Quantum Audit Logo

Is Baseline a Scam?

Early-stage security check — honeypot & rug-pull analysis

Baseline BASELINE
0xb200…fb01
Base Not verifiedLast checked 2d ago 1 audit on record New Launch · 1d old
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This report is based on an audit request for a contract on the Base network. No Solidity source code was provided for analysis, preventing a comprehensive security assessment. The contract at 0xb20000000000000000000000c6f9024862c6fb01 is unverified on-chain. Therefore, this report cannot identify specific vulnerabilities or provide detailed technical insights into its functionality or security posture.

6 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$110.8K
Liquidity
$50.6K
Price
$0.0002153
Token Age
1d
Top 10 Holders
22.8%

Security Findings

Info

No Source Code Provided for Analysis

I-01The Solidity source code for the contract at 0xb200…fb01 was not provided for this audit. This prevents any form of static analysis, manual review, or dynamic testing of the contract's logic and security posture. Without source code, it is impossible to identify vulnerabilities such as reentrancy, integer overflows, access control flaws, or other critical issues.
IssueThe Solidity source code for the contract at was not provided for this audit. This prevents any form of static analysis, manual review, or dynamic testing of the contract's logic and security posture. Without source code, it is impossible to identify vulnerabilities such as reentrancy, integer overflows, access control flaws, or other critical issues.
FixAlways provide the full Solidity source code for all contracts intended for audit. For deployed contracts, ensure the source code is publicly verified on the blockchain explorer (e.g., Etherscan, Basescan) to allow for community review and transparency.
StatusUnresolved
Info

Contract Not Verified on Blockchain Explorer

I-02The contract at 0xb200…fb01 is not verified on the Base blockchain explorer. This means that the deployed bytecode cannot be easily matched against human-readable Solidity code by the public or by security tools. Lack of verification significantly hinders transparency and trust.
IssueThe contract at is not verified on the Base blockchain explorer. This means that the deployed bytecode cannot be easily matched against human-readable Solidity code by the public or by security tools. Lack of verification significantly hinders transparency and trust.
FixIt is strongly recommended to verify the contract's source code on the respective blockchain explorer. This allows users and auditors to confirm that the deployed bytecode matches the intended Solidity logic, enhancing transparency and trust in the contract's operations.
StatusUnresolved
Info

Comprehensive Vulnerability Assessment Not Possible

I-03Due to the absence of source code, a comprehensive assessment for specific vulnerability patterns (e.g., reentrancy, front-running, flash loan attacks, oracle manipulation, access control bypasses, denial-of-service vectors) could not be conducted. The contract's security against these common attack vectors remains unknown.
IssueDue to the absence of source code, a comprehensive assessment for specific vulnerability patterns (e.g., reentrancy, front-running, flash loan attacks, oracle manipulation, access control bypasses, denial-of-service vectors) could not be conducted. The contract's security against these common attack vectors remains unknown.
FixA full security audit requires access to the complete source code. If the contract is critical, a post-deployment audit with source code verification is essential to ensure its resilience against known attack patterns.
StatusUnresolved
Info

Contract Functionality and Purpose Unknown

I-04Without the Solidity source code, the exact functionality, purpose, and intended interactions of the contract are entirely unknown. It is impossible to determine if it's a token, a vault, a lending pool, a governance contract, or any other DeFi primitive, which makes risk assessment impossible.
IssueWithout the Solidity source code, the exact functionality, purpose, and intended interactions of the contract are entirely unknown. It is impossible to determine if it's a token, a vault, a lending pool, a governance contract, or any other DeFi primitive, which makes risk assessment impossible.
FixFor any contract, clear documentation and publicly available source code are vital to communicate its intended functionality and allow users to understand its role within an ecosystem. This transparency builds user confidence and facilitates security reviews.
StatusUnresolved
Info

Potential for Hidden Malicious Logic

I-05When source code is not provided or verified, there is a significant risk that the deployed bytecode could contain malicious or unintended logic. This could include backdoors, unauthorized fund transfers, or other harmful functionalities that are not apparent from external interactions alone.
IssueWhen source code is not provided or verified, there is a significant risk that the deployed bytecode could contain malicious or unintended logic. This could include backdoors, unauthorized fund transfers, or other harmful functionalities that are not apparent from external interactions alone.
FixUsers should exercise extreme caution and avoid interacting with contracts that do not have publicly verified source code. Always assume the worst-case scenario when transparency is lacking, as malicious actors often hide their intentions in unverified code.
StatusUnresolved
Info

Upgradeability Status Undetermined

I-06It is impossible to determine if the contract implements an upgradeable proxy pattern (e.g., UUPS, Transparent, Beacon) without its source code. This means the potential for future logic changes, and the associated risks (e.g., upgradeability governance, proxy admin control), cannot be assessed.
IssueIt is impossible to determine if the contract implements an upgradeable proxy pattern (e.g., UUPS, Transparent, Beacon) without its source code. This means the potential for future logic changes, and the associated risks (e.g., upgradeability governance, proxy admin control), cannot be assessed.
FixIf the contract is intended to be upgradeable, its proxy pattern and upgrade mechanisms should be clearly documented and verifiable through source code. This includes the roles and procedures for initiating and executing upgrades, which should ideally involve robust governance or multi-signature controls.
StatusUnresolved

Category Ratings

TechnicalLow10/10

Due to the absence of Solidity source code, a technical analysis of the contract's architecture (7.1), code security (7.2), and access control mechanisms (7.3) could not be performed. Without the source, it is impossible to assess common vulnerabilities like reentrancy, integer overflows, or logic flaws. The contract's bytecode is deployed, but its functionality remains opaque.

GovernanceHigh2/10

Without access to the contract's source code, an evaluation of its economic model (7.4) and governance structure (7.5) is not possible. It is unknown if the contract interacts with external protocols (7.6), has any tokenomics, or is controlled by a multi-sig or DAO. The potential for oracle manipulation or flash loan attacks cannot be assessed.

UpgradesMedium6/10

The upgradeability status (7.7) of the contract cannot be determined without its source code. It is unknown if the contract implements a proxy pattern (e.g., UUPS, Transparent) or if its logic can be modified post-deployment. This also prevents an assessment of operational risks (7.8) related to upgrade paths or administrative controls.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

4.7% in wallets18.1% in contracts
Effective Concentration11.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 2 remaining pairs hold $9 between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Unlocked LP Held By
0x575e…fe98

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 81% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 81% of DEX liquidity)
  • Token age < 7 days (early, volatile)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

PORTALMedium RiskCoinbase Man (BRIAN)Medium RisktobyMedium RiskMeta Platforms Inc. (METAC)Medium RiskOlivia AI 2.0 ($OLIVIA2.0)Medium RiskVibestarter (VIBES)Medium Risk

Would You Like a More Detailed Audit of Baseline?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit