06 · Security
Security
We did not deploy a contract, so most of this page is about what you are trusting instead of us.
What we removed
On the chain Crumble started on, this page was a list of every power the owner of our contract held, written against the contract itself. There is no such list now, because there is no Crumble program on Solana. We did not deploy one.
That deletes a whole category of risk in one go: no admin key, no upgrade authority, no pause switch, no function that can move what you hold, no bug in our code that drains a pool, nothing to audit and nothing to trust us not to change. It also means the honest version of this page is shorter and less flattering than the old one, because what is left to trust is mostly other people.
What you are trusting instead
| Who | With what |
|---|---|
| Your wallet | Signing what it shows you, and nothing else. Every balance change is listed before you approve. |
| Jupiter | Routing the swap. It builds the instructions; we assemble them and you sign them. |
| The pools | The price you get. Your slippage setting is the limit on how far it can move against you. |
| Backed | The stock tokens themselves, and the shares behind them. Not us. See Supported assets. |
| Crumble | Assembling the transaction honestly. There is no fee in it, so there is nothing for us to take. |
That last line is the real one, so here is what backs it: the transaction is the proof. Everything we do is in it, in front of you, before you sign, and afterwards on Solscan forever.
No fee, so nothing to police
The old version of this section explained how to check that we were only taking the 1% we advertised. There is no fee any more, which removes the question entirely: open any round-up on the explorer and there is no instruction in it paying Crumble.
That also disposes of the awkward part. Without a contract there could never have been an on-chain ceiling on a fee, only a promise. Zero needs no ceiling.
Impostor tokens
This is the live risk on Solana, and it is not hypothetical. Searching for NVDAx on a token list returns several different tokens with the same symbol and the same name. One has millions of dollars of liquidity behind it. The others are worth nothing, and exist to be bought by mistake.
The app never resolves a token by its symbol. Every mint it will touch is written into its config by address, and on every load it checks each one against the chain: symbol, decimals, token program, and the issuer's own address prefix. If any of that stops matching, the app refuses to trade rather than guessing.
You can do the same check by hand against Addresses.
What can still go wrong
- A pool moves against you. Slippage catches it: past your limit, the whole transaction reverts and nothing is spent.
- The issuer of a stock token fails. That token is their obligation, not ours, and no amount of self-custody helps with it.
- You sign something else. A phishing site can look exactly like this one. Check the address bar, and read what your wallet shows you.
- Solana has a bad day. Transactions can fail or expire under load. A failed transaction costs gas and changes nothing else.
The plain list is in Risks, and it is worth reading before you put a cent in.