PancakeSwap review: cheap BNB Chain swaps, and where the real risk sits
We swapped and farmed on PancakeSwap across several BNB Chain sessions, read through its audit history and the pool exploits from the past two years, and worked out where the danger actually comes from.
Our verdict
PancakeSwap's core contracts have run since September 2020 without a confirmed exploit of the protocol itself, backed by audits from seven separate security firms including OpenZeppelin, Quantstamp, PeckShield, SlowMist and CertiK. Every loss we found in the past two years traces back to an individual pool, a scam token, or a compromised social account rather than a flaw in PancakeSwap's own code. That distinction matters for how you use it: swapping a known token is close to as safe as DEX trading gets, and farming a brand-new pair someone just launched is a different risk profile entirely.
Best for: BNB Chain users swapping established tokens who check a pool's age before farming it

PancakeSwap is the exchange most BNB Chain activity runs through by default, and that scale alone does not tell you whether it is safe. We swapped a handful of established tokens, staked LP tokens into a farm, and then spent as much time reading through PancakeSwap's audit history and its actual exploit record as we spent using the product itself.
Swapping costs almost nothing on BNB Chain
A swap on PancakeSwap typically carries a 0.25 percent fee split between liquidity providers and a CAKE burn, and BNB Chain's gas costs keep the network fee down to a fraction of a cent per transaction. That combination makes PancakeSwap genuinely cheap to use for routine trading, cheaper in gas terms than swapping the same pair on Ethereum mainnet through most competitors.

Farming works the way most Uniswap-style DEXes handle it: deposit two tokens into a pool, receive an LP token representing that position, then stake the LP token into a farm to earn CAKE rewards on top of the trading fees the pool generates. The mechanics are standard. The risk profile depends entirely on which pool you pick, and that is where most of the actual danger in using PancakeSwap lives.
The audit history is genuinely deep
PancakeSwap's V3 and StableSwap contracts have been reviewed by OpenZeppelin and Quantstamp, with PeckShield, SlowMist and CertiK covering other parts of the stack, for a combined seven security firms and a $250,000 bug bounty sitting on top.





