Quantum Audit Logo

Is Numeraire Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Numeraire NMR
0x1776…6671
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The UpgradeDelegate contract, serving as an implementation for a proxy, manages token-like balances with significant administrative control. Key findings include the ability for privileged roles to mint new tokens, directly manipulate user balances, and issues related to mapping deletion and an uninitialized state variable. These capabilities introduce considerable economic and technical risks due to the high degree of centralization and potential for misuse by authorized addresses.

2 High3 Medium4 Informational
Volume 24h
$432.9K
Liquidity
$182.7K
Price
$12.5200
Token Age
5y
Top 10 Holders
57.9%

Security Findings

High

A critical function relies on an uninitialized value, potentially leading to incorrect calculations.

CD-02The `getMintable` function uses a state variable that has never been assigned a value. This means the function's output will be based on a default or garbage value, which could lead to incorrect calculations or unexpected behavior, potentially affecting the minting logic or other critical operations.
IssueThe `getMintable` function uses a state variable that has never been assigned a value. This means the function's output will be based on a default or garbage value, which could lead to incorrect calculations or unexpected behavior, potentially affecting the minting logic or other critical operations.
FixToken holders should be concerned that a function related to minting might not operate correctly due to a programming error. It is strongly recommended that the project team initialize all state variables before use, especially those impacting critical logic like `getMintable`, to ensure the contract behaves as expected and prevents potential exploits or economic discrepancies.
StatusUnresolved
High

Tournament administrator can take or move anyone's tokens.

CP-02The `withdraw` function, controlled by the `tournament` administrator, can directly modify any token holder's balance. This means the `tournament` administrator can burn tokens from any address or move them to another address without the holder's permission.
IssueThe `withdraw` function, controlled by the `tournament` administrator, can directly modify any token holder's balance. This means the `tournament` administrator can burn tokens from any address or move them to another address without the holder's permission.
FixToken holders face a significant risk as the `tournament` administrator can arbitrarily seize or move their tokens. It is strongly recommended that this power be removed or severely restricted, ideally requiring explicit user consent for any token movement, or placing it under a robust, transparent governance mechanism.
StatusUnresolved
Medium

Certain administrative actions can unintentionally clear important data.

CD-01The `createRound` and `numeraiTransfer` functions perform operations that can delete entries from mappings. While this might be intended in some cases, it can also lead to unexpected loss of data or state, potentially causing incorrect behavior or loss of funds if not handled carefully.
IssueThe `createRound` and `numeraiTransfer` functions perform operations that can delete entries from mappings. While this might be intended in some cases, it can also lead to unexpected loss of data or state, potentially causing incorrect behavior or loss of funds if not handled carefully.
FixToken holders should be aware that administrative actions might clear certain data points. It is recommended that the project team ensure that mapping deletions are always intentional and thoroughly tested to prevent accidental data loss or state corruption that could impact the system's integrity.
StatusUnresolved
Medium

Administrator can create new tokens, diluting existing holders.

CP-01The `numeraiTransfer` function allows the contract's owner to create new tokens out of thin air. This increases the total supply, which can reduce the value of tokens held by everyone else without their consent.
IssueThe `numeraiTransfer` function allows the contract's owner to create new tokens out of thin air. This increases the total supply, which can reduce the value of tokens held by everyone else without their consent.
FixToken holders should be aware that the contract owner has the power to mint an unlimited number of new tokens. It is recommended that the ability to mint new tokens be removed or placed under strict, transparent governance control, such as a multi-signature wallet with a time-lock.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0xf58b…9131 — holds 92.6% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 72% of the token's DEX liquidity; the other pools were not assessed.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0xf58b…9131 — holds 92.6% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 72% of the token's DEX liquidity; the other pools were not assessed.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 57.9% of supply. What remains: 27.5% in wallets, 30.4% in other contracts. 42,142 holders in total.
IssueThe ten largest holders own 57.9% of supply. What remains: 27.5% in wallets, 30.4% in other contracts. 42,142 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Identity verified by independent sources

QA-IDENTITYListed on CoinGecko as Numeraire (NMR), market cap $83M, rank #336. On GoPlus's list of trusted tokens. Traded on Binance, Coinbase. 42,142 holders. Verified by: CoinGecko, GoPlus, exchange listings.
IssueListed on CoinGecko as Numeraire (NMR), market cap $83M, rank #336. On GoPlus's list of trusted tokens. Traded on Binance, Coinbase. 42,142 holders. Verified by: CoinGecko, GoPlus, exchange listings.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $255K (DexScreener, all pools). 24h trading volume $65.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $594K (DexScreener, all pools).
IssueLiquidity $255K (DexScreener, all pools). 24h trading volume $65.4M (CoinGecko, all markets, daily snapshot). 24h trading volume $594K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $255K of DEX liquidity across 8 pools. Launch: 1982 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $255K of DEX liquidity across 8 pools. Launch: 1982 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalLow7/10

The contract includes an `emergencyStop()` function, restricted to the owner, which can halt operations, providing a safety mechanism (7.8 Operations). However, the contract exhibits significant technical vulnerabilities. It lacks standard ERC-20 functions, which could lead to unexpected behavior when interacting with other protocols (7.1 Architecture). Crucially, the `tournament` role can directly change any holder's balance via `withdraw(address,address,uint256)`, allowing for arbitrary token burning or movement (7.3 Access Control, 7.2 Code Security). Additionally, the `numeraiTransfer(address,uint256)` function allows the owner to mint new tokens, diluting existing holders (7.3 Access Control, 7.2 Code Security). There are also code quality issues such as mapping deletion in `createRound` and `numeraiTransfer`, and an uninitialized state variable affecting `getMintable` (7.2 Code Security).

GovernanceHigh1/10

The `emergencyStop()` function provides a centralized control point to mitigate ongoing economic damage in an emergency (7.4 Economic, 7.5 Governance). However, the economic model is highly centralized and vulnerable to misuse by privileged roles. The `owner` can mint an unlimited supply of tokens via `numeraiTransfer`, directly impacting the token's value through inflation (7.4 Economic). The `tournament` role possesses the power to arbitrarily modify any user's token balance using `withdraw`, which could lead to unauthorized asset seizure or loss for holders (7.4 Economic, 7.5 Governance). These broad powers concentrate significant economic control in a few addresses, posing a substantial risk to token holders.

UpgradesHigh2/10

The contract is part of a proxy architecture, allowing for future upgrades to fix bugs or add features without migrating user funds (7.7 Upgrades). However, the use of a custom proxy pattern, as detected, introduces complexity. Without a detailed understanding of the specific upgrade mechanism, there's a risk of vulnerabilities in the upgrade process itself, such as improper initialization or storage collisions (7.7 Upgrades). Any future upgrade could potentially introduce new vulnerabilities or alter critical logic, impacting the security and economic stability of the system.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

27.5% in wallets30.4% in contracts
Effective Concentration39.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 2 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder92.6%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x9608…0ba0
Unlocked LP Held By
0xf58b…91310xe1d2…adee0x7958…205d

What Raised This Score

  • Owner can change any holder's balance (seize or credit tokens)
  • Mintable supply — no cap found, dilution unbounded
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool; this pool is 72% of DEX liquidity) — who holds it cannot be verified
  • Top-10 concentration > 30% (57.9% total → 39.7% effective; 27.5% in EOAs, 30.4% in contracts)
  • Code: Certain administrative actions can unintentionally clear important data. (Medium, static analysis)
  • Code: A critical function relies on an uninitialized value, potentially leading to incorrect calculations. (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Espresso (ESP)Medium RiskPRDCTR (PRD)Medium RiskAXGTMedium RiskSPACE ID (ID)Medium RiskWrapped Pulse from PulseChain (WPLS)High RiskUSDS Stablecoin (USDS)Medium Risk

Would You Like a More Detailed Audit of Numeraire?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit