Quantum Audit Logo

Is TermiX a Scam?

Early-stage security check — honeypot & rug-pull analysis

TermiX TMX
0xd0a1…1e43
Arbitrum Not verifiedLast checked 3d ago 1 audit on record New Launch · 23h old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

No source code was provided for the contract at 0xd0a132ad2acc7f8803fdcf2b034776cc0d2e1e43. Therefore, a comprehensive security audit could not be performed. This report contains general security considerations and recommendations based on the lack of transparency.

5 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$738.5100
Liquidity
$7.2K
Price
$0.1876
Token Age
23h
Top 10 Holders
94.5%

Security Findings

Info

Lack of Publicly Verified Source Code

I-01The source code for the contract at 0xd0a1…1e43 is not publicly verified on the Arbitrum block explorer. This prevents independent security analysis and verification of the contract's intended functionality and safety.
IssueThe source code for the contract at is not publicly verified on the Arbitrum block explorer. This prevents independent security analysis and verification of the contract's intended functionality and safety.
FixVerify the contract's source code on the block explorer (e.g., Arbiscan). This enhances transparency, allows users and auditors to inspect the code, and builds trust within the community.
StatusUnresolved
Info

Unknown Contract Functionality and Purpose

I-02Without access to the source code, the specific functionality, purpose, and business logic of the contract cannot be determined. This makes it impossible to assess its intended behavior, potential interactions, or adherence to any specified protocol design.
IssueWithout access to the source code, the specific functionality, purpose, and business logic of the contract cannot be determined. This makes it impossible to assess its intended behavior, potential interactions, or adherence to any specified protocol design.
FixProvide comprehensive documentation detailing the contract's purpose, functionality, and any associated protocol specifications. This should accompany the verified source code to ensure full transparency.
StatusUnresolved
Info

Unassessable Upgradeability Status

I-03The contract's upgradeability status (e.g., whether it's a proxy contract) cannot be determined without its source code. If it is an upgradeable contract, the specific proxy pattern used and the security of its upgrade mechanism are unknown, posing potential risks for future modifications.
IssueThe contract's upgradeability status (e.g., whether it's a proxy contract) cannot be determined without its source code. If it is an upgradeable contract, the specific proxy pattern used and the security of its upgrade mechanism are unknown, posing potential risks for future modifications.
FixIf the contract is upgradeable, ensure the source code for both the proxy and implementation contracts are verified. Clearly document the upgrade mechanism and any associated governance or access control for upgrades.
StatusUnresolved
Info

Unverified Access Control Mechanisms

I-04The access control mechanisms governing critical functions within the contract cannot be verified without source code. This includes identifying privileged roles (e.g., owner, admin), the scope of their permissions, and the methods used to manage these roles, which could lead to unauthorized operations.
IssueThe access control mechanisms governing critical functions within the contract cannot be verified without source code. This includes identifying privileged roles (e.g., owner, admin), the scope of their permissions, and the methods used to manage these roles, which could lead to unauthorized operations.
FixImplement robust and clearly defined access control mechanisms, such as OpenZeppelin's Ownable or AccessControl. Ensure that all privileged functions are protected and that role management is transparent and secure.
StatusUnresolved
Info

Potential for Undisclosed External Dependencies

I-05Without source code, any external contracts or protocols that this contract interacts with remain unknown. Undisclosed external dependencies can introduce cascading risks, as vulnerabilities in a dependent contract could directly impact the security and functionality of this contract.
IssueWithout source code, any external contracts or protocols that this contract interacts with remain unknown. Undisclosed external dependencies can introduce cascading risks, as vulnerabilities in a dependent contract could directly impact the security and functionality of this contract.
FixClearly document all external dependencies, including their addresses and the nature of the interaction. Perform due diligence on all integrated contracts to understand their security posture and potential risks.
StatusUnresolved

Category Ratings

TechnicalMedium4/10

Without access to the contract's source code, a detailed technical analysis of its architecture, code security, and access control mechanisms (7.1, 7.2, 7.3) cannot be performed. While well-designed contracts typically employ robust input validation and secure handling of external calls, the absence of code prevents assessment of specific vulnerabilities like reentrancy or integer overflows. Therefore, the technical security posture remains unknown, posing an inherent risk.

GovernanceHigh1/10

An assessment of economic models, governance structures, and potential oracle manipulation (7.4, 7.5) is not possible without understanding the contract's functionality. Robust economic incentives and transparent governance are critical for DeFi protocols, and secure oracle integrations prevent price manipulation. However, without source code, the presence of such safeguards or the nature of external dependencies (7.6) cannot be verified, leaving potential economic risks unquantified.

UpgradesMedium4/10

The upgradeability status and associated risks (7.7) cannot be determined without source code. If the contract is upgradeable, proper proxy patterns (e.g., UUPS, Transparent) and secure upgrade mechanisms are crucial to prevent critical vulnerabilities during transitions. Without code, it's impossible to verify if such patterns are correctly implemented or if operational aspects (7.8) like emergency pauses or administrative controls are present and secure, introducing uncertainty regarding future changes.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

92.1% in wallets2.4% in contracts
Effective Concentration93.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder96.6%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x0bad…6024
Unlocked LP Held By
0x6d55…f8fa0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (94.5% total → 93.1% effective; 92.1% in EOAs, 2.4% in contracts — extreme)
  • Liquidity < $10k ($7,158 across 1 pairs — easily drained)
  • LP top1 unlocked holder = 96.6% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • LP claimed locked but only 0.0% actually locked
  • Token age < 24h (brand new — bot activity, unproven)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Adapt (ADAP)Critical RiskAxelar Wrapped LAVA (LAVA)Critical RiskVangrid (VAN)Critical RiskMORCritical RiskDGrid AI (DGAI)Critical RiskUnicity Labs (UNYLA)Critical Risk

Would You Like a More Detailed Audit of TermiX?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit