Quantum Audit Logo

Is Lighter Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Lighter LIT
0x232c…4ee2
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 18d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit was conducted on the provided Solidity source code, which consists solely of OpenZeppelin's standard ERC20 base contract and related interfaces (IERC20, IERC20Metadata, IERC20Errors, IERC5267, IERC6093). The specific implementation of the 'Lighter' token, which would inherit from this ERC20 base and define its unique logic (e.g., supply mechanism, custom functions), was not provided for review. Therefore, this report assesses only the security of the included OpenZeppelin components, which are widely audited and considered robust. A comprehensive security assessment of the 'Lighter' token requires the full source code of its specific implementation.

2 Informational
Volume 24h
$914.7K
Liquidity
$1.00M
Price
$4.2800
Token Age
4mo
Top 10 Holders
66.1%

Security Findings

Info

Missing Project-Specific Source Code for Full Audit

I-01The provided source code only includes OpenZeppelin's abstract ERC20 contract and its interfaces. The specific implementation of the 'Lighter' token, which would inherit from this base and define its unique functionalities (e.g., `_mint`, `_burn`, custom modifiers, or other business logic), was not included in the scope of this audit. Without the full implementation, a comprehensive security assessment of the 'Lighter' token cannot be performed, as critical vulnerabilities often arise from custom logic and interactions.
IssueThe provided source code only includes OpenZeppelin's abstract ERC20 contract and its interfaces. The specific implementation of the 'Lighter' token, which would inherit from this base and define its unique functionalities (e.g., `_mint`, `_burn`, custom modifiers, or other business logic), was not included in the scope of this audit. Without the full implementation, a comprehensive security assessment of the 'Lighter' token cannot be performed, as critical vulnerabilities often arise from custom logic and interactions.
FixProvide the complete source code for the 'Lighter' token contract, including all inheriting contracts and libraries, to enable a thorough security audit. This is essential for identifying potential vulnerabilities specific to the token's design and operation.
StatusUnresolved
Info

Reliance on Well-Audited OpenZeppelin Libraries

I-02The project utilizes OpenZeppelin Contracts for its ERC20 base implementation. OpenZeppelin libraries are widely recognized for their high security standards, extensive testing, and frequent audits by the community and professional firms. This significantly reduces the risk of vulnerabilities stemming from the foundational ERC20 logic itself (7.2 Code Security).
IssueThe project utilizes OpenZeppelin Contracts for its ERC20 base implementation. OpenZeppelin libraries are widely recognized for their high security standards, extensive testing, and frequent audits by the community and professional firms. This significantly reduces the risk of vulnerabilities stemming from the foundational ERC20 logic itself (7.2 Code Security).
FixContinue to leverage well-established and audited libraries like OpenZeppelin. Ensure that any custom logic built on top of these libraries adheres to similar security best practices and is thoroughly tested and audited.
StatusResolved

Category Ratings

TechnicalLow10/10

The provided code consists of well-established OpenZeppelin ERC20 base contracts and interfaces (7.1 Architecture). These contracts are industry standards, extensively peer-reviewed, and have a strong track record of security (7.2 Code Security). They implement robust checks for common ERC20 operations, including balance and allowance validations (7.3 Access Control). No custom logic or complex interactions were present in the provided scope, limiting the potential for novel technical vulnerabilities.

GovernanceHigh1/10

The provided OpenZeppelin ERC20 base contract does not contain any specific governance mechanisms or economic models (7.5 Governance, 7.4 Economic). These aspects would typically be defined in the inheriting contract, which was not available for review. Therefore, no assessment of governance or economic risks specific to the 'Lighter' token can be made based on the provided code.

UpgradesMedium6/10

The provided code does not include any proxy or upgradeability patterns (7.7 Upgrades). It is a standard, non-upgradeable abstract ERC20 implementation. If the 'Lighter' token is intended to be upgradeable, the proxy implementation and its associated logic would need to be reviewed separately. Based on the provided code, there are no inherent upgrade safety issues.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

49.5% in wallets16.6% in contracts
Effective Concentration56.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder53.3%
Top-3 Unlocked93.0%

Key Addresses

Deployer
0x004f…3099
Unlocked LP Held By
0x5466…65160xf010…86a60x0d19…aca10x898d…58390xd6d8…4ace0xd917…7ad8

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 50% (66.1% total → 56.1% effective; 49.5% in EOAs, 16.6% in contracts — heavy)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 53.3% (independent LP — depth risk, pool = 40% of DEX liquidity)
  • LP top3 unlocked holders = 93.0% (independent LP — depth risk, pool = 40% of DEX liquidity)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Lighter a scam?

Based on the provided data, Lighter doesn't exhibit immediate red flags commonly associated with scams, such as unverified contracts or retained ownership. Its contract is verified, and ownership is renounced, preventing direct developer manipulation or hidden minting. However, high holder concentration and unlocked liquidity introduce substantial risks that investors should carefully consider. It's categorized as a medium-risk asset.

Is Lighter safe to buy?

Lighter is categorized as a medium-risk asset (42/100). While it has positive attributes like a verified contract and renounced ownership, significant risks persist. The top 10 holders control over 70% of the supply, creating centralization risks. Additionally, the liquidity is not locked, which could expose funds to withdrawal. Investors should be aware of these factors and conduct thorough due diligence before considering an investment.

Has Lighter been audited?

The provided information states that Lighter's contract is 'verified,' meaning the source code is publicly available and matches the deployed contract. This is a crucial step for transparency, allowing anyone to review the code. However, 'verified' is distinct from a formal security audit conducted by a professional firm, which would involve in-depth analysis for vulnerabilities, exploits, and best practices. An independent audit status is not indicated here.

Related Audits

Injective (INJ)Medium RiskAaveMedium RiskPepeMedium RiskShiro Neko (SHIRO)Medium RiskBeefy (BIFI)Medium RiskADIMedium Risk

Would You Like a More Detailed Audit of Lighter?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit