Quantum Audit Logo

Is Alaya Governance Token Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Alaya Governance Token AGT
0x5dbd…e274
BNB Chain Not verifiedLast checked 2d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The AlayaGovernanceToken contract is a standard ERC20 token implementation, primarily leveraging battle-tested OpenZeppelin Contracts. The technical risk is low due to the use of well-audited libraries and minimal custom logic. Key design decisions include a centralized initial token distribution and the absence of emergency administrative controls.

1 Low2 Informational
Volume 24h
$1.17M
Liquidity
$1.33M
Price
$0.01634
Token Age
1y
Top 10 Holders
56.2%

Security Findings

Low

Absence of Emergency Pause/Blacklist Functionality

L-01The ERC20 contract does not include any administrative functions for emergency control, such as pausing transfers or blacklisting malicious addresses. While this enhances decentralization by removing single points of control, it also means there is no mechanism to mitigate severe exploits, respond to regulatory demands, or freeze funds in case of theft (7.3 Access Control, 7.8 Operations).
IssueThe ERC20 contract does not include any administrative functions for emergency control, such as pausing transfers or blacklisting malicious addresses. While this enhances decentralization by removing single points of control, it also means there is no mechanism to mitigate severe exploits, respond to regulatory demands, or freeze funds in case of theft (7.3 Access Control, 7.8 Operations).
FixEvaluate the project's risk tolerance and operational needs. If emergency intervention capabilities are desired, consider integrating OpenZeppelin's `Pausable` or `AccessControl` contracts. If not, ensure the project's off-chain incident response plan accounts for the immutable nature of the token's operations.
StatusUnresolved
Info

Centralized Initial Supply Distribution

I-01The constructor of the ERC20 contract mints the entire initial supply of 5,000,000,000 * 10^18 tokens directly to `msg.sender`. This design choice results in a highly centralized initial distribution, where the deployer address holds the entire token supply at launch. While a common pattern for initial token deployment, it implies significant control by a single entity over the token's early circulation (7.4 Economic).
IssueThe constructor of the ERC20 contract mints the entire initial supply of 5,000,000,000 * 10^18 tokens directly to `msg.sender`. This design choice results in a highly centralized initial distribution, where the deployer address holds the entire token supply at launch. While a common pattern for initial token deployment, it implies significant control by a single entity over the token's early circulation (7.4 Economic).
FixAcknowledge and accept this centralized distribution as a design decision. If decentralization is a long-term goal, consider a phased distribution strategy or a multi-signature wallet for managing the initial supply.
StatusUnresolved
Info

Immutability of Token Parameters

I-02The token's name, symbol, decimals (fixed at 18), and initial total supply are set immutably within the constructor. These parameters cannot be modified after deployment. This ensures consistency and predictability for users and integrated protocols (7.1 Architecture).
IssueThe token's name, symbol, decimals (fixed at 18), and initial total supply are set immutably within the constructor. These parameters cannot be modified after deployment. This ensures consistency and predictability for users and integrated protocols (7.1 Architecture).
FixNo action required. This is a standard and often desired characteristic for ERC20 tokens, providing clarity and preventing unexpected changes to fundamental token properties.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The technical architecture is robust, built upon the latest OpenZeppelin ERC20 implementation (v5.1.0), which includes modern features like ERC-6093 custom errors and correct `unchecked` arithmetic. The contract adheres to the ERC20 standard, providing basic token functionalities (7.1 Architecture, 7.2 Code Security). The code is well-structured and follows best practices. There are no complex custom logic or external integrations that introduce significant technical attack vectors (7.6 External).

GovernanceHigh1/10

The economic model is that of a standard ERC20 token, with a fixed initial supply minted entirely to the deployer (7.4 Economic). This centralizes initial control over the token supply. There are no explicit governance mechanisms or complex economic incentives defined within the contract itself (7.5 Governance). The token's utility and broader economic implications would depend on its integration into a larger ecosystem.

UpgradesMedium6/10

The contract is implemented as a standard, non-upgradeable ERC20 token. There are no proxy patterns (e.g., UUPS, Transparent) or beacon proxies used, meaning the contract's logic cannot be modified post-deployment (7.7 Upgrades). This design choice eliminates upgrade-related risks but also removes the flexibility to fix bugs or add features in the future.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

53.3% in wallets2.9% in contracts
Effective Concentration54.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x4dcf…e3af
Unlocked LP Held By
0x8815…288b0x6b94…b028

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 50% (56.2% total → 54.5% effective; 53.3% in EOAs, 2.9% in contracts — heavy)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

mubarakMedium RiskCheese Head (CHEESE)Medium RiskAsterMedium RiskTutorial (TUT)Medium RiskMYXMedium RiskBluwhale AI (BLUAI)Medium Risk

Would You Like a More Detailed Audit of Alaya Governance Token?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit