Quantum Audit Logo

Is INFINIT Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

INFINIT IN
0x61fa…3d50
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

The IN_Token contract, an upgradeable ERC-20 OFT, implements standard token functionalities with cross-chain capabilities via LayerZero. It utilizes OpenZeppelin and LayerZero upgradeable libraries. Key security features include a multisig for ownership and proxy administration. The primary risks identified relate to the centralized control over token supply and critical external dependencies.

1 High2 Medium1 Informational
Volume 24h
$6.32M
Liquidity
$1.32M
Price
$0.04101
Token Age
10mo
Top 10 Holders
89.1%

Security Findings

High

Centralized Control over Token Supply

H-01The `mint` and `burn` functions are restricted to the contract owner, which is a 4/7 multisig. This grants significant power over the token's total supply, allowing for arbitrary inflation or deflation. While a multisig mitigates a single point of failure, it still represents a centralized authority that could impact token economics and trust assumptions (7.3 Access Control, 7.4 Economic).
IssueThe `mint` and `burn` functions are restricted to the contract owner, which is a 4/7 multisig. This grants significant power over the token's total supply, allowing for arbitrary inflation or deflation. While a multisig mitigates a single point of failure, it still represents a centralized authority that could impact token economics and trust assumptions (7.3 Access Control, 7.4 Economic).
FixClearly communicate the implications of centralized mint/burn authority to users. Consider implementing a time-locked governance mechanism or a community-driven proposal system for significant supply changes, or explore mechanisms to cap total supply if appropriate for the token's design.
StatusUnresolved
Medium

Critical Initialization Parameter (`_delegate`)

M-01The `initialize` function takes a `_delegate` parameter which is used to set both the initial `Ownable` owner and the `OFTUpgradeable` delegate. A misconfiguration during deployment, such as providing an incorrect or compromised address, would lead to the contract being controlled by an unintended entity or becoming unmanageable. This is a critical one-time setup risk (7.8 Operations, 7.3 Access Control).
IssueThe `initialize` function takes a `_delegate` parameter which is used to set both the initial `Ownable` owner and the `OFTUpgradeable` delegate. A misconfiguration during deployment, such as providing an incorrect or compromised address, would lead to the contract being controlled by an unintended entity or becoming unmanageable. This is a critical one-time setup risk (7.8 Operations, 7.3 Access Control).
FixImplement a rigorous deployment checklist and multi-party verification process for the `initialize` function parameters, especially the `_delegate` address. Consider using a well-tested deployment script that logs and verifies all parameters before execution.
StatusUnresolved
Medium

External Dependency on LayerZero Endpoint

M-02The `IN_Token` contract relies on the LayerZero v2 endpoint for its cross-chain functionality. The security, liveness, and upgradeability of this external endpoint are critical to the token's operation. Any vulnerabilities, compromises, or operational issues within the LayerZero infrastructure could directly impact the token's ability to perform cross-chain transfers (7.6 External).
IssueThe `IN_Token` contract relies on the LayerZero v2 endpoint for its cross-chain functionality. The security, liveness, and upgradeability of this external endpoint are critical to the token's operation. Any vulnerabilities, compromises, or operational issues within the LayerZero infrastructure could directly impact the token's ability to perform cross-chain transfers (7.6 External).
FixMonitor LayerZero's security announcements, audits, and operational status closely. Understand the risks associated with cross-chain bridges and communicate them transparently to users. Consider implementing emergency pause mechanisms if the LayerZero endpoint experiences critical issues.
StatusUnresolved
Info

Multisig Operational Security

I-01Both the contract owner (for `mint`/`burn`) and the proxy admin (for upgrades) are controlled by a 4/7 multisig. While this is a robust access control mechanism, the security of the system ultimately depends on the operational security practices of the multisig signers (e.g., key management, quorum procedures, resistance to social engineering) (7.5 Governance, 7.8 Operations).
IssueBoth the contract owner (for `mint`/`burn`) and the proxy admin (for upgrades) are controlled by a 4/7 multisig. While this is a robust access control mechanism, the security of the system ultimately depends on the operational security practices of the multisig signers (e.g., key management, quorum procedures, resistance to social engineering) (7.5 Governance, 7.8 Operations).
FixEnsure all multisig signers adhere to best practices for private key management, including hardware wallets, strong authentication, and secure communication channels. Regularly review and update multisig policies and procedures, and conduct periodic security awareness training for signers.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract leverages well-audited OpenZeppelin and LayerZero upgradeable libraries, contributing to a solid technical foundation (7.2 Code Security). The use of Solidity 0.8.22 mitigates common integer overflow/underflow risks. However, the reliance on the LayerZero endpoint introduces an external dependency risk (7.6 External), and the critical `_delegate` parameter in `initialize` requires careful deployment (7.8 Operations).

GovernanceHigh3/10

The contract's economic model features centralized `mint` and `burn` functions, controlled by a 4/7 multisig (7.3 Access Control). While the multisig provides a strong governance mechanism, this centralized control over token supply poses a significant economic risk, as it allows for arbitrary inflation or deflation (7.4 Economic). The security of the multisig signers is paramount (7.5 Governance).

UpgradesHigh1/10

The contract employs the Transparent Upgradeable Proxy pattern with OpenZeppelin's `initializer` functions, which is a standard and well-understood upgradeability mechanism (7.7 Upgrades). The `_disableInitializers()` call in the constructor correctly prevents re-initialization of the implementation contract. The proxy's admin is also controlled by a 4/7 multisig, enhancing upgrade safety.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEip1967 Transparent
AdminOZ ProxyAdmin → Multisig 4-of-7
ImplementationVerified source

Holder Composition

21.9% in wallets67.2% in contracts
Effective Concentration48.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x5a3f…8e49
Unlocked LP Held By
0xbbb7…bbb00x7e5c…6c500x952d…1dec

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-7)
  • Mintable supply — no cap found, dilution unbounded
  • Proxy contract (upgradeable — admin can replace logic)
  • Top-10 concentration > 30% (89.1% total → 48.8% effective; 21.9% in EOAs, 67.2% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • 1 High finding(s) from audit
  • 2 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

BicatHigh Riskb-moneyHigh RiskTrust Wallet (TWT)High RiskSTABLEHigh RiskOLYHigh RiskVelvetHigh Risk

Would You Like a More Detailed Audit of INFINIT?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit