Quantum Audit Logo
Launch App

Is NeoSoul a Scam?

Early-stage security check — honeypot & rug-pull analysis

NeoSoul NEOS
0xa201…7284
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 23h old
Executive SummaryAI Copilot

This report is generated for the contract at 0xa201eff84651d8b3e57587223ba5ce06035a7284 on Arbitrum. No contract source code was provided for analysis, therefore a comprehensive security audit could not be performed. The findings below reflect the lack of available information rather than specific code vulnerabilities.

1 Medium10 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$139.9K
Liquidity
$85.0K
Price
$0.1231
Token Age
23h
Top 10 Holders
93.7%

Security Findings

Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0x738f…04b0 — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0x738f…04b0 — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

No Contract Source Code Provided

I-01The audit request did not include the source code for the contract at 0xa201…7284. This prevents any form of static analysis, dynamic testing, or manual review of the contract's logic and security posture. All aspects of the audit, including technical, economic, governance, and upgradeability, are unassessable.
IssueThe audit request did not include the source code for the contract at . This prevents any form of static analysis, dynamic testing, or manual review of the contract's logic and security posture. All aspects of the audit, including technical, economic, governance, and upgradeability, are unassessable.
FixAlways provide the full, verified source code for all contracts intended for audit. Ensure the code is publicly verifiable on block explorers like Arbiscan to enhance transparency and trust.
StatusUnresolved
Info

Verification Status Unknown

I-02The contract at 0xa201…7284 is not indicated as verified on the block explorer (is_verified: false). Unverified contracts pose a significant risk as their deployed bytecode cannot be easily matched against human-readable source code, making it difficult for users and auditors to understand their functionality and ensure safety.
IssueThe contract at is not indicated as verified on the block explorer (is_verified: false). Unverified contracts pose a significant risk as their deployed bytecode cannot be easily matched against human-readable source code, making it difficult for users and auditors to understand their functionality and ensure safety.
FixVerify the contract's source code on the respective block explorer (e.g., Arbiscan) to provide transparency and allow for public scrutiny. This is a fundamental step for user trust and security.
StatusUnresolved
Info

Compiler Version Undetermined

I-03Without the contract's source code, the Solidity compiler version used for deployment cannot be determined. Knowing the compiler version is crucial for identifying potential vulnerabilities specific to certain compiler versions (e.g., optimizer bugs, known issues in older versions).
IssueWithout the contract's source code, the Solidity compiler version used for deployment cannot be determined. Knowing the compiler version is crucial for identifying potential vulnerabilities specific to certain compiler versions (e.g., optimizer bugs, known issues in older versions).
FixWhen providing source code, ensure the `pragma solidity` directive is correctly specified. Ideally, use a recent, stable, and well-audited compiler version, and avoid using `^` in pragma statements for production deployments.
StatusUnresolved
Info

Proxy Implementation Status Unknown

I-04The provided information indicates `is_proxy: false` and `implementation: null`, but without source code, it's impossible to confirm if this contract is part of a proxy pattern or an immutable contract. If it were a proxy, the security of the implementation contract would be paramount, and upgradeability considerations would apply.
IssueThe provided information indicates `is_proxy: false` and `implementation: null`, but without source code, it's impossible to confirm if this contract is part of a proxy pattern or an immutable contract. If it were a proxy, the security of the implementation contract would be paramount, and upgradeability considerations would apply.
FixIf the contract is intended to be part of a proxy system, provide the source code for both the proxy and its implementation(s). Clearly document the proxy pattern used (e.g., UUPS, Transparent) and the upgrade mechanism.
StatusUnresolved
Info

Lack of Operational Context and Documentation

I-05Without contract source code or accompanying documentation, the intended purpose, operational procedures (7.8 Operations), and external dependencies (7.6 External) of the contract are entirely unknown. This lack of context hinders any assessment of its overall security and integration risks.
IssueWithout contract source code or accompanying documentation, the intended purpose, operational procedures (7.8 Operations), and external dependencies (7.6 External) of the contract are entirely unknown. This lack of context hinders any assessment of its overall security and integration risks.
FixProvide comprehensive documentation outlining the contract's architecture, intended functionality, external interactions (e.g., oracles, other protocols), administrative roles, and operational procedures. This is vital for a complete security review.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 93.7% of supply. What remains: 91.2% in wallets, 2.4% in other contracts. The deployer/owner wallet itself holds 2.4%. 417 holders in total.
IssueThe ten largest holders own 93.7% of supply. What remains: 91.2% in wallets, 2.4% in other contracts. The deployer/owner wallet itself holds 2.4%. 417 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY417 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue417 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $85K (DexScreener, all pools). 24h trading volume $140K (DexScreener, all pools).
IssueLiquidity $85K (DexScreener, all pools). 24h trading volume $140K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $85K of DEX liquidity across 1 pools. Launch: under a day of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $85K of DEX liquidity across 1 pools. Launch: under a day of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — less than a day of market history

QA-RECENTThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Without access to the contract's source code, a technical security assessment (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be performed. Key areas like reentrancy, integer overflows, and access control mechanisms remain unexamined. The absence of code prevents any evaluation of implementation quality or adherence to secure coding practices.

GovernanceHigh1/10

An economic and governance risk assessment (7.4 Economic, 7.5 Governance) requires understanding the contract's logic, tokenomics, and administrative controls. Without the source code, it is impossible to evaluate potential economic exploits, oracle dependencies, or the distribution of governance power. Therefore, no assessment of these critical areas can be made.

UpgradesMedium6/10

The upgradeability status (7.7 Upgrades) of the contract cannot be determined without its source code. It is unknown if the contract utilizes a proxy pattern (e.g., UUPS, Transparent) or is immutable. This prevents an assessment of upgrade safety, potential for malicious upgrades, or the process for future enhancements.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

91.2% in wallets2.4% in contracts
Effective Concentration92.2%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.8%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xc43c…9a60
Unlocked LP Held By
0x738f…04b00x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — held by independent providers — market-depth risk
  • Top-10 concentration > 70% (93.7% total → 92.2% effective; 91.2% in EOAs, 2.4% in contracts)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ChipHigh RiskTHEA Finance (THEA)High RiskCoinbase Wrapped BTC (CBBTC)High RiskInfini (IFN)High RiskEunice (EUIAI)High RiskMonerium EURe (EURE)High Risk

Would You Like a More Detailed Audit of NeoSoul?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit