Quantum Audit Logo
Launch App

Is SPDR S&P 500 ETF (Ondo Tokenized) Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

SPDR S&P 500 ETF (Ondo Tokenized) SPYON
0xfedc…2c08
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

The GMToken contract is an upgradeable ERC-20 token utilizing a Beacon proxy pattern. It incorporates AccessControl for managing privileged roles, allowing for features like pausing transfers, setting compliance rules, and minting new tokens. Key findings highlight the ability for a privileged role to mint new tokens, potentially diluting existing holders, and the critical ability for a privileged role to replace external contracts that dictate transfer logic, posing a significant centralization risk.

1 High2 Medium4 Informational
Volume 24h
$496.8K
Liquidity
$109.8K
Price
$787.8600
Token Age
1y
Top 10 Holders
71.8%

Security Findings

High

Critical External Dependency Manipulation

CP-03The `setCompliance(address _compliance)` and `setTokenPauseManager(address _tokenPauseManager)` functions allow an address holding the `CONFIGURER_ROLE` to change the addresses of external contracts that directly influence how token transfers behave. The `compliance` and `tokenPauseManager` contracts can dictate rules, fees, or even pause transfers. This means that whoever controls the `CONFIGURER_ROLE` can effectively control or disrupt all token transfers by pointing to a malicious or arbitrary contract.
IssueThe `setCompliance(address _compliance)` and `setTokenPauseManager(address _tokenPauseManager)` functions allow an address holding the `CONFIGURER_ROLE` to change the addresses of external contracts that directly influence how token transfers behave. The `compliance` and `tokenPauseManager` contracts can dictate rules, fees, or even pause transfers. This means that whoever controls the `CONFIGURER_ROLE` can effectively control or disrupt all token transfers by pointing to a malicious or arbitrary contract.
FixToken holders should understand that the project administrators have significant control over the token's transfer mechanics. It is crucial for the project to secure the `CONFIGURER_ROLE` with the highest level of security, such as a multi-signature wallet with a high threshold. Any changes to these critical dependency addresses should be communicated transparently and ideally be subject to a time-lock to allow for community review.
StatusUnresolved
Medium

Centralized Minting Capability

CP-01The `mint(address to, uint256 amount)` function allows an address holding the `MINTER_ROLE` to create new tokens and assign them to any address. This increases the total supply of GMToken, which can dilute the value of tokens held by existing token holders without their consent.
IssueThe `mint(address to, uint256 amount)` function allows an address holding the `MINTER_ROLE` to create new tokens and assign them to any address. This increases the total supply of GMToken, which can dilute the value of tokens held by existing token holders without their consent.
FixToken holders should be aware that the supply of GMToken is not fixed and can be increased by the project's administrators. It is recommended that the project clearly communicates its minting policy and any planned minting events to the community. Consider implementing a time-lock or multi-signature requirement for minting operations to add an extra layer of security and transparency.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 94.0% is held, unlocked, by 10 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 59% of the token's DEX liquidity; the other pools were not assessed.
Issue0.0% of the pool's LP is burned or time-locked. 94.0% is held, unlocked, by 10 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 59% of the token's DEX liquidity; the other pools were not assessed.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 71.8% of supply. What remains: 32.6% in wallets, 39.2% in other contracts. 2,151 holders in total.
IssueThe ten largest holders own 71.8% of supply. What remains: 32.6% in wallets, 39.2% in other contracts. 2,151 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as SPDR S&P 500 ETF (Ondo Tokenized ETF) (SPYON), market cap $47M, rank #507. 2,151 holders.
IssueListed on CoinGecko as SPDR S&P 500 ETF (Ondo Tokenized ETF) (SPYON), market cap $47M, rank #507. 2,151 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $185K (DexScreener, all pools). 24h trading volume $2.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $867K (DexScreener, all pools).
IssueLiquidity $185K (DexScreener, all pools). 24h trading volume $2.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $867K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $185K of DEX liquidity across 17 pools. Launch: 399 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $185K of DEX liquidity across 17 pools. Launch: 399 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

The GMToken contract is built upon OpenZeppelin's upgradeable ERC-20 and AccessControl standards, ensuring a robust and well-tested foundation (7.1 Architecture, 7.2 Code Security). Access control is central, with specific roles like `MINTER_ROLE` and `CONFIGURER_ROLE` governing sensitive operations (7.3 Access Control). For instance, `grantRole` and `revokeRole` manage these permissions. However, the extensive power granted to these roles, such as the ability to `mint` new tokens or `setCompliance` and `setTokenPauseManager` to external contracts, introduces significant centralization risks.

GovernanceHigh2/10

The economic stability of the GMToken is highly dependent on the integrity of its privileged roles (7.4 Economic). A role can `mint` new tokens, directly increasing total supply and diluting existing token holders (CP-01). Furthermore, the `setCompliance` and `setTokenPauseManager` functions allow a privileged role to replace critical external contracts that govern transfer rules, potentially enabling arbitrary transfer restrictions or fees (CP-03). This level of control over core token functionality represents a high governance risk (7.5 Governance), as a compromised key or malicious actor could severely impact token value and utility.

UpgradesHigh1/10

The GMToken contract is deployed using a Beacon proxy pattern, making it upgradeable (7.7 Upgrades). This allows for future enhancements or bug fixes to the token's logic. The `AccessControlUpgradeable` inheritance ensures that upgradeability is managed through roles. While upgradeability offers flexibility, it also introduces a risk vector: a malicious or compromised upgrade administrator could deploy a harmful implementation, fundamentally altering the token's behavior or even draining funds. Careful management of the upgrade roles and thorough testing of new implementations are crucial.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeBeacon
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

32.6% in wallets39.2% in contracts
Effective Concentration48.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 7 remaining pairs hold $10.5K between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder22.5%
Top-3 Unlocked57.3%

Key Addresses

Deployer
0x61ea…9536
Unlocked LP Held By
0x1592…02550x39a3…98c10xfde9…8bad0x371a…9b180x85a0…d7810x2e14…294d0x0ce2…1ef00x4d87…c0030x0203…81240x07ad…da95

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • A privileged address can replace a contract every transfer depends on
  • Mintable supply — no cap found, dilution unbounded
  • Upgradeable proxy — the admin can replace the logic
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool; this pool is 59% of DEX liquidity) — held by independent providers — market-depth risk
  • Top-10 concentration > 30% (71.8% total → 48.3% effective; 32.6% in EOAs, 39.2% in contracts)
  • The deployer has launched a honeypot before

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

NEXOHigh RiskCronos (CRO)High RiskEpic Chain (EPIC)High RiskAZTECHigh RiskCoW Protocol Token (COW)High RiskMetronome Synth ETH (MSETH)High Risk

Would You Like a More Detailed Audit of SPDR S&P 500 ETF (Ondo Tokenized)?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit