On-chain security analysis — is it a scam or legit?
Is this your token? Publish your own audit on this page →
0x7e2a…b71a
The GoldfishToken contract, an upgradeable ERC-20, exhibits a high degree of centralization, particularly concerning the `DEFAULT_ADMIN_ROLE`. A critical finding highlights the `forceTransfer` function, which acts as a backdoor allowing the admin to move any user's tokens. The absence of multi-signature protection or time-locks for critical operations further exacerbates these risks. While the contract leverages well-audited OpenZeppelin libraries for core functionalities and implements granular access control for specific actions, the overarching administrative power presents significant security and economic concerns.
Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.
The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.
0xd22d…c2f40x946e…58b40x4236…aba80xb7f9…27880xd5d1…69e80x2c93…d23b0xbef7…9ea30xe30a…7c2d0x804f…deb10xda56…23f40xf41b…2919No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.
Get Detailed Audit