Quantum Audit Logo

Is plumber Safe?

On-chain security analysis — is it a scam or legit?

plumber PLUMBER
0xb200…29b1
Base Not verifiedLast checked 3d ago 1 audit on record
Executive SummaryAI Copilot

This audit report is based on the analysis of a contract for which no source code was provided. The contract at address 0xb20000000000000000000029440a9564b59129b1 on the Base network is unverified. Without access to the Solidity source code, a comprehensive security assessment is impossible. All risk levels are considered high or critical due to the complete lack of transparency and auditability. Users are strongly advised against interacting with unverified contracts.

3 Informational
Volume 24h
$1.34M
Liquidity
$234.6K
Price
$0.004193
Token Age
22d
Top 10 Holders
14.5%

Security Findings

Info

Absence of Verified Source Code

I-01The contract at address 0xb200…29b1 on the Base network is not verified, meaning its Solidity source code is not publicly available or linked to the deployed bytecode. This prevents any form of security analysis, functional understanding, or trust establishment.
IssueThe contract at address on the Base network is not verified, meaning its Solidity source code is not publicly available or linked to the deployed bytecode. This prevents any form of security analysis, functional understanding, or trust establishment.
FixFor any contract intended for public interaction, always verify the source code on the blockchain explorer. This allows for transparency, community review, and security audits, which are crucial for building trust and ensuring safety.
StatusUnresolved
Info

Inability to Perform Comprehensive Security Audit

I-02Due to the lack of source code, a comprehensive security audit covering aspects like reentrancy, access control, integer overflows, economic exploits, or upgradeability risks cannot be performed. The contract's behavior remains entirely opaque.
IssueDue to the lack of source code, a comprehensive security audit covering aspects like reentrancy, access control, integer overflows, economic exploits, or upgradeability risks cannot be performed. The contract's behavior remains entirely opaque.
FixPrior to any deployment or public release, ensure that all smart contracts undergo a thorough security audit by qualified professionals. This audit should be based on the complete and final source code.
StatusUnresolved
Info

High Risk of Malicious Functionality

I-03Without source code, there is an unquantifiable and extremely high risk that the contract contains malicious functionality, such as backdoors, hidden administrative privileges, self-destruct mechanisms, or arbitrary fund transfers, which could lead to a complete loss of user assets.
IssueWithout source code, there is an unquantifiable and extremely high risk that the contract contains malicious functionality, such as backdoors, hidden administrative privileges, self-destruct mechanisms, or arbitrary fund transfers, which could lead to a complete loss of user assets.
FixUsers should exercise extreme caution and avoid interacting with unverified contracts. Always prioritize transparency and only engage with protocols that have publicly verified source code and a strong track record of security.
StatusUnresolved

Category Ratings

TechnicalLow10/10

Without access to the contract's source code (7.2 Code Security), a technical assessment of its architecture (7.1 Architecture), potential vulnerabilities like reentrancy or integer overflows, and adherence to secure coding practices is impossible. The lack of transparency inherently introduces a high technical risk, as the contract's functionality and potential exploits remain unknown. Any interaction with such a contract carries significant, unquantifiable technical risk.

GovernanceMedium5/10

The economic model (7.4 Economic) and governance mechanisms (7.5 Governance) of this contract cannot be evaluated without source code. This means there is no way to determine if the contract contains backdoors, hidden fees, or centralized control that could lead to rug pulls or other malicious economic exploits. The absence of transparency makes any economic interaction extremely risky, as the contract's true intent and behavior are unknown.

UpgradesMedium6/10

The upgradeability status (7.7 Upgrades) of this contract cannot be determined without source code. It is unknown if the contract is designed to be upgradeable, and if so, what proxy pattern (e.g., UUPS, Transparent) is used, or what controls are in place for upgrades. This lack of information poses a high risk, as a malicious upgrade could alter the contract's logic, drain funds, or introduce new vulnerabilities without warning.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

1.8% in wallets12.7% in contracts
Effective Concentration6.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

The 12 remaining pairs hold $210 between them and are not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder24.2%
Top-3 Unlocked57.6%

Key Addresses

Unlocked LP Held By
0x4c12…da0a0x0d52…e7420x5004…4d870x3b0c…3fcd0x575e…fe980xb3b7…62b60x5833…63f50xd1a9…61c00x1b34…3e960x4ff4…0c71

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Token age < 30 days (still settling)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

SAIRILow RiskCoinbase Wrapped Hyperliquid (CBHYPE)Low RiskFAILow RiskKeeta (KTA)Low RiskApple Inc. (AAPLC)Low RiskvAPI Network (VAPI)Low Risk

Would You Like a More Detailed Audit of plumber?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit