Quantum Audit Logo

Is Autonomi Safe?

On-chain security analysis — is it a scam or legit?

Autonomi ANT
0xa78d…b684
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 18d ago 2 audits on record
Executive SummaryAI Copilot

The AutonomiNetworkToken contract is a standard ERC20 token implementation, leveraging battle-tested OpenZeppelin libraries for its core functionalities including burnable, permit, and voting features. The technical implementation is robust, with no critical or high-severity vulnerabilities identified. The primary risks are related to the initial centralized distribution of tokens, which impacts governance and economic decentralization.

1 Medium2 Informational
Volume 24h
$11.8K
Liquidity
$94.1K
Price
$0.03841
Token Age
1y
Top 10 Holders
80.9%

Security Findings

Medium

Centralized Initial Token Distribution

M-01The contract's constructor mints the entire initial supply of 1.2 billion tokens to a single `autonomi` address. This design choice results in a highly centralized token distribution at deployment, giving the controlling entity significant influence over governance (via ERC20Votes) and potential economic power (7.4 Economic, 7.5 Governance). A compromise of this single address could have severe consequences for the protocol.
IssueThe contract's constructor mints the entire initial supply of 1.2 billion tokens to a single `autonomi` address. This design choice results in a highly centralized token distribution at deployment, giving the controlling entity significant influence over governance (via ERC20Votes) and potential economic power (7.4 Economic, 7.5 Governance). A compromise of this single address could have severe consequences for the protocol.
FixImplement robust security measures for the `autonomi` address, such as a multi-signature wallet (e.g., Gnosis Safe) with a diverse set of signers. Consider a strategy for progressive decentralization of the token supply over time, distributing tokens to various stakeholders or a community treasury to reduce single-point-of-failure risks.
StatusUnresolved
Info

Lack of Emergency Pause Mechanism

I-01The AutonomiNetworkToken contract does not include an emergency pause mechanism. While this is common for simple ERC20 tokens and reduces complexity, it means that in the event of a critical vulnerability or exploit in an integrated system, token transfers cannot be halted (7.8 Operations).
IssueThe AutonomiNetworkToken contract does not include an emergency pause mechanism. While this is common for simple ERC20 tokens and reduces complexity, it means that in the event of a critical vulnerability or exploit in an integrated system, token transfers cannot be halted (7.8 Operations).
FixEvaluate whether an emergency pause functionality is necessary for the broader Autonomi Network ecosystem. If deemed critical for future integrations or potential risks, consider wrapping this token with a pausable contract or implementing a governance-controlled pause in a future version or related contract.
StatusUnresolved
Info

Potential Front-running of ERC20Permit

I-02The ERC20Permit functionality allows users to sign off-chain approvals. While correctly implemented using OpenZeppelin's battle-tested code, the nature of `permit` transactions means they can be susceptible to front-running (7.2 Code Security). A malicious actor could observe a pending `permit` transaction and submit their own transaction with a higher gas price to execute the `permit` call before the legitimate user, potentially manipulating the order of operations.
IssueThe ERC20Permit functionality allows users to sign off-chain approvals. While correctly implemented using OpenZeppelin's battle-tested code, the nature of `permit` transactions means they can be susceptible to front-running (7.2 Code Security). A malicious actor could observe a pending `permit` transaction and submit their own transaction with a higher gas price to execute the `permit` call before the legitimate user, potentially manipulating the order of operations.
FixUsers should be aware of the potential for front-running when using `permit` signatures. Off-chain systems integrating `permit` should implement mechanisms to mitigate front-running, such as using transaction relays that can submit transactions privately or with appropriate timing, or by educating users on best practices for submitting signed messages.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The contract demonstrates high technical quality by inheriting from well-audited OpenZeppelin Contracts (v5.0.0), including ERC20, ERC20Burnable, ERC20Permit, and ERC20Votes. This approach significantly reduces the likelihood of common vulnerabilities (7.2 Code Security). The custom logic is minimal, limited to the constructor and required overrides, which are correctly implemented. No reentrancy, integer overflow/underflow, or other critical technical flaws were identified (7.2 Code Security).

GovernanceHigh1/10

The contract implements ERC20Votes, enabling on-chain governance capabilities (7.5 Governance). However, the entire initial supply of 1.2 billion tokens is minted to a single 'autonomi' address in the constructor, creating a high degree of centralization (7.4 Economic). This centralized control over the initial token supply poses a significant risk to the project's decentralization goals and could lead to governance manipulation if not managed carefully (7.3 Access Control).

UpgradesMedium6/10

The AutonomiNetworkToken contract is not designed as an upgradeable proxy contract (7.7 Upgrades). This eliminates the complexities and potential risks associated with upgrade mechanisms, such as storage collisions, proxy logic errors, or improper upgrade path management. The contract is immutable once deployed, providing a fixed and predictable codebase.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

66.2% in wallets14.7% in contracts
Effective Concentration72.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.9%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xf141…32a1
Unlocked LP Held By
0x1d24…108c0xb713…b0e40x167f…7d4e0xc56f…fca7

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 70% (80.9% total → 72.0% effective; 66.2% in EOAs, 14.7% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 99.9% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Autonomi a scam?

Based on automated analysis, Autonomi scores 67/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is Autonomi safe to buy?

Our scanner flagged a risk score of 67/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.

Has Autonomi been audited?

The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

Sperax USD (USDS)High RiskSubsquid (SQD)High RiskArbitrum Dog (MILES)High RiskCoW Protocol Token (COW)High RiskBoopMedium RiskRAINMedium Risk

Would You Like a More Detailed Audit of Autonomi?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit