Quantum Audit Logo
Launch App

Is THEA Finance a Scam?

Early-stage security check — honeypot & rug-pull analysis

THEA Finance THEA
0xd1ff…0f8c
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 23h old
Executive SummaryAI Copilot

This audit report is based on an unverified contract on the Arbitrum network. Due to the absence of publicly available source code, a comprehensive security analysis cannot be performed. The assessment is limited to external observations and general security best practices. The contract's reported deployment date (2026-10-07) is in the future, which is unusual and may indicate data discrepancy. Users are strongly cautioned against interacting with unverified contracts.

1 Medium1 Low8 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$202.7K
Liquidity
$125.4K
Price
$0.3585
Token Age
23h
Top 10 Holders
92.3%

Security Findings

Medium

Liquidity not locked

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0x8002…9c3f — holds 99.7% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
Issue0.0% of the pool's LP is burned or time-locked. 100.0% is held, unlocked, by 2 address(es) other than the owner/deployer. One of them — a wallet, 0x8002…9c3f — holds 99.7% and can remove that share at once; who controls it is not visible on-chain, so it is not treated as an independent provider.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Low

Lack of Verified Source Code

L-01The source code for the contract at address 0xd1ff…0f8c is not verified on the Arbitrum block explorer. This prevents any form of code review or security analysis, making it impossible to ascertain the contract's intended functionality, security posture, or adherence to best practices (7.2 Code Security).
IssueThe source code for the contract at address is not verified on the Arbitrum block explorer. This prevents any form of code review or security analysis, making it impossible to ascertain the contract's intended functionality, security posture, or adherence to best practices (7.2 Code Security).
FixVerify the contract's source code on the block explorer. This allows for transparency, community review, and independent security audits, significantly reducing the trust assumption required from users.
StatusUnresolved
Info

Unusual Future Deployment Date

I-01The provided deployment date for the contract is '2026-10-07T05:23:43Z', which is in the future. This is highly unusual for a deployed contract and may indicate a data discrepancy or an error in the provided metadata. While not a direct security vulnerability, it raises questions about the accuracy of the contract's associated information (7.8 Operations).
IssueThe provided deployment date for the contract is '2026-10-07T05:23:43Z', which is in the future. This is highly unusual for a deployed contract and may indicate a data discrepancy or an error in the provided metadata. While not a direct security vulnerability, it raises questions about the accuracy of the contract's associated information (7.8 Operations).
FixConfirm the actual deployment date of the contract. If this date is incorrect, ensure that all metadata associated with the contract is accurate to avoid confusion and maintain transparency.
StatusUnresolved
Info

Inability to Assess Access Control

I-02Without the source code, it is impossible to evaluate the access control mechanisms (7.3 Access Control) implemented within the contract. It is unknown if critical functions are properly protected, if there are privileged roles, or if ownership can be transferred securely. This lack of visibility poses a potential risk of unauthorized actions or centralized control.
IssueWithout the source code, it is impossible to evaluate the access control mechanisms (7.3 Access Control) implemented within the contract. It is unknown if critical functions are properly protected, if there are privileged roles, or if ownership can be transferred securely. This lack of visibility poses a potential risk of unauthorized actions or centralized control.
FixIf the contract is intended to be permissioned or have administrative functions, ensure that robust and transparent access control mechanisms are implemented and clearly documented. Verification of source code would allow for this assessment.
StatusUnresolved
Info

Potential for Hidden Malicious Logic

I-03The absence of verified source code means that the contract could contain arbitrary or malicious logic, such as backdoors, self-destruct functions, or unexpected state changes. Users interacting with such a contract are exposed to unknown risks, including loss of funds or unexpected behavior (7.2 Code Security).
IssueThe absence of verified source code means that the contract could contain arbitrary or malicious logic, such as backdoors, self-destruct functions, or unexpected state changes. Users interacting with such a contract are exposed to unknown risks, including loss of funds or unexpected behavior (7.2 Code Security).
FixAlways prioritize interaction with contracts that have verified source code. If interaction is unavoidable, proceed with extreme caution and only after understanding the potential risks. Consider using a decompiler, though this provides limited insight and is not a substitute for verified source.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 92.3% of supply. What remains: 90.3% in wallets, 2.0% in other contracts. The deployer/owner wallet itself holds 2.0%. 415 holders in total.
IssueThe ten largest holders own 92.3% of supply. What remains: 90.3% in wallets, 2.0% in other contracts. The deployer/owner wallet itself holds 2.0%. 415 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY415 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue415 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $125K (DexScreener, all pools). 24h trading volume $203K (DexScreener, all pools).
IssueLiquidity $125K (DexScreener, all pools). 24h trading volume $203K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $125K of DEX liquidity across 1 pools. Launch: under a day of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $125K of DEX liquidity across 1 pools. Launch: under a day of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — less than a day of market history

QA-RECENTThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Without access to the source code, a detailed technical assessment of the contract's architecture (7.1) and code security (7.2) is impossible. It is unknown if the contract follows secure coding practices, is susceptible to reentrancy, integer overflows, or other common EVM vulnerabilities. The lack of verification prevents any evaluation of internal logic or state transitions.

GovernanceHigh1/10

The economic model (7.4) and governance mechanisms (7.5) of this contract cannot be assessed without source code. It is unknown if the contract manages any assets, implements fee structures, or has any governance roles. The potential for economic manipulation or centralized control remains unquantifiable.

UpgradesMedium6/10

The upgradeability (7.7) of this contract cannot be determined without source code. It is unknown if the contract utilizes a proxy pattern (e.g., UUPS, Transparent) or if its logic can be modified post-deployment. The operational aspects (7.8) and external dependencies (7.6) are also unassessable.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

90.3% in wallets2.0% in contracts
Effective Concentration91.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.7%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x4957…fe48
Unlocked LP Held By
0x8002…9c3f0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — held by independent providers — market-depth risk
  • Top-10 concentration > 70% (92.3% total → 91.1% effective; 90.3% in EOAs, 2.0% in contracts)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ChipHigh RiskCoinbase Wrapped BTC (CBBTC)High RiskInfini (IFN)High RiskEunice (EUIAI)High RiskAgentum (AGT)High RiskDai Stablecoin (DAI)High Risk

Would You Like a More Detailed Audit of THEA Finance?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit