Quantum Audit Logo

Is Basepepe a Scam?

Honeypot, rug-pull and ownership checks

Basepepe BASEPEPE
0xb200…ff01
Base Not verifiedLast checked 2d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit was conducted without access to the contract's source code. Therefore, a comprehensive security analysis for vulnerabilities such as reentrancy, access control, or economic exploits could not be performed. The findings are limited to observations based on the provided metadata, primarily highlighting the risks associated with interacting with an unverified contract.

3 Informational
i Our automated scanner reviewed Basepepe (BASEPEPE) on Base. 2 of 5 security checks passed — see the full breakdown below.
Volume 24h
$108.8K
Liquidity
$44.0K
Price
$0.0001115
Age
19d
Top 10 Holders
32.0%

Security Findings

Info

Unverified Source Code

I-01The source code for the contract at 0xb200…ff01 is not verified on the block explorer. This lack of transparency prevents users and auditors from understanding the contract's functionality, logic, and potential vulnerabilities. It significantly increases the risk of hidden malicious code or unintended behavior.
IssueThe source code for the contract at is not verified on the block explorer. This lack of transparency prevents users and auditors from understanding the contract's functionality, logic, and potential vulnerabilities. It significantly increases the risk of hidden malicious code or unintended behavior.
FixVerify the contract's source code on the block explorer. This allows for public scrutiny and independent security analysis, building trust within the community. Ensure the verified code precisely matches the deployed bytecode.
StatusUnresolved
Info

Unknown Contract Functionality and Risks

I-02Without access to the source code, the specific functionality, purpose, and internal mechanisms of the contract are unknown. This makes it impossible to assess common security risks such as reentrancy, access control flaws, integer overflows/underflows, or economic manipulation vectors (7.2 Code Security, 7.3 Access Control, 7.4 Economic). Users interact with this contract at a heightened risk.
IssueWithout access to the source code, the specific functionality, purpose, and internal mechanisms of the contract are unknown. This makes it impossible to assess common security risks such as reentrancy, access control flaws, integer overflows/underflows, or economic manipulation vectors (7.2 Code Security, 7.3 Access Control, 7.4 Economic). Users interact with this contract at a heightened risk.
FixProvide comprehensive documentation and, ideally, verified source code to explain the contract's intended functionality, design choices, and any known limitations or risks. This transparency is crucial for informed decision-making by users.
StatusUnresolved
Info

Immutability of Unverified Code

I-03The contract is not identified as a proxy, implying it is immutable once deployed. While immutability can be a security feature for well-audited code, for an unverified contract, it means any potential vulnerabilities or bugs present in the bytecode cannot be patched or upgraded (7.7 Upgrades). This locks in any undiscovered flaws, making them permanent and unfixable without a complete redeployment to a new address.
IssueThe contract is not identified as a proxy, implying it is immutable once deployed. While immutability can be a security feature for well-audited code, for an unverified contract, it means any potential vulnerabilities or bugs present in the bytecode cannot be patched or upgraded (7.7 Upgrades). This locks in any undiscovered flaws, making them permanent and unfixable without a complete redeployment to a new address.
FixIf the contract is intended to be immutable, ensure its source code is rigorously audited and verified before deployment. For unverified immutable contracts, users should be aware that any issues found later cannot be remediated.
StatusUnresolved

Category Ratings

TechnicalLow8/10

Without access to the contract's source code, a detailed technical analysis (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) is not possible. The contract's functionality and internal logic remain unknown, preventing assessment of common vulnerabilities like reentrancy or integer overflows. This significantly limits the ability to identify specific code-level security strengths or weaknesses, such as proper input validation or secure access control mechanisms.

GovernanceHigh2/10

A thorough assessment of economic and governance risks (7.4 Economic, 7.5 Governance) is not feasible without understanding the contract's logic and its interaction with other protocols or assets. Potential issues like oracle manipulation, economic exploits, or centralized control cannot be identified. The lack of transparency prevents evaluating the contract's resilience to market fluctuations or potential governance attacks.

UpgradesMedium6/10

The contract is not identified as a proxy (`is_proxy: false`), suggesting it is immutable and not directly upgradeable (7.7 Upgrades). While this eliminates upgrade-related risks like improper upgrade logic or proxy storage collisions, it also means any discovered vulnerabilities cannot be patched without a full redeployment. The immutability implies a fixed design, which can be a strength if the code is secure, but a weakness if critical flaws are present.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

11.3% in wallets20.7% in contracts
Effective Concentration19.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder98.2%
Top-3 Unlocked100.0%

Key Addresses

Unlocked LP Held By
0x0121…75c90x87d8…d0db

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $50k ($44,294 across 5 pairs — thin market)
  • LP top1 unlocked holder = 98.2% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • Token age < 30 days (still settling)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Virtual Protocol (VIRTUAL)Medium RiskCookieMedium RiskStockify (STFY)Medium RiskMoltbook (MOLT)Medium RiskKellyClaudeMedium RiskPlayMedium Risk

Would You Like a More Detailed Audit of Basepepe?

Paste the contract address into our AI-powered scanner for a deeper real-time report — free, with every scoring factor shown.

Get Detailed Audit