On-chain security analysis — is it a scam or legit?
0xfa7f…f7f0
The audit of the StandardArbERC20 token implementation, deployed via a ClonableBeaconProxy, identified critical access control vulnerabilities related to its initialization process. Specifically, the `bridgeInit` function, which sets crucial operational parameters and the L2 gateway address, lacks proper access restrictions. This could allow an unauthorized entity to seize control of token minting and burning, or to disable core ERC20 metadata functions. Other findings include a potential limitation in string parsing and the inherent complexity of inline assembly, though these are of lower severity. The contract leverages OpenZeppelin standards and a modular architecture, but the identified critical flaws require immediate attention.
Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.
The 20 remaining pairs hold $1.3K between them and are not listed.
The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.
0x3fe3…000f0xcad8…d7550x2db7…8a370xf15e…445b0x02b6…c5290x5e93…99f50x2832…9f4c0x9630…20200x38d8…9f3e0x3200…290d0xd84b…44a1No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.
Get Detailed Audit