Quantum Audit Logo

Is FTT Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

FTT FTX TOKEN
0x50d1…a4c9
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 1d ago 1 audit on record
Executive SummaryAI Copilot

The FTT token contract implements a standard ERC20 token with burnable functionality, utilizing SafeMath for arithmetic operations. The contract is straightforward, lacking complex external interactions or advanced DeFi mechanisms. Key strengths include the use of SafeMath to prevent integer overflows/underflows and adherence to the ERC20 standard. Identified issues primarily relate to the initial centralized token distribution and the inherent ERC20 approve race condition, which are common considerations for such token designs.

1 Medium1 Low1 Informational
Volume 24h
$1.01M
Liquidity
$132.2K
Price
$0.2836
Token Age
5y
Top 10 Holders
93.1%

Security Findings

Medium

Centralized Initial Token Supply

M-01The `FTT` contract's constructor mints the entire initial supply of 350,000,000 FTT tokens to `msg.sender` (the contract deployer). This design choice centralizes the initial token distribution, giving the deployer significant control over the token's supply and potential market influence. While there are no further minting capabilities, the initial concentration of tokens represents a single point of control.
IssueThe `FTT` contract's constructor mints the entire initial supply of 350,000,000 FTT tokens to `msg.sender` (the contract deployer). This design choice centralizes the initial token distribution, giving the deployer significant control over the token's supply and potential market influence. While there are no further minting capabilities, the initial concentration of tokens represents a single point of control.
FixEnsure that the initial distribution strategy is clearly communicated to the community. If decentralization is a long-term goal, consider implementing a phased distribution or vesting schedule for the initial supply to reduce immediate centralization risks. Implement robust operational security for the address holding the initial supply.
StatusUnresolved
Low

ERC20 `approve` Race Condition

L-01The standard ERC20 `approve` function is susceptible to a known race condition. If a user calls `approve(spender, newAmount)` while a `spender` is concurrently trying to spend the `oldAmount`, the `spender` might be able to spend both `oldAmount` and `newAmount` if the `newAmount` is greater than `oldAmount`. While `increaseAllowance` and `decreaseAllowance` functions are provided, the direct `approve` function remains available.
IssueThe standard ERC20 `approve` function is susceptible to a known race condition. If a user calls `approve(spender, newAmount)` while a `spender` is concurrently trying to spend the `oldAmount`, the `spender` might be able to spend both `oldAmount` and `newAmount` if the `newAmount` is greater than `oldAmount`. While `increaseAllowance` and `decreaseAllowance` functions are provided, the direct `approve` function remains available.
FixEducate users to always set the allowance to zero (`approve(spender, 0)`) before setting a new non-zero allowance, or preferably, to use `increaseAllowance` and `decreaseAllowance` functions which are designed to prevent this specific race condition. No code change is strictly required for this standard ERC20 behavior, but user education is key.
StatusUnresolved
Info

Older Solidity Compiler Version

I-01The contract is compiled using Solidity version `^0.5.2`. While this version is functional, it is an older release. Newer Solidity versions (e.g., 0.8.x) include various language improvements, optimizer enhancements, and additional security checks (like default checked arithmetic, which SafeMath already addresses here).
IssueThe contract is compiled using Solidity version `^0.5.2`. While this version is functional, it is an older release. Newer Solidity versions (e.g., 0.8.x) include various language improvements, optimizer enhancements, and additional security checks (like default checked arithmetic, which SafeMath already addresses here).
FixFor future contract deployments or significant updates, consider migrating to a more recent and actively maintained Solidity compiler version (e.g., 0.8.x). This allows leveraging the latest language features, security improvements, and compiler optimizations.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The technical implementation of the FTT token is robust for its intended purpose (7.2 Code Security). It correctly implements the ERC20 standard and incorporates SafeMath for all arithmetic operations, effectively mitigating integer overflow/underflow vulnerabilities. The contract avoids complex external calls, reducing reentrancy risks. A minor technical consideration is the standard ERC20 `approve` function's susceptibility to a race condition (7.2 Code Security), though `increaseAllowance` and `decreaseAllowance` are provided to offer safer alternatives.

GovernanceHigh1/10

The economic model involves an initial mint of 350 million FTT tokens directly to the contract deployer (7.4 Economic). This centralized initial distribution grants significant control over the token supply to a single address, which could pose a risk if not managed transparently. There are no further minting capabilities, which limits future supply inflation. The contract lacks explicit governance mechanisms (7.5 Governance), relying on the standard ERC20 transfer functions.

UpgradesLow7/10

The FTT token contract is not designed to be upgradeable (7.7 Upgrades). It does not implement any proxy patterns (e.g., UUPS, Transparent, Beacon). This eliminates upgrade-related risks such as proxy misconfigurations or logic bugs introduced during upgrades, but also means the contract's logic cannot be modified post-deployment.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

71.7% in wallets21.4% in contracts
Effective Concentration80.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.3%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x7725…cf47
Unlocked LP Held By
0xf51a…cf7f0x88ad…56710x025f…b7fc0xb50e…5fec0x0e9a…897c0x280a…207f0x1d2a…158c0x7f42…99da0x5ad6…e277

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 70% (93.1% total → 80.3% effective; 71.7% in EOAs, 21.4% in contracts — extreme)
  • LP top1 unlocked holder = 99.3% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP claimed locked but only 0.0% actually locked
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

FOXHigh RiskStorjToken (STORJ)High RiskMorphoHigh RiskUniswap (UNI)High RiskBeamHigh RiskSuperVerse (SUPER)High Risk

Would You Like a More Detailed Audit of FTT?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit