Quantum Audit Logo

Is BaseUnc Safe?

On-chain security analysis — is it a scam or legit?

BaseUnc BASEUNC
0xb200…1b01
Base Not verifiedLast checked 2d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit report is based on an analysis of the provided contract address without access to its verified source code. Therefore, a comprehensive security assessment for vulnerabilities like reentrancy, integer overflows, or access control flaws could not be performed. The findings below are informational, highlighting the inherent risks associated with unverified contracts.

3 Informational
Volume 24h
$41.0K
Liquidity
$32.9K
Price
$0.00006704
Token Age
13d
Top 10 Holders
33.2%

Security Findings

Info

Lack of Verified Source Code

I-01The contract at address 0xb200…1b01 on the Base network does not have its source code verified on the blockchain explorer. This prevents a thorough security audit and makes it impossible for users to understand the contract's logic and behavior.
IssueThe contract at address on the Base network does not have its source code verified on the blockchain explorer. This prevents a thorough security audit and makes it impossible for users to understand the contract's logic and behavior.
FixVerify the full source code of the contract on the Base blockchain explorer. This increases transparency and allows for public scrutiny and security analysis.
StatusUnresolved
Info

Inability to Perform Static Analysis

I-02Due to the absence of verified source code, static analysis tools and manual code review techniques cannot be applied. This means that common vulnerabilities such as reentrancy, integer overflows/underflows, access control flaws, or logic errors cannot be identified or confirmed.
IssueDue to the absence of verified source code, static analysis tools and manual code review techniques cannot be applied. This means that common vulnerabilities such as reentrancy, integer overflows/underflows, access control flaws, or logic errors cannot be identified or confirmed.
FixProvide the complete and accurate source code for static analysis. This is a fundamental step in identifying and mitigating potential security vulnerabilities before deployment or during an audit.
StatusUnresolved
Info

Operational Risks Due to Obscurity

I-03Operating a protocol with unverified contract code introduces significant operational risks (7.8 Operations). It becomes impossible to monitor the contract's internal state changes, understand its dependencies, or react effectively to unexpected behavior or potential exploits, as the underlying logic is opaque.
IssueOperating a protocol with unverified contract code introduces significant operational risks (7.8 Operations). It becomes impossible to monitor the contract's internal state changes, understand its dependencies, or react effectively to unexpected behavior or potential exploits, as the underlying logic is opaque.
FixEnsure all critical production contracts have verified source code. Implement robust monitoring solutions that can interpret contract events and state changes based on known, verified logic.
StatusUnresolved

Category Ratings

TechnicalLow8/10

Without access to the contract's source code, a technical security analysis (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be performed. This prevents identification of common vulnerabilities such as reentrancy, integer overflows, or improper access controls. The lack of transparency significantly increases the technical risk, as the contract's logic and potential attack vectors remain unknown, making it impossible to assess its security posture.

GovernanceHigh2/10

The economic and governance aspects (7.4 Economic, 7.5 Governance) of the contract cannot be assessed without source code. This means potential risks like oracle manipulation, economic exploits, or centralized control mechanisms are unknown. The absence of transparency makes it impossible to evaluate the contract's resilience against economic attacks or its governance structure, posing significant economic and governance risks.

UpgradesMedium6/10

The upgradeability status and mechanisms (7.7 Upgrades) of the contract are unknown due to the lack of source code. It is impossible to determine if the contract is upgradeable, what proxy pattern (e.g., UUPS, Transparent) it might use, or if upgrade safety measures are in place. This introduces significant uncertainty regarding future changes and potential upgrade-related risks, as any upgrade path remains opaque.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

3.5% in wallets29.7% in contracts
Effective Concentration15.4%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder59.7%
Top-3 Unlocked86.5%

Key Addresses

Unlocked LP Held By
0x0b23…1b140x1623…ab5b0xe254…8b8b0x8160…287d0x3dd5…599d0xf48e…29aa0xd9a2…3a88

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $50k ($33,413 across 11 pairs — thin market)
  • LP top1 unlocked holder = 59.7% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • LP top3 unlocked holders = 86.5% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • Token age < 30 days (still settling)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Aave Token (AAVE)Medium RiskRollMedium RiskOpenGradient (OPG)Medium RiskZoraMedium RiskHorizen (ZEN)Medium RiskSquid (QUID)Medium Risk

Would You Like a More Detailed Audit of BaseUnc?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit