Quantum Audit Logo

Is Gyndore a Scam?

Early-stage security check — honeypot & rug-pull analysis

Gyndore GYND
0x6cd1…9ea1
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 22h old
Executive SummaryAI Copilot

The GyndToken contract is a standard ERC-20 token with ERC-20 Permit functionality, built upon battle-tested OpenZeppelin libraries. The contract's logic is minimal and straightforward, primarily delegating core token functionalities to its inherited components. The audit identified no critical or high-severity vulnerabilities. A low-severity finding was noted regarding an incomplete code snippet for the `permit` function, which hinders full verification of that specific implementation detail. Informational findings highlight the reliance on OpenZeppelin and the fixed initial supply model.

1 Low2 Informational
! Early-stage analysis. This token has limited on-chain history (22h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$580.8K
Liquidity
$104.6K
Price
$0.07451
Token Age
22h
Top 10 Holders
92.8%

Security Findings

Low

Incomplete `ERC20Permit` Code Snippet

L-01The provided source code for the `permit` function within the `ERC20Permit` contract is truncated. Specifically, the critical `if (signer != owner)` check, which is essential for validating the signature's authenticity against the intended owner, is cut off. While it is assumed that the full, correct OpenZeppelin implementation is used, an incomplete code snippet prevents a thorough review of the entire function's logic, particularly the security-critical signature verification and signer validation steps.
IssueThe provided source code for the `permit` function within the `ERC20Permit` contract is truncated. Specifically, the critical `if (signer != owner)` check, which is essential for validating the signature's authenticity against the intended owner, is cut off. While it is assumed that the full, correct OpenZeppelin implementation is used, an incomplete code snippet prevents a thorough review of the entire function's logic, particularly the security-critical signature verification and signer validation steps.
FixEnsure that the complete and verified source code for all inherited contracts, especially security-sensitive functions like `permit`, is available for auditing and public transparency. This allows for a comprehensive review of the entire logic and confirms that no unintended modifications or omissions exist.
StatusUnresolved
Info

Standard OpenZeppelin Implementation

I-01The `GyndToken` contract is a straightforward implementation of ERC-20 and ERC-20 Permit functionality, built upon battle-tested OpenZeppelin contracts. This approach significantly reduces the risk of common vulnerabilities often found in custom token implementations, as OpenZeppelin libraries undergo extensive audits and community review.
IssueThe `GyndToken` contract is a straightforward implementation of ERC-20 and ERC-20 Permit functionality, built upon battle-tested OpenZeppelin contracts. This approach significantly reduces the risk of common vulnerabilities often found in custom token implementations, as OpenZeppelin libraries undergo extensive audits and community review.
FixContinue to leverage well-audited and maintained libraries like OpenZeppelin. Ensure that the specific versions of OpenZeppelin contracts used are up-to-date and free from known vulnerabilities.
StatusUnresolved
Info

Fixed Initial Supply and Distribution

I-02The token's entire supply of 10,000,000 tokens is minted to a single recipient address during contract deployment. This is a standard and transparent distribution model for a fixed-supply token, clearly defining the initial state of token ownership. It implies a centralized initial control over the total supply by the recipient.
IssueThe token's entire supply of 10,000,000 tokens is minted to a single recipient address during contract deployment. This is a standard and transparent distribution model for a fixed-supply token, clearly defining the initial state of token ownership. It implies a centralized initial control over the total supply by the recipient.
FixDocument the purpose and implications of the initial supply distribution for transparency to token holders and the community. This is a design choice and not a vulnerability.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The technical architecture (7.1) is robust, leveraging OpenZeppelin's ERC-20 and ERC-20 Permit implementations, which are widely audited and secure. Code security (7.2) benefits from these well-vetted libraries, mitigating common vulnerabilities like reentrancy and integer overflows through built-in checks and `unchecked` blocks. Access control (7.3) is limited to standard ERC-20 permissions, with no additional administrative roles, simplifying the attack surface. A minor concern (L-01) is the truncated `permit` function snippet, preventing full verification of its implementation.

GovernanceHigh1/10

The economic model (7.4) of the GyndToken is simple: a fixed supply of 10,000,000 tokens is minted to a single recipient during deployment. This transparent initial distribution is a clear design choice. There are no complex economic incentives, staking mechanisms, or oracle dependencies, which minimizes economic attack vectors. Governance (7.5) is not implemented within this token contract, as it functions purely as a standard ERC-20 asset without administrative control beyond its initial deployment.

UpgradesMedium6/10

The GyndToken contract is not designed to be upgradeable (7.7), as it does not implement any proxy patterns. This eliminates the complexities and potential risks associated with upgrade mechanisms, such as storage collisions or improper initialization. The contract is immutable once deployed, providing a fixed and predictable operational environment (7.8). This design choice simplifies long-term security considerations by removing the need for upgrade safety audits.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

82.8% in wallets10.0% in contracts
Effective Concentration86.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder42.3%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x2bbf…57c9
Unlocked LP Held By
0x0c0e…f1020xd537…9ce70x233c…2a18

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 70% (92.8% total → 86.8% effective; 82.8% in EOAs, 10.0% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 74% of DEX liquidity)
  • Token age < 24h (brand new — bot activity, unproven)
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

HOMEHigh RiskCTRHigh RiskDegenHigh RiskVenice Token (VVV)High RiskAUTONOMOPOLY (AUTONO)High RiskSolana (SOL)High Risk

Would You Like a More Detailed Audit of Gyndore?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit