Quantum Audit Logo
Launch App

Is Sendover Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Sendover SENDOVER
0x9925…9176
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

The LaunchToken contract is an ERC-20 token implemented as an EIP-1167 minimal clone. It features specific mechanisms for managing rewards and transfer rules. The audit identified several areas where privileged addresses (factory, rewardsource) have significant control, including the ability to mint new tokens, modify transfer fees, and influence transfer rules. The contract is not upgradeable, which eliminates upgrade-related risks but also prevents future bug fixes or feature enhancements without a new deployment.

3 Medium1 Low5 Informational
Volume 24h
$30.7K
Liquidity
$63.6K
Price
$0.0001907
Token Age
15d
Top 10 Holders
32.4%

Security Findings

Medium

A privileged address can mint new tokens

CP-01A privileged function increases the total supply, diluting every holder. Functions: initialize(string,string,string,address).
IssueA privileged function increases the total supply, diluting every holder. Functions: initialize(string,string,string,address).
FixCheck who holds these functions and whether a timelock or multisig stands between them and holders.
StatusUnresolved
Medium

A privileged address can change the transfer fee

CP-07The fee taken from transfers is a setting a privileged function can change. Functions: notifyReward, initialize, setMarket. Restricted to: factory, rewardsource.
IssueThe fee taken from transfers is a setting a privileged function can change. Functions: notifyReward, initialize, setMarket. Restricted to: factory, rewardsource.
FixCheck who holds these functions and whether a timelock or multisig stands between them and holders.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a contract, 0x8448…b1a4 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 1 address(es) other than the owner/deployer. One of them — a contract, 0x8448…b1a4 — holds 100.0% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Low

A privileged address can change transfer or wallet limits

CP-08Numeric limits checked in the transfer path (maximum transaction or wallet size, thresholds) can be changed by a privileged function. Functions: initialize.
IssueNumeric limits checked in the transfer path (maximum transaction or wallet size, thresholds) can be changed by a privileged function. Functions: initialize.
FixCheck who holds these functions and whether a timelock or multisig stands between them and holders.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 32.4% of supply. What remains: 11.6% in wallets, 20.8% in other contracts. 294 holders in total.
IssueThe ten largest holders own 32.4% of supply. What remains: 11.6% in wallets, 20.8% in other contracts. 294 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as Sendover (SENDOVER), rank #4971. 294 holders.
IssueListed on CoinGecko as Sendover (SENDOVER), rank #4971. 294 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $64K (DexScreener, all pools). 24h trading volume $30K (CoinGecko, all markets, daily snapshot). 24h trading volume $31K (DexScreener, all pools).
IssueLiquidity $64K (DexScreener, all pools). 24h trading volume $30K (CoinGecko, all markets, daily snapshot). 24h trading volume $31K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $64K of DEX liquidity across 2 pools. Launch: 15 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $64K of DEX liquidity across 2 pools. Launch: 15 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — 15 days of market history

QA-RECENTThe token's oldest DEX pool is 15 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 15 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

The LaunchToken is an ERC-20 compliant token deployed as an EIP-1167 minimal clone, ensuring its logic is fixed and non-upgradeable (7.1 Architecture). The contract includes standard ERC-20 functionalities and additional mechanisms for reward distribution and transfer rule management. Key functions like `initialize`, `setMarket`, and `notifyReward` are restricted to specific privileged addresses (7.3 Access Control). For example, `initialize` handles initial token minting and setup, while `setMarket` and `notifyReward` manage reward-related parameters. The code quality appears robust with clear error handling for restricted functions (7.2 Code Security).

GovernanceHigh1/10

The economic model of LaunchToken grants significant control to privileged addresses, primarily the `factory` and `rewardsource` (7.4 Economic). The `initialize` function allows the `factory` to mint the initial token supply, which could dilute existing holders if not managed transparently. Furthermore, the `notifyReward` and `setMarket` functions enable the `factory` and `rewardsource` to adjust transfer fees, directly impacting transaction costs for users. While these controls are likely intended for protocol management, they introduce centralized economic risk (7.5 Governance).

UpgradesHigh2/10

The LaunchToken contract is deployed as an EIP-1167 minimal clone, meaning its implementation is fixed at deployment and cannot be upgraded (7.7 Upgrades). This design choice eliminates all upgrade-related risks, such as proxy misconfigurations or malicious upgrade paths. However, it also means that any discovered vulnerabilities or desired feature enhancements would necessitate a new contract deployment and migration, which can be a complex process (7.8 Operations).

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not UpgradeablePass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

11.6% in wallets20.8% in contracts
Effective Concentration19.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x1a67…c543
Unlocked LP Held By
0x8448…b1a4

What Raised This Score

  • Owner can change the buy/sell tax; held by factory: EOA
  • A privileged address can change transfer or wallet limits
  • Mintable supply — no cap found, dilution unbounded; held by factory: EOA
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — who holds it cannot be verified

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

trUSDHigh RiskAIOZ Network (AIOZ)High RiskAethir Token (ATH)High RiskSHXHigh RiskMain Street USD (MSUSD)High RiskSynapse (SYN)High Risk

Would You Like a More Detailed Audit of Sendover?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit