Quantum Audit Logo

Is Fias Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Fias FIAS
0x8e4f…5585
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The Fias contract is an upgradeable ERC-20 token. It implements standard token functionalities including `transfer`, `transferFrom`, and `approve`. A key feature is the `multiTransfer` function, which allows sending tokens to multiple recipients in a single transaction. The audit identified one high-severity finding related to the unchecked return value of `transferFrom` calls within the `multiTransfer` function, which could lead to misleading success if the underlying `transferFrom` behavior were to change.

1 High1 Medium4 Informational
Volume 24h
$77.6K
Liquidity
$37.9K
Price
$0.0006103
Token Age
1y
Top 10 Holders
69.8%

Security Findings

High

Potential for misleading success in multi-transfers if `transferFrom` behavior changes.

CD-01The `multiTransfer` function, which allows a user to send Fias tokens to multiple recipients in a single transaction, calls `this.transferFrom` for each individual transfer. While the current `ERC20Upgradeable` implementation of `transferFrom` will revert the entire transaction if any individual transfer fails (e.g., due to insufficient balance), it is a best practice to explicitly check the boolean return value of external calls, especially for ERC-20 `transfer` and `transferFrom` functions. If the underlying `transferFrom` implementation were ever changed or overridden to return `false` on failure instead of reverting, the `multiTransfer` function would not detect these individual failure…
IssueThe `multiTransfer` function, which allows a user to send Fias tokens to multiple recipients in a single transaction, calls `this.transferFrom` for each individual transfer. While the current `ERC20Upgradeable` implementation of `transferFrom` will revert the entire transaction if any individual transfer fails (e.g., due to insufficient balance), it is a best practice to explicitly check the boolean return value of external calls, especially for ERC-20 `transfer` and `transferFrom` functions. If the underlying `transferFrom` implementation were ever changed or overridden to return `false` on failure instead of reverting, the `multiTransfer` function would not detect these individual failure…
FixTo enhance robustness and guard against future changes in `transferFrom` behavior, it is recommended to explicitly check the boolean return value of `this.transferFrom(msg.sender, recipients[i], amounts[i])` within the `multiTransfer` function. If a transfer returns `false`, the function should either revert the entire transaction or log the failure for specific recipients, ensuring transparent and reliable multi-transfers.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a wallet, 0x657c…6c83 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a wallet, 0x657c…6c83 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 69.8% of supply. Of that, 14.3% burned, 5.6% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 49.1% in wallets, 0.8% in other contracts. 2,306 holders in total.
IssueThe ten largest holders own 69.8% of supply. Of that, 14.3% burned, 5.6% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 49.1% in wallets, 0.8% in other contracts. 2,306 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as FIAS (FIAS), rank #3351. 2,306 holders.
IssueListed on CoinGecko as FIAS (FIAS), rank #3351. 2,306 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $38K (DexScreener, all pools). 24h trading volume $36K (CoinGecko, all markets, daily snapshot). 24h trading volume $78K (DexScreener, all pools).
IssueLiquidity $38K (DexScreener, all pools). 24h trading volume $36K (CoinGecko, all markets, daily snapshot). 24h trading volume $78K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner key. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $38K of DEX liquidity across 1 pools. Launch: 652 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner key. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $38K of DEX liquidity across 1 pools. Launch: 652 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The Fias contract is an ERC-20 token designed for upgradeability, inheriting from `ERC20Upgradeable` and `Initializable`. It provides standard token functionalities such as `transfer`, `transferFrom`, and `balanceOf`. A notable feature is the `multiTransfer` function, which enables batch token distribution. While the core ERC-20 functions (7.1 Architecture) appear correctly implemented, a high-severity issue (7.2 Code Security) was identified in `multiTransfer` where the return value of `this.transferFrom` is not explicitly checked, potentially leading to silent failures under certain conditions. Access control (7.3 Access Control) is standard for an ERC-20 token, with no additional privileged roles beyond the token owner for `multiTransfer`.

GovernanceHigh1/10

The Fias contract implements a standard ERC-20 token economic model (7.4 Economic), with no complex tokenomics, staking, or lending mechanisms. The `multiTransfer` function facilitates token distribution but does not introduce new economic risks beyond standard token transfers. There are no explicit governance mechanisms (7.5 Governance) within the contract itself, meaning control over the token's core parameters is limited to the standard ERC-20 functionalities and potential upgradeability. External interactions (7.6 External) are limited to standard ERC-20 approvals and transfers.

UpgradesMedium6/10

The Fias contract is designed as an upgradeable token, inheriting from `ERC20Upgradeable` and `Initializable` (7.7 Upgrades). This design allows for future enhancements or bug fixes without deploying a new token contract, typically managed through a proxy pattern. The provided code appears to be an implementation contract. No specific upgrade-related vulnerabilities were identified in the provided source code, indicating a standard and secure approach to upgradeability. Operational aspects (7.8 Operations) are standard for an ERC-20 token.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

49.1% in wallets0.8% in contracts
Effective Concentration49.4%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x83b3…66c5
Unlocked LP Held By
0x657c…6c83

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — the owner keeps admin functions
  • Liquidity NOT locked (100% of the pool) — held by independent providers — market-depth risk
  • Liquidity < $50k ($37,925 across 1 pairs — thin market)
  • Top-10 concentration > 30% (69.8% total → 49.4% effective; 49.1% in EOAs, 0.8% in contracts; 19.9% burned, locked or in pools excluded)
  • Code: Potential for misleading success in multi-transfers if `transferFrom` behavior changes. (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Sustainable Aviation Fuel (SAF)Medium RiskArbitrum (ARB)Medium RiskHelix Token (HLX)Medium RiskEuler (EUL)Medium RiskPaxos Gold (PAXG)Medium RiskIlluvium (ILV)Medium Risk

Would You Like a More Detailed Audit of Fias?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit