts as a whole if any step fails. Every swap path checks that the output is at least your signed minimum, and every final transfer step checks the minimum again.
  • PancakeSwap routes: the transaction carries PancakeSwap’s own minimum-output and deadline parameters.
  • No IOU, no off-chain settlement. The output reaches your address in the same transaction. After a swap, CADINU owes you nothing and holds nothing for you.

CADINU cannot freeze, delay, reverse or manually settle a swap. The CADINU Smart Router has no pause, blocklist, allowlist or administrative settlement function. A mined transaction is final. Checks in the interface (for example the price-impact block) apply only before you sign and do not control the contracts, which anyone can call directly.

Temporary router balances inside a transaction

Section titled “Temporary router balances inside a transaction”

On some routes the router holds tokens for a moment inside your transaction:

  • when the output is BNB, the router receives WBNB, unwraps it and sends you BNB;
  • on multi-hop V3 routes, intermediate tokens pass through the router between hops;
  • if an interface fee were ever enabled (it is off, see section 9), the router would hold the output while splitting the fee.

These balances exist only between the steps of a single transaction. Nobody, including the owner key, can act on them in the middle of the transaction, because the router blocks re-entry. The final step sends the router’s entire balance of that token to you, and any unused BNB you sent is refunded in the same transaction. Either all of this completes, or the transaction reverts. This is not persistent custody.

Small amounts left on the router by other means are not held for anyone: the router’s sweep function is open to any caller, so the owner has no special claim to them. At the time of writing the router held 1 wei of BNB and no WBNB, USDT, BUSD or USDC.

  • CADINU Smart Router. The single entry point for CADINU DEX swaps across CADINU V2 and V3 pools. It also supports stable-swap pools, but the interface routes no stable-swap pools on BNB Smart Chain today. The router is not upgradeable: it is not a proxy, and the addresses of the factories, the V3 pool deployer, WBNB and the position manager are fixed in its code at deployment.
  • CADINU V2 factory and pairs. Constant-product liquidity pools with a 0.25% swap fee.
  • CADINU V3 factory and pools. Concentrated-liquidity pools with per-pool fee tiers.
  • No MultiSwap or aggregator contract. CADINU MultiSwap is interface logic only. It sends your transaction either to the CADINU Smart Router or directly to PancakeSwap’s routers.
  • Market-maker path (CadinuSwapMMPool). The CADINU DEX interface keeps a request-for-quote path inherited from the PancakeSwap code base. Its contract, CadinuSwapMMPool, is owned by the CADINU owner key. A trade there can only be executed by the user named in a market maker’s signed quote, and it takes tokens only from that user and passes them to the market maker’s treasury, inside the user’s own transaction. At the time of writing, the market-maker signer configured in the interface is not registered or active on this contract, so this path cannot settle trades.
  • PancakeSwap contracts (Router02, V3 SwapRouter, QuoterV2) are third-party contracts. They have no owner function and CADINU cannot change them.
  • No swap keys on CADINU servers. No CADINU server holds a private key that can sign a swap or an approval for a user, and none sends swap transactions.
  • No route computation on CADINU servers. In MultiSwap, quotes and route selection run in your browser, from on-chain reads.
  • The only swap-related server function in MultiSwap is the statistics record described in section 3, step 6. It reads the chain after you have sent your transaction. It cannot send, sign, change or stop a transaction.
  • What CADINU servers do provide is the web interface itself. That is a real point of trust, covered in section 12.

Liquidity-provider fees (part of pool pricing, always on):

  • CADINU V2 pools charge 0.25% of each swap’s input, paid into the pool. When the factory’s protocol-fee address is set (it is), about 8/25 of that fee (0.08 percentage points) accrues to that address as newly minted LP tokens. The rest stays with liquidity providers.
  • CADINU V3 pools charge the fee tier of each pool. The owner key can set a protocol share of V3 pool fees (section 10).
  • PancakeSwap pools charge PancakeSwap’s own fees under PancakeSwap’s rules.
  • Pool fees are already included in every quote.

CADINU interface fee (MultiSwap fee): currently off everywhere.

  • No fee rate is stored in any CADINU contract. The CADINU Smart Router has no fee setting.
  • A fee can only exist as a parameter inside the transaction you sign. It would be taken from the output, and the contract caps it at 1% (100 basis points). The interface applies the same cap.
  • The standard CADINU DEX swap passes no fee.
  • In MultiSwap, a fee could apply only to PancakeSwap V3 routes. It is not configured. If a fee is ever enabled, its rate and recipient will be part of the quote and of the transaction you sign.

Network fees (gas) are paid by you to BNB Smart Chain validators, not to CADINU.

The CADINU DEX contracts are administered by one owner key:

0xdb2FF236A2E8E8478c8993749e7F1c1D31c28c02

  • Single key. No multisig. No timelock.
  • The address is a standard account (EOA) with an EIP-7702 delegation to a smart-account implementation named “EIP7702StatelessDeleGator”, version 1.3.0 (the name and version used by MetaMask’s Delegation Framework). Any action as owner still needs this key’s signature, either directly or through a delegation signed with it.

Every administrative function:

Contract Function What it does
CADINU Smart Router setStableSwap Points stable-swap routes to a different stable-swap factory
CADINU Smart Router transferOwnership, renounceOwnership Changes or removes the owner
CADINU V2 factory setFeeTo, setFeeToSetter Sets the address that receives the protocol share of V2 pool fees, and who may change it
CADINU V3 factory setOwner, enableFeeAmount, setWhiteListAddress, setFeeAmountExtraInfo, setLmPoolDeployer, setFeeProtocol, collectProtocol Owner change, fee tiers for new pools, protocol share of V3 pool fees and its collection, farming hooks
CADINU V3 factory setLmPool Attaches a farming contract to a pool (owner key or the LM pool deployer)
CadinuSwapMMPool createMMInfo, removeMMInfo Registers or removes a market maker
CadinuSwapMMPool redeemToken Withdraws tokens held by the pool contract itself (in a market-maker trade, tokens move directly between the user and the market maker, so the contract does not hold user funds)
CadinuSwapMMPool transferOwnership, renounceOwnership Changes or removes the owner

What the owner key cannot do:

  • move tokens from your wallet or spend your approvals (no function lets anyone pull tokens from an address other than the transaction’s sender);
  • upgrade or replace the router’s code;
  • pause, freeze, blocklist, delay or reverse a swap;
  • set a fee on the CADINU Smart Router, or change the minimum amount or deadline you signed;
  • settle, cancel or redirect a completed trade.

setStableSwap in detail. This is the only owner setting that touches the swap path. During a user’s own stable-swap route, the router approves the pool returned by the configured factory for the input that is already in the router. Even a malicious pool cannot settle a swap below the minimum you signed: the transaction reverts instead. It cannot pull from standing approvals. The interface sends no stable-swap routes on BNB Smart Chain today.

Liquidity linked to the protocol-fee address. The V2 factory’s protocol-fee address 0xA097fD3E5D1314Dc40dB52296A7f646740430ca8 was set by the owner key. At the time of writing it held about 54% of the LP tokens of the CADINU/USDT pair and about 45% of the CBON/CADINU pair. This is passive AMM liquidity: it earns pool fees like any other liquidity position and gives no control over swaps or over user funds. Traders in those pools should know that a large share of the pool’s liquidity sits at this address.

All addresses are on BNB Smart Chain (chain ID 56).

CADINU contracts

Contract Address
CADINU Smart Router 0x67E0Ff806c1a76c37b62365714fE17A1261568bc
CADINU V2 factory (CadinuFactory) 0x5DaF6fEd0E85218B275DB7D86001621043b561DA
CADINU V3 factory (CadinuV3Factory) 0x2cb62aEBa8eB609020129983A5141DB883abca85
CADINU V3 pool deployer 0x6d0f5064Eb63e979990B7cF3a1e143819a1d8b27
CADINU V3 PositionManager 0x0C26558A7Bf8be790774fc84De8e5229A4dB5BA1
CADINU V3 LM pool deployer 0xA63E8031c511B62d8eDEd49c0e210d15b26B2302
CadinuStableSwapFactory 0xA370C9A5D422CbD48EfEE1De1f7116998687f702
Stable-swap info contract 0xf67d5C80759bE8eD17C99821A9B79F5b61d6abdc
CadinuSwapMMPool 0xa51d681a4F5F4c2F7725dCc01821E293Fa315b51

Administrative addresses

Role Address
Owner key (Smart Router, V3 factory, CadinuSwapMMPool) and V2 feeToSetter 0xdb2FF236A2E8E8478c8993749e7F1c1D31c28c02
V2 protocol-fee address (feeTo) 0xA097fD3E5D1314Dc40dB52296A7f646740430ca8

Third-party contracts used by MultiSwap

Contract Address
PancakeSwap Router02 (V2) 0x10ED43C718714eb63d5aA57B78B54704E256024E
PancakeSwap V3 SwapRouter 0x1b81D678ffb9C0263b24A97847620C99d213eB14
PancakeSwap QuoterV2 (quotes only) 0xB048Bbc1Ee6b733FFfCFb9e9CeF7375518e25997

The full list of CADINU contracts is on Main Contracts.

Verifiable code

  • The source code of the CADINU Smart Router, the V2 factory, the V3 factory and the stable-swap factory is verified on Sourcify (partial match: the deployed bytecode matches the published source, only the metadata hash differs). CadinuSwapMMPool is verified as an exact match.
  • The router is not upgradeable, so the verified code is the code that runs.

