On-chain security analysis — is it a scam or legit?
0xf308…3d67
The BurnMintERC20 contract implements an ERC-20 token with minting and burning capabilities, leveraging OpenZeppelin's AccessControl. While the contract generally follows good practices for token implementation and access control, a critical vulnerability exists in the `grantMintAndBurnRoles` function, which lacks any access restrictions. This flaw allows any caller to grant themselves or others the ability to mint and burn tokens, leading to a complete compromise of the token's supply and value.
Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.
The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.
0x931f…80480x3dd5…599dNo privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.
Get Detailed Audit