Quantum Audit Logo

Is Wrapped PROS Safe?

On-chain security analysis — is it a scam or legit?

Wrapped PROS PROS
0x8b7d…9832
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 18d ago 2 audits on record
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The BurnMintERC20 contract implements a standard ERC20 token with additional minting and burning capabilities, managed through OpenZeppelin's AccessControl. The contract leverages well-audited libraries and includes checks against common pitfalls like transfers to `address(this)`. The primary risks identified are related to the centralized control of token supply and administrative roles by the `DEFAULT_ADMIN_ROLE`, which can significantly impact the token's economic stability and governance.

1 High1 Medium1 Low1 Informational
Volume 24h
$542.6K
Liquidity
$705.3K
Price
$0.4084
Token Age
1y
Top 10 Holders
91.9%

Security Findings

High

Centralized Control of Token Supply

H-01The `DEFAULT_ADMIN_ROLE` has complete authority to grant and revoke `MINTER_ROLE` and `BURNER_ROLE`. This means a single entity or a small group controlling the `DEFAULT_ADMIN_ROLE` can arbitrarily increase or decrease the token's total supply (up to `maxSupply`), significantly impacting the token's economic stability and value. This represents a high centralization risk for the token's economic model (7.3 Access Control, 7.4 Economic).
IssueThe `DEFAULT_ADMIN_ROLE` has complete authority to grant and revoke `MINTER_ROLE` and `BURNER_ROLE`. This means a single entity or a small group controlling the `DEFAULT_ADMIN_ROLE` can arbitrarily increase or decrease the token's total supply (up to `maxSupply`), significantly impacting the token's economic stability and value. This represents a high centralization risk for the token's economic model (7.3 Access Control, 7.4 Economic).
FixImplement a multi-signature wallet or a decentralized autonomous organization (DAO) to control the `DEFAULT_ADMIN_ROLE`. Consider adding a time-lock for sensitive operations like granting/revoking roles to allow for community oversight and reaction time.
StatusUnresolved
Medium

Centralized CCIPAdmin Role Management

M-01The `s_ccipAdmin` address, intended for external Chainlink CCIP integration, can be set by the `DEFAULT_ADMIN_ROLE` via `setCCIPAdmin`. While this contract does not directly use `s_ccipAdmin` for critical token operations, its centralized control by a single address (the `DEFAULT_ADMIN_ROLE`) could pose a risk to external systems relying on this role if the `DEFAULT_ADMIN_ROLE`'s private key is compromised (7.3 Access Control, 7.6 External).
IssueThe `s_ccipAdmin` address, intended for external Chainlink CCIP integration, can be set by the `DEFAULT_ADMIN_ROLE` via `setCCIPAdmin`. While this contract does not directly use `s_ccipAdmin` for critical token operations, its centralized control by a single address (the `DEFAULT_ADMIN_ROLE`) could pose a risk to external systems relying on this role if the `DEFAULT_ADMIN_ROLE`'s private key is compromised (7.3 Access Control, 7.6 External).
FixEvaluate the criticality of the `CCIPAdmin` role in external systems. If it holds significant power, consider applying similar multi-signature or time-lock controls to the `setCCIPAdmin` function as recommended for other administrative roles.
StatusUnresolved
Low

Immutable Decimals Design Choice

L-01The token's `decimals` property is set as an immutable variable (`i_decimals`) in the constructor and cannot be changed after deployment. While this ensures consistency and prevents unexpected changes, it means the token's precision is permanently fixed. This might be a limitation if future protocol requirements or ecosystem standards necessitate a change in decimal precision (7.1 Architecture).
IssueThe token's `decimals` property is set as an immutable variable (`i_decimals`) in the constructor and cannot be changed after deployment. While this ensures consistency and prevents unexpected changes, it means the token's precision is permanently fixed. This might be a limitation if future protocol requirements or ecosystem standards necessitate a change in decimal precision (7.1 Architecture).
FixThis is a design choice and not a vulnerability. Ensure that the chosen decimal precision (`i_decimals`) is suitable for all current and foreseeable use cases of the token. No code change is strictly required unless future flexibility is desired.
StatusUnresolved
Info

Lack of Explicit Admin Role Renouncement Function

I-01The contract relies on the inherited `AccessControl.renounceRole` function for the `DEFAULT_ADMIN_ROLE` to potentially relinquish its administrative powers. However, there is no explicit function within `BurnMintERC20` to facilitate or encourage this. Explicitly exposing or documenting a path for the `DEFAULT_ADMIN_ROLE` to renounce itself could be a step towards decentralization post-deployment (7.5 Governance, 7.8 Operations).
IssueThe contract relies on the inherited `AccessControl.renounceRole` function for the `DEFAULT_ADMIN_ROLE` to potentially relinquish its administrative powers. However, there is no explicit function within `BurnMintERC20` to facilitate or encourage this. Explicitly exposing or documenting a path for the `DEFAULT_ADMIN_ROLE` to renounce itself could be a step towards decentralization post-deployment (7.5 Governance, 7.8 Operations).
FixConsider adding a public function that calls `renounceRole(DEFAULT_ADMIN_ROLE, msg.sender)` to provide a clear and explicit path for the deployer to renounce the admin role, if decentralization is a future goal. Alternatively, ensure this process is clearly documented.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract demonstrates strong technical foundations (7.2 Code Security) by inheriting from battle-tested OpenZeppelin contracts like ERC20, ERC20Burnable, and AccessControl. It correctly implements `_transfer` and `_approve` overrides to prevent interactions with `address(this)`, enhancing security. The `mint` function also includes a `maxSupply` check, preventing unintended inflation beyond a set limit. However, the centralized nature of the `DEFAULT_ADMIN_ROLE` for managing `MINTER_ROLE` and `BURNER_ROLE` introduces a single point of failure (7.3 Access Control).

GovernanceHigh1/10

The contract's economic model (7.4 Economic) benefits from an optional `maxSupply` limit, which can prevent unbounded inflation if configured. However, the `DEFAULT_ADMIN_ROLE` holds significant power over the token's supply by controlling who can mint and burn tokens, posing a high centralization risk. This role also manages the `CCIPAdmin` (7.5 Governance), which, while not directly impacting token supply in this contract, could be critical for external integrations. The lack of explicit mechanisms for progressive decentralization or multi-signature control over these critical roles increases governance risk (7.8 Operations).

UpgradesHigh3/10

The BurnMintERC20 contract is implemented as a standard, non-upgradeable token (7.7 Upgrades). This design choice eliminates the complexities and potential risks associated with upgradeable proxy patterns, such as storage collisions or faulty upgrade logic. Consequently, there are no specific upgrade safety issues to address within this contract's architecture.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass

Holder Composition

38.4% in wallets53.5% in contracts
Effective Concentration59.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder97.4%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x7565…11ae
Unlocked LP Held By
0xdb6d…9ab30x8ee4…485a

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced (admin/mint authority retained)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 50% (91.9% total → 59.8% effective; 38.4% in EOAs, 53.5% in contracts — heavy)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 97.4% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Wrapped PROS a scam?

Based on automated analysis, Wrapped PROS scores 69/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is Wrapped PROS safe to buy?

Our scanner flagged a risk score of 69/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.

Has Wrapped PROS been audited?

The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

Cortex (CX)Critical RiskChipCritical Riskdefi-nativeCritical RiskXRP (Universal) (UXRP)Critical RiskVCATCritical RiskThe White Wolf (WOLF)Critical Risk

Would You Like a More Detailed Audit of Wrapped PROS?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit