Quantum Audit Logo

Is OpenUSD a Scam?

Early-stage security check — honeypot & rug-pull analysis

OpenUSD OUSD
0xb200…5344
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 1d old
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit report is based on a request for analysis of a smart contract at the provided address. However, no Solidity source code was supplied for review. Therefore, a comprehensive security assessment of the contract's implementation, logic, and potential vulnerabilities could not be performed. The findings below are general best practices and considerations for smart contract development, not specific vulnerabilities identified in the contract.

9 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$188.9K
Liquidity
$10.00M
Price
$1.0000
Token Age
1d
Top 10 Holders
0.0%

Security Findings

Info

Absence of Source Code for Review

I-01The Solidity source code for the contract at address 0xb200…5344 was not provided. This prevents any meaningful security analysis of the contract's implementation, logic, and potential vulnerabilities. Without the source, it is impossible to verify the contract's intended functionality or identify any security flaws.
IssueThe Solidity source code for the contract at address was not provided. This prevents any meaningful security analysis of the contract's implementation, logic, and potential vulnerabilities. Without the source, it is impossible to verify the contract's intended functionality or identify any security flaws.
FixAlways provide the complete and verified Solidity source code for any contract intended for audit. This includes all imported libraries and dependencies. Ensure the provided source code matches the deployed bytecode.
StatusUnresolved
Info

Importance of Comprehensive Testing

I-02Regardless of the contract's complexity, thorough testing is crucial. This includes unit tests for individual functions, integration tests for inter-contract interactions, and fuzz testing to discover edge cases. Without source code, the extent of existing testing cannot be determined.
IssueRegardless of the contract's complexity, thorough testing is crucial. This includes unit tests for individual functions, integration tests for inter-contract interactions, and fuzz testing to discover edge cases. Without source code, the extent of existing testing cannot be determined.
FixImplement a robust testing suite covering all critical paths and potential failure scenarios. Utilize tools like Hardhat, Foundry, and property-based testing frameworks to maximize test coverage and identify vulnerabilities early in the development cycle.
StatusUnresolved
Info

Access Control Best Practices

I-03Proper access control is fundamental to smart contract security, ensuring that only authorized entities can perform sensitive operations. Common patterns include `Ownable`, `AccessControl`, or custom role-based access. Without source code, the implementation of access control cannot be verified.
IssueProper access control is fundamental to smart contract security, ensuring that only authorized entities can perform sensitive operations. Common patterns include `Ownable`, `AccessControl`, or custom role-based access. Without source code, the implementation of access control cannot be verified.
FixClearly define and implement access control for all sensitive functions. Use established patterns like OpenZeppelin's `Ownable` or `AccessControl` and ensure that ownership or administrative roles are secured, ideally with multi-signature wallets.
StatusUnresolved
Info

Consideration for Upgradeability

I-04If the contract is intended to be upgradeable (e.g., via a proxy pattern), the upgrade mechanism itself introduces a significant attack surface. Proper implementation of upgrade patterns (like UUPS or Transparent proxies) is critical. Without source code, it's unknown if the contract is upgradeable or how it's implemented.
IssueIf the contract is intended to be upgradeable (e.g., via a proxy pattern), the upgrade mechanism itself introduces a significant attack surface. Proper implementation of upgrade patterns (like UUPS or Transparent proxies) is critical. Without source code, it's unknown if the contract is upgradeable or how it's implemented.
FixIf upgradeability is desired, use well-vetted proxy patterns and ensure that upgrade logic is secure, transparent, and subject to governance or multi-signature control. Thoroughly test upgrade paths and potential state migrations.
StatusUnresolved
Info

Review of Economic Model and External Dependencies

I-05The economic model of a protocol, including tokenomics, fee structures, and incentive mechanisms, must be robust against manipulation. Additionally, interactions with external contracts (oracles, other DeFi protocols) introduce external risks. Without source code, these aspects cannot be assessed.
IssueThe economic model of a protocol, including tokenomics, fee structures, and incentive mechanisms, must be robust against manipulation. Additionally, interactions with external contracts (oracles, other DeFi protocols) introduce external risks. Without source code, these aspects cannot be assessed.
FixConduct a comprehensive economic analysis to identify potential attack vectors such as flash loan exploits, oracle manipulation, or incentive misalignments. Carefully vet all external dependencies and understand their security profiles and potential failure modes.
StatusUnresolved
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as Open USD (OUSD).
IssueListed on CoinGecko as Open USD (OUSD).
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $10.0M (DexScreener, all pools). 24h trading volume $189K (CoinGecko, all markets, daily snapshot). 24h trading volume $366K (DexScreener, all pools).
IssueLiquidity $10.0M (DexScreener, all pools). 24h trading volume $189K (CoinGecko, all markets, daily snapshot). 24h trading volume $366K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Stablecoin — issuer-backed (fiat reserves)

QA-PROFILEA token designed to hold a fixed value (usually $1). Its safety rests on what backs it and on who can mint, freeze or pause it. Its identity is not independently verified, so it gets none of the allowances an established stablecoin gets: every power its owner holds over supply and transfers is scored in full, because a peg is only as good as whoever can mint. Basis: CoinGecko category: Fiat-backed Stablecoin. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $10.0M of DEX liquidity across 12 pools. Launch: 1 days of market history.
IssueA token designed to hold a fixed value (usually $1). Its safety rests on what backs it and on who can mint, freeze or pause it. Its identity is not independently verified, so it gets none of the allowances an established stablecoin gets: every power its owner holds over supply and transfers is scored in full, because a peg is only as good as whoever can mint. Basis: CoinGecko category: Fiat-backed Stablecoin. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $10.0M of DEX liquidity across 12 pools. Launch: 1 days of market history.
FixCheck what backs the peg and who controls supply: reserve attestations for an issuer-backed coin, collateral and governance for a protocol coin.
StatusAcknowledged
Info

Recently launched — 1 day of market history

QA-RECENTThe token's oldest DEX pool is 1 day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 1 day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Due to the absence of provided Solidity source code, a technical analysis of the contract's architecture (7.1), code security (7.2), and access control mechanisms (7.3) could not be conducted. Without the code, it is impossible to identify common vulnerabilities such as reentrancy, integer overflows, or logic errors. Best practices typically include modular design and robust input validation.

GovernanceHigh3/10

Without the contract's source code, it is not possible to evaluate its economic model (7.4) or governance mechanisms (7.5). A robust economic model typically includes safeguards against manipulation and clear tokenomics. Effective governance often involves decentralized decision-making and transparent upgrade paths. External dependencies (7.6) and their potential impact also remain unknown.

UpgradesMedium5/10

The upgradeability strategy (7.7) and operational procedures (7.8) for the contract cannot be determined without access to its source code. If the contract is upgradeable, it is crucial to ensure that upgrade mechanisms are secure, well-tested, and transparent. Proper operational security includes multi-signature controls for critical functions and emergency pause capabilities.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass

Liquidity Depth

Show 4 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool; this pool is 100% of DEX liquidity) — who holds it cannot be verified
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Morpho Token (MORPHO)Medium RiskTether USD (USDT)Medium RiskevoMedium RiskBIOMedium RiskHydrex (HYDX)Medium RiskAavegotchi GHST Token (GHST)Medium Risk

Would You Like a More Detailed Audit of OpenUSD?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit