Quantum Audit Logo

Is Opal a Scam?

Early-stage security check — honeypot & rug-pull analysis

Opal OPAL
0x119b…cd1f
Base Not verifiedLast checked 3d ago 1 audit on record New Launch · 1d old
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit report is based on an unverified contract address where the source code was not provided. Therefore, a comprehensive security analysis for vulnerabilities, economic risks, or upgradeability concerns could not be performed. All risk levels are set to Low as no specific issues could be identified without code. Users should exercise extreme caution when interacting with unverified contracts.

3 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$63.7K
Liquidity
$2.77M
Price
$0.123
Token Age
1d
Top 10 Holders
80.7%

Security Findings

Info

Source Code Not Provided/Verified

I-01The source code for the contract at 0x119b…cd1f was not provided or verified on the block explorer. This prevents any form of static analysis, dynamic testing, or manual review to identify vulnerabilities (7.2 Code Security). Without source code, the contract's intended functionality and security posture cannot be independently confirmed, posing a significant trust and transparency issue.
IssueThe source code for the contract at was not provided or verified on the block explorer. This prevents any form of static analysis, dynamic testing, or manual review to identify vulnerabilities (7.2 Code Security). Without source code, the contract's intended functionality and security posture cannot be independently confirmed, posing a significant trust and transparency issue.
FixAlways verify contract source code on block explorers. This allows for public scrutiny, independent audits, and user confidence in the contract's operations. Projects should prioritize transparency by publishing their code.
StatusUnresolved
Info

Centralization Risk from EOA Owner

I-02The contract is owned by an Externally Owned Account (EOA) 0xa773…b13f. Without source code, the extent of control this owner has over critical functions (e.g., pausing, upgrading, fee changes, fund withdrawals) is unknown (7.3 Access Control). This poses a potential centralization risk, as a single entity could unilaterally execute privileged operations, potentially leading to censorship, fund manipulation, or other malicious actions.
IssueThe contract is owned by an Externally Owned Account (EOA) . Without source code, the extent of control this owner has over critical functions (e.g., pausing, upgrading, fee changes, fund withdrawals) is unknown (7.3 Access Control). This poses a potential centralization risk, as a single entity could unilaterally execute privileged operations, potentially leading to censorship, fund manipulation, or other malicious actions.
FixImplement multi-signature wallets (e.g., Gnosis Safe) or decentralized governance mechanisms for critical administrative functions. This distributes control, reduces single points of failure, and enhances the security and trustlessness of the protocol.
StatusUnresolved
Info

Unknown External Dependencies and Interactions

I-03Smart contracts often interact with other contracts, such as oracles, token contracts, or other DeFi protocols. Without source code, it's impossible to identify these external dependencies, assess their security, or understand the potential cascading risks from vulnerabilities in integrated protocols (7.6 External). This lack of visibility prevents a comprehensive risk assessment of the contract's broader ecosystem interactions.
IssueSmart contracts often interact with other contracts, such as oracles, token contracts, or other DeFi protocols. Without source code, it's impossible to identify these external dependencies, assess their security, or understand the potential cascading risks from vulnerabilities in integrated protocols (7.6 External). This lack of visibility prevents a comprehensive risk assessment of the contract's broader ecosystem interactions.
FixClearly document all external dependencies and their respective contract addresses, functionalities, and security audit statuses. Ensure that all integrated protocols are robust, well-audited, and have strong security track records to minimize exposure to external risks.
StatusUnresolved

Category Ratings

TechnicalLow8/10

Without access to the contract's source code, a technical security analysis (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be performed. This prevents the identification of common vulnerabilities such as reentrancy, integer overflows, or logic errors. The lack of transparency significantly hinders any assessment of the contract's internal mechanisms and security posture, making it impossible to confirm adherence to secure coding practices.

GovernanceMedium4/10

An assessment of economic (7.4 Economic) and governance (7.5 Governance) risks is not possible without understanding the contract's functionality and tokenomics. The presence of an EOA owner () introduces a potential centralization risk, as a single entity controls critical functions. Without source code, the extent of this control and its implications for economic stability and governance remain unknown.

UpgradesLow7/10

The contract's upgradeability status (7.7 Upgrades) is unknown as no source code was provided and `is_proxy` is false. Without this information, it's impossible to determine if the contract can be modified, which patterns are used (e.g., UUPS, Transparent), or what risks might be associated with potential upgrades. This lack of clarity impacts long-term security and maintainability, as future changes cannot be predicted or audited.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionPass
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

6.1% in wallets74.6% in contracts
Effective Concentration35.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Locked100.0% · Null Address, TeamFinance

Key Addresses

Deployer
0xa773…b13f

What Raised This Score

  • Ownership NOT renounced — owner is an EOA (single private key)
  • Top-10 concentration > 30% (80.7% total → 35.9% effective; 6.1% in EOAs, 74.6% in contracts — moderate)
  • Token age < 7 days (early, volatile)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

PlayMedium RiskThe Stonks Exchange (STONKEX)Medium RiskBasehatMedium Riskaixbt by Virtuals (AIXBT)Medium RiskOpenGradient (OPG)Medium RiskZoraMedium Risk

Would You Like a More Detailed Audit of Opal?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit