Quantum Audit Logo

Is Vangrid a Scam?

Early-stage security check — honeypot & rug-pull analysis

Vangrid VANG
0x8c47…ead6
Arbitrum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 23h old
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

This audit report is based on the provided contract address 0x8c473621d3cc3dca3ba601ff36474412b9edead6 on the Arbitrum network. No source code was provided for analysis. Therefore, a comprehensive security assessment of the contract's logic, architecture, and potential vulnerabilities could not be performed. The findings and risk levels presented are general recommendations or reflect the lack of verifiable information.

3 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$128.8K
Liquidity
$79.1K
Price
$0.0976
Token Age
23h
Top 10 Holders
93.9%

Security Findings

Info

Missing Source Code for Contract Analysis

I-01The source code for the contract at address 0x8c47…ead6 was not provided or publicly verified on the blockchain explorer. This prevents a thorough security audit of the contract's logic, architecture, and potential vulnerabilities (7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8). Without the source code, it is impossible to ascertain the contract's intended functionality, identify specific attack vectors, or verify its adherence to security best practices.
IssueThe source code for the contract at address was not provided or publicly verified on the blockchain explorer. This prevents a thorough security audit of the contract's logic, architecture, and potential vulnerabilities (7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8). Without the source code, it is impossible to ascertain the contract's intended functionality, identify specific attack vectors, or verify its adherence to security best practices.
FixIt is critical to publish and verify the source code for all deployed smart contracts on the respective blockchain explorer (e.g., Etherscan, Arbiscan). This practice enhances transparency, allows for community review, and is a fundamental requirement for any credible security assessment. Users should be cautious when interacting with unverified contracts.
StatusUnresolved
Info

General Recommendation: Implement Robust Access Control

I-02While specific access control mechanisms could not be reviewed due to missing source code, robust access control (7.3) is paramount for smart contract security. Flaws in access control can lead to unauthorized function calls, asset manipulation, or critical system shutdowns. Common patterns include `Ownable`, `AccessControl.sol`, or multi-signature wallets for sensitive operations.
IssueWhile specific access control mechanisms could not be reviewed due to missing source code, robust access control (7.3) is paramount for smart contract security. Flaws in access control can lead to unauthorized function calls, asset manipulation, or critical system shutdowns. Common patterns include `Ownable`, `AccessControl.sol`, or multi-signature wallets for sensitive operations.
FixEnsure that all critical functions are protected by appropriate access control mechanisms, limiting their execution to authorized entities (e.g., contract owner, governance, or a multi-sig wallet). Implement a clear role-based access control system if multiple privileged roles are required. Thoroughly test all access control logic to prevent bypasses.
StatusUnresolved
Info

General Recommendation: Conduct Comprehensive Testing and Formal Verification

I-03Without source code, the extent of testing or formal verification (7.2) applied to this contract is unknown. Comprehensive testing, including unit, integration, and fuzz testing, is crucial for identifying logic errors and edge cases. Formal verification can mathematically prove the absence of certain classes of bugs, enhancing confidence in the contract's correctness.
IssueWithout source code, the extent of testing or formal verification (7.2) applied to this contract is unknown. Comprehensive testing, including unit, integration, and fuzz testing, is crucial for identifying logic errors and edge cases. Formal verification can mathematically prove the absence of certain classes of bugs, enhancing confidence in the contract's correctness.
FixPrior to deployment, all smart contracts should undergo rigorous testing, covering all possible execution paths and edge cases. Consider employing advanced techniques like fuzzing and formal verification for critical components. Continuous integration and deployment pipelines should include automated security checks and tests.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

Due to the absence of source code, a technical analysis covering architecture (7.1), code security (7.2), and access control (7.3) could not be conducted. Without the contract's implementation details, it is impossible to identify specific vulnerabilities such as reentrancy, integer overflows, or logic flaws. Verifying the contract's bytecode against known patterns or ABI is also limited without the corresponding source.

GovernanceHigh1/10

An assessment of economic (7.4) and governance (7.5) risks, including potential for oracle manipulation, flash loan attacks, or centralized control, could not be performed without access to the contract's source code. The economic model and governance mechanisms remain unknown, preventing evaluation of their robustness or potential for abuse. External dependencies (7.6) also cannot be identified.

UpgradesMedium6/10

Without source code, it is impossible to determine if the contract utilizes an upgradeable proxy pattern (7.7) or if it is immutable. Therefore, an assessment of upgrade safety, potential for proxy-related vulnerabilities, or the impact of future changes cannot be made. Operational aspects (7.8) such as pause mechanisms or emergency shutdowns are also unknown.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedPass
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

91.7% in wallets2.2% in contracts
Effective Concentration92.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.8%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x966a…4449
Unlocked LP Held By
0x7f19…ad980x1d2a…158c

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Contract source NOT verified
  • Top-10 concentration > 70% (93.9% total → 92.6% effective; 91.7% in EOAs, 2.2% in contracts — extreme)
  • LP top1 unlocked holder = 99.8% (independent LP — depth risk)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk)
  • LP claimed locked but only 0.0% actually locked
  • Token age < 24h (brand new — bot activity, unproven)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Catena Labs (CATE)Critical RiskCubed (CUBE)Critical RiskVision (VSN)Critical RiskUnicity Labs (UNYLA)Critical RiskOrnn Exchange (ORNN)Critical RiskAXIS Robotics (AXROB)Critical Risk

Would You Like a More Detailed Audit of Vangrid?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit