Security
What the app verifies before a transaction reaches your wallet, what the API verifies before it returns a quote, what the contracts guarantee, and what you should check yourself.
Tirio is non-custodial: a swap is a single transaction from your wallet to the Router, and the contracts hold no user funds between transactions. The checks below make sure that transaction does exactly what the quote showed you.
What the app checks before anything reaches your wallet
Every quote the app receives is validated in the browser before it is displayed or sent:
tx.tomust be the Tirio Router,0x0000000000F315f7C21DcdF4885FB01064f58da5.- The quote's
tokenIn,tokenOutandamountInmust equal what you requested. tx.valuemust equal the amount you pay for a native input and be zero for an ERC-20 input.minOutmust not exceedamountOut.- The calldata must decode as a Router
swaporswapForwardingNativeOutcall, and the decodedtokenIn,tokenOut,amountIn,recipient(your connected account),minOutanddeadlinemust match the quote and the request.
A quote that fails any of these checks is rejected and never shown as a price.
When you press Swap, the app first runs the exact transaction through eth_call against a public RPC. A revert is decoded into a plain message (for example insufficient output or an expired deadline) and nothing is sent. Only then does the wallet prompt open, with exactly the to, data, value and gas from the quote.
Approvals are for the exact amount of the swap unless you turn on unlimited approval in the settings. The app does not include WalletConnect, whose SDK ships telemetry that is on by default; only browser wallets are supported.
What the API checks before it returns a quote
- Fresh state. Every quote reads the current state of the pools it uses. If the pool state falls behind the chain, quotes pause with a 503 instead of returning stale prices.
- Exact math. Pools are quoted locally with the same math they use on chain; concentrated-liquidity pools are walked tick by tick.
- On-chain simulation. The complete transaction is simulated with
eth_callbefore the quote is returned. The simulated output and gas replace the estimates; a route that fails in simulation loses its pools and the order is routed again without them. A quote markedsimulated: trueis a route that ran successfully at the current block. - Transfer-tax probing. Tokens are probed for buy and sell taxes, and a detected tax is applied inside the quote. When a tax cannot be measured, the quote says so instead of guessing.
Honest badges
The app shows how a quote was made rather than hiding it: Exact quote when every leg was quoted exactly, Estimated when some legs were interpolated, Simulated when the full transaction was simulated on chain, plus the remaining validity in seconds. Tax notices name the taxed side and say whether the tax is known. High price impact is called out from 5 % and must be explicitly accepted from 15 %.
What the contracts guarantee
- The Router moves only your
tokenIn, only up to the amount of the swap you sent, and only inside that swap. - The output goes straight to the recipient, and the swap reverts unless the recipient's balance grew by at least
minOut. - A transaction sent after its deadline reverts.
- The Executor holds no allowances and ends every swap with a zero balance.
- The fee is capped at 100 bps in the contract; owner powers are limited to the fee, fee exemptions, the Executor address, the owner address and withdrawing accumulated fees. The Router itself is not upgradeable.
See Contracts for details. The contracts are covered by fuzz, invariant and mainnet-fork tests with full coverage of the sources, but they have not yet been audited by a third party.
What you should check yourself
- The Router address in your wallet prompt. Every Tirio swap targets
0x0000000000F315f7C21DcdF4885FB01064f58da5, the same address on every chain. A different target is not Tirio. - The token address, especially for unlisted tokens you pasted. Anyone can deploy a token with any name.
- The approval amount. Exact approvals cover one swap. An unlimited approval lets the Router move any amount of that token on your behalf until you revoke it; revoke by approving zero or with your wallet's allowance tools.
- Minimum received and price impact before you confirm. The minimum is what the contract enforces; the quoted output is what you can expect.
- Slippage. Higher settings accept a worse outcome; taxed tokens usually need 1 % or more.