Quantum Audit Logo

Is Kamirai Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Kamirai $KAMIRAI
0x12bf…a213
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The KamiraiToken contract is an ERC-20 compliant token with additional features for transfer control, including burning and anti-bot mechanisms. Ownership of the contract has been renounced on-chain, meaning that the previously privileged functions (e.g., `setBurningEnabled`, `setAntiBot`, `setTaxExclusion`) can no longer be called by anyone, rendering these controls dormant. Key findings include a high-severity issue related to shadowing state (details not fully provided), a medium-severity issue where received ETH cannot be withdrawn (7.8 Operations), and informational findings regarding the now-dormant administrative controls over transfer rules (7.3 Access Control, 7.4 Economic).

1 High2 Medium6 Informational
Volume 24h
$38.4K
Liquidity
$20.0K
Price
$0.00001106
Token Age
4mo
Top 10 Holders
61.9%

Security Findings

High

Shadowing State Vulnerability

CD-02The specific details regarding the shadowing state vulnerability are not provided in the audit input. Generally, shadowing state occurs when a variable in a derived contract has the same name as a variable in a base contract, potentially leading to unexpected behavior or incorrect state management, as the compiler might use a different variable than intended during execution.
IssueThe specific details regarding the shadowing state vulnerability are not provided in the audit input. Generally, shadowing state occurs when a variable in a derived contract has the same name as a variable in a base contract, potentially leading to unexpected behavior or incorrect state management, as the compiler might use a different variable than intended during execution.
FixReview the full source code to identify any shadowed state variables. Ensure that all state variables have unique names across the inheritance hierarchy to prevent ambiguity and unintended interactions, which could lead to critical security flaws or incorrect contract logic.
StatusUnresolved
Medium

Ether Can Be Sent To Contract But Not Withdrawn

CD-01The contract has a `receive` function, which allows it to accept Ether (ETH) sent to its address. However, there are no functions implemented in the contract that would allow any address, including the former owner, to withdraw this received ETH. Any ETH sent to this contract will be permanently locked and inaccessible.
IssueThe contract has a `receive` function, which allows it to accept Ether (ETH) sent to its address. However, there are no functions implemented in the contract that would allow any address, including the former owner, to withdraw this received ETH. Any ETH sent to this contract will be permanently locked and inaccessible.
FixIf the contract is not intended to hold ETH, consider removing the `receive` function to prevent accidental transfers. If ETH is intended to be held, implement a secure withdrawal function, preferably restricted to a trusted address, to manage these funds.
StatusUnresolved
Medium

Liquidity only partly locked or burned

QA-LIQUIDITY61.6% of the pool's LP is burned or time-locked. 61.6% is held by UNCX Locker, but the lock's end date is not published in the data we can read — its duration is unverified. 38.4% is held, unlocked, by 1 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 62% of the token's DEX liquidity; the other pools were not assessed.
Issue61.6% of the pool's LP is burned or time-locked. 61.6% is held by UNCX Locker, but the lock's end date is not published in the data we can read — its duration is unverified. 38.4% is held, unlocked, by 1 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 62% of the token's DEX liquidity; the other pools were not assessed.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Dormant Control Over Token Burning

CP-05The contract includes a `setBurningEnabled` function that, if active, would allow a privileged address to turn on or off the ability for tokens to be burned. This setting directly affects whether certain token transfers or sales would be allowed or refused. However, the contract's ownership has been renounced, meaning no one can call this function anymore. This control is now permanently inactive.
IssueThe contract includes a `setBurningEnabled` function that, if active, would allow a privileged address to turn on or off the ability for tokens to be burned. This setting directly affects whether certain token transfers or sales would be allowed or refused. However, the contract's ownership has been renounced, meaning no one can call this function anymore. This control is now permanently inactive.
FixNo action is required as ownership is renounced, rendering this function permanently inactive. This finding serves as documentation of a past control mechanism.
StatusUnresolved
Info

Dormant Control Over Anti-Bot Measures

CP-08The contract contains a `setAntiBot` function that, if active, would allow a privileged address to enable or disable anti-bot measures and set their duration (`antiBotEndTime`). These measures could impose limits on transfers or wallet sizes. However, the contract's ownership has been renounced, meaning no one can call this function anymore. This control is now permanently inactive.
IssueThe contract contains a `setAntiBot` function that, if active, would allow a privileged address to enable or disable anti-bot measures and set their duration (`antiBotEndTime`). These measures could impose limits on transfers or wallet sizes. However, the contract's ownership has been renounced, meaning no one can call this function anymore. This control is now permanently inactive.
FixNo action is required as ownership is renounced, rendering this function permanently inactive. This finding serves as documentation of a past control mechanism.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 61.9% of supply. Of that, 46.9% burned, 0.9% locked — not holders that can sell, so excluded from the concentration score. What remains: 3.3% in wallets, 10.8% in other contracts. 16,524 holders in total.
IssueThe ten largest holders own 61.9% of supply. Of that, 46.9% burned, 0.9% locked — not holders that can sell, so excluded from the concentration score. What remains: 3.3% in wallets, 10.8% in other contracts. 16,524 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY16,524 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue16,524 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $32K (DexScreener, all pools). 24h trading volume $58K (DexScreener, all pools).
IssueLiquidity $32K (DexScreener, all pools). 24h trading volume $58K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: nobody (ownership renounced). Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $32K of DEX liquidity across 3 pools. Launch: 126 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: nobody (ownership renounced). Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $32K of DEX liquidity across 3 pools. Launch: 126 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The KamiraiToken contract implements the ERC-20 standard, including `transfer` and `transferFrom` functions that utilize an internal `_transferWithTax` mechanism (7.1 Architecture). A high-severity issue concerning 'shadowing state' was identified, which could lead to unexpected behavior or incorrect state management (7.2 Code Security). Additionally, the contract has a `receive` function allowing it to accept ETH, but lacks any corresponding function to withdraw these funds, leading to permanently locked assets (7.2 Code Security). Access control for administrative functions like `setBurningEnabled` and `setAntiBot` was initially restricted to the owner, but ownership has been renounced, making these controls inactive (7.3 Access Control).

GovernanceLow7/10

The contract included several economic control mechanisms, such as `setBurningEnabled` to toggle token burning and `setAntiBot` to manage anti-bot measures with a time limit (`antiBotEndTime`) (7.4 Economic). These functions, along with `setTaxExclusion` for specific addresses, were initially restricted to the contract owner. However, the `renounceOwnership` function was called, permanently disabling all owner-privileged functions. This means there is no longer a single entity that can unilaterally alter these economic parameters or governance settings (7.5 Governance), reducing centralized control risks.

UpgradesLow8/10

The KamiraiToken contract is a standard implementation contract and does not utilize any proxy patterns or upgrade mechanisms (7.7 Upgrades). Therefore, its logic cannot be changed or updated after deployment. This eliminates upgrade-related risks but also means any discovered vulnerabilities or desired feature enhancements cannot be implemented without deploying a new contract.

Security Checklist

Contract VerifiedPass
Ownership RenouncedPass
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

3.3% in wallets10.8% in contracts
Effective Concentration7.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Locked61.6% · UNCX Locker
Top-1 Unlocked Holder38.4%
Top-3 Unlocked38.4%

Key Addresses

Deployer
0x8f96…0876
Unlocked LP Held By
0xa156…24d90xdc77…c7890xd368…a55a0x2489…445e

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Liquidity NOT locked (38% of the pool; this pool is 62% of DEX liquidity) — held by independent providers — market-depth risk
  • Liquidity < $50k ($32,119 across 3 pairs — thin market)
  • Trading cooldown between transactions
  • Code: Ether Can Be Sent To Contract But Not Withdrawn (Medium, static analysis)
  • Code: Shadowing State Vulnerability (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ChainOpera AI (COAI)Medium RiskYooldo Games (ESPORTS)Medium RiskAKEMedium RiskSIXSEVEN (67)Medium RiskOPENMedium RiskBaby Ansem (BABYANSEM)Medium Risk

Would You Like a More Detailed Audit of Kamirai?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit