Quantum Audit Logo
Launch App

Is Noah a Scam?

Early-stage security check — honeypot & rug-pull analysis

Noah NOAH
0x5166…0083
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 23h old
Executive SummaryAI Copilot

This audit report is based on an analysis where no contract source code was provided. Therefore, a comprehensive security assessment of specific vulnerabilities, architectural patterns, or economic risks could not be performed. The findings and risk levels presented are theoretical or general best practices, not specific to any deployed code.

1 Medium10 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$111.9K
Liquidity
$86.0K
Price
$0.2602
Token Age
23h
Top 10 Holders
59.2%

Security Findings

Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0xf5ff…ff45 — holds 99.9% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0xf5ff…ff45 — holds 99.9% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Importance of Comprehensive Testing

I-01Without source code, the extent of testing (unit, integration, fuzzing) is unknown. Comprehensive testing is fundamental to identifying and mitigating vulnerabilities before deployment.
IssueWithout source code, the extent of testing (unit, integration, fuzzing) is unknown. Comprehensive testing is fundamental to identifying and mitigating vulnerabilities before deployment.
FixImplement a rigorous testing framework covering all critical paths, edge cases, and potential attack vectors. Utilize tools for static analysis, dynamic analysis, and fuzzing.
StatusUnresolved
Info

Secure Access Control Design

I-02The absence of code prevents evaluation of access control mechanisms. Improper access control can lead to unauthorized function calls, administrative privilege misuse, or fund manipulation.
IssueThe absence of code prevents evaluation of access control mechanisms. Improper access control can lead to unauthorized function calls, administrative privilege misuse, or fund manipulation.
FixDesign a least-privilege access control model. Use established patterns like `Ownable` or role-based access control (RBAC) with multi-signature wallets for critical operations.
StatusUnresolved
Info

Reentrancy Protection

I-03Reentrancy is a common and critical vulnerability in Solidity. Without code, it's impossible to confirm if reentrancy guards are properly implemented for functions handling external calls or value transfers.
IssueReentrancy is a common and critical vulnerability in Solidity. Without code, it's impossible to confirm if reentrancy guards are properly implemented for functions handling external calls or value transfers.
FixAlways use the `nonReentrant` modifier from OpenZeppelin's ReentrancyGuard for any function that performs external calls and modifies state, especially when handling Ether or tokens.
StatusUnresolved
Info

Handling External Calls Safely

I-04Interactions with external contracts or addresses can introduce various risks, including reentrancy, unexpected behavior, or gas limit issues. The safety of such interactions cannot be assessed without code.
IssueInteractions with external contracts or addresses can introduce various risks, including reentrancy, unexpected behavior, or gas limit issues. The safety of such interactions cannot be assessed without code.
FixFollow the 'Checks-Effects-Interactions' pattern. Minimize external calls and ensure they are handled safely, using low-level calls with gas limits if necessary, and verifying return values.
StatusUnresolved
Info

Upgradeability Considerations

I-05If the contract is intended to be upgradeable, the specific proxy pattern and its implementation details are unknown. Incorrect upgrade patterns or faulty upgrade logic can lead to critical vulnerabilities.
IssueIf the contract is intended to be upgradeable, the specific proxy pattern and its implementation details are unknown. Incorrect upgrade patterns or faulty upgrade logic can lead to critical vulnerabilities.
FixIf upgradeability is desired, use well-audited proxy patterns (e.g., UUPS, Transparent) and ensure proper storage slot management, initializer patterns, and secure upgrade mechanisms.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 59.2% of supply. What remains: 43.8% in wallets, 15.4% in other contracts. 1,012 holders in total.
IssueThe ten largest holders own 59.2% of supply. What remains: 43.8% in wallets, 15.4% in other contracts. 1,012 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY1,012 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue1,012 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $86K (DexScreener, all pools). 24h trading volume $112K (DexScreener, all pools).
IssueLiquidity $86K (DexScreener, all pools). 24h trading volume $112K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $86K of DEX liquidity across 1 pools. Launch: under a day of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $86K of DEX liquidity across 1 pools. Launch: under a day of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — less than a day of market history

QA-RECENTThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Due to the absence of contract source code, a detailed technical analysis covering architecture (7.1), code security (7.2), and access control (7.3) could not be conducted. Without code, it is impossible to identify specific vulnerabilities like reentrancy, integer overflows, or improper access controls. General best practices for secure coding are assumed to be important for any future development.

GovernanceHigh1/10

Without contract code, an assessment of economic (7.4) and governance (7.5) risks is not feasible. This includes evaluating tokenomics, incentive mechanisms, potential for flash loan attacks, or the structure of any decentralized governance. External (7.6) dependencies and their associated risks also remain unexamined.

UpgradesMedium5/10

The upgradeability strategy (7.7) and operational procedures (7.8) could not be assessed due to the lack of contract source code. If the contract were a proxy, its implementation and proxy pattern would need careful review for upgrade safety. Without this information, potential risks related to upgradeability, such as storage collisions or improper initialization, cannot be identified.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

43.8% in wallets15.4% in contracts
Effective Concentration49.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.9%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x8505…5ab5
Unlocked LP Held By
0xf5ff…ff450x9bd2…168c

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — who holds it cannot be verified
  • Top-10 concentration > 30% (59.2% total → 49.9% effective; 43.8% in EOAs, 15.4% in contracts)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ether.fi governance token (ETHFI)High RiskCluster Protocol (CP)High RiskWorldMobileToken (WMTX)High RiskApple 3x Long (AAPLX3L)High RiskResearchCoin (RSC)High RiskFren PetHigh Risk

Would You Like a More Detailed Audit of Noah?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit