QFlow Audit Report
The QFlow audit reviews a verified token contract, including transfer burns, epoch-pool accounting, ownership controls, and adversarial tests. Its final table records no high or medium findings and one acknowledged low-severity finding.
Report Summary
The QFlow audit reviews a verified token contract, including transfer burns, epoch-pool accounting, ownership controls, and adversarial tests. Its final table records no high or medium findings and one acknowledged low-severity finding.
Verified target contract
The report scopes the verified QFlow source at the BNB Smart Chain address shown in the metadata. Its conclusions apply to that documented contract source and do not automatically cover later deployments or surrounding applications. Source: PDF page 4.
Acknowledged low-severity finding
The report identifies direct QFLOW transfers to the token contract as separate from the tracked epoch pool. Because epoch execution burns only the tracked pool and the contract has no recovery path for the surplus, directly transferred tokens can remain inaccessible. The report recommends rejecting direct transfers or explicitly accounting for donations. Source: PDF page 7.
Adversarial test coverage
The testing annex exercises transfer burns, allowances, ownership, epoch timing, pool accounting, direct donations, overdue epochs, rounding behavior, arithmetic limits, and deterministic stateful invariants. The annex provides the test logic used to support the report's conclusions. Source: PDF page 10.
Reading the final PASS result
The final summary records no high or medium findings and one acknowledged low-severity finding. It also describes the reviewed holder protections and limited owner controls. PASS is the report's conclusion for the documented contract and assumptions; the acknowledged low finding remains part of the public record. Source: PDF page 28.
How to Evaluate This Report
Check the original PDF for the code version, reviewed components, exclusions, and remediation status. An audit applies to its documented scope; it does not automatically cover later upgrades or changes to external dependencies.
Planning a similar review? Compare our audit methodology and scope checklist, then discuss your project with CTDSEC.
| Project | QFlow |
|---|---|
| Review type | Solidity token contract review on BNB Smart Chain |
| Scope | Verified QFlow contract at 0xdC0F4179492356F7bf567F80dFB350346F5B9B9A |
| Report source | Public PDF |
| Source file | Cybersecurity_Audit_CTDSEC_QFLOW_PASS.pdf |
| Target code | Verified contract source |
Severity Summary
Counts and statuses reflect the public PDF's findings and final summary, not a new assessment of the current deployment.
Check the original final summary on PDF page 28. Acknowledged findings are not verified fixes.
Open the Public Report
Use the original PDF for complete context, exact wording, and detailed remediation notes.
Planning a similar review?
Request a smart contract audit for your protocol
Send the repository, target network, language, and launch timeline so CTDSEC can scope your audit accurately.