πSecurity
BasedRaid is built with security as a top priority.
ποΈ Trustless Architecture
π PDA Vaults
All funds are held in Program Derived Addresses (PDAs) controlled by the smart contract:
π No Admin Access
Creators cannot access funds until target is met
β° Time-Locked
Funds cannot be withdrawn early
π‘οΈ Decentralized
No single party can steal funds
βοΈ On-Chain Logic
All business logic is enforced on-chain:
β Target Verification
Smart contract checks raised vs target
β° Lock Period
Enforced by blockchain timestamps
π° Fee Calculations
Automatic, transparent deductions
π Refund Eligibility
Programmatic verification
π‘οΈ Security Features
For Donors
π― 100% Refunds
Full refund if target not met (no fees)
β° Withdrawal Lock
30min-1hr delay prevents instant rugs
β Verified Creators
Trust badges based on history
π Transparent Progress
Real-time on-chain data
For Creators
π Immutable Vault
No one can take your raised funds
β‘ Automatic Unlock
No admin approval needed
β Cancellation
Cancel before donations received
π§ Smart Contract Security
π Input Validation
Max target: 1000 SOL, Max deadline: 30 days
π’ Overflow Protection
All math uses checked operations
ποΈ Treasury Validation
Hardcoded address, cannot be changed
π CEI Pattern
Prevents reentrancy attacks
β What BasedRaid Cannot Do
π³ Access your wallet funds
β Impossible
π§ Modify smart contract behavior
β Impossible
βͺ Reverse on-chain transactions
β Impossible
π° Take funds from vaults
β Impossible
π Change fee percentages
β Impossible
π‘ Best Practices
For Donors
π Verify the token
Check contract address on a block explorer
π Check creator history
Look for trust badges and past success
π° Start small
Don't put all funds in one raid
π Do your research
Join the community, verify socials
For Creators
π Be transparent
Clearly explain your goals
π Provide proof
Link socials and verify identity
π― Set realistic targets
Build trust with smaller raids first
π¬ Communicate
Keep your community updated
π¨ Reporting Issues
Security Vulnerability?
If you discover a security vulnerability, please report it responsibly. Contact the team directly before public disclosure.
Last updated