INTERNALLY REVIEWED · ZERO CRITICAL FINDINGSBNB Smart Chain (BEP-20)UUPS Proxy (ERC-1967)Solidity 0.8.24

J1USD Smart Contract Security & Technical Assessment

Comprehensive architectural analysis and verification report of the J1USD token system on BNB Smart Chain. Reviewed for upgradeability safety, immutable access controls, supply invariants, and multi-venue liquidity segregation.

Assessment Disclosure: This security and technical assessment was conducted internally by the AirJIT development and security team. It is not an independent third-party smart contract audit.

Zero Critical Findings

0 Critical

0 high / 0 critical vulnerabilities identified in core token contracts.

Hard Supply Ceiling

1,000,000,000

1,000,000,000 J1USD immutable cap enforced in bytecode.

Separation of Roles

RBAC Partitioned

Distinct addresses for Admin, Upgrader, Minter, Burner, Pauser.

UUPS Storage Gaps

__gap[42]

42-slot reserved storage gap protecting against state collisions.

VERIFIED ON-CHAIN DEPLOYMENTS

Canonical Contract Addresses & Verification

J1USD executes via a modular OpenZeppelin ERC-1967 UUPS proxy pattern. Below are the verified source contracts deployed on BNB Smart Chain mainnet.

Official Token Proxy
Hold & Trade This Address

J1USDProxy.sol

Canonical user-facing BEP-20 token address. All balances, allowances, and contract storage reside permanently here. Compatible with Grey Wallet, MetaMask, Trust Wallet, and all BNB Chain DEXs.

Proxy StandardERC-1967 (UUPS)
Token StandardBEP-20 (6 Decimals)
Logic Implementation
Do Not Send Funds Here

J1USDTokenUpgradeable.sol

Logic implementation containing compiled business rules, compliance checks, supply ceiling bounds, and role modifiers. Direct initialization is locked at deployment via constructor guard.

Versionv1.0.0 (Internally Reviewed)
Supply Ceiling1,000,000,000 J1USD
Security Notice for Integrators & Wallets: Always route transfers, deposits, and automated liquidity integrations directly to the Proxy address (0xb3B34F032923DeA2ee8476Df26894E8fA9Eb7F54). The implementation address is stateless bytecode; funds directly transferred to the implementation contract cannot be retrieved by users.

COMPLIANCE & POLICY REVIEW

Blacklist, Account Freezing & Sanctions Mechanics

Evaluation of the token's compliance mechanisms. J1USD is an open BEP-20 token that operates an active blacklist and freezing model — not a whitelist — ensuring maximum permissionless composability while enabling legal sanctions enforcement.

PERMISSIONLESSPASS · Permitted

No Whitelist Requirement (Permissionless Transfers)

J1USD has NO transfer whitelist. Any standard Web3 wallet on BNB Smart Chain can receive, hold, send, and trade J1USD freely on DEXs without KYC approval or protocol pre-registration.

Security Assessment:Standard transfer functions (transfer, transferFrom) execute unconditionally for all unflagged accounts. Normal peer-to-peer and decentralized protocol operations require zero permission.
RBAC CONTROLLEDPASS · Guarded

Explicit Blacklist Functionality (Adverse Compliance)

A dedicated BLACKLISTER_ROLE can restrict malicious addresses associated with verified hacks, sanctions, or theft from debiting or crediting funds.

Security Assessment:addToBlacklist() mandates a non-zero bytes32 complianceReference hash for on-chain auditability. Protected system addresses (DEX AMMs and Treasury) are mathematically immune to blacklist lockout.
DISPUTE ISOLATIONPASS · Isolated

Precision Partial & Full Account Freezing

The contract supports both freezeAccount() and freezeBalance(amount). During commercial disputes, only the disputed amount is locked, preserving liquidity of remaining funds.

Security Assessment:availableBalanceOf(account) dynamically isolates available from frozen balances. Innocent surplus funds remain 100% transferrable by the holder even during an active dispute investigation.
RESTRICTEDPASS · Strict Restraint

Certified Legal Wipe Protection

WIPER_ROLE may destroy frozen balances only pursuant to binding court or regulatory directives. Arbitrary wallet asset destruction is structurally impossible.

Security Assessment:Reverts with WipeRequiresRestrictedAccount if called against an unflagged or unfrozen address. Reverts with WipeExceedsFrozenBalance if the requested wipe exceeds frozen funds.

Contract-Level Hook Verification: _update(), _approve(), and transferFrom()

The bytecode implements strict debit and credit sanity validations inside _update(from, to, amount):

Debits (_requireCanDebit)

Sender must NOT be blacklisted (!isBlacklisted), account must NOT be frozen (!isAccountFrozen), and requested transfer amount cannot exceed availableBalanceOf.

Credits (_requireCanCredit)

Recipient must NOT be blacklisted and must NOT be frozen. Prevents bad actors from laundering illicit funds into restricted custody wallets.

Approvals (_approve)

Both the token owner and spender must be free of restrictions. Restricted entities are blocked from delegating allowances or executing third-party transfers.

SMART CONTRACT ARCHITECTURE

Security Mechanisms & Invariant Analysis

In-depth audit evaluation of J1USD core components: proxy upgrade safety, cryptographic deduplication, isolation of concerns, and emergency safeguards.

UUPS Upgradeability Safety

Built on OpenZeppelin's UUPS standard. State variables and user balances are stored strictly in proxy slots. The implementation constructor invokes _disableInitializers() to ensure the implementation logic cannot be claimed or initialized independently.

Storage safety: 42-slot reserved gap (__gap[42]) prevents memory layout corruption across future upgrades.

Hard Supply Ceiling Invariant

Unlike uncapped stablecoins, J1USD enforces a contract-level supplyCeiling. Every mint() checks that totalSupply() + amount <= supplyCeiling. The admin is mathematically prohibited from lowering the ceiling below current supply.

Maximum supply ceiling: 1,000,000,000.000000 J1USD (6 decimals).

Idempotent Event Deduplication

Minting and burning operations mandate a unique bytes32 reference hash (issuanceReference / burnReference). If a transaction attempts to reuse a reference, it instantly reverts with ReferenceAlreadyUsed.

Prevents operator replay vulnerabilities, double-issuance, and indexing drift.

Timelocked Admin Transitions

Leverages AccessControlDefaultAdminRulesUpgradeable. Admin role transfers cannot execute in a single block; they enforce a mandatory time delay (defaultAdminDelay), providing a failsafe against hostile compromise.

Separation of roles: Upgrader, Minter, Burner, and Pauser operate independently.

Precision Partial Freezing

Rather than solely blacklisting entire accounts, J1USD introduces freezeBalance. Contested compliance amounts can be frozen while availableBalanceOf permits legitimate spending.

Protects innocent balances during commercial disputes.

Protected System Addresses

Core protocol addresses (PancakeSwap pools, treasury, and operational infrastructure) are designated as protectedSystemAddress, rendering them immune to freeze or blacklist locks.

Prevents accidental or malicious denial-of-service on public DEX trading pairs.

AUTHORIZATION MATRIX

Role-Based Access Control (RBAC) Permissions

Verification of privileges across admin, issuance, burning, compliance, and emergency actors. All privileged functions require explicit cryptographic signatures matching assigned roles.

Role IdentifierPrivileged Function(s)Security Controls & Invariants
DEFAULT_ADMIN_ROLE0x00 (Admin Root)Configures role assignments, updates supply ceiling limits, and flags protected system addresses.Governed by OpenZeppelin AccessControlDefaultAdminRules with mandatory timelock delay.
UPGRADER_ROLEkeccak256('UPGRADER_ROLE')Authorizes UUPS implementation logic upgrades in _authorizeUpgrade().Restricted strictly to multisig protocol governance; cannot alter state without valid contract deployment.
MINTER_ROLEkeccak256('MINTER_ROLE')Issues new J1USD tokens against verified collateral or protocol settlement requirements.Strictly bounded by the immutable supplyCeiling and unique issuanceReference deduplication.
BURNER_ROLEkeccak256('BURNER_ROLE')Reduces token supply during redemption or protocol debt clearance.Requires unique burnReference. Narrowly scoped bypass allows burning from restricted accounts to maintain protocol solvency.
PAUSER_ROLEkeccak256('PAUSER_ROLE')Activates or deactivates emergency circuit breaker halting standard transfers.Emergency defensive capability for black-swan events or bridge anomalies.
BLACKLISTER_ROLEkeccak256('BLACKLISTER_ROLE')Adds or removes addresses from global debit/credit blacklist.Cannot target addresses designated under protectedSystemAddress. Requires compliance tracking reference.
FREEZER_ROLEkeccak256('FREEZER_ROLE')Freezes whole accounts or partial balances (freezeBalance, freezeAllCurrentBalance).Enables freezing specific contested amounts while keeping remaining balance available. System addresses immune.
WIPER_ROLEkeccak256('WIPER_ROLE')Destroys frozen balances pursuant to certified judicial or regulatory court order.Can only wipe accounts already frozen or blacklisted; cannot exceed frozen balance amount.
RESCUE_ROLEkeccak256('RESCUE_ROLE')Recovers unrelated third-party BEP-20 tokens sent in error.Strictly prohibited from touching J1USD token balances (RescueProhibitedToken).

LIQUIDITY INFRASTRUCTURE & POOLS ASSESSMENT

On-Chain DEX Liquidity vs. Centralized Secondary Pools

J1USD balances non-custodial decentralized AMM markets on BNB Smart Chain with centralized off-chain order books. Here is the technical breakdown of pool addresses, live trading links, and security boundaries.

On-Chain Decentralized Liquidity (DEX)

Automated Market Maker Pools

Non-custodial smart contract liquidity pools operating natively on BNB Smart Chain via PancakeSwap. Zero counterparty custody; trades execute purely peer-to-contract through immutable bytecode.

PancakeSwap V3 · J1USD / USDC
PRIMARY0.05% fee

Concentrated liquidity pool anchoring J1USD tight to 1.00 USD Coin. Designated system address protected from compliance freezes.

PancakeSwap V2 · J1USD / JIT
ECOSYSTEM0.25% fee

Decentralized AMM bridge interlinking the AirJIT utility token (JIT) and protocol settlement asset (J1USD).

Off-Chain & Centralized Secondary Pools

Internal Order Book Pools

AirJIT quotes secondary markets across major collateral pairs off-chain without dedicated smart contract addresses. Trade settlement is executed via centralized high-throughput matching engines.

Zero Smart Contract Minting Privilege

Off-chain servers possess zero private keys authorized to mint or burn J1USD tokens on BNB Smart Chain.

1:1 On-Chain Asset Backing

Internal off-chain account balances are strictly bounded by verified on-chain proxy token deposits.

ASSESSMENT FINDINGS & THREAT MODELING

Attack Vector Analysis & Formal Defenses

Comprehensive review of potential economic, mathematical, and cryptographic attack surfaces investigated during the technical review.

IMMUNE

Reentrancy Attacks

The token strictly inherits OpenZeppelin ERC-20 state updates (_update) without making untrusted external contract calls before balance commits. Complies fully with Checks-Effects-Interactions.

NOT APPLICABLE

Oracle & Spot Manipulation

The J1USD token ledger does not consult external pricing oracles during transfers or approvals. Balance arithmetic is 100% internal, eliminating flash-loan price manipulation exploits.

PREVENTED

Implementation Hijacking

The logic implementation constructor executes _disableInitializers() on deployment. The underlying implementation contract cannot be independently initialized or owned by an attacker.

MITIGATED

Hostile Governance Takeover

Admin role reassignments enforce an unalterable time delay (defaultAdminDelay). Single-key compromises cannot instantaneously seize administrative control of the token.

SECURITY INVARIANTS

Formally Checked Security Invariants

Summary of bytecode checks verifying that system integrity is preserved across all edge cases.

Status · Result

Supply Ceiling Enforceability

Minting operations revert with SupplyCeilingExceeded if totalSupply() + amount exceeds the on-chain ceiling. Admin is strictly prohibited from lowering the ceiling below current circulating supply.

Enforcing MechanismsupplyCeiling state check in mint()
Status · Result

Mint & Burn Replay Deduplication

Every mint and burn transaction requires an idempotent bytes32 reference identifier. Duplicate calls with the same reference revert with ReferenceAlreadyUsed, preventing double-execution.

Enforcing Mechanism_usedIssuanceReferences & _usedBurnReferences mappings
Status · Result

Logic Implementation Hijack Mitigation

The implementation contract locks initializers in its constructor. Malicious actors cannot initialize or claim ownership over the underlying logic contract directly.

Enforcing Mechanismconstructor _disableInitializers() call
Status · Result

Storage Layout Collision Protection

Proxy storage adheres to standard ERC-1967 slots. A reserved 42-word storage gap ensures future contract upgrades will not overwrite existing state variables.

Enforcing MechanismERC-1967 standard storage slots + uint256[42] gap
Status · Result

Hostile Admin Takeover Mitigation

Transferring DEFAULT_ADMIN_ROLE is not instantaneous. A two-step process with an enforced time delay prevents sudden hostile takeover or single-key compromise disasters.

Enforcing MechanismAccessControlDefaultAdminRules with defaultAdminDelay
Status · Result

Critical Infrastructure Immunity

Registered system addresses (DEX pools, treasury, operational contracts) cannot be frozen or blacklisted. Eliminates denial-of-service risks against public liquidity rails.

Enforcing Mechanism_requireNotProtected() check in compliance functions
Status · Result

Accidental Self-Token Rescue Lockout

The rescueERC20 function enables recovery of third-party tokens mistakenly sent to the contract, but explicitly blocks calls targeting the J1USD token contract itself.

Enforcing MechanismRescueProhibitedToken check in rescueERC20()
Status · Result

Global Emergency Circuit Breaker

Authorized PAUSER_ROLE can immediately halt token transfers and approvals in the event of upstream market anomaly, while retaining legal compliance wipe operations.

Enforcing MechanismwhenNotPaused modifier on transfer/mint/approve
Status · Result

Isolated Balance Freezing Precision

Allows contested compliance balances to be frozen without locking the holder's entire wallet, leaving surplus available funds fully liquid.

Enforcing MechanismavailableBalanceOf() arithmetic isolation

RESPONSIBLE DISCLOSURE

Report a Vulnerability

AirJIT maintains a proactive vulnerability disclosure program. If you discover a security vulnerability in the J1USD proxy, implementation, or smart contract infrastructure, report it responsibly.

Encrypt sensitive reports using PGP when possible. We acknowledge all legitimate submissions within 24 hours.