Quantum Audit Logo

Is EtherStreet a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

EtherStreet STREET
0x2b1d…eac1
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record New Launch · 16h old
Executive SummaryAI Copilot

The RobinVistaToken contract, deployed as an upgradeable proxy, exhibits a critical initialization vulnerability. The `initialize` function, intended for one-time setup, can be called by any address due to the proxy's storage being uninitialized for the `factory` variable. This allows an attacker to front-run the legitimate initializer, seize control of the token's initial supply, and dictate critical pool parameters. This severe flaw undermines the token's integrity and security.

1 Critical1 Medium1 Informational
! Early-stage analysis. This token has limited on-chain history (16h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$630.4K
Liquidity
$68.7K
Price
$0.0002746
Token Age
16h
Top 10 Holders
45.9%

Security Findings

Critical

Critical: Proxy Initialization Vulnerability

C-01The `RobinVistaToken` contract is intended to be deployed behind an upgradeable proxy. The `initialize` function is designed for one-time setup, setting the `factory` address, token metadata, and minting the initial supply. However, the constructor of the implementation contract sets `factory = address(0xdead)`. In a proxy setup, the constructor of the implementation contract is called only once upon its deployment, not when the proxy is initialized. Therefore, when the `initialize` function is called through the proxy, the `factory` state variable in the proxy's storage will initially be `address(0)`. This means the `if (factory != address(0)) revert AlreadyInitialized();` check will pass…
IssueThe `RobinVistaToken` contract is intended to be deployed behind an upgradeable proxy. The `initialize` function is designed for one-time setup, setting the `factory` address, token metadata, and minting the initial supply. However, the constructor of the implementation contract sets `factory = address(0xdead)`. In a proxy setup, the constructor of the implementation contract is called only once upon its deployment, not when the proxy is initialized. Therefore, when the `initialize` function is called through the proxy, the `factory` state variable in the proxy's storage will initially be `address(0)`. This means the `if (factory != address(0)) revert AlreadyInitialized();` check will pass…
FixImplement a secure initialization pattern. For UUPS proxies, use the `UUPSUpgradeable` base contract and its `_disableInitializers()` in the constructor. For Transparent proxies, ensure the `initialize` function is protected by an `initializer` modifier and called only once by a trusted address (e.g., the proxy admin) immediately after proxy deployment. The constructor of the implementation contract should not set any state variables that are meant to be initialized via the `initialize` functio…
StatusUnresolved
Medium

Medium: Centralized Control Over Pool Parameters

M-01The `setPool` function allows the `factory` address to set the `poolId` and `baseToken` once. While this is an intended design choice for initial setup, it represents a single point of control. If the `factory`'s private key is compromised (especially given the proxy initialization vulnerability), an attacker could set these critical parameters to malicious values, potentially disrupting the associated pool or ecosystem. The `deployer` address is also stored but has no associated privileges.
IssueThe `setPool` function allows the `factory` address to set the `poolId` and `baseToken` once. While this is an intended design choice for initial setup, it represents a single point of control. If the `factory`'s private key is compromised (especially given the proxy initialization vulnerability), an attacker could set these critical parameters to malicious values, potentially disrupting the associated pool or ecosystem. The `deployer` address is also stored but has no associated privileges.
FixConsider adding a timelock for the `setPool` function if the `factory` is a single EOA, or transition control to a multi-signature wallet or a robust governance mechanism after initial setup. This would provide a delay for critical parameter changes, allowing for community review or intervention in case of a compromised key.
StatusUnresolved
Info

Informational: Unused ERC20 Base Variables

I-01The `RobinVistaToken` contract inherits from OpenZeppelin's `ERC20` contract. The `ERC20` base contract has private state variables `_name` and `_symbol` which are initialized in its constructor. However, `RobinVistaToken` overrides the `name()` and `symbol()` functions to return its own private `_tokenName` and `_tokenSymbol` variables, which are set during the `initialize` call. As the `ERC20` constructor is not called on the proxy's storage, the base `_name` and `_symbol` variables will remain uninitialized (empty strings) in the proxy's storage, effectively wasting storage slots and potentially causing confusion.
IssueThe `RobinVistaToken` contract inherits from OpenZeppelin's `ERC20` contract. The `ERC20` base contract has private state variables `_name` and `_symbol` which are initialized in its constructor. However, `RobinVistaToken` overrides the `name()` and `symbol()` functions to return its own private `_tokenName` and `_tokenSymbol` variables, which are set during the `initialize` call. As the `ERC20` constructor is not called on the proxy's storage, the base `_name` and `_symbol` variables will remain uninitialized (empty strings) in the proxy's storage, effectively wasting storage slots and potentially causing confusion.
FixTo optimize storage and improve clarity, consider removing the `_tokenName` and `_tokenSymbol` variables from `RobinVistaToken` and instead directly initialize the `_name` and `_symbol` variables of the `ERC20` base contract within the `initialize` function. This would require making `_name` and `_symbol` in the base `ERC20` contract `internal` or providing internal setters.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The contract is a standard ERC20 token leveraging OpenZeppelin's robust base implementation, which generally provides strong code security against common vulnerabilities like integer overflows (7.2 Code Security). However, a critical access control flaw exists in the `initialize` function (7.3 Access Control). The `factory` variable, which guards initialization, is not properly set in the proxy's storage, allowing any address to call `initialize` and become the token's 'factory', minting the initial supply to themselves. This severely compromises the token's initial state and security.

GovernanceHigh1/10

The contract design grants significant control to the `factory` address, which is responsible for initial token minting and setting critical `poolId` and `baseToken` parameters (7.4 Economic). While this centralization is intended, the critical proxy initialization vulnerability means an attacker could become this `factory`, gaining control over the initial token distribution and potentially manipulating associated pool settings. There are no explicit governance mechanisms (7.5 Governance) beyond the `factory`'s initial setup role.

UpgradesMedium5/10

The contract is designed as an upgradeable proxy implementation (7.7 Upgrades). A critical vulnerability arises from the constructor setting `factory = address(0xdead)`, which only affects the implementation contract's storage, not the proxy's. Consequently, the `initialize` function, which sets the `factory` in the proxy's storage, can be front-run by any address. This compromises the initial setup and future upgrade safety, as the legitimate owner may not be able to properly initialize the contract or manage subsequent upgrades securely.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

14.5% in wallets31.5% in contracts
Effective Concentration27.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xdf76…a6a2
Unlocked LP Held By
0x996d…ad77

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 20% (45.9% total → 27.1% effective; 14.5% in EOAs, 31.5% in contracts — mild)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 95% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 95% of DEX liquidity)
  • Token age < 24h (brand new — bot activity, unproven)
  • 1 Critical finding(s) from audit
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

SEIHigh RiskDolomite (DOLO)High RiskRedstone (RED)High RiskPinLink (PIN)High RiskFuse Cat (FUSECAT)High RiskSPACE ID (ID)High Risk

Would You Like a More Detailed Audit of EtherStreet?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit