Quantum Audit Logo

Is Gstock a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

Gstock GSTOCK
0xcafd…9e20
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record New Launch · 4d old
Executive SummaryAI Copilot

The GeniusLauncherToken contract is a standard ERC20 token with burnable functionality, leveraging battle-tested OpenZeppelin libraries. The contract is simple, primarily focused on token creation and immutable metadata storage. No critical or high-severity vulnerabilities were identified. Informational findings highlight design choices regarding metadata immutability and centralized initial supply distribution. A low-severity finding notes the absence of emergency control mechanisms.

1 Low2 Informational
! Early-stage analysis. This token has limited on-chain history (4d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$3.84M
Liquidity
$491.5K
Price
$0.02889
Token Age
4d
Top 10 Holders
19.1%

Security Findings

Low

Lack of Emergency Control Mechanisms

L-01The `GeniusLauncherToken` contract, being a standard ERC20, does not include common emergency control features such as `pause` or `blacklist` functionality. In the event of a critical vulnerability, exploit, or regulatory requirement, there would be no built-in mechanism to halt transfers or restrict malicious actors. While this promotes decentralization, it removes a potential safety net for unforeseen circumstances.
IssueThe `GeniusLauncherToken` contract, being a standard ERC20, does not include common emergency control features such as `pause` or `blacklist` functionality. In the event of a critical vulnerability, exploit, or regulatory requirement, there would be no built-in mechanism to halt transfers or restrict malicious actors. While this promotes decentralization, it removes a potential safety net for unforeseen circumstances.
FixConsider implementing an `Ownable` or `AccessControl` pattern to allow a designated role (e.g., `pauser`) to pause token transfers in emergencies. This adds a layer of protection, though it introduces a point of centralization. If decentralization is paramount, this finding can be accepted as a design choice.
StatusUnresolved
Info

Immutability of Token Metadata

I-01The token's metadata, including `logo`, `description`, and the `_socials` struct, is set exclusively in the constructor and stored as immutable state variables. This means that once the contract is deployed, this information cannot be updated or modified. Any changes to project branding, social links, or descriptions would necessitate the deployment of an entirely new token contract.
IssueThe token's metadata, including `logo`, `description`, and the `_socials` struct, is set exclusively in the constructor and stored as immutable state variables. This means that once the contract is deployed, this information cannot be updated or modified. Any changes to project branding, social links, or descriptions would necessitate the deployment of an entirely new token contract.
FixEnsure that the project team is fully aware of the immutable nature of this metadata. If future updates are anticipated, consider a design where metadata is stored in an upgradeable contract or an off-chain registry referenced by a mutable URI, though this adds complexity and external dependencies.
StatusUnresolved
Info

Centralized Initial Supply Distribution

I-02The entire initial token supply (`supply_`) is minted to the `curve_` address during the contract's deployment. This design choice makes the `curve_` address a single point of control for the initial distribution and management of the token supply. The security and operational integrity of this specific address are paramount for the token's initial launch and subsequent distribution strategy.
IssueThe entire initial token supply (`supply_`) is minted to the `curve_` address during the contract's deployment. This design choice makes the `curve_` address a single point of control for the initial distribution and management of the token supply. The security and operational integrity of this specific address are paramount for the token's initial launch and subsequent distribution strategy.
FixEnsure that the `curve_` address is secured with the highest level of protection, such as a multi-signature wallet, hardware wallet, or a robust access control system. Implement strict operational procedures for managing this address to mitigate risks associated with private key compromise or unauthorized access.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The technical architecture (7.1) is straightforward, implementing a standard ERC20 token with burn functionality using OpenZeppelin contracts, which are widely audited and secure. Code security (7.2) is robust, with no identified reentrancy, integer overflows, or other common EVM vulnerabilities. Access control (7.3) is minimal, as expected for a basic token, with no privileged roles beyond the initial constructor setup. The contract includes a `ZeroAddress()` check in the constructor, enhancing robustness.

GovernanceMedium4/10

The economic model (7.4) is that of a simple ERC20 token, with the entire initial supply minted to a designated 'curve' address. This centralizes initial distribution, making the security of the 'curve' address critical. Governance (7.5) is not directly implemented within this token contract, as it lacks upgradeability or configurable parameters. The token's metadata (logo, description, socials) is immutable post-deployment, a design choice that ensures consistency but prevents updates without a new deployment.

UpgradesMedium6/10

The GeniusLauncherToken contract is not designed to be upgradeable (7.7). It does not implement any proxy patterns (e.g., UUPS, Transparent). This eliminates risks associated with upgrade mechanisms, such as proxy misconfigurations or logic errors during upgrades, but also means any future changes to the token's core logic or metadata would require a new contract deployment.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

2.4% in wallets16.6% in contracts
Effective Concentration9.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder16.4%
Top-3 Unlocked30.0%

Key Addresses

Deployer
0x4f9d…cb8d
Unlocked LP Held By
0xb969…15f40xb653…9ef00xfbd3…f0a90x214a…0b300x05dd…489d0x146e…00310x7682…2b520xdabb…e22f0xa5df…74300xe44b…f850

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Token age < 7 days (early, volatile)
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Cubus Store Coin (CSC)Low RiskLiability Vortex (LVTR)Low RiskARIA.AI (ARIA)Low RiskWorld of Dypians (WOD)Low RiskFrippyLow RiskGiggle Mascot (MAX)Low Risk

Would You Like a More Detailed Audit of Gstock?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit