Quantum Audit Logo

Is Messier Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Messier M87
0x8012…e888
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 10d ago 1 audit on record
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The audit of the M87 contract is severely limited as the source code for the main contract (M87) was not provided, only its interfaces and a utility library. This prevents any meaningful technical security analysis. Based on available metadata, significant economic and governance risks are identified, including centralized control by an EOA and unlocked liquidity pools. Users are strongly advised against interacting with this contract without full source code verification and a comprehensive audit.

1 Critical2 High1 Medium1 Low1 Informational
Volume 24h
$103.8K
Liquidity
$977.5K
Price
$0.00001178
Token Age
3y
Top 10 Holders
34.3%

Security Findings

Critical

Missing Source Code for Core Contract

C-01The source code for the main contract, M87 (0x8012…e888), was not provided for audit. Only interfaces and a utility library were available. This prevents any technical verification of the contract's logic, security mechanisms, access controls, and adherence to best practices. Without the source code, the contract is unauditable, and its behavior cannot be guaranteed.
IssueThe source code for the main contract, M87 (), was not provided for audit. Only interfaces and a utility library were available. This prevents any technical verification of the contract's logic, security mechanisms, access controls, and adherence to best practices. Without the source code, the contract is unauditable, and its behavior cannot be guaranteed.
FixPublish the complete and verified source code for the M87 contract on a public block explorer (e.g., Etherscan) to allow for full transparency and a comprehensive security audit.
StatusUnresolved
High

Centralized Control by EOA

H-01The contract's ownership is retained by an External Owned Account (EOA) (0xb306…53eb). This centralized control allows a single entity to potentially execute critical functions, modify parameters, or even drain funds if such functionalities are present in the unaudited M87 contract. This poses a single point of failure and a significant trust requirement on the owner.
IssueThe contract's ownership is retained by an External Owned Account (EOA) (). This centralized control allows a single entity to potentially execute critical functions, modify parameters, or even drain funds if such functionalities are present in the unaudited M87 contract. This poses a single point of failure and a significant trust requirement on the owner.
FixTransfer ownership to a multi-signature wallet (e.g., Gnosis Safe) with a sufficient number of signers or a time-locked contract to decentralize control and introduce a delay for critical operations, enhancing security and trust.
StatusUnresolved
High

Unlocked Liquidity Pool

H-02According to the provided metadata, the liquidity pool (LP) associated with the M87 token is reported as 'lock_expired'. This indicates that the LP tokens are no longer locked and can be withdrawn by the owner or designated address at any time. This creates a significant 'rug pull' risk, where the liquidity can be removed, rendering the token worthless.
IssueAccording to the provided metadata, the liquidity pool (LP) associated with the M87 token is reported as 'lock_expired'. This indicates that the LP tokens are no longer locked and can be withdrawn by the owner or designated address at any time. This creates a significant 'rug pull' risk, where the liquidity can be removed, rendering the token worthless.
FixLock the liquidity pool tokens for a substantial period (e.g., several years) using a reputable locker service (e.g., UNCX Network, Pinksale) to assure investors of long-term liquidity and mitigate rug pull concerns.
StatusUnresolved
Medium

Lack of Emergency Measures

M-01Without the M87 contract's source code, it is impossible to verify if any emergency functions (e.g., pause, circuit breaker, emergency withdrawal) are implemented. In the event of a critical vulnerability or exploit, the absence of such mechanisms could lead to irreversible loss of funds or protocol disruption.
IssueWithout the M87 contract's source code, it is impossible to verify if any emergency functions (e.g., pause, circuit breaker, emergency withdrawal) are implemented. In the event of a critical vulnerability or exploit, the absence of such mechanisms could lead to irreversible loss of funds or protocol disruption.
FixImplement and clearly document emergency functions, such as a pause mechanism to halt critical operations, or an emergency withdrawal function to allow users to retrieve funds in case of a severe incident. These functions should ideally be controlled by a multi-signature wallet or a governance mechanism.
StatusUnresolved
Low

No Upgradeability

L-01The contract is not deployed as a proxy, meaning it is not upgradeable. While this eliminates risks associated with complex upgrade mechanisms (e.g., proxy initialization, storage collisions), it also means that any bugs or vulnerabilities discovered post-deployment cannot be fixed without deploying an entirely new contract and migrating users/assets.
IssueThe contract is not deployed as a proxy, meaning it is not upgradeable. While this eliminates risks associated with complex upgrade mechanisms (e.g., proxy initialization, storage collisions), it also means that any bugs or vulnerabilities discovered post-deployment cannot be fixed without deploying an entirely new contract and migrating users/assets.
FixFor non-upgradeable contracts, ensure extremely rigorous testing and auditing before deployment, as the code is immutable. If future feature enhancements or bug fixes are anticipated, consider a well-vetted proxy pattern for future deployments.
StatusUnresolved
Info

Reliance on External Uniswap Interfaces

I-01The provided source code includes interfaces for Uniswap V2 Factory, Pair, and Router contracts, as well as standard ERC20 interfaces. This indicates that the M87 contract likely interacts with the Uniswap ecosystem for liquidity provision or token swapping. While these interfaces are standard and well-vetted, the contract's reliance on external protocols introduces dependency risks.
IssueThe provided source code includes interfaces for Uniswap V2 Factory, Pair, and Router contracts, as well as standard ERC20 interfaces. This indicates that the M87 contract likely interacts with the Uniswap ecosystem for liquidity provision or token swapping. While these interfaces are standard and well-vetted, the contract's reliance on external protocols introduces dependency risks.
FixEnsure that all external contract addresses used by M87 are correctly configured and verified. Implement robust error handling for external calls and consider mechanisms to mitigate risks from potential issues in dependent protocols, although Uniswap V2 is highly stable.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Due to the absence of the M87 contract's source code, a comprehensive technical security assessment (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) could not be performed. The provided interfaces (Uniswap V2, ERC20) and the Address library are standard and generally considered robust. However, the actual implementation of M87, which would utilize these interfaces, remains unverified, posing an unknown but potentially high technical risk.

GovernanceHigh2/10

The contract exhibits high governance and economic risks. Ownership is retained by an External Owned Account (EOA) (7.5 Governance), allowing centralized control over critical functions. Furthermore, the liquidity pool (LP) for the associated token is reported as 'lock_expired' (7.4 Economic), meaning liquidity is currently unlocked and can be removed by the owner, posing a significant rug pull risk. The contract also holds a balance, whose purpose and security are unknown without the source code (7.8 Operations).

UpgradesMedium6/10

The contract is not implemented as a proxy (7.7 Upgrades), meaning it is not upgradeable. While this eliminates risks associated with upgrade mechanisms (e.g., proxy initialization, storage collisions), it also means that any discovered vulnerabilities or bugs in the deployed code cannot be patched, requiring a new deployment.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

30.1% in wallets4.2% in contracts
Effective Concentration31.8%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Locked99.5% · Null Address, UNCX
Top-1 Unlocked Holder0.5%
Lock ExpiryExpired 134d ago

Key Addresses

Deployer
0x962c…ebb3
Unlocked LP Held By
0xae1d…f19f0xb3ac…68a00x0000…8a90

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — owner is an EOA (single private key)
  • Top-10 concentration > 30% (34.3% total → 31.8% effective; 30.1% in EOAs, 4.2% in contracts — moderate)
  • 1 Critical finding(s) from audit
  • 2 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

NEXOCritical RiskCronos (CRO)Critical RiskEpic Chain (EPIC)Critical RiskAZTECCritical RiskCoW Protocol Token (COW)Critical RiskMetronome Synth ETH (MSETH)Critical Risk

Would You Like a More Detailed Audit of Messier?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit