Quantum Audit Logo

Is Decentraland Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Decentraland MANA
0x0f5d…c942
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The MANAToken contract is an ERC-20 token with standard functionalities including minting, burning, and pausing. It utilizes the Ownable pattern for administrative control and SafeMath for arithmetic operations. The primary risks stem from the significant centralized control held by the owner, which is typical for tokens of this era. The contract is not upgradeable, simplifying its architecture.

2 High2 Medium1 Low6 Informational
Volume 24h
$81.2K
Liquidity
$92.3K
Price
$0.1023
Token Age
6y
Top 10 Holders
45.3%

Security Findings

High

Centralized Control by Owner

H-01The `owner` address has extensive control over the token's core functionalities. This includes the ability to `mint` an unlimited number of new tokens, which can dilute the value of existing tokens, and the ability to `pause` all token transfers, effectively freezing the token (7.3 Access Control, 7.4 Economic). This presents a single point of failure and a high centralization risk.
IssueThe `owner` address has extensive control over the token's core functionalities. This includes the ability to `mint` an unlimited number of new tokens, which can dilute the value of existing tokens, and the ability to `pause` all token transfers, effectively freezing the token (7.3 Access Control, 7.4 Economic). This presents a single point of failure and a high centralization risk.
FixImplement a multi-signature wallet (e.g., Gnosis Safe) for the `owner` address to distribute control and require multiple approvals for critical operations like minting or pausing. This significantly reduces the risk of a single point of failure or malicious action.
StatusUnresolved
High

What the token's controller can do

QA-POWERSThe contract lets its controller — a ProxyAdmin contract — mint new supply; pause all transfers. Nothing independent vouches for whoever holds them, so each is a live risk to holders.
IssueThe contract lets its controller — a ProxyAdmin contract — mint new supply; pause all transfers. Nothing independent vouches for whoever holds them, so each is a live risk to holders.
FixCheck who holds these powers and whether a timelock or multisig stands between them and holders.
StatusAcknowledged
Medium

Missing Event for Ownership Transfer

M-01The `transferOwnership` function in the `Ownable` contract allows the owner to transfer administrative control to a new address, but it does not emit an event to signal this critical change (7.5 Governance). This makes it difficult for off-chain systems, users, or monitoring tools to track ownership changes reliably.
IssueThe `transferOwnership` function in the `Ownable` contract allows the owner to transfer administrative control to a new address, but it does not emit an event to signal this critical change (7.5 Governance). This makes it difficult for off-chain systems, users, or monitoring tools to track ownership changes reliably.
FixAdd an `event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);` and emit it within the `transferOwnership` function after the `owner` is updated.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 90.6% is held, unlocked, by 10 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 53% of the token's DEX liquidity; the other pools were not assessed.
Issue0.0% of the pool's LP is burned or time-locked. 90.6% is held, unlocked, by 10 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 53% of the token's DEX liquidity; the other pools were not assessed.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Low

SafeMath.div Does Not Explicitly Check for Division by Zero

L-01The `div` function in the `SafeMath` library, as implemented, does not explicitly check if the divisor `b` is zero before performing the division (7.2 Code Security). While Solidity's default behavior would revert on division by zero, an explicit `require(b > 0)` check would make the intent clearer and provide a more informative error message. In this specific contract, `div` is not used in a critical path with user-controlled input.
IssueThe `div` function in the `SafeMath` library, as implemented, does not explicitly check if the divisor `b` is zero before performing the division (7.2 Code Security). While Solidity's default behavior would revert on division by zero, an explicit `require(b > 0)` check would make the intent clearer and provide a more informative error message. In this specific contract, `div` is not used in a critical path with user-controlled input.
FixFor robustness, consider adding `require(b > 0, "SafeMath: division by zero");` at the beginning of the `div` function in `SafeMath`.
StatusUnresolved
Info

Outdated Solidity Compiler Version

I-01The contract is compiled with Solidity version `^0.4.11`. This version is significantly outdated and lacks many security features, optimizations, and bug fixes present in newer compiler versions (e.g., 0.6.x, 0.8.x) (7.2 Code Security). While the code itself might be robust for its era, newer versions offer improved safety and better error handling.
IssueThe contract is compiled with Solidity version `^0.4.11`. This version is significantly outdated and lacks many security features, optimizations, and bug fixes present in newer compiler versions (e.g., 0.6.x, 0.8.x) (7.2 Code Security). While the code itself might be robust for its era, newer versions offer improved safety and better error handling.
FixFor any new deployments or significant upgrades, consider migrating to a recent, stable Solidity compiler version (e.g., 0.8.x) to leverage modern security enhancements and best practices.
StatusUnresolved
Info

ERC-20 Approve Race Condition Mitigation Trade-off

I-02The `approve` function includes a check `require((_value == 0) || (allowed[msg.sender][_spender] == 0));` to mitigate the known ERC-20 `approve` race condition (7.2 Code Security). While this prevents a specific front-running scenario, it also restricts legitimate use cases where a user might want to increase an existing allowance without first setting it to zero, requiring two transactions instead of one.
IssueThe `approve` function includes a check `require((_value == 0) || (allowed[msg.sender][_spender] == 0));` to mitigate the known ERC-20 `approve` race condition (7.2 Code Security). While this prevents a specific front-running scenario, it also restricts legitimate use cases where a user might want to increase an existing allowance without first setting it to zero, requiring two transactions instead of one.
FixAcknowledge this design choice. For future token designs, consider using `increaseAllowance` and `decreaseAllowance` functions (as introduced in OpenZeppelin's ERC-20 implementations) which provide a safer way to modify allowances without the need for a zero-value transaction.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 45.3% of supply. What remains: 33.8% in wallets, 11.5% in other contracts. 277,568 holders in total.
IssueThe ten largest holders own 45.3% of supply. What remains: 33.8% in wallets, 11.5% in other contracts. 277,568 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Identity verified by independent sources

QA-IDENTITYListed on CoinGecko as Decentraland (MANA), market cap $209M, rank #190. Traded on Binance, Coinbase. 277,568 holders. Verified by: CoinGecko, exchange listings.
IssueListed on CoinGecko as Decentraland (MANA), market cap $209M, rank #190. Traded on Binance, Coinbase. 277,568 holders. Verified by: CoinGecko, exchange listings.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $173K (DexScreener, all pools). 24h trading volume $175.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $126K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $5.85 on 2021-11-25; the price is now 98.1779% below it.
IssueLiquidity $173K (DexScreener, all pools). 24h trading volume $175.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $126K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $5.85 on 2021-11-25; the price is now 98.1779% below it.
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: a ProxyAdmin contract. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $173K of DEX liquidity across 18 pools. Launch: 2328 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: a ProxyAdmin contract. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $173K of DEX liquidity across 18 pools. Launch: 2328 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The contract employs the SafeMath library to prevent integer overflow/underflow vulnerabilities, a strong practice for Solidity 0.4.x. Standard ERC-20 functions are implemented correctly, and the `approve` function includes a common mitigation for the ERC-20 race condition (7.2 Code Security). However, the use of Solidity 0.4.11 is outdated, lacking modern security features and optimizations. The `SafeMath.div` function does not explicitly check for division by zero, though it's not used in a critical path with user-controlled input (7.2 Code Security).

GovernanceMedium4/10

The contract design grants significant centralized control to the `owner` address (7.3 Access Control). The owner can mint an unlimited supply of new tokens, effectively inflating the total supply, and can pause all token transfers (7.4 Economic). While common for initial token deployments, this presents a high centralization risk if the owner's private key is compromised or misused. The `transferOwnership` function lacks an event, making off-chain tracking of ownership changes difficult (7.5 Governance).

UpgradesMedium4/10

The MANAToken contract is not designed as an upgradeable proxy (7.7 Upgrades). This eliminates upgrade-related risks such as proxy implementation mismatches or storage collisions. The `Ownable` pattern allows the current owner to transfer ownership to a new address, providing a mechanism for administrative succession (7.8 Operations).

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

33.8% in wallets11.5% in contracts
Effective Concentration38.4%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 8 remaining pairs hold $619 between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder43.0%
Top-3 Unlocked79.3%

Key Addresses

Deployer
0xa66d…fb3d
Unlocked LP Held By
0x6bb2…169b0x7d92…8b6f0xd6fc…85a30xb29f…7d600x7993…e3d50x1575…22a20xa0cf…88140x6030…76780x2e52…ec6a0xb7c0…6e58

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Owner can pause all transfers
  • Mintable supply — no cap found, dilution unbounded
  • Liquidity NOT locked (100% of the pool; this pool is 53% of DEX liquidity) — held by independent providers — market-depth risk
  • Top-10 concentration > 30% (45.3% total → 38.4% effective; 33.8% in EOAs, 11.5% in contracts)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

SPX6900 (SPX)Medium RiskTRIAMedium RiskDimitra Token (DMTR)Medium RiskPendleLow RiskPowerMedium RiskWrapped SOL (SOL)Low Risk

Would You Like a More Detailed Audit of Decentraland?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit