Skip to content

Security and transparency

This page reports a line-by-line comparison, made on 7 October 2026, of every contract on the CADINU swap and farm path with the PancakeSwap contract it was copied from. It is not an audit, and no auditor has reviewed the CADINU addresses below. What applies to them is the audits of the PancakeSwap code they match, within the limits stated in How far the audits reach. An audit reviews code at one point in time; it does not make a trade risk-free.

  • CADINU side. The source published on Sourcify for each CADINU address. Every one of the eleven contracts is a Sourcify partial match: the executable bytecode on chain equals the compiled source, and only the metadata hash differs. That proves the code running at the address is the published source.
  • PancakeSwap side. The Sourcify-verified source of PancakeSwap’s own BNB Smart Chain deployment of the same contract, cross-checked against PancakeSwap’s public repository pancake-v3-contracts at commit ab804a4 (4 April 2023, the era of the BNB Smart Chain deployment).
  • Method. Comments, whitespace, licence, pragma and import lines are removed; Cadinu is renamed to Pancake (and CADINU to CAKE in MasterChef V3); each contract, library and interface is then diffed one by one.
  • Compiler. The same Solidity version everywhere except MasterChef V3 (CADINU 0.8.19, PancakeSwap 0.8.10). Optimizer settings differ on most contracts. That changes gas costs and bytecode, not the source. No compiler-bug review was made.

Addresses are shortened; each links to the full address on BscScan. “Partial match” links to the verified source on Sourcify. The audit labels link to the reports, listed in full under How far the audits reach.

Contract CADINU address Sourcify Verdict PancakeSwap reference Audits
V2 factory 0x5DaF…61DA Partial match Names only V2 factory 0xcA14…0c73 SlowMist V2
V2 pairs (8) e.g. 0xdA09…d2d8 Via the factory (note 1) Names only V2 pair 0x0eD7…4fD0 SlowMist V2
V2 router 0xeeCA…Ac4E Partial match Names and constants Router02 0x10ED…024E SlowMist V2
V3 factory 0x2cb6…ca85 Partial match Identical V3 factory 0x0BFb…1865 PeckShield V3 · SlowMist V3
V3 pool deployer 0x6d0f…8b27 Partial match Identical V3 pool deployer 0x41ff…71c9 PeckShield V3 · SlowMist V3
V3 pools (13) e.g. 0x9657…C368 Partial match, 4 of 13 (note 2) Identical V3 pool 0x3669…2050 PeckShield V3 · SlowMist V3
V3 position manager 0x0C26…5BA1 Partial match Names and constants Position manager 0x46A1…4364 PeckShield V3 · SlowMist V3
Smart Router 0x67E0…68bc Partial match Names and constants Smart Router 0x13f4…8Dd4 PeckShield V3 · SlowMist V3
Quoter (QuoterV2) 0x2F3b…836a Partial match Names and constants QuoterV2 0xB048…5997 Not clearly covered
MasterChef V3 (farms) 0x8C1e…EBae Partial match Names and constants MasterChef V3 0x556B…d59e PeckShield MCv3 · SlowMist Phase 2
LM pool deployer 0xA63E…2302 Partial match Names and constants (original 2023 version) Original LM pool deployer 0x7694…6Ad6 PeckShield MCv3 · SlowMist Phase 2
LM pools (10, one per farm) e.g. 0x3ab5…bc8A Partial match, 7 of 10 (note 3) Names and constants (original 2023 version) The LM pool inside that deployer PeckShield MCv3 · SlowMist Phase 2

Bottom line. No contract on the swap or farm path has a logic change. The V3 factory, pool deployer and pools are identical to PancakeSwap’s once the names are swapped. Every other contract differs only in names, init-code-hash constants, revert-message text or library helpers that are never called. The full addresses are on Main Contracts.

Notes on verification:

  1. V2 pairs are not verified per address. All 8 pass the CREATE2 check against the verified factory and share one runtime bytecode, so they run the pair code contained in the factory’s verified source.
  2. V3 pools: 4 of the 13 pools are verified on Sourcify; the other 9 pass the CREATE2 check against the verified pool deployer, so they run the same code.
  3. LM pools: 7 of the 10 are verified on Sourcify; the newest 3 are not yet verified.
  • V2 factory: the LP token name and symbol (“Cadinu LPs”, “Cadinu-LP”); the interface also declares the INIT_CODE_PAIR_HASH getter, a constant both factories have. 9 of 11 units identical.
  • V2 pairs: names. Same 0.25% swap fee and the same protocol-fee formula as PancakeSwap V2.
  • V2 router: the pair init-code hash; “Cadinu…” revert messages; the transfer helper uses a later wording of the same revert message.
  • V3 factory, pool deployer and pools: nothing after the rename (10 of 10, 32 of 32 and 31 of 31 units identical).
  • V3 position manager: the pool init-code hash; one expression in a number-to-text helper is written with extra brackets and gives the same result.
  • Smart Router: three init-code hashes; the order of two modifiers on one function, which is syntax only.
  • Quoter: the pool init-code hash only.
  • MasterChef V3: the reward token CAKE → CBON and the matching identifiers; built with Solidity 0.8.19 and newer OpenZeppelin helpers, which add functions this contract never calls. The MasterChef V3 body is otherwise identical.
  • LM pool deployer and LM pools: names and the init hash, against PancakeSwap’s original April 2023 LM pool (27 of 29 units identical). PancakeSwap has since replaced that version; see the farms caveat.

PancakeSwap lists its audit reports on its Audits page. These five cover the code CADINU runs:

Audit Scope stated in the report Applies to (CADINU, by identical code)
SlowMist, PancakeSwap Factory and Router, 6–12 May 2021 (No. 0x002105120002) The deployed code of PancakeSwap’s V2 factory and router: the exact contracts used as the reference here V2 factory, V2 pairs, V2 router
PeckShield, PancakeSwap V3, 28 March 2023 (report 2023-058) router, v3-core and v3-periphery in PancakeSwap’s pancake-v3 repository V3 factory, pool deployer, pools, position manager, Smart Router
SlowMist, PancakeSwap v3, 7–13 March 2023 (No. 0X002303130001) v3-core, v3-periphery excluding lens, router The same, and explicitly not the quoter
PeckShield, PancakeSwap MasterChef V3, 1 April 2023 (report 2023-065) masterchef-v3, v3-lm-pool MasterChef V3, LM pool deployer, LM pools (original version)
SlowMist, PancakeSwap v3 Phase 2, 16–22 March 2023 (No. 0X002303220001) masterchef-v3, v3-lm-pool MasterChef V3, LM pools (original version)

Read these limits before relying on the table:

  • V2: confirmed. SlowMist’s 2021 report states its scope as the deployed code of exactly the PancakeSwap factory and router used as the reference above.
  • V3 and MasterChef V3: likely, not confirmed. The audited commits live in PancakeSwap’s pancake-v3 repository, which is now private, so the audited code cannot be diffed against the deployed code directly. PancakeSwap’s docs list these reports for “Exchange V3” and “MasterChef V3”, and the first commit of the public repository (April 2023) comes after every fix commit named in the reports and matches the deployed code. Exact coverage is therefore likely, not confirmed.
  • The quoter is not clearly covered. SlowMist’s V3 scope excludes the lens folder where QuoterV2 lives, and PeckShield’s report does not name it. The quoter is a read-only helper that holds no funds: it simulates a swap and reverts to return the quote.
  • Lineage, not coverage. PancakeSwap V3 is itself a fork of Uniswap V3, whose Trail of Bits and ABDK reports are kept in PancakeSwap’s repository. They are not PancakeSwap audits and are not cited here as covering CADINU.
  • Not reviewed. The optimizer and compiler differences listed above (gas and bytecode, not source), and anything outside the contracts: the web interface, wallets and third-party DEXes are covered on CADINU Non-Custodial Exchange.

Farm reward pools (LM pools) use PancakeSwap’s original 2023 LM pool, which PancakeSwap has since replaced. PancakeSwap’s current LM pool deployer on BNB Smart Chain (0xd93F…37eD) uses a rewritten LM pool whose code comments say it fixes a case where a reward-growth value “can be underflow on purpose”. CADINU’s LM pools do not have that change. The exposure is farm reward accounting (CBON paid by Farms), not swap funds: an LM pool holds no tokens, and the CBON already funded into MasterChef V3 for the current period is the most that reward accounting can touch.

Every admin role on CADINU’s swap and farm contracts is held by a single key today: no multisig, no timelock. PancakeSwap’s equivalent roles are held by contracts. The function-by-function list is on CADINU Non-Custodial Exchange, section 10; this is the plain-words version, checked against the verified source.

Key A, 0xdb2F…8c02 (a wallet with an EIP-7702 delegation): owner of the V3 factory and of the Smart Router, and the V2 fee setter.

  • Can: set the protocol’s share of each V3 pool’s trading fee to 0, or anywhere from 10% to 40% (today 32% on every pool, the code’s default), and collect it; choose the address that receives the V2 protocol share (today 0xA097…0ca8); enable new fee tiers; attach or replace the farm module (LM pool) of any V3 pool; set the LM pool deployer; point stable-swap routes to another factory; hand each role to another address.
  • Cannot: move tokens out of a pair or a pool; spend an approval you gave; pause, upgrade or replace the router; change the route, minimum amount or deadline of a swap you signed.

Key B, 0x1f6e…0f6f (a wallet): owner of MasterChef V3, the farm contract.

  • Can: add farms and change their weights (adding a farm attaches an LM pool to that V3 pool through the LM pool deployer); set the receiver (today the contract 0x3095…a43c, the only address that can fund a reward period), the operator (today the wallet 0xe149…f0e9), the period length and a farm booster (none is set); switch on emergency mode, in which positions can still be withdrawn while reward payouts stop; hand the role over.
  • Cannot: withdraw or move a staked position (only its owner can); take the CBON funded for rewards (the contract keeps an account of what belongs to the farms, and its sweep function can only move tokens above that amount); block withdrawals.

Halting trading. A V3 pool calls its farm module (LM pool) inside every swap. Because key A can attach any contract as a pool’s farm module, and key B can attach one by adding a farm, a broken or hostile module would make swaps in that pool fail until it is replaced. That can stop trading in a pool; it cannot take the pool’s tokens or anyone’s position.

No key can take user funds from the pools. No admin function on any of these contracts moves tokens out of a pair, a pool or a staked position to the admin. Liquidity is withdrawn only by the address that owns it, and swaps settle only inside the transaction you sign.

  • Verified source. Open any address in the table on Sourcify or BscScan and read the code that runs at that address.
  • Repeat the comparison. Take the Sourcify source of a CADINU contract and of its PancakeSwap reference (or PancakeSwap’s public repository at commit ab804a4), strip comments and whitespace, rename Cadinu to Pancake, and diff them.
  • On-chain facts (fee tiers, protocol fee share, owners, LM pools) can be read with any BNB Smart Chain explorer or RPC node; the commands are on CADINU Non-Custodial Exchange, section 14.
  • Evidence. The comparison script, the normalised diffs for every contract and the on-chain readings of 7 October 2026 are kept in CADINU’s audit records and are available on request through CADINU Support.
Version 1.0
Last updated 8 October 2026
Comparison made 7 October 2026, from Sourcify-verified sources and public BNB Smart Chain reads
Covers The 11 CADINU swap and farm contracts above, their V2 pairs, V3 pools and LM pools, as deployed on BNB Smart Chain

Read on BNB Smart Chain at block 126,516,127 (2026-10-08): every address (25 with contract code, 4 wallet addresses).