Contract Powers Registry / base
Uniswap V3 Factory (Base)
0x33128a8fc17869897dce68ed026d694621f6fdfd on base
In one line: retained powers: ownership.
Can this code be replaced?
No proxy pattern found. The standard upgrade slots (EIP-1967, ZeppelinOS)
are empty, the explorer does not declare a proxy, and no implementation() answered.
The code at this address is very likely the code that runs.
Caveat: a custom upgrade mechanism that does not use those slots would not be detected here.
Who holds the keys?
| Owner / admin | 0xabea76658b205696d49b5f91b2a03536cb8a3be1 |
|---|---|
| Found via | owner() |
| That address is | A contract |
owner is a contract — could be a multisig or timelock; this endpoint does not verify which. It could be a multisig, a timelock, or a single-key wrapper — this registry does not open it. Follow the link above to see what that contract can do.
What the privileged role can still do
Each card is a capability found in the code. declared = the contract’s published interface exposes it. bytecode-heuristic = the 4-byte selector appears in the compiled code, which often means the contract implements it — but it can equally be a function this contract calls on another contract. Only a verified source settles that.
Control can be transferred
declaredThe privileged role itself can be handed to another address, or renounced.
Evidence (2)
setOwner(address)abisetOwner(address)bytecode-selector
Is there a bug bounty on this?
The contract name matched 1 live program(s) in my Bounty Radar index. A name match is not proof this address is in scope — open the program and check its asset list.
| Program | Platform | Max bounty | KYC |
|---|---|---|---|
| Uniswap | cantina | $15,500,000 | Required |
Raw facts
| Chain | base (chainId 8453) |
|---|---|
| Contract name | UniswapV3Factory |
| Compiler | v0.7.6+commit.7338295f |
| License | — |
| Bytecode size | 24,535 bytes |
| DELEGATECALL | absent |
| SELFDESTRUCT | absent |
| CREATE2 | present |
| Explorer | view on block explorer ↗ |
How this was produced, and what it cannot tell you
Storage slots, bytecode and eth_call results were read from public RPC nodes;
where the source is verified, the published interface was read too. Nothing here is copied from another
site’s opinion. Generated in 660 ms on 2026-08-29.
- confidence="declared" means the ABI exposes the function. confidence="bytecode-heuristic" means the 4-byte selector appears in the code — usually its own dispatch table, but it can also be a selector this contract CALLS on another contract. Only a verified ABI settles it.
- admin.ownerType="contract" does not mean multisig — this endpoint does not inspect the owner contract.
- bounty.match="name-heuristic" matches a contract NAME to a program name; it is not proof the address is in scope.
What would change the answer: an upgrade after the date above; a power reachable only through a contract this one trusts; or role-based access control, whose holders this registry does not enumerate. Re-read the chain before you rely on it.
Machine-readable
Same facts as JSON, free, no key: /c/base/0x33128a8fc17869897dce68ed026d694621f6fdfd.json.
Live lookups for any address (not just this list) are $0.05 per call.
Want a human-grade read?
This page is automated pattern-matching. If you need someone to actually read the code and tell you what breaks, I do fixed-scope micro-audits — you pay after you read the report.