Quantum Audit Logo

Is ApeCoin Safe?

On-chain security analysis — is it a scam or legit?

ApeCoin APE
0x7f9f…1e98
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The ApeOFT contract is an Omnichain Fungible Token (OFT) built on LayerZero, inheriting from OpenZeppelin's Ownable. The contract's primary function is to allow the owner to perform a one-time initialization, minting an initial supply to a specified lockbox address. The audit identified a High-severity issue related to centralized owner control, a Medium-severity issue concerning irreversible initialization parameters, and a Low-severity issue regarding external dependency on the LayerZero protocol. The contract's code quality is high, utilizing established libraries and clear logic. The owner is a multisig, which mitigates some centralization risks.

1 High1 Medium1 Low1 Informational
Volume 24h
$64.8K
Liquidity
$47.8K
Price
$0.1596
Token Age
1y
Top 10 Holders
99.9%

Security Findings

High

Centralized Control by Owner

H-01The `ApeOFT` contract inherits `Ownable`, granting the deployer (or the specified `_delegate` in the constructor) exclusive control over critical functions, including the one-time `initialize` function that mints the initial token supply. This centralization introduces a single point of failure; if the owner's private keys or multisig are compromised, an attacker could potentially misuse these privileges.
IssueThe `ApeOFT` contract inherits `Ownable`, granting the deployer (or the specified `_delegate` in the constructor) exclusive control over critical functions, including the one-time `initialize` function that mints the initial token supply. This centralization introduces a single point of failure; if the owner's private keys or multisig are compromised, an attacker could potentially misuse these privileges.
FixEnsure the owner address is a robustly secured multi-signature wallet with a high threshold and geographically distributed signers. Regularly review and audit the multisig's operational procedures and key management. Consider implementing a timelock for critical administrative actions if the protocol's design allows for it, providing a delay for detection and intervention.
StatusUnresolved
Medium

Irreversible Initialization Parameters

M-01The `initialize` function, callable only once by the owner, sets the `_l2LockBox` address and `_initialSupply`. Once executed, these parameters are immutable. Any error in these values during the initial call cannot be corrected without redeploying the contract, which could lead to significant operational issues or loss of funds if the initial supply is minted to an incorrect address or with an incorrect amount.
IssueThe `initialize` function, callable only once by the owner, sets the `_l2LockBox` address and `_initialSupply`. Once executed, these parameters are immutable. Any error in these values during the initial call cannot be corrected without redeploying the contract, which could lead to significant operational issues or loss of funds if the initial supply is minted to an incorrect address or with an incorrect amount.
FixImplement a rigorous pre-deployment checklist and conduct thorough testing on a testnet to verify the correctness of `_l2LockBox` and `_initialSupply` before deploying and initializing on the mainnet. Consider a timelock for the `initialize` call if feasible, allowing for a grace period to detect and react to misconfigurations.
StatusUnresolved
Low

External Dependency on LayerZero Protocol

L-01The `ApeOFT` contract is built upon the LayerZero OFT standard, making its cross-chain functionality and overall security dependent on the LayerZero protocol's integrity, security, and operational stability. Any vulnerabilities, misconfigurations, or disruptions within the LayerZero ecosystem could potentially impact the `ApeOFT` token's functionality or security.
IssueThe `ApeOFT` contract is built upon the LayerZero OFT standard, making its cross-chain functionality and overall security dependent on the LayerZero protocol's integrity, security, and operational stability. Any vulnerabilities, misconfigurations, or disruptions within the LayerZero ecosystem could potentially impact the `ApeOFT` token's functionality or security.
FixMonitor LayerZero protocol announcements, security audits, and operational status closely. Be prepared to react to any potential issues or upgrades within the LayerZero ecosystem that might affect the `ApeOFT` token. Maintain clear communication channels with the LayerZero team.
StatusUnresolved
Info

Lack of Explicit Event for Initial Owner/Delegate

I-01While the `Ownable` contract emits an `OwnershipTransferred` event upon ownership changes, the `ApeOFT` contract itself does not emit a specific event during its constructor or `initialize` function to explicitly log the initial owner or the `_delegate` address set in the constructor. This can make historical tracking of the initial owner less straightforward for off-chain tools.
IssueWhile the `Ownable` contract emits an `OwnershipTransferred` event upon ownership changes, the `ApeOFT` contract itself does not emit a specific event during its constructor or `initialize` function to explicitly log the initial owner or the `_delegate` address set in the constructor. This can make historical tracking of the initial owner less straightforward for off-chain tools.
FixConsider emitting a custom event in the constructor or `initialize` function to explicitly log the initial owner or delegate address for enhanced transparency and easier historical tracking. For example: `event InitialOwnerSet(address indexed owner);`
StatusUnresolved

Category Ratings

TechnicalLow8/10

The contract exhibits good code quality (7.2 Code Security), leveraging battle-tested OpenZeppelin and LayerZero libraries. The architecture (7.1 Architecture) is straightforward, extending standard OFT functionality with a single initialization step. Access control (7.3 Access Control) is primarily managed by the `Ownable` pattern, ensuring that critical functions like `initialize` are restricted to the owner. However, the centralized nature of this control introduces a single point of failure, as highlighted by the High-severity finding.

GovernanceHigh3/10

The economic model (7.4 Economic) involves a one-time initial minting of tokens to a specified lockbox, which is a critical setup step. Governance (7.5 Governance) is centralized, with the owner (a multisig) having exclusive control over initialization and other administrative functions inherited from `OFT` and `Ownable`. While the use of a multisig for the owner (7.8 Operations) is a positive operational security practice, the irreversible nature of the initialization parameters presents a moderate risk if incorrect values are used.

UpgradesLow7/10

The ApeOFT contract is not designed as an upgradeable proxy (7.7 Upgrades). Therefore, it does not inherit the specific upgrade-related risks associated with proxy patterns. Any changes to the contract's logic would require a new deployment and migration.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

0.1% in wallets99.9% in contracts
Effective Concentration40.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x4153…22a4
Unlocked LP Held By
0x4d09…ad40

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-7)
  • Top-10 concentration > 30% (99.9% total → 40.0% effective; 0.1% in EOAs, 99.9% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 56% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 56% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

BoopMedium RiskRAINMedium RiskWrapped liquid staked Ether 2.0 (WSTETH)Medium RiskAave Token (AAVE)Medium RiskChainLink Token (LINK)Medium RiskPepeMedium Risk

Would You Like a More Detailed Audit of ApeCoin?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit