Quantum Audit Logo

Is Alchemix Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Alchemix ALCX
0xdbdb…c8df
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

The AlchemixToken contract implements a standard ERC20 token with OpenZeppelin's AccessControl for role-based management. The primary functionality includes a minting mechanism controlled by a MINTER_ROLE, which is administered by an ADMIN_ROLE. While the technical implementation is robust, the centralized control over token minting presents a significant economic risk.

1 High2 Informational
Volume 24h
$1.14M
Liquidity
$857.8K
Price
$3.2800
Token Age
5y
Top 10 Holders
61.9%

Security Findings

High

Centralized Control of Token Minting

H-01The `AlchemixToken` contract implements a `mint` function that allows an address with the `MINTER_ROLE` to create an arbitrary amount of new tokens. The `ADMIN_ROLE` has the authority to grant and revoke the `MINTER_ROLE`. Initially, the contract deployer holds both `ADMIN_ROLE` and `MINTER_ROLE`. This design centralizes significant control over the token supply. If the private key associated with the `ADMIN_ROLE` is compromised, or if the entity holding it acts maliciously, the token supply can be arbitrarily inflated, leading to a severe devaluation for all existing token holders. This represents a single point of failure for the token's economic stability (7.4 Economic, 7.5 Governance).
IssueThe `AlchemixToken` contract implements a `mint` function that allows an address with the `MINTER_ROLE` to create an arbitrary amount of new tokens. The `ADMIN_ROLE` has the authority to grant and revoke the `MINTER_ROLE`. Initially, the contract deployer holds both `ADMIN_ROLE` and `MINTER_ROLE`. This design centralizes significant control over the token supply. If the private key associated with the `ADMIN_ROLE` is compromised, or if the entity holding it acts maliciously, the token supply can be arbitrarily inflated, leading to a severe devaluation for all existing token holders. This represents a single point of failure for the token's economic stability (7.4 Economic, 7.5 Governance).
FixImplement robust operational security for the `ADMIN_ROLE` address, such as using a multi-signature wallet (e.g., Gnosis Safe) or a time-lock contract for critical actions like granting/revoking `MINTER_ROLE`. Consider introducing a maximum minting cap per period or a total supply cap to limit potential inflation. Explore mechanisms for progressive decentralization of the `MINTER_ROLE` or its administration over time, if aligned with the project's roadmap.
StatusUnresolved
Info

Redundant Imports

I-01The `AlchemixToken` contract imports `Ownable` and `IDetailedERC20` but does not utilize any functionality or interfaces from these imported contracts. The contract uses `AccessControl` for role management, making `Ownable` redundant. `IDetailedERC20` is also not implemented or referenced (7.1 Architecture).
IssueThe `AlchemixToken` contract imports `Ownable` and `IDetailedERC20` but does not utilize any functionality or interfaces from these imported contracts. The contract uses `AccessControl` for role management, making `Ownable` redundant. `IDetailedERC20` is also not implemented or referenced (7.1 Architecture).
FixRemove unused imports (`import {Ownable} from "@openzeppelin/contracts/access/Ownable.sol";` and `import {IDetailedERC20} from "./interfaces/IDetailedERC20.sol";`) to improve code clarity and reduce compilation overhead.
StatusUnresolved
Info

Outdated Pragma Directive for ABIEncoderV2

I-02The contract includes `pragma experimental ABIEncoderV2;`. While this pragma was necessary for Solidity versions 0.6.x and 0.7.x to enable the ABIEncoderV2, it became standard in Solidity 0.8.0 and is no longer required. Although not a vulnerability, its presence indicates the use of an older compiler feature flag (7.2 Code Security).
IssueThe contract includes `pragma experimental ABIEncoderV2;`. While this pragma was necessary for Solidity versions 0.6.x and 0.7.x to enable the ABIEncoderV2, it became standard in Solidity 0.8.0 and is no longer required. Although not a vulnerability, its presence indicates the use of an older compiler feature flag (7.2 Code Security).
FixIf the project intends to upgrade to Solidity 0.8.0 or newer, this pragma can be safely removed. For the current compiler version (0.6.12), it is technically still relevant, but it's worth noting for future upgrades.
StatusUnresolved

Category Ratings

TechnicalLow7/10

The AlchemixToken contract leverages battle-tested OpenZeppelin libraries for its ERC20 and AccessControl implementations, ensuring a solid technical foundation (7.2 Code Security). Arithmetic operations are protected by SafeMath, mitigating integer overflow/underflow risks. The access control mechanism for the `mint` function is correctly implemented using the `onlyMinter` modifier (7.3 Access Control). Minor issues include redundant imports and an older pragma version (7.1 Architecture).

GovernanceHigh1/10

The contract design centralizes significant power in the `ADMIN_ROLE` and `MINTER_ROLE` (7.5 Governance). The `MINTER_ROLE` has the ability to mint an unlimited supply of tokens, which is a substantial economic risk (7.4 Economic). The `ADMIN_ROLE` (initially the deployer) controls who can be a minter. If the `ADMIN_ROLE`'s private key is compromised, the token supply can be arbitrarily inflated, potentially devaluing existing tokens. This centralization requires robust operational security for the `ADMIN_ROLE` (7.8 Operations).

UpgradesHigh3/10

The AlchemixToken contract is not designed as an upgradeable proxy (7.7 Upgrades). This simplifies the architecture by avoiding upgrade-related complexities and risks, but also means that any future changes to the token's logic would require a new deployment and migration.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

33.5% in wallets28.4% in contracts
Effective Concentration44.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 2 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder92.1%
Top-3 Unlocked94.8%

Key Addresses

Deployer
0x51e0…aaec
Unlocked LP Held By
0xa67e…57760x2ca9…2cb90xa4fc…c59a0x8e47…ec960xab8e…deca0xd1ff…c97d0x5ad6…e2770x3f09…d7600xad59…5c070xc260…13d5

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 30% (61.9% total → 44.9% effective; 33.5% in EOAs, 28.4% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 92.1% (independent LP — depth risk, pool = 46% of DEX liquidity)
  • LP top3 unlocked holders = 94.8% (independent LP — depth risk, pool = 46% of DEX liquidity)
  • 1 High finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

c8ntinuum (CTM)High RiskCurve DAO (CRV)High RiskFrax USD (FRXUSD)High RiskAdshares (ADS)High RiskDestra Network (DSYNC)High RiskEthena (ENA)High Risk

Would You Like a More Detailed Audit of Alchemix?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit