Contract Powers Registry / ethereum
FRAX
0x853d955acef822db058eb8505911ed77f175b99e on ethereum
In one line: retained powers: blacklist, burn_others, ownership.
Can this code be replaced?
No proxy pattern found. The standard upgrade slots (EIP-1967, ZeppelinOS)
are empty, the explorer does not declare a proxy, and no implementation() answered.
The code at this address is very likely the code that runs.
Caveat: a custom upgrade mechanism that does not use those slots would not be detected here.
Who holds the keys?
no owner()/getOwner()/admin() responded — access control may use roles (AccessControl) or be renounced Access control may use role-based permissions (OpenZeppelin AccessControl), or it may have been renounced. This registry does not enumerate role holders.
What the privileged role can still do
Each card is a capability found in the code. declared = the contract’s published interface exposes it. bytecode-heuristic = the 4-byte selector appears in the compiled code, which often means the contract implements it — but it can equally be a function this contract calls on another contract. Only a verified source settles that.
Addresses can be frozen
declaredA specific address can be blocked from moving its own balance.
Evidence (1)
setPriceBand(uint256)abi
Balances can be destroyed
declaredTokens can be burned from an address other than the caller’s own.
Evidence (2)
burnFrom(address,uint256)abiburnFrom(address,uint256)bytecode-selector
Control can be transferred
declaredThe privileged role itself can be handed to another address, or renounced.
Evidence (4)
grantRole(bytes32,address)abirevokeRole(bytes32,address)abisetOwner(address)abirevokeRole(bytes32,address)bytecode-selector
Is there a bug bounty on this?
No live bug-bounty program matched this contract’s name in my index (186 Immunefi + 52 Cantina programs, rebuilt daily). Matching is by name, not by address — a program can cover this contract without the names lining up. Browse the full index at Bounty Radar.
Raw facts
| Chain | ethereum (chainId 1) |
|---|---|
| Contract name | FRAXStablecoin |
| Compiler | v0.6.11+commit.5ef660b1 |
| License | MIT |
| Bytecode size | 14,894 bytes |
| DELEGATECALL | absent |
| SELFDESTRUCT | absent |
| CREATE2 | absent |
| Explorer | view on block explorer ↗ |
How this was produced, and what it cannot tell you
Storage slots, bytecode and eth_call results were read from public RPC nodes;
where the source is verified, the published interface was read too. Nothing here is copied from another
site’s opinion. Generated in 1095 ms on 2026-08-29.
- confidence="declared" means the ABI exposes the function. confidence="bytecode-heuristic" means the 4-byte selector appears in the code — usually its own dispatch table, but it can also be a selector this contract CALLS on another contract. Only a verified ABI settles it.
- admin.ownerType="contract" does not mean multisig — this endpoint does not inspect the owner contract.
- bounty.match="name-heuristic" matches a contract NAME to a program name; it is not proof the address is in scope.
What would change the answer: an upgrade after the date above; a power reachable only through a contract this one trusts; or role-based access control, whose holders this registry does not enumerate. Re-read the chain before you rely on it.
Machine-readable
Same facts as JSON, free, no key: /c/ethereum/0x853d955acef822db058eb8505911ed77f175b99e.json.
Live lookups for any address (not just this list) are $0.05 per call.
Want a human-grade read?
This page is automated pattern-matching. If you need someone to actually read the code and tell you what breaks, I do fixed-scope micro-audits — you pay after you read the report.