Quantum Audit Logo

Is Vangrid a Scam?

Early-stage security check — honeypot & rug-pull analysis

Vangrid VAN
0xcc5f…32bb
Arbitrum Not verifiedLast checked 3d ago 1 audit on record New Launch · 23h old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

This report is based on a limited analysis as no Solidity source code was provided for the contract at 0xcc5f65809fef01bfb7270345f993f19771b132bb. Without the source code, a comprehensive security audit for vulnerabilities, architectural design, and economic implications cannot be performed. The findings below are general best practices and an acknowledgment of the missing information.

4 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$148.2K
Liquidity
$89.4K
Price
$0.1363
Token Age
23h
Top 10 Holders
93.5%

Security Findings

Info

No Source Code Provided for Audit

I-01The Solidity source code for the contract at 0xcc5f…32bb was not provided. This prevents a comprehensive security audit, including detailed analysis of architecture, code security, access control, economic model, governance, external interactions, and upgrade mechanisms. Without the code, no specific vulnerabilities can be identified or confirmed.
IssueThe Solidity source code for the contract at was not provided. This prevents a comprehensive security audit, including detailed analysis of architecture, code security, access control, economic model, governance, external interactions, and upgrade mechanisms. Without the code, no specific vulnerabilities can be identified or confirmed.
FixProvide the complete and verified Solidity source code for the contract. Ensure the code is publicly available and verified on block explorers to enable transparency and allow for thorough security assessments.
StatusUnresolved
Info

Importance of Comprehensive Testing

I-02Regardless of code availability, comprehensive testing is crucial for smart contract security. This includes unit tests, integration tests, fuzz testing, and property-based testing to cover all possible execution paths and edge cases. Without a robust testing suite, the contract's resilience to unexpected inputs or interactions cannot be fully guaranteed.
IssueRegardless of code availability, comprehensive testing is crucial for smart contract security. This includes unit tests, integration tests, fuzz testing, and property-based testing to cover all possible execution paths and edge cases. Without a robust testing suite, the contract's resilience to unexpected inputs or interactions cannot be fully guaranteed.
FixDevelop and maintain a comprehensive test suite that achieves high code coverage. Implement various testing methodologies, including formal verification where appropriate, to ensure the contract behaves as expected under all conditions.
StatusUnresolved
Info

Need for Clear Documentation

I-03Clear and up-to-date documentation is essential for understanding the contract's functionality, design choices, and operational procedures. This includes inline comments, NatSpec documentation, architectural diagrams, and user guides. Lack of documentation can lead to misinterpretations, operational errors, and difficulties in future audits or upgrades.
IssueClear and up-to-date documentation is essential for understanding the contract's functionality, design choices, and operational procedures. This includes inline comments, NatSpec documentation, architectural diagrams, and user guides. Lack of documentation can lead to misinterpretations, operational errors, and difficulties in future audits or upgrades.
FixEnsure all contracts, functions, and critical variables are well-documented using NatSpec and inline comments. Provide high-level architectural documentation and detailed explanations of the contract's economic model and governance mechanisms.
StatusUnresolved
Info

Consideration of External Dependencies

I-04Smart contracts often interact with external contracts, oracles, or other protocols. The security of the audited contract is inherently tied to the security and reliability of these external dependencies. Without source code, the nature and risks associated with any such dependencies cannot be assessed.
IssueSmart contracts often interact with external contracts, oracles, or other protocols. The security of the audited contract is inherently tied to the security and reliability of these external dependencies. Without source code, the nature and risks associated with any such dependencies cannot be assessed.
FixThoroughly vet all external dependencies for their security, reliability, and potential points of failure. Implement robust error handling and fallback mechanisms for external calls, and consider using battle-tested and audited libraries or protocols.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Without access to the Solidity source code, a detailed technical analysis of the contract's implementation (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) is not possible. Therefore, no specific strengths or weaknesses related to reentrancy, integer overflows, or access control flaws can be identified. A thorough review would typically involve analyzing code for common EVM vulnerabilities and adherence to secure coding practices.

GovernanceHigh1/10

An assessment of the contract's economic model (7.4 Economic) and governance mechanisms (7.5 Governance) cannot be conducted without the underlying logic defined in the source code. This includes evaluating tokenomics, fee structures, incentive mechanisms, and decision-making processes. Similarly, potential risks from external dependencies (7.6 External) cannot be determined.

UpgradesMedium6/10

The presence and safety of any upgrade mechanisms (7.7 Upgrades) cannot be verified without the contract's source code. This includes determining if the contract uses a proxy pattern (e.g., UUPS, Transparent) and if upgradeability is implemented securely. Operational procedures (7.8 Operations) also remain unassessable.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedPass
Not a ProxyPass

Holder Composition

93.5% in wallets0.0% in contracts
Effective Concentration93.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xed16…10e1
Unlocked LP Held By
0x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (93.5% total → 93.5% effective; 93.5% in EOAs, 0.0% in contracts — extreme)
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • LP claimed locked but only 0.0% actually locked
  • Token age < 24h (brand new — bot activity, unproven)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

MORCritical RiskDGrid AI (DGAI)Critical RiskAxelar Wrapped LAVA (LAVA)Critical RiskUnicity Labs (UNYLA)Critical RiskCatena Labs (CATE)Critical RiskVision (VSN)Critical Risk

Would You Like a More Detailed Audit of Vangrid?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit