Quantum Audit Logo

Is IMDStrategy a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

IMDStrategy IMDSTR
0x8027…aca2
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record New Launch · 11h old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The ImmutableNFTStrategy contract serves as an implementation for a UUPS proxy, designed to explicitly disable further upgrades. While the provided code for ImmutableNFTStrategy is minimal and secure in its stated purpose, a comprehensive audit of the underlying NFTStrategy contract, from which it inherits core logic, was not possible due to missing source code. This significantly limits the scope of the audit and introduces unverified risks related to the strategy's economic mechanisms, access control, and interactions with external protocols.

1 High1 Medium2 Informational
! Early-stage analysis. This token has limited on-chain history (11h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$1.89M
Liquidity
$350.5K
Price
$0.0006472
Token Age
11h
Top 10 Holders
55.0%

Security Findings

High

Incomplete Audit Scope - Missing Base Contract Source

H-01The `NFTStrategy` contract, from which `ImmutableNFTStrategy` inherits its core functionality, was not provided for review. This prevents a comprehensive security assessment of the strategy's primary logic, including critical areas such as reentrancy protection, integer arithmetic, handling of funds, and complex state transitions. Without the full source, potential vulnerabilities in the base contract cannot be identified or mitigated (7.1 Architecture, 7.2 Code Security).
IssueThe `NFTStrategy` contract, from which `ImmutableNFTStrategy` inherits its core functionality, was not provided for review. This prevents a comprehensive security assessment of the strategy's primary logic, including critical areas such as reentrancy protection, integer arithmetic, handling of funds, and complex state transitions. Without the full source, potential vulnerabilities in the base contract cannot be identified or mitigated (7.1 Architecture, 7.2 Code Security).
FixProvide the complete and verified source code for the `NFTStrategy` contract to enable a full and thorough security audit of the entire system. This is essential for ensuring the robustness and security of the protocol.
StatusUnresolved
Medium

Unaudited Access Control Mechanisms

M-01The interfaces (`IPunkStrategy`, `IStrategy`, `IBaseStrategyFactory`) indicate the presence of an `owner` role and various functions that modify critical parameters (e.g., `setReward`, `setPriceMultiplier`, `updateFeeBips`, `transferOwnership`). Without the source code for `NFTStrategy`, the implementation details of these access control mechanisms (e.g., whether `Ownable` is used, if there are multi-sig requirements, or if there are any re-entrancy guards on sensitive functions) cannot be verified. Improper access control could lead to unauthorized parameter changes or fund manipulation (7.3 Access Control).
IssueThe interfaces (`IPunkStrategy`, `IStrategy`, `IBaseStrategyFactory`) indicate the presence of an `owner` role and various functions that modify critical parameters (e.g., `setReward`, `setPriceMultiplier`, `updateFeeBips`, `transferOwnership`). Without the source code for `NFTStrategy`, the implementation details of these access control mechanisms (e.g., whether `Ownable` is used, if there are multi-sig requirements, or if there are any re-entrancy guards on sensitive functions) cannot be verified. Improper access control could lead to unauthorized parameter changes or fund manipulation (7.3 Access Control).
FixProvide the source code for `NFTStrategy` to allow for a detailed review of all access control implementations. Ensure that critical functions are adequately protected, and consider implementing multi-signature wallets for sensitive administrative actions.
StatusUnresolved
Info

Reliance on External Protocols

I-01The contract interfaces indicate significant interaction with external protocols such as Uniswap V4, CryptoPunks (`IPunks`), and a Universal Router (`IUniversalRouter`). The security and correct functioning of this strategy heavily depend on the integrity, expected behavior, and upgradeability of these external contracts. Any vulnerabilities, unexpected changes, or economic exploits in these external dependencies could directly impact the strategy (7.6 External).
IssueThe contract interfaces indicate significant interaction with external protocols such as Uniswap V4, CryptoPunks (`IPunks`), and a Universal Router (`IUniversalRouter`). The security and correct functioning of this strategy heavily depend on the integrity, expected behavior, and upgradeability of these external contracts. Any vulnerabilities, unexpected changes, or economic exploits in these external dependencies could directly impact the strategy (7.6 External).
FixConduct a thorough review of all external dependencies, including their security audits, upgrade mechanisms, and potential failure modes. Implement robust error handling and sanity checks when interacting with external contracts to mitigate risks from unexpected behavior.
StatusUnresolved
Info

Explicit Immutability via `UpgradesDisabled`

I-02The `ImmutableNFTStrategy` contract explicitly prevents future upgrades by overriding the `upgradeToAndCall` function to unconditionally revert with `UpgradesDisabled()`. This design choice ensures that the current logic of the strategy, once deployed as a UUPS proxy implementation, cannot be altered via the standard UUPS upgrade mechanism, providing a strong guarantee of immutability for the current implementation (7.7 Upgrades).
IssueThe `ImmutableNFTStrategy` contract explicitly prevents future upgrades by overriding the `upgradeToAndCall` function to unconditionally revert with `UpgradesDisabled()`. This design choice ensures that the current logic of the strategy, once deployed as a UUPS proxy implementation, cannot be altered via the standard UUPS upgrade mechanism, providing a strong guarantee of immutability for the current implementation (7.7 Upgrades).
FixThis is a positive security feature. Ensure that this immutability aligns with the long-term operational and governance strategy for the protocol. If any future changes are anticipated, they would require a new deployment rather than an upgrade.
StatusResolved

Category Ratings

TechnicalMedium6/10

The `ImmutableNFTStrategy` contract is minimal, primarily overriding the `upgradeToAndCall` function to prevent further upgrades, thereby ensuring the immutability of the current implementation (7.7 Upgrades). However, a comprehensive technical review (7.2 Code Security, 7.3 Access Control) is severely limited as the core logic resides in the inherited `NFTStrategy` contract, whose source code was not provided. This prevents verification of critical security patterns and potential vulnerabilities.

GovernanceHigh1/10

The system, as indicated by various interfaces (e.g., `IPunkStrategy`, `IPunkStrategyHook`), involves complex economic interactions such as NFT trading, fee collection, reward distribution, and liquidity management (7.4 Economic). Governance functions like `setReward` and `setPriceMultiplier` are present (7.5 Governance). However, the specific implementation of these economic and governance mechanisms within the `NFTStrategy` contract remains unaudited due to missing source code, posing a risk of unverified economic assumptions or governance vulnerabilities.

UpgradesHigh1/10

The `ImmutableNFTStrategy` contract explicitly disables upgrades by reverting `upgradeToAndCall` with an `UpgradesDisabled()` error. This design choice makes the deployed proxy effectively immutable via its standard UUPS upgrade mechanism, significantly reducing the risk of unauthorized or accidental logic changes (7.7 Upgrades). This provides a strong guarantee of stability for the current implementation.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEip1967 Uups
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

7.7% in wallets47.2% in contracts
Effective Concentration26.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xfc3c…1774
Unlocked LP Held By
0x652c…6df0

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — owner is an EOA (single private key)
  • Proxy contract (upgradeable — admin can replace logic)
  • Top-10 concentration > 20% (55.0% total → 26.6% effective; 7.7% in EOAs, 47.2% in contracts — mild)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 100% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 100% of DEX liquidity)
  • Token age < 24h (brand new — bot activity, unproven)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

DAPPOS (DOS)Critical RiskICPCritical RiskPancakeSwap (CAKE)Critical RiskEveripedia IQ (IQ)Critical RiskThreshold Network Token (T)Critical RiskFARM Reward Token (FARM)Critical Risk

Would You Like a More Detailed Audit of IMDStrategy?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit