Quantum Audit Logo

Is Helix Token Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Helix Token HLX
0x28d4…9525
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 2 audits on record
Executive SummaryAI Copilot

The HelixToken contract is a standard ERC-20 implementation, inheriting from battle-tested OpenZeppelin libraries. The primary security concern identified is the highly centralized initial token distribution, where the entire supply is minted to the deployer. This introduces significant economic and governance risks related to single-entity control. The contract is not upgradeable, which simplifies its security profile by removing upgrade-related risks, but also limits future flexibility.

1 High1 Low1 Informational
Volume 24h
$352.9K
Liquidity
$347.9K
Price
$0.0481
Token Age
1mo
Top 10 Holders
97.3%

Security Findings

High

Centralized Initial Token Supply

H-01The entire token supply (100,000,000,000 HLX) is minted to the `msg.sender` (deployer) in the constructor. This grants the deployer complete control over the initial distribution and the entire token supply, posing a significant centralization risk (7.4 Economic, 7.5 Governance). This could lead to potential market manipulation, lack of trust, or a single point of failure for the token's ecosystem.
IssueThe entire token supply (100,000,000,000 HLX) is minted to the `msg.sender` (deployer) in the constructor. This grants the deployer complete control over the initial distribution and the entire token supply, posing a significant centralization risk (7.4 Economic, 7.5 Governance). This could lead to potential market manipulation, lack of trust, or a single point of failure for the token's ecosystem.
FixImplement a more decentralized and transparent distribution mechanism for the initial token supply. This could involve vesting schedules, multi-sig controlled treasury, airdrops, or immediate liquidity provision to a decentralized exchange (DEX) to mitigate the risk associated with a single entity holding the entire supply.
StatusUnresolved
Low

Lack of Emergency Controls

L-01The `HelixToken` contract does not include any emergency mechanisms such as pausing transfers or blacklisting malicious addresses (7.8 Operations). While this aligns with a minimalist ERC-20 design, it means there are no built-in safeguards to react to critical vulnerabilities or exploits in integrated protocols that might involve the token, potentially leaving users exposed in extreme scenarios.
IssueThe `HelixToken` contract does not include any emergency mechanisms such as pausing transfers or blacklisting malicious addresses (7.8 Operations). While this aligns with a minimalist ERC-20 design, it means there are no built-in safeguards to react to critical vulnerabilities or exploits in integrated protocols that might involve the token, potentially leaving users exposed in extreme scenarios.
FixConsider if emergency controls (e.g., `Pausable` or `Blacklistable` from OpenZeppelin) are necessary for the token's intended use case and ecosystem. If such controls are deemed critical, they should be implemented with robust, multi-sig controlled access to prevent abuse.
StatusUnresolved
Info

Non-Upgradeable Contract Design

I-01The `HelixToken` contract is implemented directly and is not upgradeable (7.7 Upgrades). This means that once deployed, its logic cannot be modified or updated. While this eliminates risks associated with proxy patterns (e.g., upgrade path vulnerabilities), it also prevents any future bug fixes, feature enhancements, or adaptation to evolving protocol needs without a complete redeployment and token migration process.
IssueThe `HelixToken` contract is implemented directly and is not upgradeable (7.7 Upgrades). This means that once deployed, its logic cannot be modified or updated. While this eliminates risks associated with proxy patterns (e.g., upgrade path vulnerabilities), it also prevents any future bug fixes, feature enhancements, or adaptation to evolving protocol needs without a complete redeployment and token migration process.
FixAcknowledge the immutability as a design choice. If future flexibility for bug fixes or feature additions is desired for subsequent contracts or token versions, consider implementing an upgradeable proxy pattern (e.g., UUPS) to allow for future modifications.
StatusUnresolved

Category Ratings

TechnicalLow8/10

The `HelixToken` contract is a straightforward implementation of the ERC-20 standard, inheriting from OpenZeppelin Contracts v5.5.0. This robust foundation significantly reduces technical risks (7.2 Code Security). The architecture (7.1 Architecture) is simple, with no complex custom logic, which minimizes the attack surface. The contract lacks any custom access control mechanisms beyond the initial mint to the deployer (7.3 Access Control), which is a design choice for a basic token.

GovernanceHigh1/10

The primary economic and governance risk (7.4 Economic, 7.5 Governance) stems from the initial token distribution, where the entire supply is minted to the deployer's address. This creates a highly centralized control point, potentially enabling market manipulation or a rug pull if not managed transparently. There are no built-in governance features or decentralized distribution mechanisms within the contract itself, placing full trust in the deployer's actions.

UpgradesMedium5/10

The `HelixToken` contract is not designed to be upgradeable (7.7 Upgrades). This eliminates risks associated with proxy patterns, such as improper upgrade paths or storage collisions. However, it also means that the contract's logic is immutable, preventing any future bug fixes, feature additions, or adaptations without a complete redeployment and migration process.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

19.0% in wallets78.4% in contracts
Effective Concentration50.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder97.9%
Top-3 Unlocked99.4%

Key Addresses

Deployer
0x71eb…05b3
Unlocked LP Held By
0x71eb…05b30x1c71…c5340x5d28…f0010x705b…782c0x3d86…213f0x7ed5…c3c20xe109…2f990x1bf6…3f980x5823…014c0xdded…2c83

A privileged address — the deployer, the owner, or the token contract itself — is among these holders, so that party can withdraw liquidity.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 50% (97.3% total → 50.3% effective; 19.0% in EOAs, 78.4% in contracts — heavy)
  • Liquidity NOT locked (owner can withdraw — rug-pull risk)
  • LP top1 unlocked holder = 97.9% (exit-liquidity risk, pool = 33% of DEX liquidity)
  • LP top3 unlocked holders = 99.4% (exit-liquidity risk, pool = 33% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Helix Token a scam?

Based on automated analysis, Helix Token scores 66/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is Helix Token safe to buy?

Our scanner flagged a risk score of 66/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.

Has Helix Token been audited?

The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

Euler (EUL)High RiskQuant (QNT)High RiskNeuralAI (NEURAL)High RiskMorphoHigh RiskBeamHigh RiskSuperVerse (SUPER)High Risk

Would You Like a More Detailed Audit of Helix Token?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit