Public audit report

QFlow Audit Report

The QFlow audit reviews a verified token contract, including transfer burns, epoch-pool accounting, ownership controls, and adversarial tests. Its final table records no high or medium findings and one acknowledged low-severity finding.

Report Summary

The QFlow audit reviews a verified token contract, including transfer burns, epoch-pool accounting, ownership controls, and adversarial tests. Its final table records no high or medium findings and one acknowledged low-severity finding.

Verified target contract

The report scopes the verified QFlow source at the BNB Smart Chain address shown in the metadata. Its conclusions apply to that documented contract source and do not automatically cover later deployments or surrounding applications. Source: PDF page 4.

Acknowledged low-severity finding

The report identifies direct QFLOW transfers to the token contract as separate from the tracked epoch pool. Because epoch execution burns only the tracked pool and the contract has no recovery path for the surplus, directly transferred tokens can remain inaccessible. The report recommends rejecting direct transfers or explicitly accounting for donations. Source: PDF page 7.

Adversarial test coverage

The testing annex exercises transfer burns, allowances, ownership, epoch timing, pool accounting, direct donations, overdue epochs, rounding behavior, arithmetic limits, and deterministic stateful invariants. The annex provides the test logic used to support the report's conclusions. Source: PDF page 10.

Reading the final PASS result

The final summary records no high or medium findings and one acknowledged low-severity finding. It also describes the reviewed holder protections and limited owner controls. PASS is the report's conclusion for the documented contract and assumptions; the acknowledged low finding remains part of the public record. Source: PDF page 28.

How to Evaluate This Report

Check the original PDF for the code version, reviewed components, exclusions, and remediation status. An audit applies to its documented scope; it does not automatically cover later upgrades or changes to external dependencies.

Planning a similar review? Compare our audit methodology and scope checklist, then discuss your project with CTDSEC.

ProjectQFlow
Review typeSolidity token contract review on BNB Smart Chain
ScopeVerified QFlow contract at 0xdC0F4179492356F7bf567F80dFB350346F5B9B9A
Report sourcePublic PDF
Source fileCybersecurity_Audit_CTDSEC_QFLOW_PASS.pdf
Target codeVerified contract source

Severity Summary

Counts and statuses reflect the public PDF's findings and final summary, not a new assessment of the current deployment.

Check the original final summary on PDF page 28. Acknowledged findings are not verified fixes.

0 High - None found
0 Medium - None found
1 Low - Acknowledged
0 Informational - None found

Open the Public Report

Use the original PDF for complete context, exact wording, and detailed remediation notes.

Planning a similar review?

Request a smart contract audit for your protocol

Send the repository, target network, language, and launch timeline so CTDSEC can scope your audit accurately.

Get an Audit Quote