Quantum Audit Logo

Is Hunter Biden's Laptop Safe?

On-chain security analysis — is it a scam or legit?

Hunter Biden's Laptop LAPTOP
0xb095…ec29
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 10d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The LaptopOFT contract implements an Omnichain Fungible Token (OFT) using LayerZero v2 and OpenZeppelin's Ownable2Step for ownership management. The token has a fixed total supply minted once on the Base chain. The audit identified a high-severity risk related to the centralized control over critical LayerZero configurations, which could impact cross-chain functionality. Dependencies on the external LayerZero endpoint and the security of the initial recipient address are also noted.

1 High1 Low1 Informational
Volume 24h
$1.58M
Liquidity
$1.57M
Price
$0.3626
Token Age
1y
Top 10 Holders
95.3%

Security Findings

High

Centralized Control over Critical LayerZero Configurations

H-01The `LaptopOFT` contract inherits from `OFT`, which exposes several owner-controlled functions to configure LayerZero parameters (e.g., `setTrustedRemote`, `setMinDstGas`, `setDelegate`, `setPrecrime`, `setOracle`, `setFeeManager`). These functions are critical for the correct and secure operation of cross-chain transfers. A compromised owner key could lead to a denial of service for cross-chain functionality, incorrect fee calculations, or even potential loss of funds if `setTrustedRemote` is manipulated to a malicious endpoint, redirecting tokens to an attacker-controlled contract.
IssueThe `LaptopOFT` contract inherits from `OFT`, which exposes several owner-controlled functions to configure LayerZero parameters (e.g., `setTrustedRemote`, `setMinDstGas`, `setDelegate`, `setPrecrime`, `setOracle`, `setFeeManager`). These functions are critical for the correct and secure operation of cross-chain transfers. A compromised owner key could lead to a denial of service for cross-chain functionality, incorrect fee calculations, or even potential loss of funds if `setTrustedRemote` is manipulated to a malicious endpoint, redirecting tokens to an attacker-controlled contract.
FixImplement robust multi-signature control for the owner address to prevent a single point of failure. Consider adding a time-lock to critical configuration changes (e.g., `setTrustedRemote`, `setDelegate`) to allow for community review or emergency intervention before changes take effect. Regularly review and audit the security practices surrounding the owner's private keys.
StatusUnresolved
Low

Dependency on External LayerZero Endpoint Security and Liveness

L-01The `LaptopOFT` contract's core cross-chain functionality relies entirely on the security and operational integrity of the LayerZero Endpoint (`_lzEndpoint`) provided during deployment. Any vulnerabilities, misconfigurations, or liveness issues within the LayerZero protocol or the specific endpoint contract could directly impact the `LaptopOFT` token's ability to transfer across chains, leading to a denial of service for users attempting cross-chain operations.
IssueThe `LaptopOFT` contract's core cross-chain functionality relies entirely on the security and operational integrity of the LayerZero Endpoint (`_lzEndpoint`) provided during deployment. Any vulnerabilities, misconfigurations, or liveness issues within the LayerZero protocol or the specific endpoint contract could directly impact the `LaptopOFT` token's ability to transfer across chains, leading to a denial of service for users attempting cross-chain operations.
FixAcknowledge this inherent dependency and monitor the LayerZero protocol's security posture and operational status. Ensure the `_lzEndpoint` address used during deployment is the official and verified LayerZero endpoint for the respective chain. Implement monitoring for LayerZero endpoint events and status.
StatusUnresolved
Info

Fixed Total Supply and Initial Minting Design

I-01The contract is designed with a fixed `TOTAL_SUPPLY` of 1,000,000,000 tokens, which are minted entirely to a single `_initialRecipient` address only on the `BASE_CHAIN_ID` during construction. This design choice prevents further inflation or arbitrary minting by the contract owner or any other entity, providing a predictable supply schedule. However, it also means that if the `_initialRecipient` address is incorrect or compromised at the time of deployment, the entire token supply could be misallocated.
IssueThe contract is designed with a fixed `TOTAL_SUPPLY` of 1,000,000,000 tokens, which are minted entirely to a single `_initialRecipient` address only on the `BASE_CHAIN_ID` during construction. This design choice prevents further inflation or arbitrary minting by the contract owner or any other entity, providing a predictable supply schedule. However, it also means that if the `_initialRecipient` address is incorrect or compromised at the time of deployment, the entire token supply could be misallocated.
FixEnsure the `_initialRecipient` address is thoroughly vetted, secure, and correct prior to deployment, as this is the sole opportunity for initial token distribution. This design is generally considered a positive security characteristic for fixed-supply tokens.
StatusUnresolved

Category Ratings

TechnicalLow9/10

The contract architecture (7.1) leverages the well-audited LayerZero OFT standard and OpenZeppelin's Ownable2Step, providing a robust foundation for an omnichain token. Code security (7.2) is enhanced by using Solidity 0.8.22, which includes checked arithmetic, and a fixed total supply preventing inflation. However, access control (7.3) for LayerZero configurations remains highly centralized, with the owner having the ability to set critical parameters like trusted remotes and gas limits. The contract's functionality is heavily reliant on the external LayerZero endpoint (7.6), introducing a dependency risk.

GovernanceMedium5/10

Economically (7.4), the fixed total supply and single initial minting event provide predictability and prevent arbitrary inflation. However, the governance (7.5) model is highly centralized, with a single owner (initially a delegate) controlling all critical LayerZero configurations. This centralized control, while using a two-step transfer mechanism, poses a significant risk if the owner's key is compromised, potentially leading to a denial of service for cross-chain transfers or incorrect fee calculations.

UpgradesLow7/10

The LaptopOFT contract is not designed as an upgradeable proxy (7.7). It is a standard implementation contract, meaning its logic cannot be changed after deployment. This eliminates risks associated with upgrade mechanisms, such as proxy misconfigurations or upgradeability backdoor vulnerabilities.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

4.0% in wallets91.4% in contracts
Effective Concentration40.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 20 remaining pairs hold $1.2K between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder38.1%
Top-3 Unlocked72.3%

Key Addresses

Deployer
0x0fb5…5592
Unlocked LP Held By
0xcce2…1e770xf949…02980x06e0…8fb40x0ce3…289c0xd537…9ce70xad75…29f70x847d…11290x4591…57510x49f6…c73b0xc526…d923

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — Multisig (2-of-3)
  • Top-10 concentration > 30% (95.3% total → 40.5% effective; 4.0% in EOAs, 91.4% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • 1 High finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Jerry the goat (JERRY)Medium RiskSandisk Corporation (SNDKC)Medium RiskTesla Inc. (TSLAC)Medium RiskMicrosoft Corporation (MSFTC)Medium RiskBitVault Signal (BV7X)Medium RiskCoinbase Man (BRIAN)Medium Risk

Would You Like a More Detailed Audit of Hunter Biden's Laptop?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit