Quantum Audit Logo
Launch App

Is GachaPad a Scam?

Early-stage security check — honeypot & rug-pull analysis

GachaPad GACHA
0xd5a0…3b84
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 3d old
Executive SummaryAI Copilot

The AgentTokenV4 contract is an ERC-20 token deployed as an EIP-1167 minimal clone, meaning its logic is fixed and not upgradeable. The contract exhibits a high degree of centralized control, with an owner/factory address possessing extensive privileges to modify core token parameters, including transfer rules, fees, and even individual token balances. The audit identified 8 findings, including 3 High, 3 Medium, and 2 Low severity issues, primarily related to these centralized controls and some technical implementation details.

3 High4 Medium2 Low5 Informational
! Early-stage analysis. This token has limited on-chain history (3d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$151.9K
Liquidity
$56.7K
Price
$0.0001776
Token Age
3d
Top 10 Holders
81.4%

Security Findings

High

Token transfers might fail silently without warning

CD-02The `_addInitialLiquidity` function performs an ERC-20 token transfer but does not check if the transfer was successful. If the underlying ERC-20 token's `transfer` function fails (e.g., due to reentrancy guards or insufficient allowance), the contract might not revert, leading to an inconsistent state where the tokens were not actually moved but the contract believes they were.
IssueThe `_addInitialLiquidity` function performs an ERC-20 token transfer but does not check if the transfer was successful. If the underlying ERC-20 token's `transfer` function fails (e.g., due to reentrancy guards or insufficient allowance), the contract might not revert, leading to an inconsistent state where the tokens were not actually moved but the contract believes they were.
FixToken holders should be aware that internal token movements might not always succeed as expected. The project team should ensure that all external ERC-20 `transfer` calls are wrapped with `require(success, "Transfer failed");` or use OpenZeppelin's `SafeERC20` library to prevent silent failures and maintain contract integrity.
StatusUnresolved
High

Owner/Factory can directly change anyone's token balance

CP-02The `addInitialLiquidity` function, callable by the owner or factory, can directly modify the token balances of any address. This means the owner/factory could burn tokens from your wallet or move them to another address without your consent.
IssueThe `addInitialLiquidity` function, callable by the owner or factory, can directly modify the token balances of any address. This means the owner/factory could burn tokens from your wallet or move them to another address without your consent.
FixToken holders should understand that the owner/factory has the power to alter their token holdings. The project team should implement strong governance around the use of this function, ideally requiring multi-signature approval for any such operations, and limit its scope to only necessary initial setup.
StatusUnresolved
High

Owner/Factory can redirect how token transfers work

CP-03The `setTaxAccountingAdapter` function, controlled by the owner or factory, allows them to change an external contract that the token relies on for transfer logic. If this adapter contract is replaced with a malicious one, it could alter how your tokens are transferred, potentially leading to unexpected fees, freezes, or even loss of funds during transfers.
IssueThe `setTaxAccountingAdapter` function, controlled by the owner or factory, allows them to change an external contract that the token relies on for transfer logic. If this adapter contract is replaced with a malicious one, it could alter how your tokens are transferred, potentially leading to unexpected fees, freezes, or even loss of funds during transfers.
FixToken holders should be aware that the owner/factory can fundamentally change transfer behavior. The project team should ensure the `taxAccountingAdapter` is set to a trusted, audited contract and consider making this address immutable or subject to a time-locked governance process after initial setup.
StatusUnresolved
Medium

Owner/Factory can enable or disable token transfers and sales

CP-05Functions like `setProjectTaxRates`, `addInitialLiquidity`, and `distributeTaxTokens`, controlled by the owner or factory, can activate or deactivate certain transfer rules or tax mechanisms. This means the owner/factory could potentially stop or allow transfers and sales based on these settings, impacting your ability to move your tokens.
IssueFunctions like `setProjectTaxRates`, `addInitialLiquidity`, and `distributeTaxTokens`, controlled by the owner or factory, can activate or deactivate certain transfer rules or tax mechanisms. This means the owner/factory could potentially stop or allow transfers and sales based on these settings, impacting your ability to move your tokens.
FixToken holders should be aware that transfer functionality can be altered. The project team should clearly communicate any changes to these settings and ensure they are used transparently and predictably.
StatusUnresolved
Medium

Owner/Factory can blacklist specific token holders

CP-06The `addBlacklistAddress` and `removeBlacklistAddress` functions, callable by the owner or factory, allow them to add or remove any address from a blacklist. If your address is blacklisted, you would be prevented from moving or selling your tokens.
IssueThe `addBlacklistAddress` and `removeBlacklistAddress` functions, callable by the owner or factory, allow them to add or remove any address from a blacklist. If your address is blacklisted, you would be prevented from moving or selling your tokens.
FixToken holders should understand the risk of being blacklisted. The project team should establish clear, public criteria for blacklisting and implement a robust, transparent governance process for such actions, ideally involving community input or multi-signature approval.
StatusUnresolved
Medium

Owner/Factory can change fees on token transfers

CP-07Functions such as `setProjectTaxRates`, `addInitialLiquidity`, `distributeTaxTokens`, and `setSwapThresholdBasisPoints`, controlled by the owner or factory, can modify the fees applied to token transfers (buy and sell taxes). This means the owner/factory could increase or decrease the cost of transacting with the token at any time.
IssueFunctions such as `setProjectTaxRates`, `addInitialLiquidity`, `distributeTaxTokens`, and `setSwapThresholdBasisPoints`, controlled by the owner or factory, can modify the fees applied to token transfers (buy and sell taxes). This means the owner/factory could increase or decrease the cost of transacting with the token at any time.
FixToken holders should be aware that transfer fees are subject to change by the owner/factory. The project team should clearly communicate any fee adjustments and provide a rationale for such changes to maintain trust.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 4 address(es) other than the owner/deployer. One of them — a wallet, 0xfe48…5312 — holds 83.2% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 4 address(es) other than the owner/deployer. One of them — a wallet, 0xfe48…5312 — holds 83.2% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Low

Potential for small rounding losses in tax calculations

CD-01The `_autoSwap` function, which handles tax calculations, performs division before multiplication. In Solidity, integer division truncates decimals, which can lead to minor rounding losses in calculations, potentially affecting the exact amount of tax collected or tokens swapped.
IssueThe `_autoSwap` function, which handles tax calculations, performs division before multiplication. In Solidity, integer division truncates decimals, which can lead to minor rounding losses in calculations, potentially affecting the exact amount of tax collected or tokens swapped.
FixWhile often minor, this can lead to small discrepancies. The project team should consider reordering operations to perform multiplication before division where possible to minimize rounding errors and ensure precise calculations.
StatusUnresolved
Low

Owner/Factory can change limits on token transfers or wallet sizes

CP-08The `addInitialLiquidity` function, controlled by the owner or factory, can modify numeric limits that affect token transfers, such as thresholds or other parameters. This could potentially impact the maximum amount you can transfer in a single transaction or hold in your wallet.
IssueThe `addInitialLiquidity` function, controlled by the owner or factory, can modify numeric limits that affect token transfers, such as thresholds or other parameters. This could potentially impact the maximum amount you can transfer in a single transaction or hold in your wallet.
FixToken holders should be aware that transfer limits can be adjusted. The project team should ensure that any changes to these limits are communicated transparently and do not unduly restrict legitimate token usage.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 81.4% of supply. What remains: 21.1% in wallets, 60.3% in other contracts. The deployer/owner wallet itself holds 14.2%. 480 holders in total.
IssueThe ten largest holders own 81.4% of supply. What remains: 21.1% in wallets, 60.3% in other contracts. The deployer/owner wallet itself holds 14.2%. 480 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as GachaPad (GACHA). 480 holders.
IssueListed on CoinGecko as GachaPad (GACHA). 480 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $59K (DexScreener, all pools). 24h trading volume $108K (CoinGecko, all markets, daily snapshot). 24h trading volume $156K (DexScreener, all pools).
IssueLiquidity $59K (DexScreener, all pools). 24h trading volume $108K (CoinGecko, all markets, daily snapshot). 24h trading volume $156K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: a single wallet (EOA). Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $59K of DEX liquidity across 4 pools. Launch: 3 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: a single wallet (EOA). Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $59K of DEX liquidity across 4 pools. Launch: 3 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — 3 days of market history

QA-RECENTThe token's oldest DEX pool is 3 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 3 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

The AgentTokenV4 contract implements standard ERC-20 functionality. The code security analysis (7.2) revealed several issues, such as the `_addInitialLiquidity` function directly manipulating user balances (CP-02) and an unchecked ERC-20 transfer in `_addInitialLiquidity` (CD-02). Access control (7.3) is heavily centralized, with an `ownerorfactory` role controlling critical functions like `setTaxAccountingAdapter` (CP-03), which can redirect token logic, and `addBlacklistAddress` (CP-06), which can block users. The contract also has a division before multiplication issue in `_autoSwap` (CD-01).

GovernanceHigh1/10

The economic model (7.4) and governance (7.5) of the AgentTokenV4 are highly centralized, with significant power vested in the `ownerorfactory` address. This role can unilaterally change project tax rates (`setProjectTaxRates`), affecting buy and sell taxes (CP-07), and can enable/disable tax collection (CP-05). Furthermore, the `ownerorfactory` can blacklist addresses (`addBlacklistAddress`), preventing them from transferring tokens (CP-06), and can change transfer thresholds (`setSwapThresholdBasisPoints`) (CP-07). The ability to directly modify `_balances` via `addInitialLiquidity` (CP-02) presents a critical economic risk, as tokens can be moved or burned from any holder.

UpgradesMedium6/10

The AgentTokenV4 contract is deployed as an EIP-1167 minimal clone, which means its implementation is fixed and cannot be upgraded. This architecture (7.1) eliminates risks associated with upgradeability (7.7), such as proxy misconfigurations or malicious upgrade proposals. Token holders can be assured that the contract's logic will not change post-deployment.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not UpgradeablePass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

21.1% in wallets60.3% in contracts
Effective Concentration45.2%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder83.2%
Top-3 Unlocked98.5%

Key Addresses

Deployer
0xab03…8c77
Unlocked LP Held By
0xfe48…53120x8160…287d0x3e44…b36c0x9ab3…6178

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Owner can change any holder's balance (seize or credit tokens)
  • A privileged address can replace a contract every transfer depends on
  • A privileged address controls a switch that decides whether transfers go through
  • Owner can blacklist or freeze individual holders
  • Owner can change the buy/sell tax
  • A privileged address can change transfer or wallet limits
  • Liquidity NOT locked (100% of the pool; this pool is 96% of DEX liquidity) — held by independent providers — market-depth risk
  • Top-10 concentration > 30% (81.4% total → 45.2% effective; 21.1% in EOAs, 60.3% in contracts)
  • Code: Potential for small rounding losses in tax calculations (Low, static analysis)
  • Code: Token transfers might fail silently without warning (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

The White Wolf (WOLF)High RiskSport.fun (FUN)High RiskREPPOHigh RiskChipHigh Riskdefi-nativeHigh RiskSIBYL by Virtuals (SIBYL)High Risk

Would You Like a More Detailed Audit of GachaPad?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit