What Gridinsoft observed on Dustswap.wtf
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- Legitimate DeFi Website
- Evidence basis
- First-party site analysis External vendor intelligence: Context only — not used for this decision
The independent current review found no reason to classify the official dustswap.wtf domain as malicious. The root, application, documentation, delivered client code, and documented current Base contracts were consistent with an operating DeFi product, and the reviewed wallet flows used explicit authentication, approvals, signatures, and transactions rather than covert asset access. The Safe classification describes the observed official surfaces; it is not an endorsement of the token economics, an investment recommendation, or a guarantee that the unaudited backend and smart contracts are vulnerability-free.
Analyst findings
No phishing or wallet-drainer behavior identified
The current official web surfaces, distributed client code, and verified current Base contracts showed coherent DeFi functionality and user-confirmed wallet actions. The review found no credential theft, seed-phrase or private-key collection, blanket NFT approval, automatic asset-transfer flow, or other malicious payload.
Current V3 contract enforces material transaction bounds
The verified non-proxy V3 contract restricts external call targets and spenders, binds Permit2 signatures to the transaction intent, caps fees, and uses exact temporary approvals with reset behavior. Current on-chain configuration matched the published production addresses and stated 2% fee.
DeFi and operator trust risks remain
A safe site classification is not a smart-contract or investment guarantee. The off-chain route builder and frontend lack a disclosed independent professional audit, and the current owner retains allowlist, pause, rescue, and bounded fee authority without disclosed multisig or timelock governance.
Review 6 documented observations View evidence
The official root, application, and documentation hosts returned coherent DustSwap DeFi content. Desktop, mobile, and crawler requests to the root produced the same page, and the application root consistently redirected to its profile route. The reviewed unauthenticated pages did not request a password, payment-card data, seed phrase, private key, or file upload.
-
HTTP status
200 -
Final URL
https://dustswap.wtf/ -
Redirect destination
https://app.dustswap.wtf/profile -
Page element
Public application routes for profile, sweep, swap, spin, quests, and leaderboard -
Analyst observation
The reviewed public surfaces showed no client-dependent content change across the tested desktop, mobile, and crawler request profiles.
Review of the currently delivered application scripts found ordinary wallet connection, SIWE authentication, exact ERC-20 approval, transaction submission, and structured Permit2 signing flows. No setApprovalForAll request, seed-phrase collection, private-key collection, or automatic transaction submission was identified in the reviewed application code.
-
Page element
SIWE message: Sign in to DustSwap to view your profile. -
Page element
PermitBatchWitnessTransferFrom structured signing flow -
Analyst observation
ERC-20 approvals in the reviewed sweep code are constructed for explicit approvalAmount values; no setApprovalForAll call was present. -
Analyst observation
The public client obtains quotes and transaction calldata from an off-chain DustSwap backend, then requires wallet approval or signing before submission.
The documented current DustSwapSweepRouter V3 address has verified Solidity source on Base, is not a proxy, and exposes a non-reentrant, pausable sweep entry point. The source binds Permit2 signatures to routes, output token, recipient, minimum output, deadline, and fee; validates targets and spenders against on-chain allowlists; caps the fee at 3%; and resets per-route approvals to zero.
-
Public artifact URL
https://base.blockscout.com/address/0x06e6BAa61A5Da1E4469FCa5dEa3EB68324255E20 -
Analyst observation
The deployed runtime bytecode was present on Base and the explorer identified the verified contract as DustSwapSweepRouter without a proxy implementation. -
Analyst observation
Current read-only contract calls returned paused=false, feeBps=200, MAX_FEE_BPS=300, and the canonical Permit2 address 0x000000000022D473030F116dDEE9F6B43aC78BA3. -
Analyst observation
All twelve DEX and aggregator addresses documented by DustSwap were present in the current allowedTargets mapping; applicable routers or canonical Permit2 were present in allowedSpenders.
The documented DustSpinTrigger contract is fully source-verified and contains only a non-payable spin function that increments the caller's counter and emits an event. The documented legacy V2 sweep contract is also source-verified; the legacy V1 address was not source-verified in the reviewed explorer data.
-
Public artifact URL
https://base.blockscout.com/address/0xCf10Edbc886C60086e49061c807a14E7009F9A22 -
Public artifact URL
https://base.blockscout.com/address/0x6d3C31E4a2b8e1Fe9De0d260D142183E82cbE1E3 -
Analyst observation
No payable transfer, token approval, withdrawal, delegatecall, or self-destruct path was present in the reviewed DustSpinTrigger source.
The domain used consistent Cloudflare-hosted root and application records, a documented documentation host, and active email records. HTTPS certificates covered the official root and application hosts and were valid at review time.
-
DNS fact
dustswap.wtf and app.dustswap.wtf resolved through Cloudflare addresses 104.21.77.177 and 172.67.210.160. -
DNS fact
The domain had MX, SPF, and DMARC records at the recorded review time. -
Certificate fact
A Google Trust Services certificate covered dustswap.wtf, app.dustswap.wtf, and *.app.dustswap.wtf and was valid during the review.
DustSwap explicitly states that its published contract review is internal and AI-assisted, not a third-party professional audit, and does not cover the off-chain route builder or frontend. The contract owner currently controls the allowlist, fee within the hard cap, pause function, and rescue functions without disclosed multisig or timelock hardening.
-
HTTP status
200 -
Final URL
https://docs.dustswap.wtf/docs/security/audit-status -
Analyst observation
The audit-status and security-model pages disclose the absence of an external professional audit and the current owner-governance concentration.
Scope and limitations
- No wallet signature or real-value transaction was submitted during the review; transaction intent was assessed from the current public interface, delivered scripts, verified source code, and read-only Base state.
- The off-chain route builder and production backend were not source-audited, and DustSwap's published review explicitly excludes them.
- The published contract review is internal and AI-assisted rather than an independent professional audit.
- The contract owner can change allowlists, pause the contract, rescue stuck balances, and set the fee up to the on-chain 3% cap; disclosed multisig or timelock hardening was not present.
- Web content, backend behavior, contract configuration, and deployed addresses can change after the recorded review.
Help protect others by sharing this page on social media! The more people who know about dustswap.wtf, the fewer chances they have to deceive someone else. Help others evaluate dustswap.wtf by sharing this page on social media!