MSC-BB-CVR-2026-001BASEDBID Lock Contracts
Consolidated verification of published source metadata, constructor configuration, and deployed-runtime consistency for fourteen mainnet lock-contract deployments.
Executive conclusion
Deployment consistency established
All fourteen listed deployments were recorded and compared. Equivalent deployments were runtime-identical directly or after normalization of the documented immutable position-manager address, except for the localized BNB Smart Chain BasedV3UniswapLock variance described below.
Scope boundaryThis establishes deployment consistency under the stated methodology. It does not establish that the underlying source is secure, functionally correct, or suitable for every token, pool, hook, or user condition.
Verification controls
Work performed
All fourteen listed deployments were recorded with published source-verification status.
Solidity 0.8.36, Prague EVM target, optimizer enabled with 200 runs.
Immutable position-manager addresses were decoded and recorded for every deployment.
Equivalent deployments were compared byte-for-byte, with immutable normalization used only where documented.
Deployment register
Fourteen mainnet contracts
| Network | Contract | Address | Verification result |
|---|---|---|---|
| BNB Smart Chain | BasedV3UniswapLock | 0xb8f4eDA82c2c9D514FFF646e88e7297480C5dEaD | Exact match · localized variance documented |
| BNB Smart Chain | BasedV3PCSLock | 0x82306A00f4Dd54482F708066142492f96DeBdEaD | Exact match · runtime identical to Base |
| BNB Smart Chain | BasedV4Lock | 0xD77cBAcE1E6dEE8230Ac38294CEf13fA6871dEaD | Exact match · identical after immutable normalization |
| BNB Smart Chain | BasedInfinityLock | 0xDdfa9b6EB5b6f5cFF64289c9391820889BabdEaD | Exact match · runtime identical to Base |
| Robinhood Chain | BasedV3UniswapLock | 0x635f5b6A566573bef2E4E631DFf004baf3fEdEaD | Verified · identical to Base after immutable normalization |
| Robinhood Chain | BasedV3PCSLock | 0x82306A00f4Dd54482F708066142492f96DeBdEaD | Verified · runtime identical to Base |
| Robinhood Chain | BasedV4Lock | 0xF49Ddb31213C75C41776EdB41E06B821c4DadEaD | Verified · identical to Base after immutable normalization |
| Base | BasedV3UniswapLock | 0xE91FC414B872859b4d3a37B3309EEdd44820dEaD | Explorer exact match |
| Base | BasedV3PCSLock | 0x82306A00f4Dd54482F708066142492f96DeBdEaD | Explorer exact match |
| Base | BasedV4Lock | 0xF537120Ec2fF398AD11F07DA7421C7B043A0dEaD | Explorer exact match |
| Base | BasedInfinityLock | 0xDdfa9b6EB5b6f5cFF64289c9391820889BabdEaD | Explorer exact match |
| Ethereum | BasedV3UniswapLock | 0x08740c80287603A8071287AD8d259e70e1C3dEaD | Explorer exact match |
| Ethereum | BasedV3PCSLock | 0x82306A00f4Dd54482F708066142492f96DeBdEaD | Explorer exact match |
| Ethereum | BasedV4Lock | 0x92746C1fc7eD907Cb678D09425d67062054BdEaD | Explorer exact match |
Documented variance
Localized BNB runtime difference
After immutable normalization, the BNB Smart Chain BasedV3UniswapLock contains one localized three-byte sequence, 0x526024, in the ZeroAddress() revert-data construction. Removing that sequence produces an otherwise exact runtime match to Base.
The variance is documented without making a broader behavioral-equivalence or security conclusion.
Future review leads
Not security findings
These observations were noticed during the limited structural screen. They were not comprehensively validated and were not assigned security severities in this report.
BBL-01Hook compatibility
V4 and Infinity positions whose hooks require nonempty decrease data may require deeper compatibility validation.
Deferred to separate deep reviewBBL-02Refund and balance assumptions
Whole-balance refund behavior and third-party position-manager accounting merit targeted testing.
Deferred to separate deep reviewBBL-03Fee-receiver handoff
The one-step receiver change has no acceptance step or administrator recovery path.
Deferred to separate deep reviewIntentional exclusions
What this engagement did not include
The following activities were intentionally excluded by the agreed verification-first scope. Their absence is not an omission or incomplete performance.
- Comprehensive or line-by-line security auditing of every execution path
- Full vulnerability discovery, security grading, or a no-findings conclusion
- Exploit development, attack simulation, penetration testing, or transaction replay
- Formal verification, exhaustive fuzzing, invariant, unit, integration, fork, gas, or economic testing
- Deep review of third-party position managers, pool managers, tokens, hooks, or imported libraries
- Validation of live locks, balances, historical transactions, fee accounting, or liquidity positions
- Review of the BASEDBID launchpad, front end, back end, treasury, governance, or unlisted contracts
- Operational-key, custody, legal, regulatory, tokenomic, market, or business-model review