Quantum Audit Logo

Is Trusta.AI Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Trusta.AI TA
0x539a…b140
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 9d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The TrustaOFT contract is an ERC20 token implementing LayerZero's Omnichain Fungible Token (OFT) standard and OpenZeppelin's ERC20Permit. The contract is minimal, primarily inheriting from well-audited libraries. Initial token minting occurs only on a designated main chain. The primary risks identified are related to the inherent reliance on the LayerZero protocol's security and the operational management of its configurations by the multisig owner.

1 High1 Low1 Informational
Volume 24h
$1.52M
Liquidity
$237.1K
Price
$0.05328
Token Age
1y
Top 10 Holders
95.4%

Security Findings

High

Reliance on LayerZero Protocol and Configuration

H-01The `TrustaOFT` contract relies heavily on the LayerZero protocol for its cross-chain functionality. The security and integrity of the token's supply across different chains are directly dependent on the correct functioning and security of the LayerZero endpoint and its underlying infrastructure. Any vulnerabilities or misconfigurations within the LayerZero protocol itself could impact the `TrustaOFT` token's cross-chain operations and overall supply integrity.
IssueThe `TrustaOFT` contract relies heavily on the LayerZero protocol for its cross-chain functionality. The security and integrity of the token's supply across different chains are directly dependent on the correct functioning and security of the LayerZero endpoint and its underlying infrastructure. Any vulnerabilities or misconfigurations within the LayerZero protocol itself could impact the `TrustaOFT` token's cross-chain operations and overall supply integrity.
FixWhile this is an inherent design choice for an Omnichain Fungible Token, it is crucial to monitor LayerZero's security announcements and ensure the `_lzEndpoint` address provided during deployment is correct and trusted. Implement robust monitoring for cross-chain transactions and LayerZero endpoint health.
StatusUnresolved
Low

Operational Risk of LayerZero Configuration

L-01The owner (a multisig, according to prefill data) has significant control over LayerZero-specific configurations, such as setting trusted remotes (`setPeer`), minimum destination gas (`setMinDstGas`), and other parameters. Incorrect or malicious configuration by the owner, even if it's a multisig, could lead to funds being stuck, lost, or enable unauthorized cross-chain transfers if not handled carefully.
IssueThe owner (a multisig, according to prefill data) has significant control over LayerZero-specific configurations, such as setting trusted remotes (`setPeer`), minimum destination gas (`setMinDstGas`), and other parameters. Incorrect or malicious configuration by the owner, even if it's a multisig, could lead to funds being stuck, lost, or enable unauthorized cross-chain transfers if not handled carefully.
FixThe multisig owners should establish strict internal procedures and multiple-party review for any changes to LayerZero configurations. Thoroughly test configuration changes in a staging environment before applying them to production. Consider time-locks for critical configuration changes.
StatusUnresolved
Info

Front-running Risk with ERC20Permit

I-01The `ERC20Permit` functionality allows users to sign off-chain approvals, which can then be submitted on-chain by anyone. This introduces a potential front-running vector where a malicious actor could observe a signed `permit` message, front-run the transaction to use the approval themselves, or cause the original transaction to fail, leading to a poor user experience.
IssueThe `ERC20Permit` functionality allows users to sign off-chain approvals, which can then be submitted on-chain by anyone. This introduces a potential front-running vector where a malicious actor could observe a signed `permit` message, front-run the transaction to use the approval themselves, or cause the original transaction to fail, leading to a poor user experience.
FixUsers should be educated on the risks associated with `permit` functionality, especially regarding transaction submission. Off-chain relayers should implement anti-front-running measures (e.g., using a trusted relayer, setting strict gas price limits, or using commit-reveal schemes if applicable) to protect users.
StatusUnresolved

Category Ratings

TechnicalLow9/10

The contract (7.1 Architecture) is well-structured, inheriting from battle-tested OpenZeppelin and LayerZero libraries. The code (7.2 Code Security) is minimal and straightforward, reducing the surface area for vulnerabilities. No direct reentrancy or integer overflow issues were found. However, the system's security is heavily dependent on the external LayerZero protocol (7.6 External), which introduces a significant technical dependency risk. The `ERC20Permit` functionality (7.2 Code Security) also introduces a potential front-running vector for users.

GovernanceMedium4/10

The contract utilizes `Ownable` for access control (7.3 Access Control), with the owner being a multisig address, which is a strong security practice (7.5 Governance). The token's economic model (7.4 Economic) is straightforward: a fixed supply minted on a single main chain, with cross-chain functionality managed by LayerZero. There are no complex economic mechanisms or oracle dependencies that could introduce manipulation risks. Operational risks (7.8 Operations) are present due to the owner's control over LayerZero configurations, but mitigated by multisig ownership.

UpgradesLow7/10

The TrustaOFT contract is not designed as an upgradeable proxy (7.7 Upgrades). It is a standard implementation contract, meaning its logic cannot be changed after deployment. This eliminates upgrade-related risks such as proxy misconfigurations or logic bugs introduced during upgrades, contributing to a low upgrade risk profile.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

13.7% in wallets81.7% in contracts
Effective Concentration46.4%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder44.0%
Top-3 Unlocked95.1%

Key Addresses

Deployer
0x2ee8…92da
Unlocked LP Held By
0x5fbe…94c40x0360…692a0xaaf2…a6010x35bc…01750x1262…3df00x3b86…b62e

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-5)
  • Top-10 concentration > 30% (95.4% total → 46.4% effective; 13.7% in EOAs, 81.7% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top3 unlocked holders = 95.1% (independent LP — depth risk, pool = 94% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ARKMedium Risk牛来Medium RiskSaturnMedium RiskMax Sister (LILY)Medium RiskMeta Financial AI (MEFAI)Medium RiskXPIN Token (XPIN)Medium Risk

Would You Like a More Detailed Audit of Trusta.AI?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit