cryptoasset
LAB LAB
LAB is a standard BEP-20 token on BNB Chain with no custom cryptography and no token-specific admin keys. Per QRI Section 7.2 (Token Inheritance), it inherently shares BNB Chain's L1 QRI posture. BNB Chain is at Stage 1 (Quantum Risk Assessed), independently rated QRI 19/100 by LayerQu — it published a PQC research report in May 2026 but has zero production PQC deployment. All LAB transactions depend on BNB Chain's quantum-vulnerable ECDSA secp256k1 signatures and BLS consensus. The LAB project itself has published no quantum risk assessment, cryptographic inventory, or migration plan. The token contract (verified on BscScan) is fully immutable with no admin keys — the dossier's 'unrenounced minting authority' claim is contradicted by on-chain source code. The QRI Score of 10 reflects the binding constraint of 'No public cryptographic inventory' at the token project level.
Category breakdown
QRI Factors
Critical Quantum Blockers
- Active production spend authorization remains entirely ECDSA-only (inherited from BNB Chain, which has no production PQC deployment). All LAB token transfers depend on BNB Chain's quantum-vulnerable ECDSA secp256k1 signature scheme.
- No public cryptographic inventory published by the LAB project itself. The token project has not acknowledged quantum risk, published a threat model, or identified affected cryptographic surfaces.
Key Risks
- All LAB token value is secured by BNB Chain's ECDSA secp256k1 signatures, which are vulnerable to Shor's algorithm on a cryptographically relevant quantum computer.
- BNB Chain consensus uses BLS12-381 signatures — also quantum-vulnerable. A quantum attacker compromising BNB Chain consensus could censor or reorder LAB transactions.
- >95% insider supply control means the vast majority of LAB value-at-risk is concentrated in a small number of quantum-vulnerable wallets on BNB Chain.
- LAB project has no published quantum risk acknowledgement, threat model, migration plan, or incident-response process.
- BNB Chain's PQC research is prototype-stage only with no production timeline. Migration remains years away and will impose 40-50% throughput reduction when deployed.
Assurance Notes
- LAB inherits BNB Chain L1 QRI posture per Section 7.2 (Token Inheritance). BNB Chain is independently rated at QRI 19/100 (Stage 1: Acknowledged) by LayerQu as of 2026-06-05.
- BNB Chain published a Post-Quantum Cryptography Migration Report on 2026-05-14 exploring ML-DSA-44 transaction signatures and pqSTARK consensus aggregation. This is research/prototype only — explicitly not a production deployment.
- LAB token contract (LabToken) is verified on BscScan as standard ERC20 + ERC20Burnable with no admin keys, no owner, no mint function, no proxy/upgrade mechanism. The contract is fully immutable post-deployment.
- The evidence dossier claim of 'unrenounced minting authority' is CONTRADICTED by verified on-chain source code. The constructor mints 1B tokens to deployer with no subsequent mint capability.
- No independent audit of the LAB token contract exists.
- ZachXBT investigation (May 2026) alleges >95% insider supply control. This is an operational/product caveat that does not create additional quantum-attack surfaces beyond BNB Chain's ECDSA vulnerability.
- BNB Chain's PQC report explicitly excludes P2P handshakes and KZG commitments from current scope.
Non-Scoring Caveats
- Extreme supply concentration: >95% of LAB supply allegedly controlled by insiders per ZachXBT investigation (May 2026). This concentrates quantum-exposed value-at-risk in a small number of ECDSA wallets on BNB Chain.
- ~77% of total supply remains locked or unallocated. Future unlocks may create additional quantum-vulnerable value pools.
- No public independent audit of the LAB token contract. The contract is extremely simple (standard OpenZeppelin with zero custom logic) mitigating this concern.
- BNB Chain's PQC research report shows 40-50% throughput reduction under PQ signatures — any future BNB Chain PQC migration will significantly impact LAB trading performance.
- Multi-chain deployment (BSC, Solana, Ethereum) means LAB tokens bridged to other chains inherit those chains' quantum postures.
Evidence record
Claims and Caveats
Token Inheritance
Token type classification
Claim: LAB is a standard BEP-20 token on BNB Chain with no custom cryptographic or cross-chain dependencies.
Coverage basis: Standard smart-contract token inheriting L1 QRI
Implementation score: 1 · Evidence confidence: High
Issue classification: none · Score treatment: not applicable
Assurance: Multiple independent sources confirm LAB is a standard BEP-20 token.
Per QRI Section 7.2, LAB inherently shares BNB Chain's L1 QRI score.
Token Admin Keys
Critical wallet, custody, HSM, signer, and hardware-wallet workflows
Claim: LAB token contract has no admin keys, no owner, no mint function, no proxy, and no upgrade mechanism.
Coverage basis: Satisfied by design — no token-specific admin attack surface exists
Implementation score: 1 · Evidence confidence: High
Issue classification: none · Score treatment: not applicable
Assurance: Contract source code is verified on BscScan (Exact Match). Solidity v0.8.28.
CONTRADICTS evidence dossier claim of 'unrenounced minting authority.'
Production Cryptographic Protection
Spend authorization / transaction signatures
Claim: All LAB token transfers depend on BNB Chain's ECDSA secp256k1 transaction signatures.
Coverage basis: Inherited from BNB Chain L1 — ECC-only spend authorization
Implementation score: 0 · Evidence confidence: High
Issue classification: quantum-critical vulnerability · Score treatment: cap-applying
Quantum blocker: Active production spend authorization remains entirely ECDSA-only (inherited from BNB Chain)
Assurance: BNB Chain's production status is independently verified by LayerQu (QRI 19/100, Stage 1).
BNB Chain's PQC research report tested ML-DSA-44 but is research only.
Security Assessment & Evidence Preparedness
Public cryptographic inventory and quantum threat model
Claim: LAB project has not published any cryptographic inventory, quantum threat model, or risk assessment.
Coverage basis: No token-specific assessment exists
Implementation score: 0 · Evidence confidence: High
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No public cryptographic inventory published by the LAB project
Assurance: Triggers Readiness & Risk Cap of 10 ('No public cryptographic inventory').
The cap applies at the token project level even though the crypto surface is trivially characterized.
Migration Status & Value-at-Risk
Percentage of economically relevant value-at-risk protected
Claim: 0% of LAB token value-at-risk is protected from quantum key-recovery attacks.
Coverage basis: 0% migration coverage — <25% threshold
Implementation score: 0.05 · Evidence confidence: High
Issue classification: quantum-critical vulnerability · Score treatment: score-reducing
Assurance: BNB Chain has 0% PQC production coverage.
Per Section 9.3.1: <25% coverage scores 1 out of 20. Implementation Score = 1/20 = 0.05.
L1 (BNB Chain)
Consensus-critical authentication
Claim: BNB Chain uses BLS12-381 for validator vote aggregation. PQ research report tested pqSTARK but no mainnet deployment exists.
Coverage basis: L1 dependency; BNB Chain research report May 2026
Implementation score: 0 · Evidence confidence: Medium
Issue classification: quantum-critical vulnerability · Score treatment: cap-applying
Assurance: BNB Chain's own blog confirms the research/test nature of the PQ work.
Inherited from BNB Chain L1. Production validators remain BLS12-381.
Report metadata