Quantum Audit Logo

Is Catena Labs a Scam?

Early-stage security check — honeypot & rug-pull analysis

Catena Labs CATE
0x53ab…ca42
Arbitrum Not verifiedLast checked 3d ago 1 audit on record New Launch · 1d old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

No Solidity source code was provided for analysis. Therefore, a comprehensive security audit could not be performed. The assessment is based solely on the provided metadata, and no specific vulnerabilities can be identified or ruled out. Users should exercise extreme caution when interacting with unverified contracts.

5 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$100.1K
Liquidity
$80.6K
Price
$0.1214
Token Age
1d
Top 10 Holders
93.5%

Security Findings

Info

Unverified Source Code

I-01The Solidity source code for the contract at 0x53ab…ca42 is not publicly verified on the Arbitrum block explorer. This prevents any form of static analysis or manual code review.
IssueThe Solidity source code for the contract at is not publicly verified on the Arbitrum block explorer. This prevents any form of static analysis or manual code review.
FixVerify the Solidity source code on the block explorer. This increases transparency and allows for community and professional security audits.
StatusUnresolved
Info

Unknown Contract Functionality

I-02Without access to the source code, the exact purpose, logic, and intended functionality of the contract cannot be determined. This makes it impossible to assess its adherence to specifications or identify logical flaws.
IssueWithout access to the source code, the exact purpose, logic, and intended functionality of the contract cannot be determined. This makes it impossible to assess its adherence to specifications or identify logical flaws.
FixProvide the source code and a clear specification or documentation outlining the contract's intended behavior and business logic.
StatusUnresolved
Info

Inability to Assess Technical Security Risks

I-03Critical technical vulnerabilities such as reentrancy, integer overflows/underflows, denial-of-service vectors, or improper input validation cannot be identified or ruled out without the source code (7.2 Code Security).
IssueCritical technical vulnerabilities such as reentrancy, integer overflows/underflows, denial-of-service vectors, or improper input validation cannot be identified or ruled out without the source code (7.2 Code Security).
FixA full technical security audit, including static analysis and manual review, should be performed once the source code is made available.
StatusUnresolved
Info

Inability to Assess Access Control and Economic Risks

I-04The contract's access control mechanisms (7.3 Access Control), potential for economic manipulation (7.4 Economic), or governance structures (7.5 Governance) cannot be evaluated. This includes risks like centralized control, oracle manipulation, or flash loan vulnerabilities.
IssueThe contract's access control mechanisms (7.3 Access Control), potential for economic manipulation (7.4 Economic), or governance structures (7.5 Governance) cannot be evaluated. This includes risks like centralized control, oracle manipulation, or flash loan vulnerabilities.
FixProvide source code and documentation detailing access control roles, economic models, and governance processes for a comprehensive review.
StatusUnresolved
Info

Inability to Assess Upgradeability and Operational Risks

I-05The contract's upgradeability pattern (7.7 Upgrades), if any, and operational aspects such as pausing mechanisms or emergency procedures (7.8 Operations) are unknown. This prevents an assessment of potential upgrade safety issues or operational single points of failure.
IssueThe contract's upgradeability pattern (7.7 Upgrades), if any, and operational aspects such as pausing mechanisms or emergency procedures (7.8 Operations) are unknown. This prevents an assessment of potential upgrade safety issues or operational single points of failure.
FixClarify the contract's upgradeability status and operational procedures through source code and documentation to allow for a proper risk assessment.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Without access to the Solidity source code, a technical security assessment (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be conducted. No specific vulnerabilities related to reentrancy, integer overflows, or access control flaws can be identified or ruled out. The contract's functionality and security mechanisms remain unknown, making it impossible to evaluate its robustness or adherence to secure coding practices.

GovernanceHigh1/10

An economic and governance risk assessment (7.4 Economic, 7.5 Governance) is not possible without understanding the contract's logic, tokenomics, or administrative structures. Potential risks such as oracle manipulation, flash loan vulnerabilities, or centralized control cannot be evaluated. External dependencies (7.6 External) are also unknown, preventing an analysis of potential cascading failures or reliance on untrusted protocols.

UpgradesMedium6/10

The upgradeability status (7.7 Upgrades) of the contract cannot be determined without source code. It is unknown if the contract employs a proxy pattern (e.g., UUPS, Transparent) or if its logic is immutable. Operational risks (7.8 Operations) related to pausing, emergency shutdowns, or administrative key management are also unknown, leaving potential points of failure or centralized control unaddressed.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedPass
Not a ProxyPass

Holder Composition

93.5% in wallets0.0% in contracts
Effective Concentration93.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xa3da…3c8c
Unlocked LP Held By
0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (93.5% total → 93.5% effective; 93.5% in EOAs, 0.0% in contracts — extreme)
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • LP claimed locked but only 0.0% actually locked
  • Token age < 7 days (early, volatile)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Vision (VSN)Critical RiskUnicity Labs (UNYLA)Critical RiskOrnn Exchange (ORNN)Critical RiskVangrid (VAN)Critical RiskMORCritical RiskDGrid AI (DGAI)Critical Risk

Would You Like a More Detailed Audit of Catena Labs?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit