Quantum Audit Logo

Is HOME Safe?

On-chain security analysis — is it a scam or legit?

HOME HOME
0x4bfa…714f
Base Not verifiedLast checked 3d ago 1 audit on record
Executive SummaryAI Copilot

This report covers a security review of the provided Solidity source code. It is important to note that the submitted code consists solely of LayerZero v2 interface definitions. The actual implementation code for the 'HomeCanonical' contract, which is the target of this audit, was not provided. Consequently, a comprehensive security assessment of the contract's logic, state management, access control, and potential vulnerabilities could not be performed. The findings below highlight the critical limitation of this audit due to the absence of the core contract implementation.

1 Critical3 Informational
Volume 24h
$47.1K
Liquidity
$24.2K
Price
$0.006027
Token Age
1y
Top 10 Holders
87.8%

Security Findings

Critical

Missing Core Contract Implementation

C-01The provided source code consists solely of LayerZero v2 interface definitions (e.g., `ILayerZeroEndpointV2`, `ILayerZeroReceiver`). The actual implementation code for the `HomeCanonical` contract, which is the stated target of this audit, was not included. This prevents any meaningful security analysis of the contract's logic, state variables, access control, and potential vulnerabilities like reentrancy, integer overflows, or specific business logic flaws.
IssueThe provided source code consists solely of LayerZero v2 interface definitions (e.g., `ILayerZeroEndpointV2`, `ILayerZeroReceiver`). The actual implementation code for the `HomeCanonical` contract, which is the stated target of this audit, was not included. This prevents any meaningful security analysis of the contract's logic, state variables, access control, and potential vulnerabilities like reentrancy, integer overflows, or specific business logic flaws.
FixProvide the complete and verified Solidity source code for the `HomeCanonical` contract, including all its dependencies and libraries, to enable a comprehensive security audit.
StatusUnresolved
Info

Reliance on LayerZero v2 Protocol Security

I-01The `HomeCanonical` contract, as indicated by the provided interfaces, relies heavily on the LayerZero v2 protocol for cross-chain messaging. The security and integrity of the `HomeCanonical` contract will be directly dependent on the robustness and security of the underlying LayerZero v2 infrastructure, including its endpoints, message libraries, and relayers. Any vulnerabilities or compromises within the LayerZero v2 protocol could potentially impact the `HomeCanonical` contract.
IssueThe `HomeCanonical` contract, as indicated by the provided interfaces, relies heavily on the LayerZero v2 protocol for cross-chain messaging. The security and integrity of the `HomeCanonical` contract will be directly dependent on the robustness and security of the underlying LayerZero v2 infrastructure, including its endpoints, message libraries, and relayers. Any vulnerabilities or compromises within the LayerZero v2 protocol could potentially impact the `HomeCanonical` contract.
FixWhile the LayerZero v2 protocol is designed for security, it is crucial for the project team to stay informed about any security updates, audits, or known vulnerabilities related to LayerZero. Implement robust monitoring for cross-chain operations and consider circuit breakers for extreme scenarios.
StatusUnresolved
Info

Unassessable Access Control Mechanisms

I-02Without the implementation code for `HomeCanonical`, it is impossible to assess the access control mechanisms (7.3 Access Control) governing critical functions. This includes identifying privileged roles (e.g., owner, admin, governor), verifying proper authorization checks (e.g., `onlyOwner`, `require(msg.sender == _someRole)`), and ensuring that sensitive operations are adequately protected against unauthorized execution.
IssueWithout the implementation code for `HomeCanonical`, it is impossible to assess the access control mechanisms (7.3 Access Control) governing critical functions. This includes identifying privileged roles (e.g., owner, admin, governor), verifying proper authorization checks (e.g., `onlyOwner`, `require(msg.sender == _someRole)`), and ensuring that sensitive operations are adequately protected against unauthorized execution.
FixOnce the full contract code is available, a detailed review of all access control patterns should be conducted. Ensure that the principle of least privilege is applied, and that multi-signature wallets are used for critical administrative functions where appropriate.
StatusUnresolved
Info

Unverified Economic and Governance Model

I-03The economic model (7.4 Economic) and governance structure (7.5 Governance) of the `HomeCanonical` contract cannot be verified or audited without its full implementation. This includes aspects such as fee collection, reward distribution, tokenomics, and any on-chain voting or administrative processes. Unforeseen economic incentives or governance flaws could lead to instability or manipulation.
IssueThe economic model (7.4 Economic) and governance structure (7.5 Governance) of the `HomeCanonical` contract cannot be verified or audited without its full implementation. This includes aspects such as fee collection, reward distribution, tokenomics, and any on-chain voting or administrative processes. Unforeseen economic incentives or governance flaws could lead to instability or manipulation.
FixUpon receiving the full contract code, a thorough review of the economic and governance logic should be performed. This includes simulating various scenarios to identify potential attack vectors or unintended consequences related to incentives, fees, and decision-making processes.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The technical review was severely limited as only LayerZero v2 interface definitions were provided, not the implementation code for the 'HomeCanonical' contract. This prevents any assessment of the contract's internal logic, state variables, or specific vulnerability patterns (e.g., reentrancy, integer overflows). The interfaces themselves appear standard for LayerZero v2, defining cross-chain messaging functions (7.1 Architecture). However, without the concrete implementation, no code security (7.2 Code Security) or access control (7.3 Access Control) analysis could be performed.

GovernanceHigh2/10

The economic and governance aspects of the 'HomeCanonical' contract could not be evaluated due to the absence of its implementation code. This means no assessment of tokenomics, fee structures, incentive mechanisms, or governance decision-making processes (7.5 Governance) was possible. Cross-chain protocols inherently carry economic risks (7.4 Economic) related to message integrity and potential bridge exploits, which cannot be mitigated or analyzed without the specific contract logic. External dependencies (7.6 External) on LayerZero v2 are present, but their integration cannot be reviewed.

UpgradesMedium6/10

The upgradeability mechanisms (7.7 Upgrades) of the 'HomeCanonical' contract could not be assessed as its implementation code was not provided. Without the contract's source, it is impossible to determine if it uses a proxy pattern (e.g., UUPS, Transparent), if it has an owner-controlled upgrade path, or if it is immutable. This poses a significant risk as potential upgrade vulnerabilities or lack of upgradeability cannot be identified. Operational aspects (7.8 Operations) related to upgrades are also unassessable.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

24.1% in wallets63.7% in contracts
Effective Concentration49.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder97.9%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x81f6…2977
Unlocked LP Held By
0xfa2b…52bb0x8ee4…485a0x0855…7eba

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-7)
  • Top-10 concentration > 30% (87.8% total → 49.6% effective; 24.1% in EOAs, 63.7% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $50k ($25,421 across 2 pairs — thin market)
  • LP top1 unlocked holder = 97.9% (independent LP — depth risk, pool = 95% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 95% of DEX liquidity)
  • 1 Critical finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

CTRHigh RiskDegenHigh RiskVenice Token (VVV)High RiskAUTONOMOPOLY (AUTONO)High RiskSolana (SOL)High RiskTAOTHigh Risk

Would You Like a More Detailed Audit of HOME?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit