On-chain security analysis — is it a scam or legit?
Every audit run adds a dated snapshot — history is append-only and cannot be edited.
The Pump (PUMP) token mint on Solana demonstrates a strong security posture with all critical authorities, including Mint and Freeze authorities, permanently revoked. The token utilizes the spl-token-2022 program without active transfer hooks or default frozen accounts. Holder distribution data was unavailable from chain-native RPC, preventing an assessment of supply concentration.
Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed
It's not definitively labeled a scam based on available data, but significant risks exist. While ownership is renounced and no mint function prevents new token creation, the unverified contract, highly concentrated holder distribution (75.8% by top 10), and unlocked liquidity introduce substantial potential for malicious activity or adverse market events. Investors should be aware of these structural vulnerabilities.
Pump.fun is associated with a high risk score of 52/100. Key risks include the contract not being verified, meaning its security hasn't been audited. A large portion (75.8%) of tokens is held by the top 10 wallets, risking manipulation. Additionally, the liquidity is not locked, which poses a significant rug pull risk. These factors suggest a high level of speculative risk for potential investors.
No, the Pump.fun contract is explicitly listed as "False" for verification. This means its code has not been publicly validated or audited by a third party. Without verification, there's no transparency into the contract's functionality or security, leaving potential vulnerabilities undisclosed and raising the overall risk profile for investors.
Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, no signup required.
Get Detailed Audit