Quantum Audit Logo

Is Arcadia Safe?

On-chain security analysis — is it a scam or legit?

Arcadia AAA
0xaaa8…2aaa
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 10d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The Arcadia token contract is a standard ERC20 implementation built upon the well-audited Solmate library. The contract is minimal, non-upgradeable, and includes a basic burn function. Key observations include the fixed token supply after initial minting and the centralized control of the initial token distribution to a single treasury address. No critical or high-severity vulnerabilities were identified.

3 Informational
Volume 24h
$43.4K
Liquidity
$125.1K
Price
$0.01732
Token Age
1y
Top 10 Holders
88.1%

Security Findings

Info

Centralized Initial Token Supply

I-01Upon deployment, the entire initial supply of 100,000,000 AAA tokens is minted to a single `treasury` address specified in the constructor. This design choice centralizes the control of the initial token distribution to a single entity or wallet (7.4 Economic).
IssueUpon deployment, the entire initial supply of 100,000,000 AAA tokens is minted to a single `treasury` address specified in the constructor. This design choice centralizes the control of the initial token distribution to a single entity or wallet (7.4 Economic).
FixWhile common for initial token deployments, it is recommended to manage the `treasury` address with robust security practices, such as a multi-signature wallet (e.g., Gnosis Safe) to mitigate the risks associated with a single point of failure. Clearly communicate the role and management of this treasury to the community.
StatusUnresolved
Info

Fixed Token Supply After Initial Mint

I-02The `Arcadia` contract's `_mint` function is only called once during construction. There is no public function or mechanism to mint additional tokens after deployment. This means the total supply of tokens is fixed at 100,000,000 (minus any tokens burned) and cannot be increased in the future (7.4 Economic).
IssueThe `Arcadia` contract's `_mint` function is only called once during construction. There is no public function or mechanism to mint additional tokens after deployment. This means the total supply of tokens is fixed at 100,000,000 (minus any tokens burned) and cannot be increased in the future (7.4 Economic).
FixThis is a design decision rather than a vulnerability. Ensure this fixed supply model aligns with the project's long-term tokenomics and economic strategy. If future flexibility for supply adjustments is desired, an upgradeable contract or a separate minting mechanism would be required, which is not present in the current design.
StatusUnresolved
Info

Reliance on Solmate's `unchecked` Blocks for Arithmetic

I-03The underlying Solmate ERC20 library utilizes `unchecked` blocks for certain arithmetic operations, specifically additions to `balanceOf` and `totalSupply`, and increments to `nonces`. While Solidity 0.8.0+ includes default overflow/underflow checks, `unchecked` blocks bypass these for gas optimization (7.2 Code Security).
IssueThe underlying Solmate ERC20 library utilizes `unchecked` blocks for certain arithmetic operations, specifically additions to `balanceOf` and `totalSupply`, and increments to `nonces`. While Solidity 0.8.0+ includes default overflow/underflow checks, `unchecked` blocks bypass these for gas optimization (7.2 Code Security).
FixSolmate's implementation is widely audited and these `unchecked` blocks are generally considered safe within the context of standard ERC20 operations, as underflows are explicitly guarded against before subtraction (e.g., `balanceOf[from] -= amount;` will revert if `balanceOf` is insufficient). No action is required, but it's important to be aware of this design choice and its implications for gas efficiency and safety.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The Arcadia token contract is a straightforward ERC20 implementation leveraging the battle-tested Solmate library (7.1 Architecture). The code is minimal, well-structured, and adheres to standard ERC20 behaviors (7.2 Code Security). Solmate's use of `unchecked` blocks for arithmetic operations is gas-efficient and generally safe for ERC20 logic, as underflows are prevented by explicit checks before subtraction (e.g., `balanceOf[msg.sender] -= amount;` will revert if `balanceOf` is insufficient). No reentrancy or complex attack vectors were identified (7.3 Access Control).

GovernanceHigh2/10

The token's economic model is simple: a fixed supply of 100,000,000 tokens is minted entirely to a single `treasury` address upon deployment (7.4 Economic). This design centralizes initial token distribution and control, as the `treasury` address holds the entire circulating supply. There are no governance mechanisms implemented within the contract (7.5 Governance). The `burn` function allows token holders to reduce their own supply, providing a deflationary mechanism.

UpgradesMedium6/10

The `Arcadia` contract is not designed to be upgradeable (7.7 Upgrades). It is a standard, non-proxy implementation, meaning its logic is immutable once deployed. This eliminates risks associated with upgrade mechanisms, such as proxy misconfigurations or malicious upgrade paths. Any future changes would require a new contract deployment and migration.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

1.8% in wallets86.3% in contracts
Effective Concentration36.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 1 more pairShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder51.6%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x07d5…f338
Unlocked LP Held By
0xfa2b…52bb0xdb6d…9ab30x57d5…eb05

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 30% (88.1% total → 36.3% effective; 1.8% in EOAs, 86.3% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 51.6% (independent LP — depth risk, pool = 70% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 70% of DEX liquidity)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

BankrCoin (BNKR)Medium Risko1.exchange (O)Medium RiskCLAWNCHMedium RiskKittehCoin (MEOW)Medium RiskLimitless Official Token (LMTS)Medium RiskSurplus Intelligence (SURPLUS)Medium Risk

Would You Like a More Detailed Audit of Arcadia?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit