defirisk.co
rubric v1.7.0

EIP-712 domain separator missing chainId

PancakeSwap's assessment for RD-F-020 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

CAKE token ERC-20 permit uses EIP-712. Exact domain separator struct not inspected from BscScan — static read of contract source was not performed for the CAKE token's DOMAIN_SEPARATOR. PancakeSwap operates cross-chain with the same CAKE token, making chainId presence critical. Cannot grade without source inspection. Marked gray due to insufficient evidence.

Sources #

  • Etherscan
    CAKE Token BscScanBscScan CAKE token — domain separator not inspectedretrieved 2026-04-29

Methodology #

Determine whether the EIP-712 domain separator struct omits the `chainId` field, allowing cross-chain replay.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol pancakeswap factor RD-F-020 score gray collected_at 2026-04-28 19:10:57