Quantum Audit Logo

Is AUTONOMOPOLY Safe?

On-chain security analysis — is it a scam or legit?

AUTONOMOPOLY AUTONO
0xb3d7…6d8e
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 18d ago 2 audits on record
Executive SummaryAI Copilot

The LiquidToken contract implements a standard ERC-20 token with extensions for burning, permit functionality, and voting. It includes specific cross-chain minting and burning capabilities restricted to a Superchain Token Bridge. The contract leverages well-audited OpenZeppelin libraries, contributing to its robustness. Key areas of review included access control for administrative functions and the implications of cross-chain operations. Identified risks are primarily related to centralized administrative control and the interpretation of supply limits.

1 Medium1 Low1 Informational
Volume 24h
$11.8K
Liquidity
$378.3K
Price
$0.000004948
Token Age
2mo
Top 10 Holders
74.1%

Security Findings

Medium

Centralized Admin Control

M-01The `_admin` role in the LiquidToken contract possesses significant control, including the ability to update the `_admin` address itself, as well as the token's `_image` and `_metadata` strings. A compromise of this single `_admin` address could lead to unauthorized changes to the token's administrative control and its associated descriptive data. While the `_originalAdmin` can only call `verify()` once, the mutable `_admin` retains broad powers.
IssueThe `_admin` role in the LiquidToken contract possesses significant control, including the ability to update the `_admin` address itself, as well as the token's `_image` and `_metadata` strings. A compromise of this single `_admin` address could lead to unauthorized changes to the token's administrative control and its associated descriptive data. While the `_originalAdmin` can only call `verify()` once, the mutable `_admin` retains broad powers.
FixConsider implementing a multi-signature wallet for the `_admin` role to require multiple approvals for sensitive actions, thereby reducing the risk associated with a single point of failure. Alternatively, a time-lock mechanism could be introduced for critical administrative changes, providing a window for community or governance intervention if an unauthorized change is detected.
StatusUnresolved
Low

`maxSupply_` is not a strict global hard cap

L-01The `maxSupply_` parameter in the constructor is used to mint the initial supply to `msg.sender` only if `block.chainid == initialSupplyChainId_`. However, the `crosschainMint` function, which is callable by the `Predeploys.SUPERCHAIN_TOKEN_BRIDGE`, allows for additional tokens to be minted without any explicit check against the `maxSupply_` value. This implies that `maxSupply_` is only a limit for the initial distribution on a specific chain, not a global hard cap for the token's total supply across all chains.
IssueThe `maxSupply_` parameter in the constructor is used to mint the initial supply to `msg.sender` only if `block.chainid == initialSupplyChainId_`. However, the `crosschainMint` function, which is callable by the `Predeploys.SUPERCHAIN_TOKEN_BRIDGE`, allows for additional tokens to be minted without any explicit check against the `maxSupply_` value. This implies that `maxSupply_` is only a limit for the initial distribution on a specific chain, not a global hard cap for the token's total supply across all chains.
FixClarify in the project documentation that `maxSupply_` refers specifically to the initial supply minted on the designated chain and does not represent a global hard cap. If a global hard cap is intended, a mechanism to enforce this limit across all minting functions, including `crosschainMint`, should be implemented. This could involve a state variable tracking total supply and a check in `_mint`.
StatusUnresolved
Info

Reliance on External Superchain Token Bridge

I-01The `crosschainMint` and `crosschainBurn` functions are critical for the token's multi-chain functionality, and their execution is exclusively authorized by the `Predeploys.SUPERCHAIN_TOKEN_BRIDGE`. The security and operational integrity of this external bridge are paramount, as any vulnerability or compromise within the bridge could directly impact the supply control and integrity of the LiquidToken across different chains.
IssueThe `crosschainMint` and `crosschainBurn` functions are critical for the token's multi-chain functionality, and their execution is exclusively authorized by the `Predeploys.SUPERCHAIN_TOKEN_BRIDGE`. The security and operational integrity of this external bridge are paramount, as any vulnerability or compromise within the bridge could directly impact the supply control and integrity of the LiquidToken across different chains.
FixAcknowledge and continuously monitor the security posture and operational status of the `SUPERCHAIN_TOKEN_BRIDGE`. Ensure that robust security audits, incident response plans, and operational security practices are in place for the bridge itself, as it represents a significant external dependency for the token's cross-chain functionality.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The technical implementation of the LiquidToken contract is robust, leveraging battle-tested OpenZeppelin libraries for ERC-20, ERC20Permit, ERC20Votes, and ERC20Burnable functionalities (7.2 Code Security). The contract adheres to modern Solidity best practices, including explicit error messages and a recent compiler version. The `crosschainMint` and `crosschainBurn` functions correctly restrict access to the `SUPERCHAIN_TOKEN_BRIDGE`, ensuring controlled supply management (7.3 Access Control). No reentrancy or integer overflow/underflow vulnerabilities were identified due to the reliance on OpenZeppelin's secure implementations.

GovernanceHigh2/10

The contract's economic model is a standard ERC-20 token with a defined initial supply and cross-chain mint/burn capabilities (7.4 Economic). A key strength is the initial supply being minted only on a specified chain, preventing accidental multi-chain initial mints. However, the `_admin` role holds significant power, including the ability to update administrative privileges and token metadata, posing a centralization risk if compromised (7.3 Access Control). Additionally, the `maxSupply_` parameter in the constructor is not a global hard cap, as the `crosschainMint` function allows for additional supply by the bridge, which could lead to an unexpected total supply if not properly understood (7.4 Economic).

UpgradesMedium6/10

The LiquidToken contract is not designed as an upgradeable proxy, meaning its logic is immutable once deployed (7.7 Upgrades). This eliminates risks associated with proxy implementation bugs or upgradeability mechanism flaws. Any future changes to the token's core logic would require a new contract deployment and migration, which is a standard approach for non-upgradeable tokens. The immutability provides a high degree of certainty regarding the contract's long-term behavior.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

1.0% in wallets73.1% in contracts
Effective Concentration30.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.1%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x49f5…7cda
Unlocked LP Held By
0xe115…b3c20xe0eb…a2cd

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced (admin/mint authority retained)
  • Top-10 concentration > 30% (74.1% total → 30.3% effective; 1.0% in EOAs, 73.1% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 99.1% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is AUTONOMOPOLY a scam?

Based on automated analysis, AUTONOMOPOLY scores 63/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is AUTONOMOPOLY safe to buy?

Our scanner flagged a risk score of 63/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.

Has AUTONOMOPOLY been audited?

The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

Solana (SOL)High RiskTAOTHigh RiskCheckmate (CHECK)High RiskSoSoValue (SOSO)High RiskSally (A1C)High RiskOFCHigh Risk

Would You Like a More Detailed Audit of AUTONOMOPOLY?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit