On-chain security analysis — is it a scam or legit?
0x3119…cf82
The CrossChainERC20 contract implements a standard ERC20 token with minting and burning capabilities controlled by an immutable bridge address. It leverages the well-regarded Solady library for its ERC20 base and `Initializable` pattern. A critical design flaw was identified where the `initialize` function, intended for token configuration, is rendered unusable due to a call to `_disableInitializers()` in the constructor, assuming direct deployment. The contract's security heavily relies on the external bridge's integrity, and its immutable bridge address lacks operational flexibility. The provided metadata indicates this is not a proxy, which makes the `initialize` issue critical.
Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.
The 13 remaining pairs hold $28.1K between them and are not listed.
The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.
0xfb42…1e600x7d27…fd550xbefd…ec9d0x97d1…59550x0c2f…6af40x5caa…bb0a0x2e33…47cf0x4cb0…160f0xcd19…c7350x130b…0f460x2e63…3202No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
Based on automated analysis, Solana scores 63/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.
Our scanner flagged a risk score of 63/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.
The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.
Get Detailed Audit