Contract Powers Registry / polygon

USDT (Polygon)

0xc2132d05d31c914a87c6611c10748aeb04b58e8f on polygon

In one line: upgradeable proxy (etherscan-declared); retained powers: burn_others, mint, ownership, upgrade.

UpgradeableYes
Source verifiedYes
Controlled byNo owner() found
Confirmed powers4

Can this code be replaced?

Yes — this is a proxy. The address you interact with holds no logic of its own; it forwards calls to a second contract. Whoever holds the upgrade right can point it somewhere else, and every behaviour described on this page changes with it.

Patternetherscan-declared
Current logic0x90040487a6c9f949c4f07cadcfb0f3b8eeab4229
Logic nameUChildUSDT0
Logic source verifiedYes
Raw storage evidence (1)

Who holds the keys?

no owner()/getOwner()/admin() responded — access control may use roles (AccessControl) or be renounced Access control may use role-based permissions (OpenZeppelin AccessControl), or it may have been renounced. This registry does not enumerate role holders.

What the privileged role can still do

Each card is a capability found in the code. declared = the contract’s published interface exposes it. bytecode-heuristic = the 4-byte selector appears in the compiled code, which often means the contract implements it — but it can equally be a function this contract calls on another contract. Only a verified source settles that.

Balances can be destroyed

declared

Tokens can be burned from an address other than the caller’s own.

Evidence (2)
  • redeem(uint256) implementation-abi
  • redeem(uint256) implementation-bytecode

New tokens can be created

declared

Supply is not fixed by the code — the privileged role can issue more.

Evidence (2)
  • mint(address,uint256) implementation-abi
  • mint(address,uint256) implementation-bytecode

Control can be transferred

declared

The privileged role itself can be handed to another address, or renounced.

Evidence (4)
  • grantRole(bytes32,address) implementation-abi
  • revokeRole(bytes32,address) implementation-abi
  • revokeRole(bytes32,address) implementation-bytecode
  • grantRole(bytes32,address) implementation-bytecode

Code can be replaced

declared

The logic behind this address can be swapped for different code. Everything below can change with it.

Evidence (3)
  • upgradeToUSDT0(address,address) implementation-abi
  • updateImplementation(address) abi
  • updateImplementation(address) bytecode-selector

Is there a bug bounty on this?

No live bug-bounty program matched this contract’s name in my index (186 Immunefi + 52 Cantina programs, rebuilt daily). Matching is by name, not by address — a program can cover this contract without the names lining up. Browse the full index at Bounty Radar.

Raw facts

Chainpolygon (chainId 137)
Contract nameUChildERC20Proxy
Compilerv0.6.6+commit.6c089d02
LicenseNone
Bytecode size2,949 bytes (logic: 14,504)
DELEGATECALLpresent
SELFDESTRUCTabsent
CREATE2absent
Explorerview on block explorer ↗

How this was produced, and what it cannot tell you

Storage slots, bytecode and eth_call results were read from public RPC nodes; where the source is verified, the published interface was read too. Nothing here is copied from another site’s opinion. Generated in 890 ms on 2026-08-29.

What would change the answer: an upgrade after the date above; a power reachable only through a contract this one trusts; or role-based access control, whose holders this registry does not enumerate. Re-read the chain before you rely on it.

Machine-readable

Same facts as JSON, free, no key: /c/polygon/0xc2132d05d31c914a87c6611c10748aeb04b58e8f.json. Live lookups for any address (not just this list) are $0.05 per call.

Want a human-grade read?

This page is automated pattern-matching. If you need someone to actually read the code and tell you what breaks, I do fixed-scope micro-audits — you pay after you read the report.