Quantum Audit Logo

Is Plasma Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Plasma XPL
0x405f…26b0
BNB Chain Not verifiedLast checked 3d ago 1 audit on record
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The PlasmaOFT contract is an Omnichain Fungible Token (OFT) built on LayerZero, inheriting from OpenZeppelin's Ownable. The contract itself is minimal, primarily serving as a wrapper for LayerZero's OFT functionality. Key strengths include the use of well-audited OpenZeppelin components and a robust multisig ownership structure. The primary risks stem from its reliance on the LayerZero protocol's security and the inherent complexities of cross-chain bridge operations.

1 High2 Medium1 Low1 Informational
Volume 24h
$1.32M
Liquidity
$406.3K
Price
$0.09253
Token Age
10mo
Top 10 Holders
89.9%

Security Findings

High

Cross-Chain Bridge Security Risk

H-01The contract's core functionality relies on the LayerZero protocol for cross-chain token transfers. Bridge protocols are complex and have historically been targets for significant exploits, leading to substantial asset losses. Any vulnerability in the LayerZero endpoint, message passing, or associated relayers could directly impact the security of PlasmaOFT tokens across chains.
IssueThe contract's core functionality relies on the LayerZero protocol for cross-chain token transfers. Bridge protocols are complex and have historically been targets for significant exploits, leading to substantial asset losses. Any vulnerability in the LayerZero endpoint, message passing, or associated relayers could directly impact the security of PlasmaOFT tokens across chains.
FixConduct continuous monitoring of LayerZero protocol security announcements and audits. Implement robust off-chain monitoring for unusual cross-chain activity. Diversify bridge reliance if possible in future iterations.
StatusUnresolved
Medium

Dependency on LayerZero Protocol

M-01The PlasmaOFT contract is a wrapper around LayerZero's OFT implementation. Its security and functionality are entirely dependent on the correctness and security of the LayerZero libraries and the underlying LayerZero endpoint. While LayerZero is a prominent solution, any undiscovered vulnerability or operational issue within their extensive codebase could directly affect this contract.
IssueThe PlasmaOFT contract is a wrapper around LayerZero's OFT implementation. Its security and functionality are entirely dependent on the correctness and security of the LayerZero libraries and the underlying LayerZero endpoint. While LayerZero is a prominent solution, any undiscovered vulnerability or operational issue within their extensive codebase could directly affect this contract.
FixMaintain a deep understanding of the LayerZero protocol's architecture and security model. Regularly review LayerZero's official documentation, security updates, and audit reports. Ensure the `_lzEndpoint` address is correctly configured and points to the official, audited LayerZero endpoint.
StatusUnresolved
Medium

Lack of Emergency Pause Mechanism

M-02The PlasmaOFT contract, as a standard ERC-20/OFT implementation, does not include an emergency pause or circuit breaker mechanism. In the event of a critical vulnerability, exploit, or market manipulation, there is no immediate way for the owner to halt token transfers or cross-chain operations to prevent further loss of funds.
IssueThe PlasmaOFT contract, as a standard ERC-20/OFT implementation, does not include an emergency pause or circuit breaker mechanism. In the event of a critical vulnerability, exploit, or market manipulation, there is no immediate way for the owner to halt token transfers or cross-chain operations to prevent further loss of funds.
FixEvaluate the feasibility of integrating a pause mechanism, potentially at a higher protocol level or through a governance-controlled wrapper, to provide an emergency stop functionality. This would allow the owner (multisig) to temporarily freeze operations in critical situations, subject to predefined conditions and governance approval.
StatusUnresolved
Low

Configuration Risk for LayerZero Parameters

L-01The constructor takes `_lzEndpoint` and `_delegate` as parameters, which are critical for LayerZero operations and ownership. Incorrectly setting these parameters during deployment could lead to the contract being inoperable, funds being sent to the wrong endpoint, or control being assigned to an unintended address.
IssueThe constructor takes `_lzEndpoint` and `_delegate` as parameters, which are critical for LayerZero operations and ownership. Incorrectly setting these parameters during deployment could lead to the contract being inoperable, funds being sent to the wrong endpoint, or control being assigned to an unintended address.
FixImplement a rigorous deployment checklist and multi-party verification process for all constructor arguments, especially `_lzEndpoint` and `_delegate`. Ensure these addresses are thoroughly vetted and correspond to the intended, audited components.
StatusUnresolved
Info

Centralized Owner Privileges (Mitigated by Multisig)

I-01The contract inherits `Ownable`, granting the owner (the `_delegate` address) significant administrative control. While the provided prefill indicates this owner is a 4-of-6 multisig, centralizing control, even with a multisig, means that a compromise of the multisig signers could lead to unauthorized actions, such as reconfiguring LayerZero parameters or potentially impacting token functionality.
IssueThe contract inherits `Ownable`, granting the owner (the `_delegate` address) significant administrative control. While the provided prefill indicates this owner is a 4-of-6 multisig, centralizing control, even with a multisig, means that a compromise of the multisig signers could lead to unauthorized actions, such as reconfiguring LayerZero parameters or potentially impacting token functionality.
FixMaintain strict security practices for all multisig signers, including hardware wallets, strong authentication, and secure key management. Regularly review the multisig's operational procedures and ensure a clear understanding of the owner's capabilities and responsibilities.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The PlasmaOFT contract is a straightforward implementation of an Omnichain Fungible Token (OFT) using LayerZero's OFT library and OpenZeppelin's Ownable. The code is minimal and leverages battle-tested libraries, contributing to its technical robustness (7.2 Code Security). However, the contract's security is heavily dependent on the underlying LayerZero protocol, which introduces inherent complexities and potential attack vectors associated with cross-chain bridges (7.6 External). There is no explicit emergency pause mechanism, which could limit response capabilities during a critical incident (7.8 Operations).

GovernanceHigh1/10

The contract's ownership is managed by a robust 4-of-6 multisig, significantly mitigating risks associated with single points of failure or compromised private keys (7.3 Access Control, 7.5 Governance). This strong governance structure enhances the overall security posture. Economic risks are primarily tied to the stability and security of the underlying LayerZero bridge and the broader ecosystem rather than specific contract logic (7.4 Economic).

UpgradesMedium6/10

The PlasmaOFT contract is deployed as a standard, non-upgradeable implementation (7.7 Upgrades). This eliminates upgrade-specific risks such as proxy misconfigurations or logic contract vulnerabilities introduced during upgrades. Any future changes would require a new deployment and migration.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

88.3% in wallets1.5% in contracts
Effective Concentration88.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 2 remaining pairs hold $2 between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder95.1%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x277e…2483
Unlocked LP Held By
0xaa4c…b9080xcbac…d9b60x966d…e41a0x757e…7cdc0x1458…8fbe0xa873…45880x3cf3…6aaf0x3f52…40d40xfaad…fcf40x122e…9a0a

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-6)
  • Top-10 concentration > 70% (89.9% total → 88.9% effective; 88.3% in EOAs, 1.5% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 95.1% (independent LP — depth risk, pool = 92% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 92% of DEX liquidity)
  • 1 High finding(s) from audit
  • 2 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Anoma (XAN)Critical RiskMirex (MRX)Critical RiskCoinMarketCap 20 Index DTF (CMC20)Critical RiskPancakeSwap Token (CAKE)Critical RiskSubsquid (SQD)Critical RiskInfinity Ground AI (AIN)High Risk

Would You Like a More Detailed Audit of Plasma?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit