SECURITY

Built so there is little to steal.

P2Flux never holds your money. Payments go from the buyer's wallet to the merchant's wallet in one transaction, through small contracts that nobody, including us, can change.

Read the threat model Report a vulnerability
BUYER
Wallet
signs
P2FLUX
Contract
passes through
MERCHANT
Wallet
receives
ONE TRANSACTION
NO P2FLUX BALANCENO WITHDRAWALSNO UPGRADES
NON-CUSTODIAL

Funds move from payer to merchant in the same transaction. No balances, no withdrawals, nothing waiting in our wallets.

IMMUTABLE

No upgrades, no proxies, no admin who can move funds. The code on chain is the code you can read.

VERIFIED

Every contract's source is published and verified on Sourcify and BaseScan.

SIGNED, NOT TRUSTED

Every payment needs the payer's own signature over the exact recipient and amount. Our servers submit transactions; they cannot change them.

HOW WE CHECK THE CONTRACTS

What we run, and where to see the results.

Our contracts have not yet had a paid third-party audit. Until they do, this is what we run, and every result is public.

Security analysis → Contracts source →

Static analysis

Slither and Aderyn, the industry's standard open-source analysers, on every change. Every finding is reviewed and explained publicly; none is a vulnerability.

RUNNING

Fuzzing and invariant tests

157 Foundry tests drive thousands of random payments, signatures, timings and attack sequences through the contracts and check that no money appears, disappears or goes anywhere it was not signed for. A 20,000-run deep soak before every release.

RUNNING

Real-network tests

The same payments replayed against the real USDC, Permit2 and x402 contracts on copies of Base Mainnet and Base Sepolia.

RUNNING

Tests that test the tests

We deliberately break guards in the code and confirm the tests catch every change.

RUNNING

Independent review

Next. An independent review of the subscription contract comes first.

NEXT
7
contracts on Base Mainnet
~970
lines of contract code
316
automated contract tests
157 Foundry + 159 deployment
0
admin keys that can move customer funds
WHAT IF SOMETHING IS COMPROMISED?

We plan for our own systems being attacked.

Here is the worst case for each.

IF THIS IS TAKEN

Our server and its transaction key

WORST CASE

Cannot redirect a payment or change an amount. At most it could submit charges that are already due under what the payer signed, and spend a capped amount of our own gas budget. The key can be replaced without redeploying anything.

IF THIS IS TAKEN

Our admin key

WORST CASE

Kept offline. It can only replace the server key above. Nothing else.

IF THIS IS TAKEN

Our payment page

WORST CASE

Your wallet always shows what you sign, and the page only works with the published contracts. Merchants can host the payment page themselves, with checksummed releases.

IF THIS HAPPENS

A bug in a contract

THE RISK WE TAKE MOST SERIOUSLY

Subscriptions use a USDC approval, so the subscription contract has the most tests and is first for independent review. Payers can revoke a subscription or remove the approval from their wallet at any time.

COMPLIANCE

In one line each.

SANCTIONSPayer and merchant wallets checked against the U.S. OFAC list, no KYC.
NETWORKPayments run on Base (Coinbase's network) with Circle's USDC.
PRIVACYWe never ask for names, emails or card data to pay. Privacy policy →
CONTRACT ADDRESSES · BASE MAINNET

Check them yourself.

Source on GitHub →
Splitter (one-time payments) 0x5A3bD0945cd0C80B124870881dE49a717D20E0D0 View ↗
Recurring (subscriptions) 0xb415A9910Ef627e3bEF10F5Cb9DC92a3271e0975 View ↗
Sponsored Splitter (pay without ETH) 0x95E18ec05D4282acB3aab7aD60325bA4EEeEa8df View ↗
Gas Sponsor 0xD1DDAaa301403d18fD4A23Fc69493ef48af90285 View ↗
x402 Splitter (AI agents) 0x9A11CE97eaE8674a70487b1D18C06b1C7f654Ec1 View ↗
Batch Vaults (AI agents, prepaid) 0xa62eDD9B45a0564a63C248564335BA7B2E3877A4 View ↗
Gas Refill 0x78cb470600EA0D68cE846bfc3bB455786BF56537 View ↗
REPORT A VULNERABILITY

Found something?

Email contact@p2flux.com privately. Please don't disclose it publicly or test against real users' funds. We reply within five business days. We don't run a paid bug bounty at the moment; with your permission, we credit you publicly for a confirmed report.

Read our security policy

Last reviewed 8 October 2026. This page describes our own testing and analysis; it is not a third-party audit.