Quantum Audit Logo
Launch App

Is HodlHer a Scam?

Early-stage security check — honeypot & rug-pull analysis

HodlHer HODL
0x664a…cfb0
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 23h old
Executive SummaryAI Copilot

This report is based on a limited analysis due to the absence of provided source code for the contract at 0x664a588a2f77a090a734512b0b3ee67bba10cfb0. Without source code, a comprehensive security assessment cannot be performed. The analysis relies solely on available on-chain data and general security principles, leading to several informational findings regarding transparency and best practices.

1 Medium8 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$145.1K
Liquidity
$76.2K
Price
$0.0205
Token Age
23h
Top 10 Holders
91.0%

Security Findings

Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a contract, 0xf737…58f0 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a contract, 0xf737…58f0 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Unverified Contract Source Code

I-01The source code for the contract at 0x664a…cfb0 is not publicly verified on the blockchain explorer. This prevents a thorough security audit and makes it impossible to ascertain the contract's intended functionality and security posture. Users are forced to trust the deployer without independent verification.
IssueThe source code for the contract at is not publicly verified on the blockchain explorer. This prevents a thorough security audit and makes it impossible to ascertain the contract's intended functionality and security posture. Users are forced to trust the deployer without independent verification.
FixThe project team should immediately verify the contract's source code on the Base blockchain explorer. This action is fundamental for transparency, community trust, and enabling proper security analysis.
StatusUnresolved
Info

Unknown Contract Functionality and Logic

I-02Without access to the source code, the specific functionality, business logic, and internal mechanisms of the contract remain unknown. This includes critical aspects such as token handling, access control, state transitions, and external interactions (7.6 External). Users cannot independently confirm if the contract behaves as expected or if it contains malicious logic.
IssueWithout access to the source code, the specific functionality, business logic, and internal mechanisms of the contract remain unknown. This includes critical aspects such as token handling, access control, state transitions, and external interactions (7.6 External). Users cannot independently confirm if the contract behaves as expected or if it contains malicious logic.
FixPublishing the source code is the primary recommendation. Additionally, comprehensive documentation outlining the contract's purpose, architecture (7.1 Architecture), and all functions should be provided to users and auditors.
StatusUnresolved
Info

Lack of Transparency and Trust

I-03The absence of verified source code significantly diminishes transparency and trust in the contract and the associated protocol. This lack of visibility can deter potential users and investors, as it raises concerns about potential hidden backdoors, rug pulls, or other malicious activities. It also hinders community-driven security reviews.
IssueThe absence of verified source code significantly diminishes transparency and trust in the contract and the associated protocol. This lack of visibility can deter potential users and investors, as it raises concerns about potential hidden backdoors, rug pulls, or other malicious activities. It also hinders community-driven security reviews.
FixTo build and maintain trust, the project team must prioritize transparency by verifying the source code, providing clear documentation, and engaging with the community regarding the contract's security and functionality.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 91.0% of supply. What remains: 72.7% in wallets, 18.3% in other contracts. 1,739 holders in total.
IssueThe ten largest holders own 91.0% of supply. What remains: 72.7% in wallets, 18.3% in other contracts. 1,739 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY1,739 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue1,739 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $76K (DexScreener, all pools). 24h trading volume $145K (DexScreener, all pools).
IssueLiquidity $76K (DexScreener, all pools). 24h trading volume $145K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $76K of DEX liquidity across 1 pools. Launch: under a day of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $76K of DEX liquidity across 1 pools. Launch: under a day of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — less than a day of market history

QA-RECENTThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Without access to the contract's source code, a detailed technical security analysis (7.2 Code Security) is not possible. On-chain data indicates a deployed contract on Base. Potential vulnerabilities related to reentrancy, integer overflows, or access control (7.3 Access Control) cannot be evaluated. It is crucial for users to exercise caution when interacting with unverified contracts, as fundamental security properties remain unconfirmed.

GovernanceHigh1/10

The economic model and governance structure (7.4 Economic, 7.5 Governance) of the contract cannot be assessed without source code. This introduces inherent risks as potential mechanisms for value extraction, rug pulls, or centralized control remain unknown. Users should be aware of the lack of transparency regarding tokenomics, fee structures, and administrative privileges, which could lead to unexpected financial outcomes.

UpgradesMedium5/10

The upgradeability status (7.7 Upgrades) of the contract is unknown without source code. If the contract is upgradeable, the upgrade mechanism and its associated risks (e.g., centralized upgrade keys, lack of time locks) cannot be evaluated. If it is not upgradeable, any discovered vulnerabilities would be immutable, posing a permanent risk. This uncertainty contributes to a medium risk level for future operational changes (7.8 Operations).

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

72.7% in wallets18.3% in contracts
Effective Concentration80.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x8e2f…22b3
Unlocked LP Held By
0xf737…58f00x9bd2…168c

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — who holds it cannot be verified
  • Top-10 concentration > 70% (91.0% total → 80.0% effective; 72.7% in EOAs, 18.3% in contracts)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

RatspeakHigh RiskWrapped PROS (PROS)High RiskCortex (CX)High RiskSuperfluid Token (SUP)High RiskChipHigh Riskdefi-nativeHigh Risk

Would You Like a More Detailed Audit of HodlHer?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit