Quantum Audit Logo

Is Wrapped eETH Safe?

On-chain security analysis — is it a scam or legit?

Wrapped eETH WEETH
0x3575…4dbe
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
Executive SummaryAI Copilot

This audit covers a StandardArbERC20 token contract, deployed as a Beacon proxy on Arbitrum. The contract implements standard ERC-20 functionality and includes specific bridging mechanisms. Key findings highlight significant control held by designated `gateway` and `l2gateway` addresses, allowing them to mint new tokens and directly manipulate user balances.

6 Informational
Volume 24h
$656.7K
Liquidity
$155.0K
Price
$2968.0140
Token Age
2y
Top 10 Holders
98.2%

Security Findings

Info

Centralized Control: Unlimited Token Minting

CP-01The `gateway` and `l2gateway` addresses have the ability to call the `bridgeMint` function, which allows them to create an unlimited number of new tokens. This means that these controllers can increase the total supply of the token at any time, potentially diluting the value of tokens held by other users.
IssueThe `gateway` and `l2gateway` addresses have the ability to call the `bridgeMint` function, which allows them to create an unlimited number of new tokens. This means that these controllers can increase the total supply of the token at any time, potentially diluting the value of tokens held by other users.
FixToken holders should be aware that the value of their tokens can be diluted by the `gateway` and `l2gateway` controllers. It is critical that these addresses are secured with the highest possible standards, such as multi-signature wallets, to prevent unauthorized minting.
StatusUnresolved
Info

Critical Control: Arbitrary Token Burning from Any Account

CP-02The `gateway` and `l2gateway` addresses can execute the `bridgeBurn` function, which allows them to remove tokens from *any* token holder's balance. This means that these controllers have the power to unilaterally reduce or eliminate any user's token holdings, posing a severe risk to individual ownership and trust in the token.
IssueThe `gateway` and `l2gateway` addresses can execute the `bridgeBurn` function, which allows them to remove tokens from *any* token holder's balance. This means that these controllers have the power to unilaterally reduce or eliminate any user's token holdings, posing a severe risk to individual ownership and trust in the token.
FixToken holders must understand that the `gateway` and `l2gateway` controllers possess the ability to directly burn their tokens. The security of these controlling addresses is paramount. It is strongly recommended that these addresses are managed through highly secure mechanisms, such as multi-signature wallets with strict operational procedures, to prevent any misuse or compromise.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 98.2% of supply. What remains: 4.5% in wallets, 93.7% in other contracts. 18,885 holders in total. For a verified reference asset the largest holders are custodians, exchanges and bridges; concentration is reported, not scored.
IssueThe ten largest holders own 98.2% of supply. What remains: 4.5% in wallets, 93.7% in other contracts. 18,885 holders in total. For a verified reference asset the largest holders are custodians, exchanges and bridges; concentration is reported, not scored.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Identity verified by independent sources

QA-IDENTITYListed on CoinGecko as Arbitrum Bridged Wrapped eETH (Arbitrum) (WEETH), market cap $145M. 18,885 holders. Verified by: CoinGecko.
IssueListed on CoinGecko as Arbitrum Bridged Wrapped eETH (Arbitrum) (WEETH), market cap $145M. 18,885 holders. Verified by: CoinGecko.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $245K (DexScreener, all pools). 24h trading volume $39K (CoinGecko, all markets, daily snapshot). 24h trading volume $727K (DexScreener, all pools).
IssueLiquidity $245K (DexScreener, all pools). 24h trading volume $39K (CoinGecko, all markets, daily snapshot). 24h trading volume $727K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Wrapped or bridged asset

QA-PROFILEA token representing another asset's units 1:1, backed by a wrapping contract, a custodian or a bridge. Scored as an established reference asset: its identity is verified, so the issuer's or protocol's controls (listed as findings) are real and are priced once as counterparty risk, and LP locks and holder concentration are not scored — its pools belong to market makers and its largest holders are exchanges, bridges and custody. Basis: CoinGecko category: Wrapped-Tokens. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $245K of DEX liquidity across 6 pools. Launch: 967 days of market history.
IssueA token representing another asset's units 1:1, backed by a wrapping contract, a custodian or a bridge. Scored as an established reference asset: its identity is verified, so the issuer's or protocol's controls (listed as findings) are real and are priced once as counterparty risk, and LP locks and holder concentration are not scored — its pools belong to market makers and its largest holders are exchanges, bridges and custody. Basis: CoinGecko category: Wrapped-Tokens. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $245K of DEX liquidity across 6 pools. Launch: 967 days of market history.
FixThe backing is the risk: check who holds the underlying asset and how redemption works.
StatusAcknowledged

Category Ratings

TechnicalLow9/10

The StandardArbERC20 contract provides standard ERC-20 token functionalities (7.2 Code Security). It includes `bridgeMint` and `bridgeBurn` functions, restricted to `gateway` and `l2gateway` addresses, which allow for direct manipulation of token supply and individual balances (7.3 Access Control). While the core ERC-20 logic appears standard, the ability of privileged addresses to directly burn any holder's tokens via `bridgeBurn` represents a significant technical risk. The `bridgeMint` function also allows for arbitrary token creation.

GovernanceLow9/10

The economic model of this token is heavily reliant on the integrity and security of the `gateway` and `l2gateway` addresses (7.4 Economic). These addresses have the power to mint an unlimited supply of new tokens through `bridgeMint`, which can dilute the value for all existing token holders. More critically, they can use `bridgeBurn` to remove tokens from any holder's balance without consent, posing a direct threat to individual token ownership and trust in the system (7.5 Governance). This centralized control introduces substantial economic risk.

UpgradesMedium5/10

The contract is deployed using a Beacon proxy pattern (7.1 Architecture), which allows for its implementation logic to be upgraded (7.7 Upgrades). This provides flexibility for bug fixes and feature enhancements. However, the control over the Beacon (which dictates the implementation address) is centralized. An unauthorized or malicious upgrade could introduce new vulnerabilities or alter the contract's behavior, potentially impacting all token holders. Careful management of the Beacon controller is essential.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeBeacon
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

4.5% in wallets93.7% in contracts
Effective Concentration42.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder36.6%
Top-3 Unlocked79.2%

Key Addresses

Deployer
0xb4b8…1ffd
Unlocked LP Held By
0x1a1e…e88a0x5852…58af0x6b10…acb90x8431…84040x1038…ca6d0xdc6f…8af30x37ac…8f050x46b4…be210xd1ba…52570x3c02…50dc

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Issuer controls retained (mint, upgrade, seize balances) — counterparty risk on a known issuer, not a rug vector

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Lido DAO Token (LDO)Low RiskPearLow RiskPendleLow RiskArbitrum (ARB)Low RiskLayerZero (ZRO)Low RiskChainLink Token (LINK)Medium Risk

Would You Like a More Detailed Audit of Wrapped eETH?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit