Quantum Audit Logo

Is GUA Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

GUA GUA
0xa5c8…69be
BNB Chain Not verifiedLast checked 3d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The GUA token contract is a standard ERC20 implementation, inheriting from OpenZeppelin's battle-tested contracts. It features a fixed supply minted to a single address upon deployment. The contract's simplicity and reliance on well-audited libraries contribute to a low overall risk profile, with the primary consideration being the centralized initial distribution of tokens.

1 Informational
Volume 24h
$220.6900
Liquidity
$7.6K
Price
$0.03823
Token Age
8mo
Top 10 Holders
93.2%

Security Findings

Info

Centralized Initial Token Distribution

I-01The contract's constructor mints the entire token supply (1,000,000,000 * 1e18 GUA) to a single `receiver` address. This design choice means that 100% of the token supply is initially controlled by one address (7.4 Economic, 7.8 Operations). While not a direct code vulnerability, this creates a significant centralization point. If the `receiver` address is compromised, or if the entity controlling it acts maliciously, the entire token supply could be at risk or subject to unilateral actions.
IssueThe contract's constructor mints the entire token supply (1,000,000,000 * 1e18 GUA) to a single `receiver` address. This design choice means that 100% of the token supply is initially controlled by one address (7.4 Economic, 7.8 Operations). While not a direct code vulnerability, this creates a significant centralization point. If the `receiver` address is compromised, or if the entity controlling it acts maliciously, the entire token supply could be at risk or subject to unilateral actions.
FixAcknowledge and manage the implications of this centralized distribution. Ensure the `receiver` address is a highly secured multi-signature wallet or a cold storage address with robust access control and operational security procedures. Consider a phased distribution strategy or a vesting schedule if broader decentralization of the token supply is desired in the future.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The GUA contract is a minimal ERC20 implementation, primarily leveraging OpenZeppelin's secure and battle-tested libraries (7.2 Code Security). It introduces no complex custom logic, external calls, or intricate state transitions, significantly reducing the attack surface. Standard ERC20 functions like `transfer` and `approve` are implemented safely. No reentrancy or integer overflow/underflow vulnerabilities were identified due to Solidity 0.8+ default checks and OpenZeppelin's careful use of `unchecked` blocks.

GovernanceHigh1/10

The economic model of the GUA token is straightforward, with a fixed total supply minted entirely to a single `receiver` address during deployment (7.4 Economic). There are no administrative functions for minting, burning (beyond standard internal `_burn`), pausing, or blacklisting post-deployment, which minimizes governance risk (7.5 Governance). The primary economic consideration is the initial centralized distribution of the entire token supply, which places significant control with one entity.

UpgradesMedium6/10

The GUA contract is not designed to be upgradeable (7.7 Upgrades). It is deployed as a standalone, immutable contract. This eliminates risks associated with upgrade mechanisms, such as proxy implementation bugs or insecure upgrade paths, contributing to a stable and predictable contract lifecycle.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

4.7% in wallets88.5% in contracts
Effective Concentration40.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xa89f…b7bb
Unlocked LP Held By
0x1866…a4970xfacd…2a14

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 30% (93.2% total → 40.1% effective; 4.7% in EOAs, 88.5% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $10k ($7,742 across 2 pairs — easily drained)
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 99% of DEX liquidity)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

TrenchesStarterPack (战壕入门包)Medium RiskChainbase Token (C)Medium RiskmemestockMedium RiskGiggle Cat (NIANNIAN)Medium RiskBabySharkMedium Risk吉祥马Medium Risk

Would You Like a More Detailed Audit of GUA?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit