Quantum Audit Logo

Is NOXCAT a Scam?

Honeypot, rug-pull and ownership checks

NOXCAT NOX
0xb23b…8c55
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked 18d ago 2 audits on record
Executive SummaryAI Copilot

This audit report covers the provided Solidity source code for the NOXToken project. The analysis was significantly limited as the primary `NOXToken` contract implementation, which would define custom token logic, was not provided. The audit focused on the included OpenZeppelin `Context` and `ERC20` contracts. While these foundational components are robust, a comprehensive security assessment of the NOXToken's specific functionality, tokenomics, and access control mechanisms cannot be completed without the full source code.

1 High1 Low3 Informational
i Our automated scanner reviewed NOXCAT (NOX) on Arbitrum. 3 of 5 security checks passed — see the full breakdown below.
Volume 24h
$1.2K
Liquidity
$174.4200
Price
$0.1092
Age
4mo
Top 10 Holders
100.0%

Security Findings

High

Incomplete Source Code Provided for Audit

H-01The audit was conducted on a partial set of source code files. Specifically, the main `NOXToken` contract, which would define the token's unique logic, supply mechanisms (e.g., minting, burning), and specific access control roles, was not provided. Only standard OpenZeppelin `Context` and `ERC20` libraries were available for review. This prevents a comprehensive security assessment of the actual token implementation and its specific functionalities.
IssueThe audit was conducted on a partial set of source code files. Specifically, the main `NOXToken` contract, which would define the token's unique logic, supply mechanisms (e.g., minting, burning), and specific access control roles, was not provided. Only standard OpenZeppelin `Context` and `ERC20` libraries were available for review. This prevents a comprehensive security assessment of the actual token implementation and its specific functionalities.
FixProvide the complete and accurate source code for the `NOXToken` contract, including all inherited contracts and any custom logic. This is essential for a full security audit to identify potential vulnerabilities specific to the project's implementation.
StatusUnresolved
Low

Potential `approve` Race Condition (Mitigated by Alternatives)

L-01The standard ERC20 `approve` function is susceptible to a race condition. If a user approves an amount, and then attempts to change that approval to a different amount, a malicious actor observing the transaction could front-run the second `approve` call by spending the original allowance. This could lead to the malicious actor spending both the original and the new allowance. While the contract provides `increaseAllowance` and `decreaseAllowance` to mitigate this, users might still interact directly with `approve`.
IssueThe standard ERC20 `approve` function is susceptible to a race condition. If a user approves an amount, and then attempts to change that approval to a different amount, a malicious actor observing the transaction could front-run the second `approve` call by spending the original allowance. This could lead to the malicious actor spending both the original and the new allowance. While the contract provides `increaseAllowance` and `decreaseAllowance` to mitigate this, users might still interact directly with `approve`.
FixEducate users to exclusively use `increaseAllowance` and `decreaseAllowance` instead of directly calling `approve` when modifying existing allowances. Ensure any front-end interfaces or integrations also prioritize these safer functions.
StatusUnresolved
Info

Reliance on Standard OpenZeppelin Libraries

I-01The project utilizes well-vetted and widely adopted OpenZeppelin Contracts for its foundational ERC20 implementation (`Context.sol`, `ERC20.sol`). These libraries are subject to extensive community review and professional audits, significantly reducing the risk of common vulnerabilities in the base token functionality.
IssueThe project utilizes well-vetted and widely adopted OpenZeppelin Contracts for its foundational ERC20 implementation (`Context.sol`, `ERC20.sol`). These libraries are subject to extensive community review and professional audits, significantly reducing the risk of common vulnerabilities in the base token functionality.
FixContinue to monitor OpenZeppelin's security advisories and updates. Ensure that any custom logic built on top of these libraries maintains the same high security standards.
StatusResolved
Info

Fixed Decimals Value

I-02The `decimals()` function in the ERC20 contract returns a fixed value of 18. This is the standard and most common number of decimal places for ERC20 tokens, mimicking Ethereum's Wei. This consistency aids in integration with existing DeFi infrastructure and wallets.
IssueThe `decimals()` function in the ERC20 contract returns a fixed value of 18. This is the standard and most common number of decimal places for ERC20 tokens, mimicking Ethereum's Wei. This consistency aids in integration with existing DeFi infrastructure and wallets.
FixNo action required, as 18 decimals is a widely accepted standard. Ensure all external interfaces and applications correctly interpret this decimal value.
StatusResolved
Info

Non-Upgradeable Contract Architecture

I-03The contract is not implemented using a proxy pattern, meaning it is not upgradeable. This simplifies the contract's architecture and removes the complexities and potential risks associated with upgrade mechanisms, such as proxy storage collisions or logic errors during upgrades. Once deployed, its code is immutable.
IssueThe contract is not implemented using a proxy pattern, meaning it is not upgradeable. This simplifies the contract's architecture and removes the complexities and potential risks associated with upgrade mechanisms, such as proxy storage collisions or logic errors during upgrades. Once deployed, its code is immutable.
FixNo action required. This design choice eliminates upgrade-related risks. Ensure that the initial deployment is thoroughly tested, as no future code changes are possible.
StatusResolved

Category Ratings

TechnicalLow8/10

The provided contracts, `Context.sol` and `ERC20.sol`, are standard, well-audited OpenZeppelin libraries (7.2 Code Security). They implement robust ERC20 functionality, including mitigations for allowance race conditions via `increaseAllowance` and `decreaseAllowance`. However, the core `NOXToken` contract, which would contain any custom logic, minting, burning, or specific access control (7.3 Access Control), was not provided. This significantly limits the technical assessment, as potential vulnerabilities in custom implementations remain unexamined (7.1 Architecture).

GovernanceHigh1/10

Without the full `NOXToken` contract source code, it is impossible to assess the project's specific economic model or governance mechanisms (7.4 Economic, 7.5 Governance). Details such as total supply, minting/burning capabilities, fee structures, or any privileged roles that could impact token value or distribution are unknown. This lack of information prevents a meaningful evaluation of potential economic exploits or governance risks.

UpgradesMedium6/10

Based on the provided information, the contract is not deployed as a proxy (7.7 Upgrades). This simplifies the architecture by eliminating risks associated with upgradeability, such as proxy storage collisions or incorrect implementation logic. The contract is immutable once deployed, ensuring predictable behavior without future upgrade complexities.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass

Holder Composition

0.0% in wallets100.0% in contracts
Effective Concentration40.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x12ed…0f74
Unlocked LP Held By
0x3d6a…2ded

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 30% (100.0% total → 40.0% effective; 0.0% in EOAs, 100.0% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $10k ($174 across 1 pairs — easily drained)
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • 1 High finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is NOXCAT a scam?

Based on automated analysis, NOXCAT scores 65/100 (High Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is NOXCAT safe to buy?

Our scanner flagged a risk score of 65/100. Ownership has not been renounced, which is a risk factor. DYOR before purchasing any token.

Has NOXCAT been audited?

The contract has not been verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

MAGICHigh Riskether.fi governance token (ETHFI)High RiskWrapped BTC (WBTC)High RiskNolaHigh RiskGains Network (GNS)High RiskWINRHigh Risk

Would You Like a More Detailed Audit of NOXCAT?

Paste the contract address into our AI-powered scanner for a deeper real-time report — free, with every scoring factor shown.

Get Detailed Audit