Quantum Audit Logo
Launch App

Is SPA Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

SPA SPA
0xe26a…f22e
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
Executive SummaryAI Copilot

This report details the security audit of the SPA token contract. The contract implements standard ERC-20 functionality, with its ownership having been renounced. Several technical issues were identified, including unchecked external token transfers and the inability to withdraw received Ether.

1 High2 Medium5 Informational
Volume 24h
$2.68M
Liquidity
$794.9K
Price
$7.9600
Token Age
1y
Top 10 Holders
58.9%

Security Findings

High

Token Transfer Result Not Checked in `distributeDividend`

CD-02The `distributeDividend` function performs external ERC-20 token transfers. However, it does not check the boolean return value of these `transfer` calls. If an external token's `transfer` function fails (e.g., due to reentrancy guards, insufficient balance, or other custom logic), the `distributeDividend` function will proceed as if the transfer was successful, potentially leading to incorrect accounting or a failure to distribute dividends as intended without any error indication.
IssueThe `distributeDividend` function performs external ERC-20 token transfers. However, it does not check the boolean return value of these `transfer` calls. If an external token's `transfer` function fails (e.g., due to reentrancy guards, insufficient balance, or other custom logic), the `distributeDividend` function will proceed as if the transfer was successful, potentially leading to incorrect accounting or a failure to distribute dividends as intended without any error indication.
FixDevelopers should ensure that all external ERC-20 `transfer` calls are checked for their return value to confirm successful execution. If the return value is `false`, the transaction should revert or handle the failure appropriately.
StatusUnresolved
Medium

Ether Sent to Contract Cannot Be Withdrawn

CD-01The contract has a `receive` function, allowing it to accept Ether (ETH). However, there are no corresponding functions (like `withdrawETH`) that would permit anyone, including the original deployer or any other address, to send this received ETH out of the contract. Any ETH sent to this contract will be permanently locked and inaccessible.
IssueThe contract has a `receive` function, allowing it to accept Ether (ETH). However, there are no corresponding functions (like `withdrawETH`) that would permit anyone, including the original deployer or any other address, to send this received ETH out of the contract. Any ETH sent to this contract will be permanently locked and inaccessible.
FixToken holders should be advised not to send Ether directly to this contract, as it will be irretrievably lost.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY25.9% of the pool's LP is burned or time-locked. 25.9% is locked in PinkLock02 until 01 Oct 2123 (35418 days). Until then nobody — the project included — can withdraw it unless the locker contract itself is flawed; after that date the lock's owner can. 60.7% is held, unlocked, by 9 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
Issue25.9% of the pool's LP is burned or time-locked. 25.9% is locked in PinkLock02 until 01 Oct 2123 (35418 days). Until then nobody — the project included — can withdraw it unless the locker contract itself is flawed; after that date the lock's owner can. 60.7% is held, unlocked, by 9 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

Privileged Addresses Could Change Transfer Fees (Now Dormant)

CP-07The `setLPFeefenhong` and `setdistributorGas` functions were designed to allow the contract owner to change the fees applied to token transfers. However, the contract's ownership has been renounced, meaning no one can currently call these functions.
IssueThe `setLPFeefenhong` and `setdistributorGas` functions were designed to allow the contract owner to change the fees applied to token transfers. However, the contract's ownership has been renounced, meaning no one can currently call these functions.
FixNo action is required as ownership is renounced, rendering these functions inactive. This is noted for historical context regarding the contract's design.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 58.9% of supply. Of that, 48.8% burned, 0.5% locked, 4.8% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 4.2% in wallets, 0.6% in other contracts. 35,814 holders in total.
IssueThe ten largest holders own 58.9% of supply. Of that, 48.8% burned, 0.5% locked, 4.8% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 4.2% in wallets, 0.6% in other contracts. 35,814 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY35,814 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue35,814 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $803K (DexScreener, all pools). 24h trading volume $2.7M (DexScreener, all pools).
IssueLiquidity $803K (DexScreener, all pools). 24h trading volume $2.7M (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: nobody (ownership renounced). Code: not upgradeable (no proxy). Fees: 2% on buy, 4% on sell. Market: $803K of DEX liquidity across 2 pools. Launch: 710 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: nobody (ownership renounced). Code: not upgradeable (no proxy). Fees: 2% on buy, 4% on sell. Market: $803K of DEX liquidity across 2 pools. Launch: 710 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

The `spa` token implements standard ERC-20 functionality, allowing transfers and approvals. However, a critical issue exists where the `distributeDividend` function does not check the return value of external ERC-20 `transfer` calls, potentially leading to failed transfers being silently ignored (7.2 Code Security). Additionally, the contract can receive ETH but lacks any mechanism to withdraw it, causing funds to be permanently locked (7.2 Code Security).

GovernanceMedium6/10

The contract's ownership has been renounced on-chain, meaning no single entity can currently control the contract's privileged functions (7.3 Access Control). Functions like `setLPFeefenhong`, `setdistributorGas`, and `setDEV`, which could alter transfer fees or recipient addresses, are now dormant and cannot be called (7.4 Economic). This significantly reduces governance and economic risks associated with centralized control.

UpgradesMedium6/10

The `spa` contract is a standard token implementation and does not utilize any proxy patterns or upgrade mechanisms (7.1 Architecture). This means the contract's logic is immutable once deployed and cannot be changed or updated (7.7 Upgrades). This provides certainty regarding its behavior but also means any discovered vulnerabilities cannot be patched.

Security Checklist

Contract VerifiedPass
Ownership RenouncedPass
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax2.0%Sell Tax4.0%

Holder Composition

4.2% in wallets0.6% in contracts
Effective Concentration4.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

LP Locked25.9% · PinkLock02
Top-1 Unlocked Holder39.8%
Top-3 Unlocked56.1%

Key Addresses

Deployer
0x3c96…d362
Unlocked LP Held By
0x5e53…9a100xeb12…08540x054d…7d510x1d3a…43330xc4f1…fabf0x4d8b…7e7f0x1aa6…e2720x8c36…28920xa483…a886

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Liquidity NOT locked (74% of the pool; this pool is 99% of DEX liquidity) — held by independent providers — market-depth risk
  • Holders cannot sell their entire balance
  • Code: Ether Sent to Contract Cannot Be Withdrawn (Medium, static analysis)
  • Code: Token Transfer Result Not Checked in `distributeDividend` (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

SpaceX (SPCXB)High RiskLorenzo Governance Token (BANK)High RiskVenusCoinHigh RiskBedrock (BR)High RiskCysic Token (CYS)High RiskWorld Liberty Financial USD (USD1)High Risk

Would You Like a More Detailed Audit of SPA?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit