On-chain security analysis — is it a scam or legit?
0xbfbc…ad9c
The audit of the `StandardArbERC20` implementation contract, used by `ClonableBeaconProxy` on Arbitrum, identified a critical access control vulnerability. This flaw allows any caller to initialize a new token proxy instance and designate themselves as the `l2Gateway`, granting unauthorized minting and burning capabilities. Additional findings include a medium-severity issue related to specific string parsing logic and a low-severity concern regarding the `selfdestruct` function. Addressing the critical vulnerability is paramount for the security and integrity of token instances.
Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.
The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.
0x3fe3…000f0x1d21…6dc8No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.
Get Detailed Audit