Quantum Audit Logo

Is veridiacoin a Scam?

Early-stage security check — honeypot & rug-pull analysis

Is this your token? Publish your own audit on this page →

veridiacoin VC
0x1165…ac04
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record New Launch · 23h old
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The RobinVistaToken contract, intended as a proxy implementation, contains a critical vulnerability related to its initialization function. The `initialize` function lacks proper access control, allowing any caller to become the designated 'factory' and mint the entire token supply to themselves. This flaw severely compromises the token's security, economic model, and intended operational control. While the contract utilizes well-audited OpenZeppelin ERC20 components, this fundamental design flaw in the initialization process poses an immediate and severe risk.

1 Critical1 Medium1 Low6 Informational
! Early-stage analysis. This token has limited on-chain history (23h old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$69.7K
Liquidity
$42.2K
Price
$0.0001133
Token Age
23h
Top 10 Holders
86.8%

Security Findings

Critical

Unprotected Initialization Allows Token Hijack

C-01The `initialize` function, which is intended for initial setup of the token, lacks any access control. In a proxy deployment scenario, this means any external address can call `initialize` on the proxy contract. The first caller will become the `factory` address and will receive the entire `totalSupply_` of tokens, effectively hijacking the token's initial distribution and control. The constructor's assignment of `factory = address(0xdead);` does not protect the proxy's storage from this vulnerability.
IssueThe `initialize` function, which is intended for initial setup of the token, lacks any access control. In a proxy deployment scenario, this means any external address can call `initialize` on the proxy contract. The first caller will become the `factory` address and will receive the entire `totalSupply_` of tokens, effectively hijacking the token's initial distribution and control. The constructor's assignment of `factory = address(0xdead);` does not protect the proxy's storage from this vulnerability.
FixImplement a robust access control mechanism for the `initialize` function. For proxy contracts, consider using OpenZeppelin's `UUPSUpgradeable` or `Initializable` base contracts which provide an `initializer` modifier. This modifier ensures the function can only be called once and by a designated address (e.g., the deployer or a governance contract).
StatusUnresolved
Medium

What the token's controller can do

QA-POWERSThe contract lets its controller — an owner that could not be resolved — mint new supply. Nothing independent vouches for whoever holds them, so each is a live risk to holders.
IssueThe contract lets its controller — an owner that could not be resolved — mint new supply. Nothing independent vouches for whoever holds them, so each is a live risk to holders.
FixCheck who holds these powers and whether a timelock or multisig stands between them and holders.
StatusAcknowledged
Low

Unused State Variables

L-01The state variables `deployer` and `metadataURI` are set during the `initialize` function call but are never subsequently read or used within the contract's logic. Storing these variables consumes unnecessary gas during deployment and each time `initialize` is called, without providing any functional benefit to the contract.
IssueThe state variables `deployer` and `metadataURI` are set during the `initialize` function call but are never subsequently read or used within the contract's logic. Storing these variables consumes unnecessary gas during deployment and each time `initialize` is called, without providing any functional benefit to the contract.
FixRemove the `deployer` and `metadataURI` state variables if they are not intended to be used by the contract's logic. If they are meant for off-chain consumption, consider emitting them as events during initialization instead of storing them on-chain to save gas.
StatusUnresolved
Info

Inconsistent Constructor Logic for Proxy Implementation

I-01The constructor of `RobinVistaToken` sets `factory = address(0xdead);`. For an implementation contract used with a proxy, the constructor runs only once when the implementation itself is deployed, not when the proxy is initialized. The state variables of the implementation contract are not directly used by the proxy; instead, the proxy operates on its own storage. Therefore, setting `factory` in the constructor is misleading and irrelevant for the proxy's operational state, although in this specific case, it does not directly cause a vulnerability due to the `initialize` check (which itself is flawed).
IssueThe constructor of `RobinVistaToken` sets `factory = address(0xdead);`. For an implementation contract used with a proxy, the constructor runs only once when the implementation itself is deployed, not when the proxy is initialized. The state variables of the implementation contract are not directly used by the proxy; instead, the proxy operates on its own storage. Therefore, setting `factory` in the constructor is misleading and irrelevant for the proxy's operational state, although in this specific case, it does not directly cause a vulnerability due to the `initialize` check (which itself is flawed).
FixConstructors for proxy implementation contracts should generally be empty or only set `immutable` variables. All mutable state initialization should occur within an `initialize` function, which is called via the proxy, to correctly set the proxy's storage.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 86.8% of supply. What remains: 6.9% in wallets, 79.9% in other contracts. 57 holders in total.
IssueThe ten largest holders own 86.8% of supply. What remains: 6.9% in wallets, 79.9% in other contracts. 57 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY57 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue57 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $42K (DexScreener, all pools). 24h trading volume $70K (DexScreener, all pools).
IssueLiquidity $42K (DexScreener, all pools). 24h trading volume $70K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $42K of DEX liquidity across 2 pools. Launch: under a day of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mintable with no on-chain cap found. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $42K of DEX liquidity across 2 pools. Launch: under a day of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — less than a day of market history

QA-RECENTThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is less than a day old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The contract leverages OpenZeppelin's robust ERC20 implementation, providing a solid foundation for token functionality and mitigating common integer overflow/underflow risks (7.2 Code Security). However, a critical vulnerability exists in the `initialize` function, which lacks access control, allowing any caller to become the `factory` and mint the entire token supply to themselves (7.3 Access Control). Additionally, some state variables (`deployer`, `metadataURI`) are set but unused, leading to inefficient gas consumption (7.1 Architecture).

GovernanceHigh1/10

The economic model is severely compromised by the unprotected `initialize` function (7.4 Economic). An attacker can front-run the legitimate deployment, minting all tokens to their address and gaining control over the `factory` role, which can then call `setPool` (7.5 Governance). This directly impacts the intended distribution and control of the token, rendering the project's economic design vulnerable to complete hijack. The `deployer` address is set but has no governance privileges, and `metadataURI` is stored but not utilized.

UpgradesHigh2/10

The contract is designed as an implementation for a proxy, which necessitates careful handling of initialization (7.7 Upgrades). The constructor's assignment of `factory = address(0xdead);` is ineffective for proxy storage, as the proxy's storage slot for `factory` will be `address(0)` by default. This, combined with the lack of access control in `initialize`, creates a critical vulnerability where the proxy's initialization can be hijacked by any caller, leading to unauthorized control and token minting.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not UpgradeablePass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

6.9% in wallets79.9% in contracts
Effective Concentration38.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

Key Addresses

Deployer
0x1ed4…7cbc

What Raised This Score

  • Mintable supply — no cap found, dilution unbounded
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool; this pool is 99% of DEX liquidity) — who holds it cannot be verified
  • Liquidity < $50k ($42,465 across 2 pairs — thin market)
  • Top-10 concentration > 30% (86.8% total → 38.9% effective; 6.9% in EOAs, 79.9% in contracts)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

SEIMedium RiskDolomite (DOLO)Medium RiskRedstone (RED)Medium RiskPinLink (PIN)Medium RiskFuse Cat (FUSECAT)Medium RiskEtherStreet (STREET)Medium Risk

Would You Like a More Detailed Audit of veridiacoin?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit