Quantum Audit Logo

Is Coinbase Wrapped ZEC Safe?

On-chain security analysis — is it a scam or legit?

Coinbase Wrapped ZEC CBZEC
0xb200…b2ec
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This report is based on an audit of a contract deployed at 0xb2000000000000000000008501b13360000cb2ec on the Base network. No source code was provided for analysis, limiting the scope of this audit to publicly available on-chain information and general security considerations. Therefore, specific code-level vulnerabilities cannot be identified.

4 Informational
Volume 24h
$1.40M
Liquidity
$878.4K
Price
$1583.2400
Token Age
1y
Top 10 Holders
0.0%

Security Findings

Info

Source Code Not Provided for Audit

I-01The primary source code for the contract at 0xb200…b2ec was not provided for this audit. This severely limits the scope of the security review, as detailed analysis of the contract's logic, potential vulnerabilities (7.2 Code Security), and adherence to best practices cannot be performed.
IssueThe primary source code for the contract at was not provided for this audit. This severely limits the scope of the security review, as detailed analysis of the contract's logic, potential vulnerabilities (7.2 Code Security), and adherence to best practices cannot be performed.
FixAlways provide the full, verified source code for all contracts intended for audit. This enables a thorough security assessment and builds trust with users and the community.
StatusUnresolved
Info

Contract Source Code Not Verified on Block Explorer

I-02The contract at 0xb200…b2ec is not verified on the Base network block explorer (is_verified: false). This means the deployed bytecode cannot be publicly matched against its corresponding source code, making it impossible for users, auditors, or other protocols to independently verify its intended functionality or security properties. This impacts transparency and trust (7.8 Operations).
IssueThe contract at is not verified on the Base network block explorer (is_verified: false). This means the deployed bytecode cannot be publicly matched against its corresponding source code, making it impossible for users, auditors, or other protocols to independently verify its intended functionality or security properties. This impacts transparency and trust (7.8 Operations).
FixVerify the contract's source code on the Base network block explorer. This is a fundamental step for transparency and allows for public scrutiny and understanding of the contract's operations.
StatusUnresolved
Info

Unknown Contract Functionality and Purpose

I-03Without the source code, the specific functionality, purpose, and intended behavior of the contract at 0xb200…b2ec remain unknown. This prevents any assessment of its architecture (7.1 Architecture), economic model (7.4 Economic), or potential interactions with other protocols (7.6 External).
IssueWithout the source code, the specific functionality, purpose, and intended behavior of the contract at remain unknown. This prevents any assessment of its architecture (7.1 Architecture), economic model (7.4 Economic), or potential interactions with other protocols (7.6 External).
FixClearly document the contract's intended functionality, design principles, and any external dependencies. Providing source code is the best way to convey this information.
StatusUnresolved
Info

Inability to Assess Access Control Mechanisms

I-04The absence of source code makes it impossible to analyze the access control mechanisms implemented within the contract (7.3 Access Control). Critical functions might be callable by unauthorized entities, or privileged roles might be poorly secured, leading to potential misuse or loss of funds.
IssueThe absence of source code makes it impossible to analyze the access control mechanisms implemented within the contract (7.3 Access Control). Critical functions might be callable by unauthorized entities, or privileged roles might be poorly secured, leading to potential misuse or loss of funds.
FixImplement robust access control using established patterns (e.g., OpenZeppelin's Ownable or AccessControl). Ensure all privileged functions are adequately protected and roles are clearly defined and managed.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Without access to the contract's source code (7.2 Code Security), a comprehensive technical security assessment is impossible. The lack of verification means the deployed bytecode cannot be definitively linked to any known source, introducing significant trust and security risks. This prevents analysis of common vulnerabilities like reentrancy, integer overflows, or access control flaws (7.3 Access Control).

GovernanceHigh3/10

The economic model (7.4 Economic) and governance structure (7.5 Governance) of the contract cannot be determined without source code. This introduces a high level of uncertainty regarding potential economic exploits, such as flash loan attacks or oracle manipulation, and whether critical functions are protected by appropriate governance mechanisms. External dependencies (7.6 External) are also unknown.

UpgradesMedium5/10

The contract is not identified as a proxy (is_proxy: false), suggesting it is not directly upgradeable (7.7 Upgrades). This reduces the risk associated with upgrade mechanisms, as there is no upgrade logic to exploit. However, if the contract relies on external, upgradeable components, those risks would remain unassessed.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Liquidity NOT locked (owner can withdraw — rug-pull risk)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

OWBMedium RiskFlowerMedium RiskStrategy Inc. (MSTRC)Medium RiskAmazon.com Inc. (AMZNC)Medium RiskBitVault Signal (BV7X)Medium RiskMoltbook (MOLT)Medium Risk

Would You Like a More Detailed Audit of Coinbase Wrapped ZEC?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit