Quantum Audit Logo

Is Unicity Labs a Scam?

Early-stage security check — honeypot & rug-pull analysis

Unicity Labs UNYLA
0x537c…0abb
Arbitrum Not verifiedLast checked 3d ago 1 audit on record New Launch · 23h old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

This audit report is based on the provided contract address 0x537c48bc8585bfd83e2c6ab47d9ddd5348ce0abb on Arbitrum. No source code was provided for analysis, therefore a comprehensive security assessment of the contract's logic, architecture, and potential vulnerabilities could not be performed. The risk levels assigned reflect the absence of identified issues due to lack of source, rather than an assurance of security. Users should exercise extreme caution when interacting with unverified contracts.

4 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$7.1K
Liquidity
$109.7K
Price
$0.01978
Token Age
23h
Top 10 Holders
83.1%

Security Findings

Info

Source Code Not Provided for Audit

I-01The source code for the contract at 0x537c…0abb was not provided for this audit. This prevents any meaningful security analysis of the contract's internal logic, architecture, and potential vulnerabilities. Without source code, it is impossible to assess critical security aspects such as reentrancy, access control, integer overflows, or business logic flaws.
IssueThe source code for the contract at was not provided for this audit. This prevents any meaningful security analysis of the contract's internal logic, architecture, and potential vulnerabilities. Without source code, it is impossible to assess critical security aspects such as reentrancy, access control, integer overflows, or business logic flaws.
FixAlways provide the full, verified source code for all contracts intended for audit. Deploying contracts without publicly verified source code significantly increases risk for users and makes security assessments impossible. Ensure source code is published on block explorers (e.g., Etherscan, Arbiscan) and matches the deployed bytecode.
StatusUnresolved
Info

Importance of Comprehensive Testing

I-02Even with well-written code, comprehensive testing is crucial for smart contract security. This includes unit tests, integration tests, and fuzz testing to cover various scenarios and edge cases. Without source code, the extent and quality of existing tests cannot be verified, leaving a gap in the overall security assurance.
IssueEven with well-written code, comprehensive testing is crucial for smart contract security. This includes unit tests, integration tests, and fuzz testing to cover various scenarios and edge cases. Without source code, the extent and quality of existing tests cannot be verified, leaving a gap in the overall security assurance.
FixImplement a robust testing suite covering all functions, access control, and potential attack vectors. Utilize tools like Foundry or Hardhat for unit and integration testing, and incorporate property-based testing (fuzzing) to explore unexpected inputs and states. Document test coverage and results.
StatusUnresolved
Info

Consideration for Formal Verification

I-03Formal verification provides mathematical proof of a contract's adherence to a specified set of properties, offering the highest level of assurance for critical components. Without source code, it's impossible to determine if formal verification has been applied or to assess its scope.
IssueFormal verification provides mathematical proof of a contract's adherence to a specified set of properties, offering the highest level of assurance for critical components. Without source code, it's impossible to determine if formal verification has been applied or to assess its scope.
FixFor critical smart contracts, consider engaging with formal verification experts to mathematically prove the absence of certain bugs and the adherence to key security properties. This adds an additional layer of security beyond traditional auditing and testing.
StatusUnresolved
Info

Review of External Dependencies and Operational Security

I-04Smart contracts often interact with external contracts (7.6) or rely on off-chain operations (7.8). The security of these dependencies and operational procedures is paramount. Without source code, it's impossible to identify external calls, understand their implications, or assess the operational security practices of the project.
IssueSmart contracts often interact with external contracts (7.6) or rely on off-chain operations (7.8). The security of these dependencies and operational procedures is paramount. Without source code, it's impossible to identify external calls, understand their implications, or assess the operational security practices of the project.
FixThoroughly document and audit all external dependencies, including oracles, other DeFi protocols, and administrative interfaces. Implement robust operational security procedures, including multi-signature wallets for critical actions, time-locks, and emergency pause mechanisms. Ensure clear incident response plans are in place.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Due to the absence of source code, a detailed technical analysis of the contract's architecture (7.1), code security (7.2), and access control mechanisms (7.3) could not be conducted. Without the code, it is impossible to identify specific vulnerabilities such as reentrancy, integer overflows, or logic flaws. While the contract might be well-designed, the lack of transparency prevents any assessment of its robustness or adherence to security best practices.

GovernanceHigh1/10

An assessment of the contract's economic model (7.4) and governance structure (7.5) was not possible without access to the source code. Key aspects like tokenomics, fee structures, or administrative privileges cannot be evaluated. The potential for economic manipulation or centralized control remains unknown. While a well-designed contract could mitigate these risks, the current lack of information prevents any such determination.

UpgradesMedium6/10

Without the contract's source code, it is impossible to determine if it implements any upgradeability patterns (7.7) or to assess their safety. If the contract is upgradeable, the mechanism (e.g., UUPS, Transparent) and the associated access control for upgrades are critical security considerations. The lack of this information means potential risks related to upgradeability cannot be evaluated, leaving users unaware of possible future changes to the contract's logic.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

80.4% in wallets2.8% in contracts
Effective Concentration81.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xa1ae…d68b
Unlocked LP Held By
0xf858…7c6f0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (83.1% total → 81.5% effective; 80.4% in EOAs, 2.8% in contracts — extreme)
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • LP claimed locked but only 0.0% actually locked
  • Token age < 24h (brand new — bot activity, unproven)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Catena Labs (CATE)Critical RiskVision (VSN)Critical RiskVangrid (VAN)Critical RiskMORCritical RiskOrnn Exchange (ORNN)Critical RiskDGrid AI (DGAI)Critical Risk

Would You Like a More Detailed Audit of Unicity Labs?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit