Quantum Audit Logo

Is Bubblemaps Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Bubblemaps BMT
0x7d81…1b62
BNB Chain Not verifiedLast checked 3d ago 1 audit on record
Executive SummaryAI Copilot

The MyOFT contract is an Omnichain Fungible Token (OFT) implementation built on LayerZero v2 and OpenZeppelin's Ownable standard. The contract itself is minimal, primarily inheriting functionality from well-audited external libraries. Key risks identified relate to the inherent centralization of administrative control, the critical dependency on the LayerZero protocol's security, and the potential for misconfiguration of cross-chain parameters by the owner. The owner is a multisig, which significantly mitigates single-point-of-failure risks.

3 Medium1 Low
Volume 24h
$21.2K
Liquidity
$360.3K
Price
$0.01827
Token Age
1y
Top 10 Holders
91.8%

Security Findings

Medium

Centralized Control by Owner/Delegate

M-01The MyOFT contract inherits from OpenZeppelin's Ownable, granting the designated `_delegate` address (which is the owner) significant administrative control. This owner can configure various LayerZero parameters, including setting send/receive libraries, minimum destination gas, and LayerZero token addresses. While the provided information indicates the owner is a multisig, this still represents a centralized point of control over critical cross-chain functionality.
IssueThe MyOFT contract inherits from OpenZeppelin's Ownable, granting the designated `_delegate` address (which is the owner) significant administrative control. This owner can configure various LayerZero parameters, including setting send/receive libraries, minimum destination gas, and LayerZero token addresses. While the provided information indicates the owner is a multisig, this still represents a centralized point of control over critical cross-chain functionality.
FixEnsure the owner address is a robustly secured and actively managed multisig wallet. Implement strict internal governance procedures for any administrative actions, especially those involving LayerZero configuration changes. Consider implementing time-locks for critical parameter changes to allow for community review or emergency intervention.
StatusUnresolved
Medium

Critical Dependency on LayerZero Protocol Security

M-02The MyOFT contract's core functionality, specifically cross-chain token transfers, is entirely dependent on the security and correct operation of the external LayerZero v2 protocol and its endpoint. Any vulnerabilities, exploits, or operational failures within the LayerZero protocol itself could directly impact the OFT, potentially leading to frozen assets, loss of funds, or disruption of cross-chain services.
IssueThe MyOFT contract's core functionality, specifically cross-chain token transfers, is entirely dependent on the security and correct operation of the external LayerZero v2 protocol and its endpoint. Any vulnerabilities, exploits, or operational failures within the LayerZero protocol itself could directly impact the OFT, potentially leading to frozen assets, loss of funds, or disruption of cross-chain services.
FixAcknowledge and monitor the inherent risks associated with relying on an external cross-chain messaging protocol. Stay informed about LayerZero security updates, audits, and any reported vulnerabilities. Implement robust monitoring for LayerZero endpoint health and cross-chain transaction finality.
StatusUnresolved
Medium

Potential for Misconfiguration of LayerZero Parameters

M-03The owner/delegate has the ability to set various LayerZero-specific parameters, such as `minDstGas`, `lzToken`, `sendLibrary`, and `receiveLibrary`. Incorrect or malicious configuration of these parameters could lead to several issues, including failed cross-chain transactions, unexpected or excessive transaction fees for users, or even the inability to transfer tokens across certain chains, effectively halting the OFT's primary function.
IssueThe owner/delegate has the ability to set various LayerZero-specific parameters, such as `minDstGas`, `lzToken`, `sendLibrary`, and `receiveLibrary`. Incorrect or malicious configuration of these parameters could lead to several issues, including failed cross-chain transactions, unexpected or excessive transaction fees for users, or even the inability to transfer tokens across certain chains, effectively halting the OFT's primary function.
FixEstablish a rigorous process for reviewing and testing all LayerZero parameter changes. Implement a 'dry run' or staging environment to validate configurations before applying them to the mainnet contract. Provide clear documentation and guidelines for the multisig signers regarding the implications of each configurable parameter.
StatusUnresolved
Low

Lack of Direct Emergency Pause Mechanism

L-01The MyOFT contract does not implement a direct, contract-specific emergency pause mechanism. While the underlying LayerZero protocol may have its own emergency controls, a dedicated pause function within the OFT contract could provide an additional layer of defense, allowing the owner to temporarily halt cross-chain transfers in response to a critical vulnerability or exploit specific to the OFT or its immediate environment.
IssueThe MyOFT contract does not implement a direct, contract-specific emergency pause mechanism. While the underlying LayerZero protocol may have its own emergency controls, a dedicated pause function within the OFT contract could provide an additional layer of defense, allowing the owner to temporarily halt cross-chain transfers in response to a critical vulnerability or exploit specific to the OFT or its immediate environment.
FixConsider adding a `Pausable` mechanism (e.g., from OpenZeppelin) to the MyOFT contract. This would allow the owner to pause and unpause cross-chain operations in emergency situations, providing a circuit breaker for unforeseen events. Ensure that any pause mechanism is carefully designed to avoid creating new attack vectors or centralizing too much power.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The contract (7.1 Architecture) is a straightforward implementation of LayerZero's OFT standard, inheriting from battle-tested OpenZeppelin and LayerZero libraries. This minimizes direct code security risks (7.2 Code Security) within MyOFT itself. However, the contract's functionality is entirely dependent on the security and correct operation of the external LayerZero v2 protocol (7.6 External). Any vulnerabilities in the LayerZero endpoint or messaging libraries could directly impact the OFT's cross-chain capabilities and asset safety.

GovernanceHigh3/10

The contract utilizes OpenZeppelin's Ownable pattern, granting significant administrative control to a single owner address (7.3 Access Control). This owner, designated as the `_delegate` in the constructor, is responsible for configuring critical LayerZero parameters (7.8 Operations) that affect cross-chain transfers and fees. While the prefill indicates the owner is a multisig (7.5 Governance), which enhances security, incorrect configuration could still lead to economic issues (7.4 Economic) such as failed transactions or unexpected costs.

UpgradesLow7/10

The MyOFT contract is not designed as an upgradeable proxy (7.7 Upgrades). It is a standard implementation contract, meaning its logic is immutable once deployed. This simplifies the upgrade safety analysis, as there are no proxy-specific vulnerabilities to consider. Any future changes would require a new deployment and migration.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

43.1% in wallets48.7% in contracts
Effective Concentration62.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 1 more pairShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.9%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x40b0…cc85
Unlocked LP Held By
0x5d36…7bf00x12e3…eb970x9ceb…ec5e0x5e91…fac10x4125…df6c0x5dba…a82a0x3a8c…f9ca0x8f3b…8cad0x5138…d7300x5036…6a20

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (3-of-5)
  • Top-10 concentration > 50% (91.8% total → 62.6% effective; 43.1% in EOAs, 48.7% in contracts — heavy)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 99.9% (independent LP — depth risk, pool = 79% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 79% of DEX liquidity)
  • 3 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Baby Ansem (BABYANSEM)High RiskEVAAHigh RiskPIZZAHigh RiskDGrid AI (DGAI)High RiskStupid Kid (傻孩子)High RiskChainOpera AI (COAI)High Risk

Would You Like a More Detailed Audit of Bubblemaps?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit