Quantum Audit Logo

Is Cycle Network Token Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Cycle Network Token CYC
0x5845…7ac6
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

The CycleNetworkToken is an ERC-20 token with LayerZero omnichain capabilities, inheriting from OFT, ERC20Permit, and Ownable. It features a fixed supply minted at deployment and standard EIP-2612 permit functionality. The primary risks stem from the centralized control granted to the owner over LayerZero configurations and the inherent dependency on the LayerZero protocol's security. The contract is immutable, which prevents future upgrades but also eliminates upgrade-related risks.

1 High2 Medium1 Low1 Informational
Volume 24h
$658.1K
Liquidity
$1.11M
Price
$0.07199
Token Age
1y
Top 10 Holders
78.1%

Security Findings

High

Centralized Control by Owner over LayerZero Configuration

H-01The contract inherits `Ownable` and `OFT`. The owner address has significant control over the LayerZero configuration parameters, such as setting send/receive libraries, timeouts, and general configurations via `setConfig`. A compromised owner key could lead to malicious configuration, potentially disrupting cross-chain transfers or redirecting funds.
IssueThe contract inherits `Ownable` and `OFT`. The owner address has significant control over the LayerZero configuration parameters, such as setting send/receive libraries, timeouts, and general configurations via `setConfig`. A compromised owner key could lead to malicious configuration, potentially disrupting cross-chain transfers or redirecting funds.
FixImplement robust security measures for the owner address, such as a multi-signature wallet with a high threshold. Regularly review and audit the owner's permissions and actions. Consider a time-lock for critical configuration changes.
StatusUnresolved
Medium

Reliance on LayerZero Protocol Security

M-01The `CycleNetworkToken` heavily relies on the security and correct functioning of the LayerZero protocol, specifically the `ILayerZeroEndpointV2` contract. Any vulnerabilities or exploits within the LayerZero endpoint or its underlying infrastructure could directly impact the integrity and functionality of cross-chain token transfers.
IssueThe `CycleNetworkToken` heavily relies on the security and correct functioning of the LayerZero protocol, specifically the `ILayerZeroEndpointV2` contract. Any vulnerabilities or exploits within the LayerZero endpoint or its underlying infrastructure could directly impact the integrity and functionality of cross-chain token transfers.
FixProject teams should stay informed about LayerZero security updates, audits, and potential vulnerabilities. Consider implementing monitoring for LayerZero endpoint activity relevant to the token and have contingency plans for potential LayerZero disruptions.
StatusUnresolved
Medium

Delegate Address Privileges

M-02The `OFT` constructor allows setting a `_delegate` address. While the exact powers of this delegate are defined within the `OFT` contract (not fully provided here), delegates typically have permissions to perform certain LayerZero operations on behalf of the OFT. A compromised delegate address could potentially manipulate cross-chain operations.
IssueThe `OFT` constructor allows setting a `_delegate` address. While the exact powers of this delegate are defined within the `OFT` contract (not fully provided here), delegates typically have permissions to perform certain LayerZero operations on behalf of the OFT. A compromised delegate address could potentially manipulate cross-chain operations.
FixCarefully review the `OFT` contract's definition of delegate privileges. If the delegate has significant control, ensure it is a highly secure address, preferably a multi-signature wallet, and its role is clearly defined and monitored. If not strictly necessary, consider setting the delegate to `address(0)`.
StatusUnresolved
Low

Immutability and Lack of Upgradeability

L-01The `CycleNetworkToken` contract is deployed as an immutable contract and does not implement any upgradeability pattern (e.g., proxies). This means that once deployed, its logic cannot be modified or patched. While this reduces upgrade-related risks, it also means that any discovered vulnerabilities or necessary feature enhancements would require a complete redeployment and migration of token holders.
IssueThe `CycleNetworkToken` contract is deployed as an immutable contract and does not implement any upgradeability pattern (e.g., proxies). This means that once deployed, its logic cannot be modified or patched. While this reduces upgrade-related risks, it also means that any discovered vulnerabilities or necessary feature enhancements would require a complete redeployment and migration of token holders.
FixAcknowledge the implications of immutability. Ensure thorough testing and auditing before deployment. For future projects, consider if an upgradeable architecture might be beneficial for long-term maintenance and security patching, weighing the trade-offs.
StatusUnresolved
Info

Fixed Token Supply

I-01The contract mints a fixed supply of 1,000,000,000 tokens (1 billion) to a specified receiver during construction. There are no further minting or burning mechanisms implemented in this contract, ensuring a predictable and non-inflationary supply.
IssueThe contract mints a fixed supply of 1,000,000,000 tokens (1 billion) to a specified receiver during construction. There are no further minting or burning mechanisms implemented in this contract, ensuring a predictable and non-inflationary supply.
FixDocument the fixed supply and its implications for the token's economic model. This is generally a positive security characteristic for a token, providing transparency and predictability.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The contract (7.1 Architecture) is a standard ERC-20 token enhanced with LayerZero's OFT capabilities and EIP-2612 permit functionality. It leverages well-audited OpenZeppelin and LayerZero libraries, contributing to a solid foundation (7.2 Code Security). However, the contract's functionality is heavily reliant on the external LayerZero endpoint (7.6 External), introducing a dependency risk. The owner has significant control over LayerZero configurations (7.3 Access Control), which centralizes power.

GovernanceHigh3/10

The token has a fixed supply of 1 billion tokens minted at deployment (7.4 Economic), ensuring a predictable and non-inflationary model. The `Ownable` pattern grants the deployer significant control over critical LayerZero configurations (7.5 Governance), such as setting send/receive libraries and general parameters. This centralization of power, while common, requires robust security measures for the owner's private key.

UpgradesLow7/10

The CycleNetworkToken contract is immutable and does not implement any upgradeability pattern (7.7 Upgrades). This design choice eliminates risks associated with proxy upgrades, such as storage collisions or incorrect initialization. However, it also means that any future bug fixes or feature enhancements would necessitate a complete redeployment and migration of token holders.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

4.0% in wallets74.1% in contracts
Effective Concentration33.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.5%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x13e3…5b69
Unlocked LP Held By
0x7bd1…13c20xb78b…95a8

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — Multisig (2-of-3)
  • Top-10 concentration > 30% (78.1% total → 33.6% effective; 4.0% in EOAs, 74.1% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 99.5% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • 1 High finding(s) from audit
  • 2 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Baby Ansem (BABYANSEM)High RiskEVAAHigh RiskBubblemaps (BMT)High RiskPIZZAHigh RiskDGrid AI (DGAI)High RiskStupid Kid (傻孩子)High Risk

Would You Like a More Detailed Audit of Cycle Network Token?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit