Quantum Audit Logo

Is Humanity a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

Humanity H
0xe76c…5de1
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 1 audit on record New Launch · 5d old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

This audit focuses on a TransparentUpgradeableProxy contract, which utilizes standard OpenZeppelin libraries. A critical finding is that the implementation contract, identified as 'HToken' at address 0x85d0b85f290ba575c50a6be38f24f9e99f94e7d3, has unverified source code. This prevents a comprehensive security assessment of the core protocol logic. While the proxy's administrative control is secured by a 4-of-7 Gnosis Safe multisig, the unknown nature of the implementation's code introduces significant technical, economic, and upgrade risks.

1 Critical1 High1 Medium2 Informational
! Early-stage analysis. This token has limited on-chain history (5d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$277.8K
Liquidity
$970.6K
Price
$0.07843
Token Age
5d
Top 10 Holders
86.3%

Security Findings

Critical

Unverified Implementation Contract

C-01The source code for the `HToken` implementation contract (0x85d0…e7d3) is not verified on the blockchain. This prevents any security analysis of the core logic and functionality of the protocol. Without verified source code, it is impossible to ascertain the contract's behavior, identify vulnerabilities, or confirm its adherence to stated specifications, posing an extreme risk to users and the protocol's integrity (7.2 Code Security).
IssueThe source code for the `HToken` implementation contract () is not verified on the blockchain. This prevents any security analysis of the core logic and functionality of the protocol. Without verified source code, it is impossible to ascertain the contract's behavior, identify vulnerabilities, or confirm its adherence to stated specifications, posing an extreme risk to users and the protocol's integrity (7.2 Code Security).
FixImmediately verify the source code of the `HToken` implementation contract on Etherscan or the relevant block explorer. Conduct a comprehensive security audit of the implementation contract to identify and remediate any vulnerabilities before further operations.
StatusUnresolved
High

Centralized Upgrade Authority

H-01While the proxy's admin is a 4-of-7 Gnosis Safe multisig, this still represents a centralized point of control for upgrades. The multisig owners have the power to upgrade the implementation contract to any arbitrary code, potentially introducing malicious logic or critical vulnerabilities without broader community consensus or review (7.3 Access Control, 7.7 Upgrades).
IssueWhile the proxy's admin is a 4-of-7 Gnosis Safe multisig, this still represents a centralized point of control for upgrades. The multisig owners have the power to upgrade the implementation contract to any arbitrary code, potentially introducing malicious logic or critical vulnerabilities without broader community consensus or review (7.3 Access Control, 7.7 Upgrades).
FixConsider decentralizing the upgrade mechanism further, potentially by integrating a governance module or a more distributed decision-making process. Ensure that all multisig signers are trusted, distinct entities, and that their private keys are secured with best practices.
StatusUnresolved
Medium

Lack of Timelock for Upgrades

M-01The current Transparent Proxy setup does not incorporate a timelock for upgrade operations. This means that once an upgrade transaction is approved by the multisig admin, it can be executed immediately. This lack of a delay period prevents users and the community from reviewing proposed changes or reacting to potentially malicious upgrades before they are deployed (7.7 Upgrades, 7.8 Operations).
IssueThe current Transparent Proxy setup does not incorporate a timelock for upgrade operations. This means that once an upgrade transaction is approved by the multisig admin, it can be executed immediately. This lack of a delay period prevents users and the community from reviewing proposed changes or reacting to potentially malicious upgrades before they are deployed (7.7 Upgrades, 7.8 Operations).
FixImplement a timelock mechanism for all critical administrative actions, especially upgrades. This would introduce a mandatory delay between the approval of an upgrade and its actual execution, providing a window for scrutiny and emergency response.
StatusUnresolved
Info

Use of Standard OpenZeppelin Contracts

I-01The proxy contract leverages battle-tested and widely audited OpenZeppelin libraries for its core functionality, including `ERC1967Proxy` and `ERC1967Utils`. This significantly reduces the risk of vulnerabilities within the proxy's own code (7.1 Architecture, 7.2 Code Security).
IssueThe proxy contract leverages battle-tested and widely audited OpenZeppelin libraries for its core functionality, including `ERC1967Proxy` and `ERC1967Utils`. This significantly reduces the risk of vulnerabilities within the proxy's own code (7.1 Architecture, 7.2 Code Security).
FixContinue to rely on well-established and audited libraries for core functionalities. Regularly update to the latest stable versions of OpenZeppelin contracts to benefit from ongoing security improvements.
StatusResolved
Info

Multisig Admin for Proxy

I-02The administrative control over the proxy, including upgrade capabilities, is managed by a 4-of-7 Gnosis Safe multisig. This setup enhances security by requiring multiple independent approvals for critical operations, mitigating the risk of a single point of failure or compromise (7.3 Access Control, 7.8 Operations).
IssueThe administrative control over the proxy, including upgrade capabilities, is managed by a 4-of-7 Gnosis Safe multisig. This setup enhances security by requiring multiple independent approvals for critical operations, mitigating the risk of a single point of failure or compromise (7.3 Access Control, 7.8 Operations).
FixEnsure robust operational security practices for all multisig signers, including strong key management and phishing prevention. Regularly review the list of multisig owners to ensure it remains appropriate and active.
StatusResolved

Category Ratings

TechnicalMedium4/10

The provided proxy contract utilizes well-audited OpenZeppelin `ERC1967Proxy` and `ERC1967Utils` for its upgradeability mechanism (7.1 Architecture). This ensures a robust and standard proxy implementation. However, the critical technical risk lies with the unverified source code of the `HToken` implementation contract (7.2 Code Security), which means its internal logic, potential vulnerabilities, and adherence to security best practices cannot be assessed. Without verification, the actual functionality and security of the protocol remain unknown.

GovernanceHigh1/10

The proxy's administrative control is managed by a 4-of-7 Gnosis Safe multisig (7.3 Access Control), which enhances security by requiring multiple approvals for critical operations like upgrades. This setup mitigates single points of failure for administrative actions. However, the economic model and any governance mechanisms of the underlying `HToken` implementation are entirely unknown due to its unverified source (7.4 Economic, 7.5 Governance). This lack of transparency prevents an assessment of potential economic exploits or governance centralization within the core logic.

UpgradesHigh1/10

The contract employs the Transparent Proxy pattern, managed by an OpenZeppelin `ProxyAdmin` contract, whose owner is a Gnosis Safe multisig (7.7 Upgrades). This provides a secure and standard upgrade path, requiring multiple approvals for implementation changes. However, a significant risk is the absence of a timelock mechanism for upgrades, allowing immediate changes to the implementation. Furthermore, the unverified nature of the current `HToken` implementation means any future upgrade, even if approved by the multisig, could introduce unknown or malicious code without prior public scrutiny.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyFail

Proxy Upgrade Controls

Proxy TypeEip1967 Transparent
AdminOZ ProxyAdmin → Multisig 4-of-7
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

85.5% in wallets0.8% in contracts
Effective Concentration85.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x04a1…8e0f
Unlocked LP Held By
0x40dd…53df

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — strong Multisig (4-of-7)
  • Mintable supply — no cap found, dilution unbounded
  • Proxy contract (upgradeable — admin can replace logic)
  • Top-10 concentration > 70% (86.3% total → 85.8% effective; 85.5% in EOAs, 0.8% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • Token age < 7 days (early, volatile)
  • 1 Critical finding(s) from audit
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Humanity a scam?

Based on the provided data, Humanity (H) does not exhibit overt scam indicators like a hidden mint function or unverified contract code. The contract is verified, and ownership is renounced. However, the severe token concentration (89.5% by top 10 holders) combined with unlocked liquidity ($854,223) presents a substantial risk of market manipulation or a liquidity rug pull, which are common characteristics associated with scam projects. Investors should proceed with extreme caution due to these structural vulnerabilities.

Is Humanity safe to buy?

Humanity (H) carries a High Risk score of 59/100, indicating it is not considered safe for investment without significant caution. Key safety concerns include the fact that 89.5% of the supply is held by the top 10 addresses, creating immense centralization risk. Furthermore, the project's $854,223 in liquidity is not locked, exposing investors to a potential rug pull. While contract verification and renounced ownership are positive, these severe structural risks undermine overall safety.

Has Humanity been audited?

The Humanity (H) contract is verified on Ethereum, making its code transparent and publicly viewable. While beneficial for scrutiny, this is distinct from a formal security audit. An independent third-party audit rigorously assesses code for vulnerabilities and exploits. The provided data does not indicate that Humanity has undergone a comprehensive security audit by an independent firm.

Related Audits

Apple (Ondo Tokenized) (AAPLON)Critical RiskNEARCritical RiskVision (VSN)Critical RiskSpaceX xStock (SPCXX)Critical RisktapCritical RiskBananaCritical Risk

Would You Like a More Detailed Audit of Humanity?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit