Quantum Audit Logo

Is MAGIC Safe?

On-chain security analysis — is it a scam or legit?

MAGIC MAGIC
0xf157…3f43
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
Executive SummaryAI Copilot

The MagicBridgeBase contract, deployed as a UUPS proxy, functions as a cross-chain bridge and an ERC-20 token. It enables token transfers across different chains and includes standard ERC-20 functionalities. The contract is owned, granting the owner significant control over bridge configurations, administrative functions, and upgrades. Two high-severity technical findings were identified, related to potential fund locking due to `msg.value` handling and state variable shadowing.

2 High1 Medium4 Informational
Volume 24h
$106.1K
Liquidity
$317.5K
Price
$0.06799
Token Age
11mo
Top 10 Holders
92.0%

Security Findings

High

Funds Sent to Non-Payable Function

CD-01The `transferRemote` functions are marked as `payable`, allowing users to send Ether along with their token transfers. However, the internal `_dispatch` function (or a function it calls) is identified as non-payable, meaning it is not designed to receive or handle Ether. If Ether is sent to this non-payable function, it could become permanently locked within the contract, making it inaccessible to users or the protocol.
IssueThe `transferRemote` functions are marked as `payable`, allowing users to send Ether along with their token transfers. However, the internal `_dispatch` function (or a function it calls) is identified as non-payable, meaning it is not designed to receive or handle Ether. If Ether is sent to this non-payable function, it could become permanently locked within the contract, making it inaccessible to users or the protocol.
FixEnsure that any function receiving `msg.value` is explicitly marked `payable` and includes logic to properly handle or forward the received Ether. If `_dispatch` is not intended to receive Ether, the `transferRemote` functions should either remove the `payable` keyword or ensure that `msg.value` is handled before calling `_dispatch`.
StatusUnresolved
High

State Variable Shadowing

CD-02The contract contains instances where a state variable is 'shadowed' by another variable (e.g., a local variable or an inherited variable with the same name). This can lead to confusion for developers and potentially cause the contract to use an incorrect variable value, leading to unexpected behavior or logic errors, especially in complex inheritance hierarchies.
IssueThe contract contains instances where a state variable is 'shadowed' by another variable (e.g., a local variable or an inherited variable with the same name). This can lead to confusion for developers and potentially cause the contract to use an incorrect variable value, leading to unexpected behavior or logic errors, especially in complex inheritance hierarchies.
FixRename shadowed variables to ensure unique identifiers across the contract's scope and its inheritance chain. This improves code clarity and prevents accidental use of the wrong variable, enhancing the contract's reliability.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0x7f4e…15ca — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0x7f4e…15ca — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 92.0% of supply. Of that, 52.7% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 23.4% in wallets, 15.9% in other contracts. 744 holders in total.
IssueThe ten largest holders own 92.0% of supply. Of that, 52.7% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 23.4% in wallets, 15.9% in other contracts. 744 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as Treasure (MAGIC), market cap $23M, rank #802. 744 holders.
IssueListed on CoinGecko as Treasure (MAGIC), market cap $23M, rank #802. 744 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $318K (DexScreener, all pools). 24h trading volume $29.3M (CoinGecko, all markets, daily snapshot). 24h trading volume $106K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $6.32 on 2022-02-19; the price is now 98.9108% below it.
IssueLiquidity $318K (DexScreener, all pools). 24h trading volume $29.3M (CoinGecko, all markets, daily snapshot). 24h trading volume $106K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $6.32 on 2022-02-19; the price is now 98.9108% below it.
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: a single wallet (EOA). Code: upgradeable proxy. Fees: no buy or sell tax. Market: $318K of DEX liquidity across 1 pools. Launch: 343 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: a single wallet (EOA). Code: upgradeable proxy. Fees: no buy or sell tax. Market: $318K of DEX liquidity across 1 pools. Launch: 343 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

The contract implements a cross-chain bridge with ERC-20 token functionalities, including `transferRemote` for sending tokens across chains and standard ERC-20 operations like `transfer` and `approve`. Key administrative functions such as `setDestinationGas`, `enrollRemoteRouter`, and `handle` are restricted to the owner or a designated mailbox. However, two high-severity issues were identified: `CD-01 Msg value in nonpayable` in the `_dispatch` function, which could lead to locked funds if Ether is sent to a non-payable internal function, and `CD-02 Shadowing state`, which can introduce subtle bugs due to variable name conflicts. (7.1 Architecture, 7.2 Code Security)

GovernanceHigh1/10

The contract utilizes an `OwnableUpgradeable` pattern, granting the owner extensive control over critical bridge parameters and administrative functions. The owner can `setDestinationGas` to configure gas costs for cross-chain transfers, `enrollRemoteRouter` to manage approved bridge routers, and `setHook` or `setInterchainSecurityModule` to modify core bridge logic. This centralized control, while efficient for management, introduces a single point of failure where a compromised owner key could lead to significant operational and economic risks, including potential manipulation of transfer fees or routing. (7.3 Access Control, 7.4 Economic, 7.5 Governance, 7.8 Operations)

UpgradesHigh1/10

The contract is deployed as a UUPS proxy, allowing for future upgrades of its logic. The `upgradeToAndCall` function, which facilitates these upgrades, is restricted to a specific role or the proxy itself, implying owner or designated administrator control. While UUPS provides flexibility for bug fixes and feature enhancements, the centralized control over upgrades means that a malicious or compromised owner could deploy a malicious implementation, potentially leading to loss of funds or control. Regular audits of upgrade proposals are crucial. (7.7 Upgrades)

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEip1967 Uups
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

23.4% in wallets15.9% in contracts
Effective Concentration29.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.9%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x76d0…2297
Unlocked LP Held By
0x7f4e…15ca0x6be1…f69d0x6313…1a600x6189…84d0

What Raised This Score

  • Upgradeable proxy — the admin can replace the logic
  • Liquidity NOT locked (100% of the pool) — who holds it cannot be verified
  • Top-10 concentration > 20% (92.0% total → 29.8% effective; 23.4% in EOAs, 15.9% in contracts; 52.7% burned, locked or in pools excluded)
  • Code: Funds Sent to Non-Payable Function (High, static analysis)
  • Code: State Variable Shadowing (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

XMAQUINA (DEUS)High RiskTownsHigh RiskICPHigh RiskGAME by Virtuals (GAME)High RiskRecallHigh RiskVANRYHigh Risk

Would You Like a More Detailed Audit of MAGIC?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit