Quantum Audit Logo

Is Ondo Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Ondo ONDO
0xfaba…9be3
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit covers a truncated Solidity contract identified as a component of the Ondo project, specifically implementing OpenZeppelin's AccessControl module. The provided code is a standard, well-vetted library component, which generally implies high code quality. However, the truncation limits a comprehensive assessment of its full implementation and integration within the broader protocol. Key risks identified relate to the inherent centralization of the `DEFAULT_ADMIN_ROLE` and the critical importance of secure key management for all administrative roles.

1 Medium2 Low2 Informational
Volume 24h
$233.2K
Liquidity
$824.1K
Price
$0.3643
Token Age
2y
Top 10 Holders
68.7%

Security Findings

Medium

Centralization Risk with DEFAULT_ADMIN_ROLE

M-01The `DEFAULT_ADMIN_ROLE` in the AccessControl contract possesses extensive power, including the ability to grant and revoke all other roles, and it is its own admin. A compromise of the private key associated with an account holding this role could lead to a complete takeover of all access-controlled functions within the protocol (7.3, 7.5). This represents a single point of failure.
IssueThe `DEFAULT_ADMIN_ROLE` in the AccessControl contract possesses extensive power, including the ability to grant and revoke all other roles, and it is its own admin. A compromise of the private key associated with an account holding this role could lead to a complete takeover of all access-controlled functions within the protocol (7.3, 7.5). This represents a single point of failure.
FixImplement robust security measures for accounts holding the `DEFAULT_ADMIN_ROLE`. Consider using a multi-signature wallet (e.g., Gnosis Safe) for this role, or a time-locked contract for critical administrative actions. Distribute the control of the multi-sig among trusted, independent parties. Regularly review and rotate administrative keys if feasible.
StatusUnresolved
Low

Reliance on OpenZeppelin Standard Library

L-01The contract utilizes OpenZeppelin's `AccessControl` module, which is a widely adopted, well-audited, and community-vetted standard library. This significantly reduces the likelihood of fundamental vulnerabilities within the access control mechanism itself (7.2).
IssueThe contract utilizes OpenZeppelin's `AccessControl` module, which is a widely adopted, well-audited, and community-vetted standard library. This significantly reduces the likelihood of fundamental vulnerabilities within the access control mechanism itself (7.2).
FixContinue to leverage well-established and audited libraries like OpenZeppelin. Ensure that the specific version used is free from known vulnerabilities and that any custom modifications or integrations are thoroughly reviewed.
StatusResolved
Low

Lack of On-Chain Role Enumerability

L-02The `AccessControl` contract, as implemented, does not provide functions to enumerate all members of a given role on-chain. While this design choice reduces gas costs, it can make it more challenging to perform on-chain audits or verify current permissions without relying on off-chain event log parsing (7.3).
IssueThe `AccessControl` contract, as implemented, does not provide functions to enumerate all members of a given role on-chain. While this design choice reduces gas costs, it can make it more challenging to perform on-chain audits or verify current permissions without relying on off-chain event log parsing (7.3).
FixIf on-chain enumerability is desired for transparency or specific protocol needs, consider using OpenZeppelin's `AccessControlEnumerable` variant. Otherwise, ensure robust off-chain monitoring and tooling are in place to track role assignments and revocations effectively.
StatusUnresolved
Info

Incomplete Code Provided for Audit

I-01The provided source code for the 'Ondo.sol' contract is truncated, specifically cutting off in the middle of the `renounceRole` function. This limitation prevents a complete and comprehensive security assessment of the entire contract, its full functionality, and its interactions with other potential components of the Ondo protocol.
IssueThe provided source code for the 'Ondo.sol' contract is truncated, specifically cutting off in the middle of the `renounceRole` function. This limitation prevents a complete and comprehensive security assessment of the entire contract, its full functionality, and its interactions with other potential components of the Ondo protocol.
FixProvide the complete and untruncated source code for all relevant contracts to enable a thorough security audit. This includes all inherited contracts, libraries, and any custom logic specific to the Ondo protocol.
StatusUnresolved
Info

Critical Importance of Secure Key Management

I-02The overall security and integrity of the access control system, and by extension the entire protocol, are fundamentally dependent on the secure management of private keys associated with accounts holding administrative roles. Any compromise of these keys could lead to unauthorized control and potential loss of funds (7.8).
IssueThe overall security and integrity of the access control system, and by extension the entire protocol, are fundamentally dependent on the secure management of private keys associated with accounts holding administrative roles. Any compromise of these keys could lead to unauthorized control and potential loss of funds (7.8).
FixEducate all role holders on best practices for private key security, including hardware wallets, secure storage, and phishing awareness. Implement strict operational procedures for managing and accessing these keys. Consider emergency procedures in case of key compromise.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The provided code snippet is a standard implementation of OpenZeppelin's AccessControl, demonstrating robust architecture (7.1) and adherence to secure coding practices (7.2). The use of `_msgSender()` for meta-transaction compatibility is a positive design choice. However, the truncation of the source code prevents a full technical review of the complete contract, including its specific business logic and potential interactions, which could introduce unforeseen vulnerabilities.

GovernanceMedium4/10

The contract establishes a role-based access control system (7.3), which is a fundamental governance mechanism. The `DEFAULT_ADMIN_ROLE` holds significant power, capable of managing all other roles, which introduces a centralization risk (7.5). While this design is standard for AccessControl, it necessitates extremely secure management of the associated private keys to prevent unauthorized control over the protocol's functions. The economic implications (7.4) are tied to the security of these administrative roles, as their compromise could lead to unauthorized actions affecting protocol assets.

UpgradesHigh3/10

The provided contract is a base AccessControl module and does not inherently include upgradeability mechanisms (7.7). Its role in an upgradeable system would depend on how it's integrated (e.g., as a logic contract in a proxy pattern). Without the full context of the 'Ondo' contract, it's assumed to be a non-upgradeable component or a base for a non-proxy token. Therefore, direct upgrade safety concerns for this specific snippet are minimal.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass

Holder Composition

13.6% in wallets55.1% in contracts
Effective Concentration35.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 5 remaining pairs hold $2.6K between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder29.4%
Top-3 Unlocked78.2%

Key Addresses

Deployer
0xe2d0…4bbe
Unlocked LP Held By
0xa10f…2a370xc998…188d0x9bd0…529f0x9823…d98e0xf35f…520a0x9d81…93ad0x54bd…d6470xe387…42450x3fb3…a48d0x0df8…eb63

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 30% (68.7% total → 35.6% effective; 13.6% in EOAs, 55.1% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • 1 Medium finding(s) from audit
  • 2 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Ondo a scam?

Based on the provided data, Ondo does not exhibit typical scam characteristics. The contract is verified, ownership has been renounced, and there is no function to mint new tokens, all of which are strong positive indicators of legitimate intent and foundational security. While a medium risk score of 43/100 exists due to other factors like holder concentration, these technical safeguards suggest it's not designed as a rug-pull or scam project.

Is Ondo safe to buy?

Investing in Ondo carries a medium risk profile, as indicated by its 43/100 score. Key safety aspects include a verified contract, renounced ownership, and no mint function, which mitigate several common smart contract risks. However, significant risk factors remain, primarily the high concentration of 71.1% of tokens among the top 10 holders and the lack of locked liquidity. Investors should weigh these risks against the project's overall transparency and technical safeguards.

Has Ondo been audited?

The provided data confirms that the Ondo contract is 'Verified: True'. This means its code is publicly available and transparent on the blockchain, allowing for anyone, including auditors, to review it. While contract verification is a crucial step for security and transparency, the data does not explicitly state that a formal third-party security audit has been completed and published. Investors typically seek full audit reports for comprehensive assurance beyond verification.

Related Audits

Artificial Superintelligence Alliance (FET)Medium RiskRequest Token (REQ)Medium RiskIdentity.md (IMD)Medium RiskHighstreet token (HIGH)Medium RiskOutBurnMedium RiskWrapped Gonka (WGNK)Medium Risk

Would You Like a More Detailed Audit of Ondo?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit