Contract Powers Registry / base

DEGEN

0x4ed4e862860bed51a9570b96d89af5e1b0efefed on base

In one line: retained powers: burn_others, mint, ownership, pause.

UpgradeableNot found
Source verifiedYes
Controlled byA contract
Confirmed powers4

Can this code be replaced?

No proxy pattern found. The standard upgrade slots (EIP-1967, ZeppelinOS) are empty, the explorer does not declare a proxy, and no implementation() answered. The code at this address is very likely the code that runs. Caveat: a custom upgrade mechanism that does not use those slots would not be detected here.

Who holds the keys?

Owner / admin0x704ec5c12ca20a293c2c0b72b22619a4231f3c0d
Found viaowner()
That address isA contract

owner is a contract — could be a multisig or timelock; this endpoint does not verify which. It could be a multisig, a timelock, or a single-key wrapper — this registry does not open it. Follow the link above to see what that contract can do.

What the privileged role can still do

Each card is a capability found in the code. declared = the contract’s published interface exposes it. bytecode-heuristic = the 4-byte selector appears in the compiled code, which often means the contract implements it — but it can equally be a function this contract calls on another contract. Only a verified source settles that.

Balances can be destroyed

declared

Tokens can be burned from an address other than the caller’s own.

Evidence (2)
  • burnFrom(address,uint256) abi
  • burnFrom(address,uint256) bytecode-selector

New tokens can be created

declared

Supply is not fixed by the code — the privileged role can issue more.

Evidence (1)
  • mint(address,uint96) abi

Control can be transferred

declared

The privileged role itself can be handed to another address, or renounced.

Evidence (4)
  • renounceOwnership() abi
  • transferOwnership(address) abi
  • transferOwnership(address) bytecode-selector
  • renounceOwnership() bytecode-selector

Transfers can be halted

declared

A privileged role can stop activity, including your ability to exit.

Evidence (4)
  • pause() abi
  • unpause() abi
  • pause() bytecode-selector
  • unpause() bytecode-selector

Is there a bug bounty on this?

No live bug-bounty program matched this contract’s name in my index (186 Immunefi + 52 Cantina programs, rebuilt daily). Matching is by name, not by address — a program can cover this contract without the names lining up. Browse the full index at Bounty Radar.

Raw facts

Chainbase (chainId 8453)
Contract nameDegenToken
Compilerv0.8.20+commit.a1b79de6
License
Bytecode size11,608 bytes
DELEGATECALLabsent
SELFDESTRUCTabsent
CREATE2present
Explorerview on block explorer ↗

How this was produced, and what it cannot tell you

Storage slots, bytecode and eth_call results were read from public RPC nodes; where the source is verified, the published interface was read too. Nothing here is copied from another site’s opinion. Generated in 591 ms on 2026-08-29.

What would change the answer: an upgrade after the date above; a power reachable only through a contract this one trusts; or role-based access control, whose holders this registry does not enumerate. Re-read the chain before you rely on it.

Machine-readable

Same facts as JSON, free, no key: /c/base/0x4ed4e862860bed51a9570b96d89af5e1b0efefed.json. Live lookups for any address (not just this list) are $0.05 per call.

Want a human-grade read?

This page is automated pattern-matching. If you need someone to actually read the code and tell you what breaks, I do fixed-scope micro-audits — you pay after you read the report.