Quantum Audit Logo

Is CREPE Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

CREPE CREPE
0xeb2b…931d
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 2 audits on record
Executive SummaryAI Copilot

The provided source code consists of standard Uniswap V2 interfaces (IUniswapV2Router01, IUniswapV2Router02, IUniswapV2Factory) and a utility library (Address). No concrete contract implementation, such as the 'CREPE' contract mentioned in the prefill, was provided for a comprehensive security audit. The analysis is therefore limited to the provided interfaces and library. The Address library implements common low-level call wrappers, which appear robust, though one function was truncated. Without the full contract logic, a complete assessment of potential vulnerabilities, economic risks, or upgradeability concerns is not possible.

3 Informational
Volume 24h
$69.0K
Liquidity
$808.8K
Price
$0.00001455
Token Age
1y
Top 10 Holders
27.1%

Security Findings

Info

Incomplete Contract Code Provided for Audit

I-01The audit scope was limited to standard Uniswap V2 interfaces (IUniswapV2Router01, IUniswapV2Router02, IUniswapV2Factory) and a utility library (Address). The main contract, referred to as 'CREPE' in the prefill, was not provided. This prevents a comprehensive security assessment of the protocol's core logic, architecture (7.1 Architecture), access control (7.3 Access Control), economic model (7.4 Economic), and overall operational security (7.8 Operations).
IssueThe audit scope was limited to standard Uniswap V2 interfaces (IUniswapV2Router01, IUniswapV2Router02, IUniswapV2Factory) and a utility library (Address). The main contract, referred to as 'CREPE' in the prefill, was not provided. This prevents a comprehensive security assessment of the protocol's core logic, architecture (7.1 Architecture), access control (7.3 Access Control), economic model (7.4 Economic), and overall operational security (7.8 Operations).
FixProvide the complete source code for all contracts comprising the 'CREPE' protocol, including any implementation contracts, proxy contracts, and all custom libraries or dependencies. This will enable a full security review.
StatusUnresolved
Info

Truncated Function in Address Library

I-02The `verifyCallResultFromTarget` function within the `Address` library was truncated in the provided source code. While the visible parts of the library's call wrappers appear robust, the full implementation of this critical error-handling function could not be reviewed (7.2 Code Security).
IssueThe `verifyCallResultFromTarget` function within the `Address` library was truncated in the provided source code. While the visible parts of the library's call wrappers appear robust, the full implementation of this critical error-handling function could not be reviewed (7.2 Code Security).
FixEnsure the complete and correct source code for all libraries is provided. Verify that `verifyCallResultFromTarget` correctly handles return data and error conditions, similar to established libraries like OpenZeppelin's `Address` library.
StatusUnresolved
Info

Reliance on External Uniswap V2 Interfaces

I-03The provided code includes interfaces for Uniswap V2 routers and factory. Any contract interacting with these interfaces will be dependent on the security and correct functioning of the deployed Uniswap V2 contracts (7.6 External). While Uniswap V2 is a widely audited and established protocol, the security of the overall system relies on the correct integration and assumptions made about these external contracts.
IssueThe provided code includes interfaces for Uniswap V2 routers and factory. Any contract interacting with these interfaces will be dependent on the security and correct functioning of the deployed Uniswap V2 contracts (7.6 External). While Uniswap V2 is a widely audited and established protocol, the security of the overall system relies on the correct integration and assumptions made about these external contracts.
FixWhen integrating with external protocols like Uniswap V2, ensure that all interactions are carefully designed to handle potential slippage, front-running, and unexpected behavior. Implement robust checks on return values and consider using trusted or whitelisted router addresses. This is a general best practice for external dependencies.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The provided code includes standard Uniswap V2 interfaces and a robust Address utility library. The library's functions for `sendValue` and `functionCallWithValue` include essential checks for `address(this).balance` and call success, enhancing security (7.2 Code Security). However, the `verifyCallResultFromTarget` function in the Address library was truncated, preventing a full review of its implementation (7.2 Code Security). No specific vulnerabilities were identified within the provided interfaces or the visible portion of the library.

GovernanceLow10/10

No specific contract logic related to governance or economic models was provided for review (7.4 Economic, 7.5 Governance). The interfaces define standard DeFi primitives, but their integration into a larger protocol's economic or governance framework cannot be assessed without the full contract implementation. Therefore, no direct economic or governance risks can be identified from the given code.

UpgradesLow10/10

The provided code does not include any proxy contracts or upgradeability patterns (7.7 Upgrades). The interfaces and utility library are not inherently upgradeable components. Without the main contract's architecture, it is impossible to assess any upgrade-related risks or safety mechanisms.

Security Checklist

Contract VerifiedPass
Ownership RenouncedPass
No Mint FunctionPass
Liquidity LockedPass
Not a ProxyPass

Holder Composition

18.1% in wallets9.1% in contracts
Effective Concentration21.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Burned3.5%
LP Locked99.9% · Null Address, PinkLock02
Top-1 Unlocked Holder0.0%

Key Addresses

Deployer
0x9d3f…4324
Unlocked LP Held By
0x0ed9…97060x69ec…a75a0x0378…dead0xd27f…df8b0xb2ce…4c690x7294…88e50x0d60…d37c0x97bf…b013

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Top-10 concentration > 20% (27.1% total → 21.7% effective; 18.1% in EOAs, 9.1% in contracts — mild)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is CREPE a scam?

Based on automated analysis, CREPE scores 0/100 (Low Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is CREPE safe to buy?

Our scanner flagged a risk score of 0/100. Ownership is renounced which reduces rug-pull risk. DYOR before purchasing any token.

Has CREPE been audited?

The contract is open-source and verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

TCryptochicks (TCC)Low Risk币安人生Low RiskSKYAILow RiskBLow RiskDOYRLow Risk4Low Risk

Would You Like a More Detailed Audit of CREPE?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit