Quantum Audit Logo

Is HeyAnon Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

HeyAnon ANON
0x79bb…e07c
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 10d ago 1 audit on record
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The HeyAnon contract implements an Omnichain Fungible Token (OFT) utilizing LayerZero V2 for cross-chain functionality and OpenZeppelin's Ownable for access control. The audit identified a high degree of centralization of control through the owner/delegate address and a critical dependency on the LayerZero V2 protocol's security. The contract's simplicity and reliance on well-audited libraries are strengths, but these centralized points of control and external dependencies introduce inherent risks.

1 High1 Medium1 Low1 Informational
Volume 24h
$369.2K
Liquidity
$104.7K
Price
$0.4223
Token Age
7mo
Top 10 Holders
72.6%

Security Findings

High

High Centralization of Control

H-01The `_delegate` address provided in the constructor becomes both the `Ownable` owner and the `OFT` delegate. This grants a single entity extensive control over the token's administrative functions, including LayerZero configurations, pausing, and potentially other critical operations inherited from `OFT`. A compromise of this address would severely impact the protocol's cross-chain functionality and overall integrity (7.3 Access Control, 7.4 Economic).
IssueThe `_delegate` address provided in the constructor becomes both the `Ownable` owner and the `OFT` delegate. This grants a single entity extensive control over the token's administrative functions, including LayerZero configurations, pausing, and potentially other critical operations inherited from `OFT`. A compromise of this address would severely impact the protocol's cross-chain functionality and overall integrity (7.3 Access Control, 7.4 Economic).
FixIf possible, consider separating the `Ownable` owner role from the `OFT` delegate role, assigning them to different, highly secured entities or multisig wallets. If a single address must hold both roles, ensure it is a robustly secured multisignature wallet with a high threshold and strict operational security protocols.
StatusUnresolved
Medium

Critical Dependency on LayerZero V2 Protocol Security

M-01The `HeyAnon` token's core functionality relies entirely on the security and correct operation of the LayerZero V2 protocol, including its endpoint, message libraries, relayers, and oracles. Any vulnerabilities, misconfigurations, or compromises within the LayerZero infrastructure could directly affect the cross-chain transfer capabilities and overall integrity of the `HeyAnon` token (7.6 External).
IssueThe `HeyAnon` token's core functionality relies entirely on the security and correct operation of the LayerZero V2 protocol, including its endpoint, message libraries, relayers, and oracles. Any vulnerabilities, misconfigurations, or compromises within the LayerZero infrastructure could directly affect the cross-chain transfer capabilities and overall integrity of the `HeyAnon` token (7.6 External).
FixMaintain continuous monitoring of LayerZero V2 security announcements, audits, and operational status. Implement robust monitoring for cross-chain transactions and LayerZero-specific events related to the `HeyAnon` token. Develop a contingency plan for scenarios where LayerZero V2 experiences significant disruptions or security incidents.
StatusUnresolved
Low

Reliance on OFT's Pausing Mechanism

L-01While the underlying `OFT` contract likely provides pausing mechanisms (e.g., `_pause` function callable by the owner/delegate), the `HeyAnon` contract itself does not implement any additional custom emergency functions or circuit breakers. This means the project relies solely on the inherited `OFT` controls for crisis management, without adding any specific `HeyAnon`-level emergency logic (7.8 Operations).
IssueWhile the underlying `OFT` contract likely provides pausing mechanisms (e.g., `_pause` function callable by the owner/delegate), the `HeyAnon` contract itself does not implement any additional custom emergency functions or circuit breakers. This means the project relies solely on the inherited `OFT` controls for crisis management, without adding any specific `HeyAnon`-level emergency logic (7.8 Operations).
FixEvaluate if any specific `HeyAnon` business logic (if it were to expand beyond a simple token) would benefit from a dedicated, custom emergency pause or circuit breaker. For the current simple token, ensure the `OFT`'s pausing mechanism is well understood and accessible for rapid response by the owner/delegate.
StatusUnresolved
Info

Constructor Input Validation

I-01The constructor initializes critical addresses such as `_lzEndpoint` and `_delegate`. While `Ownable` checks for `address(0)` for the owner, explicit validation for `_lzEndpoint` to ensure it's a non-zero address and potentially a known valid LayerZero endpoint, or additional checks for `_delegate` (e.g., not a contract address if it's expected to be an EOA or multisig), could enhance robustness (7.2 Code Security).
IssueThe constructor initializes critical addresses such as `_lzEndpoint` and `_delegate`. While `Ownable` checks for `address(0)` for the owner, explicit validation for `_lzEndpoint` to ensure it's a non-zero address and potentially a known valid LayerZero endpoint, or additional checks for `_delegate` (e.g., not a contract address if it's expected to be an EOA or multisig), could enhance robustness (7.2 Code Security).
FixConsider adding explicit `require` statements in the constructor to validate that `_lzEndpoint` is not `address(0)`. For `_delegate`, while `Ownable` handles `address(0)`, further checks could be added if specific types of addresses (e.g., EOA vs. contract) are expected.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract `HeyAnon` is a straightforward implementation of an Omnichain Fungible Token (OFT) using LayerZero V2 and OpenZeppelin's `Ownable` for access control (7.1 Architecture). The code is minimal, leveraging battle-tested libraries, which contributes to its inherent security (7.2 Code Security). However, a key concern is the high centralization of control, where a single `_delegate` address acts as both the `Ownable` owner and the `OFT` delegate, granting extensive administrative power (7.3 Access Control). Additionally, the contract's functionality is critically dependent on the security and operational integrity of the external LayerZero V2 protocol (7.6 External).

GovernanceHigh1/10

The economic model is that of a standard ERC-20 token with cross-chain capabilities, relying on the underlying `OFT` implementation. The primary governance and economic risk stems from the highly centralized control vested in the `_delegate` address (7.5 Governance). This single address can manage critical LayerZero configurations and potentially pause token transfers, making it a single point of failure (7.4 Economic). While the use of a multisig for this address mitigates some risk, its compromise could lead to significant economic impact.

UpgradesMedium6/10

The `HeyAnon` contract is deployed as a standard, non-upgradeable implementation (7.7 Upgrades). This design choice eliminates upgrade-specific risks such as proxy storage collisions or incorrect upgrade logic. However, it also means that any discovered vulnerabilities or desired feature enhancements would necessitate a new contract deployment and migration of assets, which can be a complex and costly process. The immutability provides certainty but sacrifices flexibility.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

50.1% in wallets22.6% in contracts
Effective Concentration59.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x8054…b92f
Unlocked LP Held By
0x8789…95f00xb9d9…91ff

A privileged address — the deployer, the owner, or the token contract itself — is among these holders, so that party can withdraw liquidity.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (3-of-5)
  • Top-10 concentration > 50% (72.6% total → 59.1% effective; 50.1% in EOAs, 22.6% in contracts — heavy)
  • Liquidity NOT locked (owner can withdraw — rug-pull risk)
  • LP top1 unlocked holder = 100.0% (exit-liquidity risk, pool = 96% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (exit-liquidity risk, pool = 96% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Global Dollar (USDG)Critical RiskBigShortBets (BIGSB)Critical RiskFrankencoin (ZCHF)Critical RiskKyber Network Crystal v2 (KNC)Critical RiskRe Protocol reUSD (REUSD)Critical RiskRallyCritical Risk

Would You Like a More Detailed Audit of HeyAnon?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit