Quantum Audit Logo
Launch App

Is Lity protocol Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Lity protocol LITY
0xcd6a…0c0c
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The ERC20Template contract functions as an upgradeable ERC-20 token, utilizing a Beacon proxy pattern. Key functionalities include standard ERC-20 operations, along with capabilities for pausing transfers, minting new tokens, and managing transfer fees. Ownership of the implementation contract is renounced, rendering several privileged functions dormant. The audit identified a medium-severity issue related to a tautology in initialization and a potential for rounding loss, alongside two medium/low severity findings concerning the historical ability of the owner to modify fees and transfer limits, which are now inactive due to renounced ownership.

2 Medium2 Low5 Informational
Volume 24h
$202.2K
Liquidity
$59.1K
Price
$0.0005773
Token Age
2mo
Top 10 Holders
26.7%

Security Findings

Medium

Tautology in Initialization Function

CD-02The `initialize` function contains a tautological condition, meaning a logical expression that is always true. This indicates redundant code that does not affect the contract's logic but can be a sign of oversight or unnecessary complexity. While not a direct vulnerability, it can make the code harder to read and maintain.
IssueThe `initialize` function contains a tautological condition, meaning a logical expression that is always true. This indicates redundant code that does not affect the contract's logic but can be a sign of oversight or unnecessary complexity. While not a direct vulnerability, it can make the code harder to read and maintain.
FixReview the `initialize` function to identify and remove the tautological condition. Simplifying the logic will improve code clarity and maintainability without altering the intended functionality.
StatusUnresolved
Medium

Privileged Address Could Change Transfer Fees

CP-07Historically, the contract owner had the ability to modify the fees taken from token transfers by calling the `setFeeReceivers` function. This function allowed the owner to add, remove, or update fee recipient addresses and their respective shares. Additionally, the `mint` function could also influence fee-related state variables. However, it is important to note that the ownership of this contract has been renounced, meaning the `owner` address can no longer execute these functions, rendering this capability dormant.
IssueHistorically, the contract owner had the ability to modify the fees taken from token transfers by calling the `setFeeReceivers` function. This function allowed the owner to add, remove, or update fee recipient addresses and their respective shares. Additionally, the `mint` function could also influence fee-related state variables. However, it is important to note that the ownership of this contract has been renounced, meaning the `owner` address can no longer execute these functions, rendering this capability dormant.
FixWhile the `owner` can no longer change transfer fees due to renounced ownership, token holders should be aware that if ownership were ever to be reinstated or transferred, this function would allow a single entity to alter the token's economic model. For future projects, consider implementing a decentralized governance mechanism or a timelock for such critical parameter changes to enhance security and trust.
StatusUnresolved
Low

Rounding Loss from Division Before Multiplication

CD-01The functions `_isReflectionEligible` and `_update` perform division operations before multiplication. In Solidity, integer division truncates any fractional part, leading to a loss of precision. If the division result is less than 1, it will be rounded down to 0, potentially causing minor discrepancies or unexpected behavior in calculations, especially with small numbers.
IssueThe functions `_isReflectionEligible` and `_update` perform division operations before multiplication. In Solidity, integer division truncates any fractional part, leading to a loss of precision. If the division result is less than 1, it will be rounded down to 0, potentially causing minor discrepancies or unexpected behavior in calculations, especially with small numbers.
FixTo prevent potential rounding losses, it is generally recommended to perform multiplication operations before division whenever possible. For example, instead of `(a / b) * c`, consider `(a * c) / b`. This ensures that precision is maintained for as long as possible during calculations.
StatusUnresolved
Low

Privileged Address Could Change Transfer or Wallet Limits

CP-08The `mint` function, which was restricted to the contract owner, had the capability to influence state variables such as `totalReflectionShares`, `reflectionShares`, `magnifiedReflectionPerShare`, and `magnifiedReflectionCorrections`. These variables are often used to manage token distribution, reflection mechanics, and could indirectly affect effective transfer or wallet limits within the token's logic. However, since the contract ownership has been renounced, the `owner` can no longer call the `mint` function, making this potential control dormant.
IssueThe `mint` function, which was restricted to the contract owner, had the capability to influence state variables such as `totalReflectionShares`, `reflectionShares`, `magnifiedReflectionPerShare`, and `magnifiedReflectionCorrections`. These variables are often used to manage token distribution, reflection mechanics, and could indirectly affect effective transfer or wallet limits within the token's logic. However, since the contract ownership has been renounced, the `owner` can no longer call the `mint` function, making this potential control dormant.
FixGiven that ownership is renounced, the ability to change these parameters is currently inactive. In scenarios where such controls are active, it is recommended to implement robust access control, potentially involving multi-signature wallets or decentralized governance, to prevent a single entity from arbitrarily changing critical token parameters that affect user holdings or transfer behavior.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 26.7% of supply. Of that, 5.1% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 21.6% in wallets, 0.0% in other contracts. The deployer/owner wallet itself holds 1.8%. 671 holders in total.
IssueThe ten largest holders own 26.7% of supply. Of that, 5.1% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 21.6% in wallets, 0.0% in other contracts. The deployer/owner wallet itself holds 1.8%. 671 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY671 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue671 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

Liquidity burned — cannot be withdrawn

QA-LIQUIDITY100.0% of the pool's LP is burned or time-locked. 100.0% of the LP tokens were sent to a burn address — that liquidity can never be withdrawn by anyone.
Issue100.0% of the pool's LP is burned or time-locked. 100.0% of the LP tokens were sent to a burn address — that liquidity can never be withdrawn by anyone.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $59K (DexScreener, all pools). 24h trading volume $202K (DexScreener, all pools).
IssueLiquidity $59K (DexScreener, all pools). 24h trading volume $202K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: nobody (ownership renounced). Code: upgradeable proxy. Fees: no buy or sell tax. Market: $59K of DEX liquidity across 1 pools. Launch: 67 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: nobody (ownership renounced). Code: upgradeable proxy. Fees: no buy or sell tax. Market: $59K of DEX liquidity across 1 pools. Launch: 67 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalLow7/10

The contract implements a standard ERC-20 token with additional features such as pausing, minting, and reflection mechanics. The code includes robust array management for fee receivers and adheres to upgradeable patterns (7.1 Architecture). A significant security strength is the renounced ownership of the implementation contract, which means functions like `setFeeReceivers`, `pause`, `unpause`, and `mint` are currently dormant and cannot be invoked (7.3 Access Control). However, the analysis identified a tautology in the `initialize` function and a potential for minor rounding loss in `_isReflectionEligible` and `_update` due to division before multiplication (7.2 Code Security).

GovernanceLow8/10

The economic model includes configurable transfer fees and potential for minting, which could historically be controlled by the owner (7.4 Economic). However, the renounced ownership of the implementation contract significantly reduces governance risk, as the `owner` can no longer call `setFeeReceivers` to change transfer fees or `mint` to alter token supply or limits (7.5 Governance). This makes the token's economic parameters immutable from the implementation side. While this enhances decentralization, it also means that if the contract were paused via `pause`, it could not be unpaused, and no new tokens could be minted, limiting operational flexibility (7.8 Operations).

UpgradesHigh2/10

The contract is deployed as a Beacon proxy, meaning its logic can be upgraded by changing the implementation address stored in the associated Beacon contract (7.7 Upgrades). While the implementation contract itself has renounced ownership, control over the Beacon contract, which dictates the upgrade path, is not specified in the provided analysis. This introduces a centralized point of control for future upgrades, where the Beacon owner could potentially deploy new logic, including malicious code or reintroducing privileged functions. Without knowing the Beacon owner, the upgradeability presents a medium risk.

Security Checklist

Contract VerifiedPass
Ownership RenouncedPass
No Mint FunctionFail
Liquidity LockedPass
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeBeacon
ImplementationVerified source

Holder Composition

21.6% in wallets0.0% in contracts
Effective Concentration21.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Burned100.0% · ≈ permanent lock
LP Locked100.0% · Null Address

Key Addresses

Deployer
0x03b0…45ab

What Raised This Score

  • Owner can change the buy/sell tax; held by tradeguardian: Other-Contract
  • A privileged address can change transfer or wallet limits; held by tradeguardian: Other-Contract
  • Upgradeable proxy — the admin can replace the logic
  • Top-10 concentration > 20% (26.7% total → 21.6% effective; 21.6% in EOAs, 0.0% in contracts; 5.1% burned, locked or in pools excluded)
  • Code: Rounding Loss from Division Before Multiplication (Low, static analysis)
  • Code: Tautology in Initialization Function (Medium, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

VelvetMedium Risk牛梦Medium RiskUcan fix life in1day (1)Medium RiskCookieMedium RiskCrossMedium RiskBicatMedium Risk

Would You Like a More Detailed Audit of Lity protocol?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit