Quantum Audit Logo

Is Superfluid Token Safe?

On-chain security analysis — is it a scam or legit?

Superfluid Token SUP
0xa69f…8792
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
Executive SummaryAI Copilot

The SuperToken contract implements an ERC-20 compatible token with Superfluid features, operating as a UUPS proxy. The contract is owned by a multisig and includes extensive privileged functions for managing token supply, balances, and upgradeability. Key findings include a critical vulnerability allowing anyone to initialize or destroy the upgradeable logic, high-severity issues related to privileged balance manipulation and uninitialized state, and medium-severity concerns regarding token minting by privileged addresses.

1 Critical2 High2 Medium1 Low4 Informational
Volume 24h
$74.0K
Liquidity
$66.7K
Price
$0.003851
Token Age
10mo
Top 10 Holders
67.8%

Security Findings

Critical

Critical Vulnerability: Anyone Can Initialize or Destroy Upgradeable Logic

CD-03The implementation contract, which contains the core logic for the SuperToken, is not adequately protected. Functions such as `burn`, `castrate`, `disableYieldBackend`, `downgrade`, `downgradeTo`, `enableYieldBackend`, `initialize`, and `initializeWithAdmin` can be called by *anyone* on the implementation contract directly. This allows an attacker to potentially re-initialize the contract, disable critical features, or even destroy its state, leading to severe disruption or loss of funds.
IssueThe implementation contract, which contains the core logic for the SuperToken, is not adequately protected. Functions such as `burn`, `castrate`, `disableYieldBackend`, `downgrade`, `downgradeTo`, `enableYieldBackend`, `initialize`, and `initializeWithAdmin` can be called by *anyone* on the implementation contract directly. This allows an attacker to potentially re-initialize the contract, disable critical features, or even destroy its state, leading to severe disruption or loss of funds.
FixThis is a critical security flaw. The contract developers must immediately ensure that the implementation contract's `initialize` and other sensitive functions are protected from external calls, typically by using an `initializer` modifier that prevents re-initialization and by ensuring that the implementation contract cannot be directly interacted with after deployment, except through the proxy. This usually involves deploying the implementation contract in an uninitialized state and never cal…
StatusUnresolved
High

Uninitialized State Variable Could Lead to Unexpected Behavior

CD-02The `getAccountActiveAgreements` function attempts to use a state variable that has not been explicitly initialized with a starting value. This could lead to the function operating with a default or unexpected value, potentially causing incorrect logic or errors in how active agreements are retrieved.
IssueThe `getAccountActiveAgreements` function attempts to use a state variable that has not been explicitly initialized with a starting value. This could lead to the function operating with a default or unexpected value, potentially causing incorrect logic or errors in how active agreements are retrieved.
FixThe contract developers should ensure that all state variables are properly initialized before being used. This involves reviewing the `getAccountActiveAgreements` function and its dependencies to set a clear initial value for any uninitialized variables.
StatusUnresolved
High

Privileged Address Can Directly Alter Token Balances

CP-02The 'self' controller has the power to directly reduce the balance of any token holder by calling the `selfBurn` function. This allows the controller to burn tokens from any targeted address, effectively moving them out of the holder's control without their consent.
IssueThe 'self' controller has the power to directly reduce the balance of any token holder by calling the `selfBurn` function. This allows the controller to burn tokens from any targeted address, effectively moving them out of the holder's control without their consent.
FixToken holders should understand that the 'self' controller possesses significant power over individual token balances. Verify the security and trustworthiness of the 'self' controller, as it can unilaterally burn tokens from any account.
StatusUnresolved
Medium

Privileged Addresses Can Create New Tokens

CP-01The 'host' or 'self' controller has the ability to increase the total supply of SuperTokens by calling functions like `selfMint`, `upgrade`, `upgradeTo`, `downgrade`, `downgradeTo`, `operationUpgrade`, `operationDowngrade`, and `operationUpgradeTo`. This means new tokens can be generated, which could dilute the value of existing token holdings.
IssueThe 'host' or 'self' controller has the ability to increase the total supply of SuperTokens by calling functions like `selfMint`, `upgrade`, `upgradeTo`, `downgrade`, `downgradeTo`, `operationUpgrade`, `operationDowngrade`, and `operationUpgradeTo`. This means new tokens can be generated, which could dilute the value of existing token holdings.
FixToken holders should be aware that the 'host' or 'self' controller can mint new tokens. Ensure that these controllers are highly trusted and that their operational procedures are robust to prevent unauthorized or excessive minting.
StatusUnresolved
Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0x0deb…c75f — holds 54.3% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 24% of the token's DEX liquidity; the other pools were not assessed.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a contract, 0x0deb…c75f — holds 54.3% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider. Some pools are concentrated-liquidity (V3/V4) positions; shares above are by position as GoPlus reports them. This assessment covers the main pool, which holds 24% of the token's DEX liquidity; the other pools were not assessed.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Low

Potential for Minor Value Loss Due to Calculation Order

CD-01The `_toUnderlyingAmount` function performs a division operation before a multiplication. In Solidity, integer division truncates any remainder, which can lead to a small loss of precision or value if the division occurs before the multiplication that would have preserved the value.
IssueThe `_toUnderlyingAmount` function performs a division operation before a multiplication. In Solidity, integer division truncates any remainder, which can lead to a small loss of precision or value if the division occurs before the multiplication that would have preserved the value.
FixWhile often minor, this issue can result in small discrepancies. The contract developers should review the `_toUnderlyingAmount` function to ensure calculations are ordered to minimize or eliminate any rounding losses, typically by performing multiplication before division where possible.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 67.8% of supply. What remains: 13.1% in wallets, 54.7% in other contracts. 51,377 holders in total.
IssueThe ten largest holders own 67.8% of supply. What remains: 13.1% in wallets, 54.7% in other contracts. 51,377 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Identity verified by independent sources

QA-IDENTITYListed on CoinGecko as Superfluid (SUP), market cap $1M, rank #2705. Traded on Coinbase. 51,377 holders. Verified by: exchange listings.
IssueListed on CoinGecko as Superfluid (SUP), market cap $1M, rank #2705. Traded on Coinbase. 51,377 holders. Verified by: exchange listings.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $273K (DexScreener, all pools). 24h trading volume $161K (CoinGecko, all markets, daily snapshot). 24h trading volume $111K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $0.0639 on 2025-12-07; the price is now 94.0135% below it.
IssueLiquidity $273K (DexScreener, all pools). 24h trading volume $161K (CoinGecko, all markets, daily snapshot). 24h trading volume $111K (DexScreener, all pools). CoinGecko's record for this coin: all-time high $0.0639 on 2025-12-07; the price is now 94.0135% below it.
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: a 3-of-7 multisig. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $273K of DEX liquidity across 5 pools. Launch: 316 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: a 3-of-7 multisig. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $273K of DEX liquidity across 5 pools. Launch: 316 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged

Category Ratings

TechnicalMedium4/10

The SuperToken contract provides standard ERC-20 functionality alongside advanced Superfluid features, including mechanisms for balance settlement and liquidation payouts (7.1 Architecture). The code includes numerous privileged functions restricted to 'admin', 'host', 'agreement', or 'self' roles, which manage core token operations and state (7.3 Access Control). However, technical issues were identified, such as an uninitialized state variable in `getAccountActiveAgreements` (CD-02) that could lead to unexpected behavior, and a minor rounding loss in `_toUnderlyingAmount` due to division before multiplication (CD-01) (7.2 Code Security).

GovernanceHigh1/10

The contract's economic model relies heavily on privileged roles ('host', 'self', 'agreement', 'admin') that can significantly impact token supply and individual balances (7.4 Economic). For instance, the 'host' or 'self' controller can mint new tokens via functions like `selfMint` or `upgrade` (CP-01), potentially diluting existing holdings. Furthermore, the 'self' controller has the ability to directly burn tokens from any account using `selfBurn` (CP-02), allowing unilateral alteration of user balances. These extensive powers necessitate robust governance and operational controls for the privileged addresses (7.5 Governance).

UpgradesHigh1/10

The SuperToken utilizes the UUPS proxy pattern, allowing for future upgrades of its logic (7.7 Upgrades). The `updateCode` and `changeAdmin` functions are restricted to the 'admin' role, providing controlled upgrade paths. However, a critical vulnerability exists where the implementation contract's sensitive functions, such as `initialize` and `disableYieldBackend`, are not protected and can be called by anyone directly (CD-03). This allows unauthorized initialization or destruction of the contract's logic, posing a severe risk to the system's integrity and funds.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEip1967 Uups
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

13.1% in wallets54.7% in contracts
Effective Concentration35.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder54.3%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x011e…642a
Unlocked LP Held By
0x0deb…c75f0xc688…115b0x5a01…a692

What Raised This Score

  • Owner can change any holder's balance (seize or credit tokens)
  • Mintable supply — no cap found, dilution unbounded
  • Upgradeable proxy — the admin can replace the logic
  • Liquidity NOT locked (100% of the pool; this pool is 24% of DEX liquidity) — who holds it cannot be verified
  • Top-10 concentration > 30% (67.8% total → 35.0% effective; 13.1% in EOAs, 54.7% in contracts)
  • Code: Potential for Minor Value Loss Due to Calculation Order (Low, static analysis)
  • Code: Uninitialized State Variable Could Lead to Unexpected Behavior (High, static analysis)
  • Code: Critical Vulnerability: Anyone Can Initialize or Destroy Upgradeable Logic (Critical, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

RatspeakHigh RiskCysic (CYS)High RiskWrapped PROS (PROS)High RiskFLock.io (FLOCK)Critical RiskCoinbase Wrapped MEGA (CBMEGA)Critical Riskbasedpad.fun (BPAD)Critical Risk

Would You Like a More Detailed Audit of Superfluid Token?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit