Quantum Audit Logo

Is rsFIRO Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

rsFIRO RSFIRO
0x2744…ddc2
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 3d ago 1 audit on record
Executive SummaryAI Copilot

The rsFIRO token contract is a standard ERC20 implementation, largely based on OpenZeppelin's robust and audited patterns. It features a fixed supply, custom error handling, and an overridden decimals function. No critical or high-severity vulnerabilities were identified. The primary characteristic noted is the initial distribution of the entire token supply to the deployer, which is common for new tokens.

3 Informational
Volume 24h
$65.9K
Liquidity
$61.5K
Price
$1.2300
Token Age
1mo
Top 10 Holders
200.0%

Security Findings

Info

Standard ERC20 Implementation

I-01The rsFIRO token contract is a standard implementation of the ERC20 token interface, inheriting from a well-vetted base similar to OpenZeppelin's contracts. It provides all expected functionalities such as `transfer`, `approve`, `transferFrom`, `balanceOf`, `totalSupply`, `name`, `symbol`, and `decimals`. The contract correctly overrides the `decimals()` function to return 8.
IssueThe rsFIRO token contract is a standard implementation of the ERC20 token interface, inheriting from a well-vetted base similar to OpenZeppelin's contracts. It provides all expected functionalities such as `transfer`, `approve`, `transferFrom`, `balanceOf`, `totalSupply`, `name`, `symbol`, and `decimals`. The contract correctly overrides the `decimals()` function to return 8.
FixNo action required. This is a standard and secure implementation.
StatusUnresolved
Info

Use of Custom Errors

I-02The contract utilizes custom errors (e.g., `ERC20InsufficientBalance`, `ERC20InvalidSender`) instead of traditional `require()` statements with string messages. This is a modern Solidity best practice that improves gas efficiency for failed transactions and provides clearer error reporting for off-chain applications.
IssueThe contract utilizes custom errors (e.g., `ERC20InsufficientBalance`, `ERC20InvalidSender`) instead of traditional `require()` statements with string messages. This is a modern Solidity best practice that improves gas efficiency for failed transactions and provides clearer error reporting for off-chain applications.
FixNo action required. This is a positive design choice.
StatusUnresolved
Info

Fixed Supply and Initial Distribution

I-03The rsFIRO token has a fixed total supply of 2,140,000 tokens (with 8 decimals) minted entirely to the contract deployer (`msg.sender`) during construction. There are no further public minting or burning capabilities exposed, ensuring a predictable supply schedule. This initial distribution model centralizes the entire supply with the deployer at launch.
IssueThe rsFIRO token has a fixed total supply of 2,140,000 tokens (with 8 decimals) minted entirely to the contract deployer (`msg.sender`) during construction. There are no further public minting or burning capabilities exposed, ensuring a predictable supply schedule. This initial distribution model centralizes the entire supply with the deployer at launch.
FixEnsure transparency regarding the initial distribution and the deployer's role. If the project aims for decentralization, a plan for further distribution of the initial supply should be communicated.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The rsFIRO contract is a well-structured ERC20 token, inheriting from a robust base (7.1 Architecture). It utilizes modern Solidity features such as custom errors and `unchecked` blocks for gas efficiency, while maintaining strong security checks against common issues like integer underflows (7.2 Code Security). All standard ERC20 functions are implemented correctly, and access control is appropriately managed for a public token (7.3 Access Control). No reentrancy or other common technical vulnerabilities were found.

GovernanceHigh1/10

The token implements a fixed supply model with no further minting capabilities after deployment, which enhances scarcity and predictability (7.4 Economic). The entire initial supply is minted to the deployer's address during construction, establishing a centralized initial distribution (7.5 Governance). This design choice means the deployer holds significant influence over the token's initial market dynamics, which should be considered by users.

UpgradesMedium6/10

The rsFIRO contract is not designed to be upgradeable (7.7 Upgrades). This eliminates the complexities and potential risks associated with proxy patterns and upgrade mechanisms, providing a fixed and immutable contract logic.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x36bd…4f86
Unlocked LP Held By
0xde36…b07a

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (200.0% total → 200.0% effective; 200.0% in EOAs, 0.0% in contracts — extreme)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 90% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 90% of DEX liquidity)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

OpenServ (SERV)High RiskSKY Governance Token (SKY)High RiskOrigin Ether (OETH)High RiskWootrade Network (WOO)High RiskGram (prev. Toncoin) (GRAM)High RiskDAPPOS (DOS)Critical Risk

Would You Like a More Detailed Audit of rsFIRO?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit