CRUMBLE Docs

06 · Security

Security

We did not deploy a contract, so most of this page is about what you are trusting instead of us.

What we removed

On the chain Crumble started on, this page was a list of every power the owner of our contract held, written against the contract itself. There is no such list now, because there is no Crumble program on Solana. We did not deploy one.

That deletes a whole category of risk in one go: no admin key, no upgrade authority, no pause switch, no function that can move what you hold, no bug in our code that drains a pool, nothing to audit and nothing to trust us not to change. It also means the honest version of this page is shorter and less flattering than the old one, because what is left to trust is mostly other people.

What you are trusting instead

WhoWith what
Your walletSigning what it shows you, and nothing else. Every balance change is listed before you approve.
JupiterRouting the swap. It builds the instructions; we assemble them and you sign them.
The poolsThe price you get. Your slippage setting is the limit on how far it can move against you.
BackedThe stock tokens themselves, and the shares behind them. Not us. See Supported assets.
CrumbleAssembling the transaction honestly. There is no fee in it, so there is nothing for us to take.

That last line is the real one, so here is what backs it: the transaction is the proof. Everything we do is in it, in front of you, before you sign, and afterwards on Solscan forever.

No fee, so nothing to police

The old version of this section explained how to check that we were only taking the 1% we advertised. There is no fee any more, which removes the question entirely: open any round-up on the explorer and there is no instruction in it paying Crumble.

That also disposes of the awkward part. Without a contract there could never have been an on-chain ceiling on a fee, only a promise. Zero needs no ceiling.

Impostor tokens

This is the live risk on Solana, and it is not hypothetical. Searching for NVDAx on a token list returns several different tokens with the same symbol and the same name. One has millions of dollars of liquidity behind it. The others are worth nothing, and exist to be bought by mistake.

The app never resolves a token by its symbol. Every mint it will touch is written into its config by address, and on every load it checks each one against the chain: symbol, decimals, token program, and the issuer's own address prefix. If any of that stops matching, the app refuses to trade rather than guessing.

You can do the same check by hand against Addresses.

What can still go wrong

The plain list is in Risks, and it is worth reading before you put a cent in.