Known limits, stated openly

  • Single owner key. Administration rests on one key with no multisig and no timelock (section 10). Its powers cannot move user funds, but governance depends on that one key.
  • Trust in the web interface. CADINU serves the web interface that builds the transaction you sign: the target contract, the recipient, the minimum amount and any fee. A compromised interface could ask you to sign a harmful transaction or approval. This applies to every web-based DEX interface. Before you sign, check that your wallet shows a router address from section 11. MultiSwap also shows the router address on its confirmation screen and simulates the exact transaction first.
  • Standing approvals. Unlimited approvals stay in place after a swap. The owner cannot use them, but they rely on the router’s code being free of bugs. Revoke approvals you no longer need.
  • Third parties. PancakeSwap routes depend on PancakeSwap’s contracts.
  • Records. MultiSwap keeps a record of each swap it submits, including your wallet address and transaction details, for statistics. See the Privacy Policy.
QUOTE AND ROUTE SELECTION (MultiSwap; read-only)
Your browser (CADINU interface)
|-- reads CADINU V2/V3 pool state --------> BNB Smart Chain
|-- reads PancakeSwap Router02 / QuoterV2 -> BNB Smart Chain
|-- compares quotes, picks the better executable route
'-- simulates the exact transaction from your address
(no CADINU server in this step)
SIGNING (all routes)
Your wallet --signs approval (spender = chosen router)--> token contract
Your wallet --signs swap (to = chosen router, recipient = you)--> BNB Smart Chain
CADINU servers: no keys, no signing. MultiSwap only: receives
the transaction hash afterwards, for statistics.
ASSET FLOW (one atomic transaction, or nothing happens)
CADINU DEX route:
Your wallet --> CADINU pools --> Your wallet
(BNB output or multi-hop V3: pools --> CADINU Smart Router,
inside the same transaction --> Your wallet)
PancakeSwap route (MultiSwap):
Your wallet --> PancakeSwap router --> PancakeSwap pools --> Your wallet
(no CADINU contract in the path)
OWNER KEY (single key; cannot move user funds or spend approvals)
CADINU Smart Router: setStableSwap, transferOwnership, renounceOwnership
CADINU V2 factory: setFeeTo, setFeeToSetter
CADINU V3 factory: fee tiers, protocol fee share, farming hooks, setOwner
CadinuSwapMMPool: register/remove market makers, redeemToken

You can check the on-chain facts on this page yourself, with any BNB Smart Chain explorer or RPC node. The examples below use Foundry’s cast and a public BNB Smart Chain RPC.

Set the RPC once:

Terminal window
RPC=https://bsc-dataseed1.binance.org

The router’s owner is the single owner key:

Terminal window
cast call 0x67E0Ff806c1a76c37b62365714fE17A1261568bc "owner()(address)" --rpc-url $RPC

The router is not a proxy (both standard EIP-1967 slots are empty):

Terminal window
cast storage 0x67E0Ff806c1a76c37b62365714fE17A1261568bc 0x360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3ca505d382bbc --rpc-url $RPC
cast storage 0x67E0Ff806c1a76c37b62365714fE17A1261568bc 0xb53127684a568b3173ae13b9f8a6016e243e63b6e8ee1178d6a717850b5d6103 --rpc-url $RPC

The router has no pause and no stored fee (both calls revert):

Terminal window
cast call 0x67E0Ff806c1a76c37b62365714fE17A1261568bc "paused()(bool)" --rpc-url $RPC
cast call 0x67E0Ff806c1a76c37b62365714fE17A1261568bc "feeBips()(uint256)" --rpc-url $RPC

The owner key is an EOA with an EIP-7702 delegation (code 0xef0100 followed by the delegate address), and the delegate’s name and version:

Terminal window
cast code 0xdb2FF236A2E8E8478c8993749e7F1c1D31c28c02 --rpc-url $RPC
cast call 0x63c0c19a282a1B52b07dD5a65b58948A07DAE32B "NAME()(string)" --rpc-url $RPC
cast call 0x63c0c19a282a1B52b07dD5a65b58948A07DAE32B "VERSION()(string)" --rpc-url $RPC

The V2 factory’s protocol-fee address and who may change it:

Terminal window
cast call 0x5DaF6fEd0E85218B275DB7D86001621043b561DA "feeTo()(address)" --rpc-url $RPC
cast call 0x5DaF6fEd0E85218B275DB7D86001621043b561DA "feeToSetter()(address)" --rpc-url $RPC

The market-maker signer configured in the interface is not registered on CadinuSwapMMPool (empty name, zero treasury, inactive):

Terminal window
cast call 0xa51d681a4F5F4c2F7725dCc01821E293Fa315b51 "getMMInfo(address)(string,address,bool)" 0x2008b6c3D07B061A84F790C035c2f6dC11A0be70 --rpc-url $RPC

Check one of your own swaps. Open the transaction on BscScan. The “To” field is the router you chose (section 11), the sender is your address, and the token transfers end at your address in that same transaction.

The on-chain values on this page were read on 2 October 2026, between BNB Smart Chain blocks 125,313,408 and 125,317,391. Balances and LP shares change over time.

Version 1.1
Last updated 4 October 2026
Covers The CADINU DEX swap and CADINU MultiSwap as live on apps.cadinu.io on that date
Changes 1.1: MultiSwap (in-app route comparison) is live; the embedded third-party swap pages are gone; high price impact asks for confirmation instead of blocking. 1.0 (2 October 2026): first publication

Read on BNB Smart Chain at block 125,732,887 (2026-10-04): every address (12 with contract code, 2 wallet addresses).