Quantum Audit Logo

Is Adshares Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Adshares ADS
0xcfce…d22a
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 10d ago 1 audit on record
Executive SummaryAI Copilot

The audit of the WrappedADS ERC20 token contract identified a high-severity centralization risk related to the Pauser role, which could lead to a single point of failure and potential permanent loss of control over the pausing mechanism. Minor issues include an outdated Solidity compiler version and a negligible gas optimization opportunity. The contract otherwise follows standard ERC20 implementations with robust arithmetic safety.

1 High1 Low1 Informational
Volume 24h
$240.3K
Liquidity
$941.0K
Price
$0.4668
Token Age
1y
Top 10 Holders
98.2%

Security Findings

High

Centralized Pauser Role with Potential for Permanent Loss of Control

H-01The `PauserRole` grants significant control to a single `Pauser` address (initially the deployer) to pause and unpause all token transfers. This introduces a high centralization risk. Furthermore, the `renouncePauser()` function allows any pauser to remove themselves from the role. If the *sole* pauser renounces their role without first assigning a new pauser, the contract will be left without any active pausers. In this scenario, no new pausers can be added, and the pausing mechanism (both `pause()` and `unpause()`) would become permanently inaccessible, potentially locking the contract in a paused or unpaused state indefinitely.
IssueThe `PauserRole` grants significant control to a single `Pauser` address (initially the deployer) to pause and unpause all token transfers. This introduces a high centralization risk. Furthermore, the `renouncePauser()` function allows any pauser to remove themselves from the role. If the *sole* pauser renounces their role without first assigning a new pauser, the contract will be left without any active pausers. In this scenario, no new pausers can be added, and the pausing mechanism (both `pause()` and `unpause()`) would become permanently inaccessible, potentially locking the contract in a paused or unpaused state indefinitely.
FixImplement a more robust and decentralized access control mechanism for the pauser role. Consider using a multi-signature wallet (e.g., Gnosis Safe) for the `Pauser` address. Alternatively, modify the `renouncePauser` function to prevent the sole pauser from renouncing their role unless a new pauser has already been designated, or implement a timelock for critical role changes.
StatusUnresolved
Low

Outdated Solidity Compiler Version

L-01The contract uses Solidity `^0.5.0`. While `SafeMath` is used to mitigate common arithmetic overflows, newer compiler versions (e.g., `^0.8.0`) offer built-in overflow checks, improved security features, and gas optimizations. Using an older version might expose the contract to known compiler bugs or make it harder to integrate with newer tools and libraries.
IssueThe contract uses Solidity `^0.5.0`. While `SafeMath` is used to mitigate common arithmetic overflows, newer compiler versions (e.g., `^0.8.0`) offer built-in overflow checks, improved security features, and gas optimizations. Using an older version might expose the contract to known compiler bugs or make it harder to integrate with newer tools and libraries.
FixConsider upgrading the Solidity compiler version to a more recent stable release (e.g., `^0.8.0` or higher). This would allow for the removal of `SafeMath` (as `uint256` operations would revert on overflow/underflow by default) and provide access to the latest language features and security improvements. Thorough testing would be required after such an upgrade.
StatusUnresolved
Info

Unnecessary `this;` in `_msgData()`

I-01The `_msgData()` function in the `Context` contract includes an unnecessary `this;` statement. This statement has no functional effect and can be removed.
IssueThe `_msgData()` function in the `Context` contract includes an unnecessary `this;` statement. This statement has no functional effect and can be removed.
FixRemove the `this;` statement from the `_msgData()` function to slightly reduce bytecode size and improve readability, although the gas impact is negligible.
StatusUnresolved

Category Ratings

TechnicalLow7/10

The contract implements a standard ERC20 token with pausing capabilities, leveraging OpenZeppelin-like patterns and `SafeMath` for arithmetic safety (7.2 Code Security). The architecture is clear, with well-defined roles for pausing (7.1 Architecture). However, the `PauserRole` introduces a high centralization risk, as a single compromised or lost pauser address can halt all token transfers and potentially lead to permanent loss of control over the pausing mechanism (7.3 Access Control). Additionally, the contract uses an older Solidity compiler version.

GovernanceHigh1/10

The token's economic model is a standard ERC20, with no complex DeFi primitives or oracle dependencies (7.4 Economic). There are no explicit governance mechanisms beyond the `PauserRole` (7.5 Governance). The centralized control over pausing token transfers by a single `Pauser` address presents a significant operational and economic risk, as it could lead to a complete halt of token utility if compromised or mismanaged, or if the role is accidentally renounced (7.8 Operations).

UpgradesHigh3/10

The contract is not designed to be upgradeable, as indicated by `is_proxy: false` (7.7 Upgrades). This eliminates upgrade-related risks such as proxy storage collisions or logic errors during upgrades. The immutability ensures consistent behavior post-deployment, reducing complexity and potential attack vectors associated with upgrade mechanisms.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

5.8% in wallets92.4% in contracts
Effective Concentration42.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xb6fe…ae1f
Unlocked LP Held By
0xefa6…167e

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 30% (98.2% total → 42.7% effective; 5.8% in EOAs, 92.4% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 33% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 33% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

c8ntinuum (CTM)High RiskCurve DAO (CRV)High RiskFrax USD (FRXUSD)High RiskDestra Network (DSYNC)High RiskEthena (ENA)High RiskEigenCloud (prev. EigenLayer) (EIGEN)High Risk

Would You Like a More Detailed Audit of Adshares?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit