Quantum Audit Logo

Is Chainbase Token Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Chainbase Token C
0xc32c…ffc8
BNB Chain Not verifiedLast checked 3d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The ChainbaseOFT contract is an Omnichain Fungible Token (OFT) implementation utilizing LayerZero v2 for cross-chain transfers. The contract is simple, inheriting functionality from audited LayerZero OFT and OpenZeppelin Ownable libraries. No critical or high-severity vulnerabilities were identified. The primary risks are associated with the inherent reliance on the LayerZero protocol's security and the owner's configuration management.

1 Low2 Informational
Volume 24h
$199.0K
Liquidity
$727.5K
Price
$0.06064
Token Age
1y
Top 10 Holders
96.9%

Security Findings

Low

Non-Upgradeability of Contract Logic

L-01The `ChainbaseOFT` contract is implemented as a standard, non-upgradeable contract. This means that any future bug fixes, feature enhancements, or adaptations to evolving LayerZero protocol standards would necessitate deploying an entirely new contract and migrating existing token holders. This process can be complex, costly, and disruptive to users.
IssueThe `ChainbaseOFT` contract is implemented as a standard, non-upgradeable contract. This means that any future bug fixes, feature enhancements, or adaptations to evolving LayerZero protocol standards would necessitate deploying an entirely new contract and migrating existing token holders. This process can be complex, costly, and disruptive to users.
FixWhile non-upgradeability can offer simplicity and immutability guarantees, for long-term projects, consider the implications. If future flexibility for logic updates is desired, a proxy-based upgradeable architecture should be evaluated for new deployments. For the current contract, ensure that the initial design is robust and future-proof to minimize the need for disruptive migrations.
StatusUnresolved
Info

Reliance on LayerZero Protocol Security

I-01The contract's core functionality for cross-chain transfers is entirely dependent on the security and operational integrity of the LayerZero v2 protocol. Any vulnerabilities or compromises within the LayerZero network (e.g., endpoint, relayers, oracles) could directly impact the security and functionality of this OFT. This is an inherent risk when utilizing external bridging protocols.
IssueThe contract's core functionality for cross-chain transfers is entirely dependent on the security and operational integrity of the LayerZero v2 protocol. Any vulnerabilities or compromises within the LayerZero network (e.g., endpoint, relayers, oracles) could directly impact the security and functionality of this OFT. This is an inherent risk when utilizing external bridging protocols.
FixThe project team should actively monitor LayerZero security announcements, audits, and operational status. Diversification strategies or contingency plans for LayerZero-related incidents should be considered for critical applications. Regular review of LayerZero's documentation and security practices is advised.
StatusUnresolved
Info

Owner Privileges and Configuration Management

I-02The contract owner (a 3/5 multisig) has significant control over critical LayerZero configurations, such as setting trusted remote addresses, minimum destination gas, and other parameters. While the use of a multisig mitigates single points of failure, incorrect or malicious configuration by the owner could disrupt cross-chain operations or lead to unintended behavior, such as failed transactions or excessive fees.
IssueThe contract owner (a 3/5 multisig) has significant control over critical LayerZero configurations, such as setting trusted remote addresses, minimum destination gas, and other parameters. While the use of a multisig mitigates single points of failure, incorrect or malicious configuration by the owner could disrupt cross-chain operations or lead to unintended behavior, such as failed transactions or excessive fees.
FixImplement robust internal processes for managing owner keys and executing privileged operations. All configuration changes should undergo thorough review and testing in a staging environment before deployment to production. Access to the multisig should be restricted to authorized personnel only, following strict operational security guidelines.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The ChainbaseOFT contract (7.1 Architecture) is a straightforward implementation, inheriting core logic from the well-audited LayerZero OFT library and OpenZeppelin's Ownable. This approach significantly reduces the attack surface and the likelihood of custom code vulnerabilities (7.2 Code Security). The contract's simplicity and reliance on battle-tested components contribute to a high level of technical security. No complex custom logic was found that could introduce new security flaws.

GovernanceHigh1/10

The contract employs the Ownable pattern (7.3 Access Control), with a 3/5 multisig wallet acting as the owner, which is a strong practice for decentralized control. This owner has significant control over LayerZero-specific configurations, such as setting trusted remote addresses and gas parameters (7.4 Economic). While the multisig mitigates single points of failure (7.5 Governance), the overall economic security is heavily dependent on the LayerZero protocol's integrity (7.6 External) and the careful management of these owner-controlled parameters.

UpgradesLow7/10

The ChainbaseOFT contract is deployed as a standard, non-upgradeable implementation (7.7 Upgrades). This design choice provides immutability but means that any future bug fixes, feature enhancements, or adaptations to LayerZero protocol changes would require a new contract deployment and token migration. While not a vulnerability, it introduces operational complexity for future changes (7.8 Operations).

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

86.6% in wallets10.2% in contracts
Effective Concentration90.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder54.4%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xd9a3…0ab9
Unlocked LP Held By
0x797d…eb550x745b…d37f

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (3-of-5)
  • Top-10 concentration > 70% (96.9% total → 90.7% effective; 86.6% in EOAs, 10.2% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 54.4% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

GUAMedium RiskTrenchesStarterPack (战壕入门包)Medium RiskmemestockMedium RiskGiggle Cat (NIANNIAN)Medium RiskBabySharkMedium Risk吉祥马Medium Risk

Would You Like a More Detailed Audit of Chainbase Token?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit