Quantum Audit Logo

Is Unibase Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Unibase UB
0x40b8…6fde
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 1 audit on record
Executive SummaryAI Copilot

This audit reviews the provided Solidity interface definitions for LayerZero V2. As only interfaces were provided, the scope is limited to design patterns, potential integration risks, and general security considerations for systems implementing these cross-chain communication primitives. The provided contract address likely refers to a concrete implementation of these interfaces. No executable contract logic was available for direct vulnerability analysis.

1 High3 Medium1 Low1 Informational
Volume 24h
$2.72M
Liquidity
$3.76M
Price
$0.1241
Token Age
10mo
Top 10 Holders
76.0%

Security Findings

High

Critical Access Control for Administrative Functions

H-01The LayerZero V2 interfaces define numerous functions that can alter the behavior or economic parameters of the LayerZero endpoint (e.g., `setLzToken`, `setDelegate`, `registerLibrary`, `setDefaultSendLibrary`, `setDefaultReceiveLibrary`, `setConfig`). Without proper access control implemented in the concrete contract, these functions could be exploited by unauthorized entities, leading to misconfiguration, denial of service, or theft of funds. The interfaces themselves do not enforce any access control.
IssueThe LayerZero V2 interfaces define numerous functions that can alter the behavior or economic parameters of the LayerZero endpoint (e.g., `setLzToken`, `setDelegate`, `registerLibrary`, `setDefaultSendLibrary`, `setDefaultReceiveLibrary`, `setConfig`). Without proper access control implemented in the concrete contract, these functions could be exploited by unauthorized entities, leading to misconfiguration, denial of service, or theft of funds. The interfaces themselves do not enforce any access control.
FixAll administrative functions in the implementing contract must be protected by robust access control mechanisms, such as `onlyOwner`, `onlyRole`, or multi-signature wallet control. Access should be granted on a least-privilege basis.
StatusUnresolved
Medium

Complexity and Implementation Risk

M-01The LayerZero V2 interfaces expose a highly modular and configurable system for cross-chain communication. While flexible, this complexity increases the likelihood of implementation errors in concrete OApp contracts. Misunderstanding the message lifecycle (`send`, `verify`, `lzReceive`, `clear`, `skip`, `nilify`, `burn`) or configuration parameters could lead to vulnerabilities like message loss, replay attacks, or unintended state changes.
IssueThe LayerZero V2 interfaces expose a highly modular and configurable system for cross-chain communication. While flexible, this complexity increases the likelihood of implementation errors in concrete OApp contracts. Misunderstanding the message lifecycle (`send`, `verify`, `lzReceive`, `clear`, `skip`, `nilify`, `burn`) or configuration parameters could lead to vulnerabilities like message loss, replay attacks, or unintended state changes.
FixImplementers should thoroughly understand the LayerZero V2 documentation and best practices. Extensive unit, integration, and cross-chain testing is crucial. Consider formal verification for critical message handling logic to ensure correctness.
StatusUnresolved
Medium

Economic Parameter Manipulation Risk

M-02Functions like `quote` and `send` involve `MessagingFee` (native and LZ token fees). The `setLzToken` function allows changing the LZ token. If the logic for calculating or accepting fees in the implementing contract is flawed, or if `setLzToken` is compromised, it could lead to economic exploits, such as users paying incorrect fees or attackers manipulating the system for profit.
IssueFunctions like `quote` and `send` involve `MessagingFee` (native and LZ token fees). The `setLzToken` function allows changing the LZ token. If the logic for calculating or accepting fees in the implementing contract is flawed, or if `setLzToken` is compromised, it could lead to economic exploits, such as users paying incorrect fees or attackers manipulating the system for profit.
FixEnsure fee calculation logic in the implementing contract is robust and resistant to manipulation. Implement strict validation for `_params.options` and `_refundAddress`. Access to `setLzToken` must be highly restricted and subject to strong governance.
StatusUnresolved
Medium

External Dependency Risk

M-03The security of any system built on LayerZero V2 inherently depends on the security and liveness of the underlying LayerZero network, including its relayer infrastructure and oracle mechanisms. While the interfaces define the interaction points, they do not mitigate risks stemming from potential compromises or failures within the LayerZero protocol itself (7.6 External).
IssueThe security of any system built on LayerZero V2 inherently depends on the security and liveness of the underlying LayerZero network, including its relayer infrastructure and oracle mechanisms. While the interfaces define the interaction points, they do not mitigate risks stemming from potential compromises or failures within the LayerZero protocol itself (7.6 External).
FixOApp developers should be aware of the trust assumptions and potential failure modes of the LayerZero protocol. Implement robust monitoring for LayerZero network status and consider emergency shutdown or pause mechanisms if critical external dependencies fail or exhibit malicious behavior.
StatusUnresolved
Low

Delegate Pattern Implications

L-01The `setDelegate` function allows an address to delegate its authority. While useful for operational flexibility, if not managed carefully, a compromised delegate address could perform unauthorized actions on behalf of the delegator, potentially leading to unintended consequences.
IssueThe `setDelegate` function allows an address to delegate its authority. While useful for operational flexibility, if not managed carefully, a compromised delegate address could perform unauthorized actions on behalf of the delegator, potentially leading to unintended consequences.
FixImplementers should ensure that the delegate pattern is used judiciously and that delegated addresses are highly trusted and secured. Consider time-bound delegations or granular permissions for delegates to limit potential impact.
StatusUnresolved
Info

Grace Periods and Timeouts Management

I-01Functions like `setDefaultReceiveLibraryTimeout` and `setReceiveLibraryTimeout` introduce time-based controls for library transitions. While beneficial for graceful upgrades and mitigating immediate risks, incorrect management of these timeouts (e.g., setting excessively long or short periods) could either delay critical security updates or create windows of vulnerability.
IssueFunctions like `setDefaultReceiveLibraryTimeout` and `setReceiveLibraryTimeout` introduce time-based controls for library transitions. While beneficial for graceful upgrades and mitigating immediate risks, incorrect management of these timeouts (e.g., setting excessively long or short periods) could either delay critical security updates or create windows of vulnerability.
FixImplementers should carefully consider the appropriate grace periods and timeouts based on their operational needs and risk tolerance. Ensure that the process for managing these timeouts is well-defined, transparent, and secure.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The LayerZero V2 interfaces define a robust and modular framework for cross-chain communication, leveraging distinct components for message management, composition, and channel handling (7.1 Architecture). The design promotes flexibility through configurable message libraries and explicit lifecycle management for packets (e.g., `verify`, `lzReceive`, `clear`). However, the inherent complexity of a multi-chain messaging system, with numerous configuration parameters and administrative functions, introduces a significant attack surface for concrete implementations (7.2 Code Security). Proper implementation of message verification and execution logic is paramount to prevent issues like message loss or unauthorized actions.

GovernanceHigh3/10

The interfaces expose numerous critical administrative functions, such as `setLzToken`, `setDefaultSendLibrary`, `setReceiveLibrary`, and `setConfig`, which directly impact the system's operational parameters and security (7.3 Access Control, 7.5 Governance). The economic model involves quoting and sending messages with associated `nativeFee` and `lzTokenFee`, requiring careful management to prevent economic exploits or denial of service through fee manipulation (7.4 Economic). Robust access control mechanisms and multi-signature governance are essential for these privileged functions to mitigate risks of unauthorized configuration changes or asset manipulation.

UpgradesLow7/10

As interfaces, these contracts are not directly upgradeable. However, any concrete contract implementing these LayerZero V2 interfaces would require a well-designed upgrade mechanism (7.7 Upgrades), such as a proxy pattern (e.g., UUPS), to allow for future enhancements or bug fixes. The modular nature of message libraries and configurable parameters within the LayerZero V2 design can facilitate certain types of 'upgrades' by swapping out library implementations or adjusting configurations, offering flexibility without requiring full contract redeployments. Careful consideration of upgrade paths and potential state migrations is crucial for the long-term security and maintainability of an OApp.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

15.0% in wallets61.0% in contracts
Effective Concentration39.4%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder93.1%
Top-3 Unlocked98.8%

Key Addresses

Deployer
0xf0a4…455f
Unlocked LP Held By
0xf949…02980xa5f3…4cf20x4f7b…cd370xce14…f4a20x8e0a…76c10x176e…43f00x5e91…fac10xd379…60d80x8bf6…ccbf0xb262…eeed

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (3-of-5)
  • Top-10 concentration > 30% (76.0% total → 39.4% effective; 15.0% in EOAs, 61.0% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 93.1% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • LP top3 unlocked holders = 98.8% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • 1 High finding(s) from audit
  • 3 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

CapHigh RiskVELOHigh RiskGriotHigh RiskAEGIS X (AGX)High RiskSTABLEHigh RiskOLYHigh Risk

Would You Like a More Detailed Audit of Unibase?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit