Quantum Audit Logo

Is OpenGradient Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

OpenGradient OPG
0x5fec…cb9d
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 1d ago 1 audit on record
Executive SummaryAI Copilot

The OpenGradientOFT contract is an Omnichain Fungible Token (OFT) built on LayerZero v2, inheriting from LayerZero's OFT and OpenZeppelin's Ownable contracts. The contract's logic is minimal, primarily relying on battle-tested external libraries. The primary risks are associated with the owner's centralized control over LayerZero configurations and the inherent dependency on the LayerZero protocol's security. The owner is a 2/3 multisig, which mitigates some centralization risks.

1 Medium1 Low3 Informational
Volume 24h
$53.9K
Liquidity
$21.2K
Price
$0.1397
Token Age
5mo
Top 10 Holders
92.3%

Security Findings

Medium

Centralized Control by Owner

M-01The contract inherits from OpenZeppelin's `Ownable` contract, granting the deployer-designated owner significant control over critical LayerZero configurations. The owner can call functions like `setTrustedRemoteAddress`, `setMinDstGas`, and `setDelegate` on the underlying OFT contract. While the owner is a 2/3 multisig, a compromise of the multisig's keys could lead to unauthorized configuration changes, potentially disrupting cross-chain transfers or leading to loss of funds.
IssueThe contract inherits from OpenZeppelin's `Ownable` contract, granting the deployer-designated owner significant control over critical LayerZero configurations. The owner can call functions like `setTrustedRemoteAddress`, `setMinDstGas`, and `setDelegate` on the underlying OFT contract. While the owner is a 2/3 multisig, a compromise of the multisig's keys could lead to unauthorized configuration changes, potentially disrupting cross-chain transfers or leading to loss of funds.
FixWhile the use of a multisig mitigates some risk, consider implementing a time-lock mechanism for critical administrative actions. This would introduce a delay between the initiation and execution of sensitive operations, allowing time for detection and intervention in case of a malicious or erroneous transaction. Additionally, ensure robust key management practices for the multisig signers.
StatusUnresolved
Low

Non-Upgradeable Contract

L-01The OpenGradientOFT contract is deployed as a standard, non-upgradeable contract. This means that its logic cannot be modified after deployment. While this eliminates risks associated with upgrade mechanisms (e.g., proxy vulnerabilities), it also means that any discovered bugs or desired feature enhancements would necessitate a new contract deployment and a potentially complex token migration process.
IssueThe OpenGradientOFT contract is deployed as a standard, non-upgradeable contract. This means that its logic cannot be modified after deployment. While this eliminates risks associated with upgrade mechanisms (e.g., proxy vulnerabilities), it also means that any discovered bugs or desired feature enhancements would necessitate a new contract deployment and a potentially complex token migration process.
FixThis is a design choice. If future upgradeability is desired, a proxy pattern (e.g., UUPS or Transparent) should be considered during the initial design phase. For the current non-upgradeable design, ensure thorough testing and auditing to minimize the likelihood of needing future changes.
StatusUnresolved
Info

Heavy Dependency on LayerZero v2 Protocol

I-01The `OpenGradientOFT` contract is built upon LayerZero v2's `OFT` contract, making it entirely dependent on the security, correctness, and operational integrity of the LayerZero protocol and its associated endpoints. Any vulnerabilities, misconfigurations, or operational failures within the LayerZero infrastructure could directly impact the functionality and security of the OpenGradientOFT token, potentially leading to frozen assets or incorrect cross-chain transfers.
IssueThe `OpenGradientOFT` contract is built upon LayerZero v2's `OFT` contract, making it entirely dependent on the security, correctness, and operational integrity of the LayerZero protocol and its associated endpoints. Any vulnerabilities, misconfigurations, or operational failures within the LayerZero infrastructure could directly impact the functionality and security of the OpenGradientOFT token, potentially leading to frozen assets or incorrect cross-chain transfers.
FixMaintain continuous monitoring of LayerZero's security announcements, audits, and operational status. Establish clear procedures for responding to potential LayerZero-related incidents. Diversify cross-chain solutions if the project's risk tolerance allows for it, or ensure a robust incident response plan is in place for LayerZero-specific issues.
StatusUnresolved
Info

Constructor Delegate as Owner

I-02In the constructor, the `_delegate` address is used for both initializing the `OFT` base contract (as the LayerZero delegate) and the `Ownable` base contract (as the contract owner). This design choice ensures that the same entity controls both the LayerZero-specific delegate functions and the general contract ownership functions.
IssueIn the constructor, the `_delegate` address is used for both initializing the `OFT` base contract (as the LayerZero delegate) and the `Ownable` base contract (as the contract owner). This design choice ensures that the same entity controls both the LayerZero-specific delegate functions and the general contract ownership functions.
FixThis is a consistent design choice. Ensure that the chosen `_delegate` address (which is a multisig in this case) is highly secure and trusted, as it holds comprehensive control over the token's administrative and cross-chain functionalities.
StatusUnresolved
Info

Fixed Token Name and Symbol

I-03The token's `NAME` ('OpenGradient') and `SYMBOL` ('OPG') are declared as `private constant` variables within the contract. This means they are immutable and cannot be changed after deployment.
IssueThe token's `NAME` ('OpenGradient') and `SYMBOL` ('OPG') are declared as `private constant` variables within the contract. This means they are immutable and cannot be changed after deployment.
FixThis is standard and expected behavior for ERC-20 compliant tokens. No action is required unless there was an explicit requirement for these properties to be mutable.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The OpenGradientOFT contract is a straightforward implementation of an Omnichain Fungible Token (OFT) using LayerZero v2. It leverages well-audited OpenZeppelin `Ownable` and LayerZero `OFT` base contracts, minimizing custom logic and potential for new vulnerabilities (7.2 Code Security). The contract's architecture (7.1 Architecture) is simple and follows established patterns for cross-chain tokens. Access control (7.3 Access Control) is managed via the `Ownable` pattern, granting the designated owner significant configuration capabilities over LayerZero parameters, which is a standard design for such tokens.

GovernanceHigh1/10

The contract's economic model (7.4 Economic) is that of a standard fungible token, with its value derived from external factors not within the contract's scope. Governance (7.5 Governance) is centralized through the `Ownable` pattern, where the owner address has control over critical LayerZero configurations such as setting trusted remotes and minimum destination gas. This centralization is mitigated by the owner being a 2/3 multisig, reducing the risk of a single point of failure or malicious action. However, the security of the multisig's keys remains paramount for the overall security of the token.

UpgradesMedium6/10

The OpenGradientOFT contract is not designed to be upgradeable (7.7 Upgrades), as it does not implement any proxy pattern. This eliminates all risks associated with upgradeability, such as proxy misconfigurations or logic errors during upgrades. However, it also means that any future bug fixes, feature enhancements, or changes to the token's core logic would require a new contract deployment and a migration of existing tokens, which can be a complex and costly process.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

79.3% in wallets13.0% in contracts
Effective Concentration84.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder67.8%
Top-3 Unlocked98.4%

Key Addresses

Deployer
0x93ce…cb85
Unlocked LP Held By
0xf949…02980x5fbe…94c40xbc7a…3e710x234b…f3b70x1c59…2ef30x0ca1…4769

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — Multisig (2-of-3)
  • Top-10 concentration > 70% (92.3% total → 84.5% effective; 79.3% in EOAs, 13.0% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $50k ($21,231 across 5 pairs — thin market)
  • LP top1 unlocked holder = 67.8% (independent LP — depth risk, pool = 100% of DEX liquidity)
  • LP top3 unlocked holders = 98.4% (independent LP — depth risk, pool = 100% of DEX liquidity)
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Quack AI Token (Q)High RiskHoloworld AI (HOLO)High RiskPowerHigh RiskCreoEngine (CREO)High RiskXPULSHigh RiskHana Token (HANA)High Risk

Would You Like a More Detailed Audit of OpenGradient?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit