Quantum Audit Logo

Is Pepe a Scam?

Honeypot, rug-pull and ownership checks

Is this your token? Publish your own audit on this page →

Pepe PEPE
0x6982…1933
Ethereum Not verifiedLast checked 3d ago 2 audits on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The audit of the PepeToken contract, an ERC20 token, reveals a robust implementation primarily leveraging battle-tested OpenZeppelin libraries. A key characteristic is the renounced ownership, which enhances decentralization and immutability. This design choice, while beneficial for trust, also means the contract lacks administrative flexibility for future changes or emergency responses.

1 Low2 Informational
i Our automated scanner reviewed Pepe (PEPE) on Ethereum. 5 of 5 security checks passed — see the full breakdown below.
Volume 24h
$2.33M
Liquidity
$27.93M
Price
$0.000003665
Age
3y
Top 10 Holders
38.7%

Security Findings

Low

No Emergency Mechanism or Upgradeability

L-01Given the renounced ownership and non-proxy architecture, there is no mechanism to pause the contract, recover accidentally sent tokens (if applicable), or upgrade the contract to address future vulnerabilities or feature requirements. This lack of administrative flexibility is a direct consequence of the design choice for maximum decentralization.
IssueGiven the renounced ownership and non-proxy architecture, there is no mechanism to pause the contract, recover accidentally sent tokens (if applicable), or upgrade the contract to address future vulnerabilities or feature requirements. This lack of administrative flexibility is a direct consequence of the design choice for maximum decentralization.
FixFor future projects where administrative flexibility or upgradeability might be desired, consider implementing a multi-signature wallet for critical administrative functions or utilizing an upgradeable proxy pattern. For this specific contract, ensure users are fully aware of its immutable nature.
StatusUnresolved
Info

Ownership Renounced and Immutability

I-01The contract's ownership has been renounced (the `owner` address is `address(0)`), rendering all `onlyOwner` functions inaccessible. This makes the contract highly immutable and decentralized regarding administrative control. While this prevents malicious owner actions, it also means no one can perform administrative tasks, fix potential bugs, or upgrade the contract in the future.
IssueThe contract's ownership has been renounced (the `owner` address is `address(0)`), rendering all `onlyOwner` functions inaccessible. This makes the contract highly immutable and decentralized regarding administrative control. While this prevents malicious owner actions, it also means no one can perform administrative tasks, fix potential bugs, or upgrade the contract in the future.
FixThis is a design choice that enhances decentralization. Ensure that all stakeholders understand the implications of this immutability, particularly the inability to modify contract logic or parameters post-deployment.
StatusUnresolved
Info

Reliance on OpenZeppelin Standards

I-02The contract extensively uses battle-tested OpenZeppelin libraries (Context, Ownable, ERC20). This significantly reduces the likelihood of common vulnerabilities like reentrancy, integer overflows, and basic access control flaws, as these libraries are widely audited and considered secure.
IssueThe contract extensively uses battle-tested OpenZeppelin libraries (Context, Ownable, ERC20). This significantly reduces the likelihood of common vulnerabilities like reentrancy, integer overflows, and basic access control flaws, as these libraries are widely audited and considered secure.
FixContinue to leverage well-audited and maintained libraries for core functionalities. Regularly check for updates and security advisories related to these dependencies.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The technical architecture (7.1) is sound, relying on standard OpenZeppelin ERC20 and Ownable contracts. Code security (7.2) is high due to the use of well-audited libraries and Solidity 0.8.0, which includes SafeMath by default. Access control (7.3) is effectively decentralized as ownership has been renounced, preventing any single entity from controlling critical functions. No complex custom logic was identified that could introduce novel technical vulnerabilities.

GovernanceMedium4/10

The economic model (7.4) is a standard ERC20 token, with no apparent complex tokenomics in the provided code. Governance (7.5) is highly decentralized due to the renounced ownership, meaning no single entity can alter contract parameters or perform administrative actions. While this prevents malicious owner behavior, it also removes the ability to address unforeseen issues or upgrade the contract, representing a trade-off between decentralization and flexibility.

UpgradesLow10/10

The contract is not designed with upgradeability (7.7) in mind, as indicated by its non-proxy architecture. Furthermore, with ownership renounced, there is no administrative mechanism to implement an upgrade path even if it were technically feasible. This design choice ensures immutability but means the contract cannot be modified or improved post-deployment.

Security Checklist

Contract VerifiedPass
Ownership RenouncedPass
No Mint FunctionPass
Liquidity LockedPass
Not a ProxyPass

Holder Composition

38.7% in wallets0.0% in contracts
Effective Concentration38.7%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

One more pair holds $3.5K and is not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Burned0.0%
LP Locked0.0%
Top-1 Unlocked Holder99.9%
Top-3 Unlocked99.9%

Key Addresses

Deployer
0xfbfe…8c9a
Unlocked LP Held By
0x6982…19330x371d…37390x4c39…cd500xe151…1a310x4dc7…e11f0x0fbf…a4c30xb0e2…d3880xb481…d4ac0x5f8e…0b5f

A privileged address — the deployer, the owner, or the token contract itself — is among these holders, so that party can withdraw liquidity.

What Raised This Score

  • Top-10 concentration > 30% (38.7% total → 38.7% effective; 38.7% in EOAs, 0.0% in contracts — moderate)
  • LP top1 unlocked holder = 99.9% (exit-liquidity risk, pool = 92% of DEX liquidity)
  • LP top3 unlocked holders = 99.9% (exit-liquidity risk, pool = 92% of DEX liquidity)
  • LP claimed locked but only 0.0% actually locked
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Frequently Asked Questions

Is Pepe a scam?

Based on automated analysis, Pepe scores 0/100 (Low Risk) on our risk scale. No honeypot was detected, but always verify independently before investing.

Is Pepe safe to buy?

Our scanner flagged a risk score of 0/100. Ownership is renounced which reduces rug-pull risk. DYOR before purchasing any token.

Has Pepe been audited?

The contract is open-source and verified on-chain. Verification is not the same as a full security audit. Use Quantum Audit's free tool to run a deeper analysis of the contract code.

Related Audits

Injective (INJ)Medium RiskLighter (LIT)Medium RiskAaveMedium RiskADIMedium Risk01Medium Riskether.fi governance token (ETHFI)Medium Risk

Would You Like a More Detailed Audit of Pepe?

Paste the contract address into our AI-powered scanner for a deeper real-time report — free, with every scoring factor shown.

Get Detailed Audit