Quantum Audit Logo

Is Flower Safe?

On-chain security analysis — is it a scam or legit?

Flower FLOWER
0x3e12…b380
Base Not verifiedLast checked 3d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The FlowerOFT contract implements an ERC-20 token with Pausable and ERC-1363 extensions, leveraging LayerZero v2 for omnichain functionality. The contract is well-structured, inheriting from established OpenZeppelin and LayerZero libraries. Key controls, such as pausing transfers, are managed by a single owner address, which is a multisig, mitigating some centralization risks.

1 Medium3 Informational
Volume 24h
$42.5K
Liquidity
$283.7K
Price
$0.1749
Token Age
1y
Top 10 Holders
91.4%

Security Findings

Medium

Centralized Control by Owner

M-01The `Ownable` owner has significant control over the contract, specifically the ability to pause and unpause all token transfers. While the prefill indicates the owner is a multisig (2/5 threshold), this still represents a central point of control. If the multisig keys are compromised, or if the signers collude or act maliciously, it could lead to a denial of service for token holders or other adverse actions.
IssueThe `Ownable` owner has significant control over the contract, specifically the ability to pause and unpause all token transfers. While the prefill indicates the owner is a multisig (2/5 threshold), this still represents a central point of control. If the multisig keys are compromised, or if the signers collude or act maliciously, it could lead to a denial of service for token holders or other adverse actions.
FixEnsure robust security practices for the multisig, including strong key management, secure operational procedures, and regular audits of multisig members. For critical operations like pausing, consider implementing a time-lock to provide a delay before execution, allowing users to react and increasing transparency. Explore options for more decentralized governance if the project's roadmap allows.
StatusUnresolved
Info

Dependency on LayerZero v2 Security

I-01The `FlowerOFT` contract heavily relies on the security and correct functioning of the LayerZero v2 protocol and its endpoint for its omnichain capabilities (7.6 External). Any vulnerabilities, misconfigurations, or operational issues within the LayerZero infrastructure could directly impact the cross-chain functionality, integrity, and availability of the FlowerOFT token.
IssueThe `FlowerOFT` contract heavily relies on the security and correct functioning of the LayerZero v2 protocol and its endpoint for its omnichain capabilities (7.6 External). Any vulnerabilities, misconfigurations, or operational issues within the LayerZero infrastructure could directly impact the cross-chain functionality, integrity, and availability of the FlowerOFT token.
FixMaintain continuous monitoring of LayerZero security announcements, updates, and best practices. Ensure the `_lzEndpoint` address configured in the constructor is the official and trusted LayerZero endpoint for the respective network. Understand the implications of LayerZero's security model and its impact on the token's overall risk profile.
StatusUnresolved
Info

Immutability and Lack of Upgradeability

I-02The contract is not designed with an upgradeability mechanism (e.g., proxy pattern), as confirmed by the `is_proxy: false` status (7.7 Upgrades). While this reduces complexity and eliminates certain upgrade-related risks, it means that any discovered critical vulnerabilities or desired feature enhancements would necessitate a new contract deployment and a potentially complex migration process for existing token holders and integrated protocols.
IssueThe contract is not designed with an upgradeability mechanism (e.g., proxy pattern), as confirmed by the `is_proxy: false` status (7.7 Upgrades). While this reduces complexity and eliminates certain upgrade-related risks, it means that any discovered critical vulnerabilities or desired feature enhancements would necessitate a new contract deployment and a potentially complex migration process for existing token holders and integrated protocols.
FixAcknowledge the implications of immutability. For future projects or if long-term flexibility, bug fixes, or feature additions are anticipated, consider implementing an upgradeable proxy pattern (e.g., UUPS) from the outset. For the current contract, ensure thorough testing and auditing before deployment to minimize the chance of needing a redeployment.
StatusUnresolved
Info

Pausable Mechanism Impact

I-03The `Pausable` mechanism allows the `onlyOwner` to halt all token transfers by calling `pause()` (7.3 Access Control). While intended for emergency situations like critical bug discovery or exploit mitigation, it introduces a single point of failure for token utility. If the owner account is compromised or acts maliciously, it could lead to a denial of service for all token holders.
IssueThe `Pausable` mechanism allows the `onlyOwner` to halt all token transfers by calling `pause()` (7.3 Access Control). While intended for emergency situations like critical bug discovery or exploit mitigation, it introduces a single point of failure for token utility. If the owner account is compromised or acts maliciously, it could lead to a denial of service for all token holders.
FixClearly communicate the purpose and conditions under which the pause function would be used to the community. Consider adding a time-lock for the `pause()` and `unpause()` functions, or requiring a multi-party decision mechanism for unpausing in future versions, to further decentralize control and provide transparency.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The technical architecture (7.1) is sound, utilizing battle-tested OpenZeppelin and LayerZero libraries for core ERC-20, pausable, and omnichain functionalities. Code security (7.2) benefits from Solidity 0.8.20 and standard patterns, with the `_update` function correctly integrating the `whenNotPaused` modifier. However, the contract's reliance on the LayerZero v2 protocol means its cross-chain security is directly tied to the underlying LayerZero infrastructure (7.6 External), which introduces an external dependency risk.

GovernanceMedium4/10

Access control (7.3) is primarily managed by the `Ownable` pattern, granting the owner the ability to pause and unpause token transfers. The prefill indicates the owner is a multisig with a 2/5 threshold, which significantly enhances security and decentralization compared to an EOA. Economically (7.4), the token's value and stability are dependent on its utility and the LayerZero bridging mechanism. The centralized pause function (7.5 Governance) represents a potential point of control that could impact token utility if misused.

UpgradesMedium6/10

The FlowerOFT contract is deployed as an immutable contract, as confirmed by the `is_proxy: false` status (7.7 Upgrades). This design choice eliminates risks associated with upgrade mechanisms, such as proxy storage collisions or faulty upgrade logic. However, it also means that any future bug fixes or feature enhancements would necessitate a new contract deployment and a token migration process, which can be complex for users.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

2.8% in wallets88.6% in contracts
Effective Concentration38.2%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder37.1%
Top-3 Unlocked55.1%

Key Addresses

Deployer
0x68a9…8e92
Unlocked LP Held By
0x1aa8…aab20x4698…92ed0x7243…73170xe8db…d38d0x873e…6f690x67e4…26160x2cdd…284b0xb141…178d0x0e4b…7e600x734a…a381

A privileged address — the deployer, the owner, or the token contract itself — is among these holders, so that party can withdraw liquidity.

What Raised This Score

  • Ownership NOT renounced — Multisig (2-of-5)
  • Top-10 concentration > 30% (91.4% total → 38.2% effective; 2.8% in EOAs, 88.6% in contracts — moderate)
  • Liquidity NOT locked (owner can withdraw — rug-pull risk)
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

OWBMedium RiskBitVault Signal (BV7X)Medium RiskMoltbook (MOLT)Medium RiskKellyClaudeMedium RiskOpenAIMedium RiskGoogle T-REX (TREX)Medium Risk

Would You Like a More Detailed Audit of Flower?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit