Quantum Audit Logo

Is Orthogonal a Scam?

Early-stage security check — honeypot & rug-pull analysis

Orthogonal ORTGO
0x868a…9d1f
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 1d old
Executive SummaryAI Copilot

No contract source code was provided for analysis. Therefore, a comprehensive security audit could not be performed. The report reflects general security best practices and informational findings regarding the importance of source code availability for a thorough assessment.

1 Medium8 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$147.9K
Liquidity
$74.4K
Price
$0.01902
Token Age
1d
Top 10 Holders
78.9%

Security Findings

Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0xce1f…a2cf — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0xce1f…a2cf — holds 99.8% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Missing Source Code for Comprehensive Audit

I-01The source code for the contract at 0x868a…9d1f was not provided. This prevents a thorough security audit, including analysis of architectural design (7.1 Architecture), code-level vulnerabilities (7.2 Code Security), and specific access control mechanisms (7.3 Access Control).
IssueThe source code for the contract at was not provided. This prevents a thorough security audit, including analysis of architectural design (7.1 Architecture), code-level vulnerabilities (7.2 Code Security), and specific access control mechanisms (7.3 Access Control).
FixAlways provide verified source code for all deployed contracts. This allows for a complete security assessment, enhances transparency, and enables the community to verify the contract's intended behavior.
StatusUnresolved
Info

Inability to Verify Security Best Practices

I-02Without source code, it is impossible to verify if standard security best practices, such as reentrancy guards, integer overflow/underflow protections, proper event emission, and secure handling of external calls (7.6 External), have been implemented. This leaves potential unknown vulnerabilities unaddressed.
IssueWithout source code, it is impossible to verify if standard security best practices, such as reentrancy guards, integer overflow/underflow protections, proper event emission, and secure handling of external calls (7.6 External), have been implemented. This leaves potential unknown vulnerabilities unaddressed.
FixEnsure all smart contracts adhere to established security best practices. Implement robust testing, including unit, integration, and fuzz testing, to validate the correctness and security of the code. Utilize secure development patterns and libraries.
StatusUnresolved
Info

Lack of Transparency and Trust

I-03The absence of publicly available and verified source code for a deployed contract significantly reduces transparency and trust for users and the broader ecosystem. It prevents independent verification of the contract's logic, economic model (7.4 Economic), and governance structure (7.5 Governance), raising concerns about hidden functionalities or potential backdoors.
IssueThe absence of publicly available and verified source code for a deployed contract significantly reduces transparency and trust for users and the broader ecosystem. It prevents independent verification of the contract's logic, economic model (7.4 Economic), and governance structure (7.5 Governance), raising concerns about hidden functionalities or potential backdoors.
FixPublish and verify the source code for all deployed contracts on block explorers (e.g., Etherscan, Arbiscan). This promotes transparency, allows for community scrutiny, and builds confidence in the project's integrity and security posture.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 78.9% of supply. What remains: 50.9% in wallets, 28.0% in other contracts. The deployer/owner wallet itself holds 7.2%. 2,240 holders in total.
IssueThe ten largest holders own 78.9% of supply. What remains: 50.9% in wallets, 28.0% in other contracts. The deployer/owner wallet itself holds 7.2%. 2,240 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY2,240 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue2,240 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $74K (DexScreener, all pools). 24h trading volume $148K (DexScreener, all pools).
IssueLiquidity $74K (DexScreener, all pools). 24h trading volume $148K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $74K of DEX liquidity across 1 pools. Launch: 1 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $74K of DEX liquidity across 1 pools. Launch: 1 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — 1 day of market history

QA-RECENTThe token's oldest DEX pool is 1 day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 1 day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Without access to the contract's source code, a detailed technical security assessment (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be conducted. General best practices for EVM smart contracts include robust input validation and reentrancy protection. The absence of source code prevents verification of these critical security measures, such as ensuring proper access control mechanisms are in place or that common vulnerabilities like reentrancy are mitigated.

GovernanceHigh1/10

The economic and governance aspects (7.4 Economic, 7.5 Governance) of the contract cannot be assessed without source code. Key considerations typically include tokenomics, fee structures, and decision-making processes. Without visibility into the contract's logic, potential economic exploits or governance vulnerabilities, such as oracle manipulation or centralized control, remain unknown.

UpgradesMedium6/10

Upgradeability mechanisms (7.7 Upgrades) and their associated risks cannot be determined without the contract's source code. Proxy patterns (e.g., UUPS, Transparent) introduce specific upgrade safety considerations, such as storage collisions and proper initialization. The lack of source prevents any assessment of upgrade safety or operational risks (7.8 Operations), including potential for malicious upgrades or administrative control over the contract.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

50.9% in wallets28.0% in contracts
Effective Concentration62.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.8%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x06c7…1527
Unlocked LP Held By
0xce1f…a2cf0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — held by independent providers — market-depth risk
  • Top-10 concentration > 50% (78.9% total → 62.1% effective; 50.9% in EOAs, 28.0% in contracts)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Dai Stablecoin (DAI)High RiskAethir Token (ATH)High RiskOrthogonal (ORGOL)High RiskArbitrum Intern (INTERN)High RiskChipHigh RiskCurve DAO Token (CRV)Medium Risk

Would You Like a More Detailed Audit of Orthogonal?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit