Quantum Audit Logo

Is Kava Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Kava KAVA
0x9baf…ad79
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 8d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The KavaOFT contract is a minimal wrapper around LayerZero's Omnichain Fungible Token (OFT) standard, inheriting from `OFT` and OpenZeppelin's `Ownable`. It facilitates cross-chain token transfers via the LayerZero v2 protocol. The contract itself is simple and well-structured, primarily relying on the security and functionality of the underlying LayerZero libraries. Key security considerations revolve around the extensive control granted to the contract owner (a multisig) over LayerZero configurations and the inherent dependency on the LayerZero protocol's security.

1 High1 Medium1 Low1 Informational
Volume 24h
$1.28M
Liquidity
$436.7K
Price
$0.06348
Token Age
1y
Top 10 Holders
86.6%

Security Findings

High

Centralized Control by Owner over LayerZero Configurations

H-01The `_delegate` address, which becomes the `Ownable` owner, has extensive control over the LayerZero OFT's operational parameters. This includes the ability to call functions like `setTrustedRemoteAddress`, `setMinDstGas`, `setPrecrime`, `setFeeManager`, and `setDelegate` (from `ILayerZeroEndpointV2`). Misuse or compromise of this owner address could lead to funds being misrouted, stuck, or subject to excessive fees, impacting the integrity and economic security of cross-chain transfers. While the prefill indicates the owner is a multisig, the concentration of power remains a significant risk factor (7.3 Access Control, 7.4 Economic, 7.8 Operations).
IssueThe `_delegate` address, which becomes the `Ownable` owner, has extensive control over the LayerZero OFT's operational parameters. This includes the ability to call functions like `setTrustedRemoteAddress`, `setMinDstGas`, `setPrecrime`, `setFeeManager`, and `setDelegate` (from `ILayerZeroEndpointV2`). Misuse or compromise of this owner address could lead to funds being misrouted, stuck, or subject to excessive fees, impacting the integrity and economic security of cross-chain transfers. While the prefill indicates the owner is a multisig, the concentration of power remains a significant risk factor (7.3 Access Control, 7.4 Economic, 7.8 Operations).
FixEnsure the owner's multisig is secured with robust key management practices, including strong operational security, geographical distribution of signers, and regular audits. Consider implementing a timelock for critical administrative actions to provide a window for detection and mitigation of malicious or erroneous changes. All configuration changes should undergo thorough review and testing.
StatusUnresolved
Medium

Heavy Reliance on LayerZero Protocol Security

M-01The KavaOFT contract is a thin wrapper around the LayerZero OFT library and directly interacts with the LayerZero v2 Endpoint. Its security and functionality are entirely dependent on the correctness and security of these underlying LayerZero components. Any vulnerabilities, bugs, or design flaws within the LayerZero protocol itself (e.g., in `OFT.sol` or `ILayerZeroEndpointV2.sol`) could directly impact the KavaOFT contract and potentially lead to loss of funds or operational failures (7.6 External).
IssueThe KavaOFT contract is a thin wrapper around the LayerZero OFT library and directly interacts with the LayerZero v2 Endpoint. Its security and functionality are entirely dependent on the correctness and security of these underlying LayerZero components. Any vulnerabilities, bugs, or design flaws within the LayerZero protocol itself (e.g., in `OFT.sol` or `ILayerZeroEndpointV2.sol`) could directly impact the KavaOFT contract and potentially lead to loss of funds or operational failures (7.6 External).
FixWhile direct auditing of LayerZero's core contracts is outside the scope of this specific contract audit, it is crucial for the project team to stay informed about LayerZero's security posture, including any audits, bug bounties, or reported vulnerabilities. Maintain a strategy for responding to potential LayerZero-level incidents, such as pausing functionality if possible or communicating risks to users.
StatusUnresolved
Low

Immutable LayerZero Endpoint Address

L-01The `_lzEndpoint` address is set during the contract's construction and cannot be modified thereafter. This design choice ensures that the contract always interacts with a specific, known LayerZero endpoint (7.1 Architecture). However, it also means that if the LayerZero protocol were to deprecate the current endpoint, or if a critical vulnerability in the endpoint required an immediate replacement, the KavaOFT contract would need to be redeployed to point to a new endpoint (7.8 Operations).
IssueThe `_lzEndpoint` address is set during the contract's construction and cannot be modified thereafter. This design choice ensures that the contract always interacts with a specific, known LayerZero endpoint (7.1 Architecture). However, it also means that if the LayerZero protocol were to deprecate the current endpoint, or if a critical vulnerability in the endpoint required an immediate replacement, the KavaOFT contract would need to be redeployed to point to a new endpoint (7.8 Operations).
FixAcknowledge this design trade-off. For future versions or similar contracts, consider if a mechanism for the owner to update the LayerZero endpoint address (e.g., via a controlled `setLzEndpoint` function with a timelock) might be beneficial, weighing the added complexity and attack surface against the flexibility gained. For the current contract, ensure the chosen endpoint is stable and well-supported.
StatusUnresolved
Info

Dual Role of Constructor `_delegate` Parameter

I-01The `_delegate` parameter in the `KavaOFT` constructor serves two distinct roles: it is passed to the `OFT` base contract as its delegate and also becomes the `Ownable` owner of the `KavaOFT` contract. This dual assignment means the same address controls both the LayerZero-specific delegate functions and the general contract ownership (7.1 Architecture, 7.3 Access Control).
IssueThe `_delegate` parameter in the `KavaOFT` constructor serves two distinct roles: it is passed to the `OFT` base contract as its delegate and also becomes the `Ownable` owner of the `KavaOFT` contract. This dual assignment means the same address controls both the LayerZero-specific delegate functions and the general contract ownership (7.1 Architecture, 7.3 Access Control).
FixEnsure that deployers and administrators are fully aware of this dual role. While not a vulnerability, clarity on the responsibilities and powers associated with the `_delegate` address is important for proper operational security and understanding of the contract's control structure.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The KavaOFT contract exhibits high code quality, being a straightforward implementation that primarily delegates logic to the audited LayerZero OFT library (7.2 Code Security). The architecture is simple, extending standard and well-vetted components (7.1 Architecture). However, the contract's operational security is heavily reliant on the external LayerZero v2 protocol, meaning any vulnerabilities in LayerZero's core contracts could directly impact KavaOFT (7.6 External). Access control is managed via the Ownable pattern, granting significant configuration power to the owner (7.3 Access Control).

GovernanceHigh3/10

The contract owner, specified as a multisig, holds extensive administrative control over critical LayerZero configurations (7.5 Governance). This includes setting trusted remote addresses, minimum destination gas, and fee managers, which directly impact the economic flow and security of cross-chain transfers (7.4 Economic). While a multisig mitigates single-point-of-failure risks, compromise of the multisig or misconfiguration could lead to significant economic loss or operational disruption (7.8 Operations). Careful management of the owner's keys and configuration parameters is paramount.

UpgradesLow7/10

The KavaOFT contract itself is not designed as an upgradeable proxy (7.7 Upgrades). Its implementation is immutable once deployed. This simplifies its security profile by removing upgrade-related risks. However, if the underlying LayerZero endpoint or OFT logic requires significant changes that are not backward compatible, a new KavaOFT contract deployment would be necessary.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

10.0% in wallets76.6% in contracts
Effective Concentration40.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder50.3%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x3e75…d82b
Unlocked LP Held By
0xdfd1…379a0xf6cd…15c30xfdf7…76560x1458…8fbe

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (3-of-5)
  • Top-10 concentration > 30% (86.6% total → 40.6% effective; 10.0% in EOAs, 76.6% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 50.3% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

吉祥马Medium RiskARAI Token (AA)Medium RiskCZBURN (CBURN)Medium RiskGeniusMedium RiskRiverMedium RiskGUAMedium Risk

Would You Like a More Detailed Audit of Kava?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit