Quantum Audit Logo

Is Spiral a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

Spiral SPIRAL
0x6a77…b12b
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 10d ago 1 audit on record New Launch · 1d old
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The Spiral token contract is a straightforward ERC20 implementation, leveraging battle-tested OpenZeppelin libraries for its core functionality, including ERC20 and ERC20Permit. The contract features a fixed total supply minted entirely during deployment and a basic burn mechanism. No complex tokenomics, governance, or upgradeability features are present, contributing to a low overall risk profile. The primary risks identified are informational, related to design choices such as centralized initial distribution and the inherent front-running potential of the permit function.

3 Informational
! Early-stage analysis. This token has limited on-chain history (1d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$780.0K
Liquidity
$226.0K
Price
$1.1500
Token Age
1d
Top 10 Holders
29.4%

Security Findings

Info

Centralized Initial Supply Distribution

I-01The entire `TOTAL_SUPPLY` of 1,000,000 tokens is minted to a single `mintTo` address during the contract's construction. This design choice centralizes the initial distribution of all tokens to one entity, which then holds significant control over the token's initial market dynamics and liquidity provision.
IssueThe entire `TOTAL_SUPPLY` of 1,000,000 tokens is minted to a single `mintTo` address during the contract's construction. This design choice centralizes the initial distribution of all tokens to one entity, which then holds significant control over the token's initial market dynamics and liquidity provision.
FixThis is a design decision. If a more decentralized initial distribution is desired, consider implementing a vesting schedule, a public sale mechanism, or distributing to multiple addresses in the constructor. However, for a simple token, this approach is common and acceptable if the `mintTo` address is managed securely.
StatusUnresolved
Info

Immutability and Lack of Emergency Pause

I-02The Spiral contract is immutable and does not incorporate any upgradeability features or an emergency pause mechanism. While immutability enhances decentralization and removes the attack surface associated with privileged administrative roles, it also means that no interventions are possible post-deployment. In the event of unforeseen critical bugs, exploits in integrated protocols, or market manipulation, there is no way to halt transfers or fix issues within the contract itself.
IssueThe Spiral contract is immutable and does not incorporate any upgradeability features or an emergency pause mechanism. While immutability enhances decentralization and removes the attack surface associated with privileged administrative roles, it also means that no interventions are possible post-deployment. In the event of unforeseen critical bugs, exploits in integrated protocols, or market manipulation, there is no way to halt transfers or fix issues within the contract itself.
FixThis is a conscious design choice for maximum decentralization. If the project's risk tolerance allows for it, consider the trade-offs of adding a limited, multi-sig controlled pause mechanism for extreme emergencies. However, for a simple, non-governed token, immutability is often preferred.
StatusUnresolved
Info

User-Side Front-Running Risk with `permit` Function

I-03The `permit` function, inherited from OpenZeppelin's ERC20Permit, allows users to approve token transfers via a signed message instead of an on-chain transaction. However, this function is susceptible to front-running. A malicious actor could observe a pending `permit` transaction, reconstruct the signed message, and submit their own transaction with a higher gas price to execute the `permit` before the legitimate user. This could lead to the legitimate user's transaction failing or being exploited.
IssueThe `permit` function, inherited from OpenZeppelin's ERC20Permit, allows users to approve token transfers via a signed message instead of an on-chain transaction. However, this function is susceptible to front-running. A malicious actor could observe a pending `permit` transaction, reconstruct the signed message, and submit their own transaction with a higher gas price to execute the `permit` before the legitimate user. This could lead to the legitimate user's transaction failing or being exploited.
FixThis is an inherent characteristic of the `permit` design and not a vulnerability in the contract's implementation. Users should be aware of this risk and take precautions, such as setting a sufficiently short `deadline` for their signed messages to minimize the window for front-running. Applications integrating with `permit` should also educate their users on these risks.
StatusUnresolved

Category Ratings

TechnicalLow10/10

The technical architecture (7.1 Architecture) of the Spiral contract is robust, relying almost entirely on well-audited OpenZeppelin ERC20 and ERC20Permit implementations. The custom logic is minimal, limited to the constructor's initial mint and a simple burn function, both correctly implemented. Code security (7.2 Code Security) is high due to the use of Solidity 0.8.x, which includes default overflow/underflow checks, and the proven security of the underlying libraries. Access control (7.3 Access Control) is decentralized, with no privileged roles beyond the initial deployer receiving the total supply.

GovernanceMedium4/10

The economic model (7.4 Economic) of the Spiral token is very simple: a fixed total supply of 1,000,000 tokens, with no further minting capabilities. A burn function allows users to reduce their own token balance. There are no complex tokenomics such as fees, taxes, or staking rewards. Governance (7.5 Governance) is entirely absent, meaning no on-chain voting or administrative control mechanisms are implemented, which contributes to a highly decentralized and predictable economic behavior.

UpgradesMedium6/10

The Spiral contract is not designed to be upgradeable (7.7 Upgrades). It is deployed as a standard, immutable contract. This design choice eliminates the risks associated with upgrade mechanisms, such as proxy implementation bugs or centralized upgrade keys, but also means that no post-deployment modifications or bug fixes are possible.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

15.6% in wallets13.8% in contracts
Effective Concentration21.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 3 more pairsShow less

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder28.9%
Top-3 Unlocked75.4%

Key Addresses

Deployer
0xbbbd…8c19
Unlocked LP Held By
0x5004…4d870x4c12…da0a0xc119…1fcd0x8ffe…6f9b0xf5f2…4a4a0x5c79…2db90x996d…ad770x7118…ce180xc10c…a4610xc796…6c47

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Top-10 concentration > 20% (29.4% total → 21.1% effective; 15.6% in EOAs, 13.8% in contracts — mild)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Token age < 7 days (early, volatile)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Tsutsuji the Cate (CATE)Medium RiskBook of Ethereum (BOOE)Medium RiskAsteroid Shiba (ASTEROID)Low RiskClawdMedium RiskKekius Maximus (KEKIUS)Medium RiskFuseMedium Risk

Would You Like a More Detailed Audit of Spiral?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit