Quantum Audit Logo

Is WorldMobileToken Safe?

On-chain security analysis — is it a scam or legit?

WorldMobileToken WMTX
0x3e31…e98d
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record
Executive SummaryAI Copilot

The WorldMobileToken contract is an ERC20 token implementation leveraging OpenZeppelin's ERC20Capped, ERC20Permit, and AccessControl libraries. It features a fixed supply cap and defined roles for minting and burning. The primary security concern identified is the high degree of centralization, with the deployer initially holding all critical administrative roles, posing a single point of failure.

1 High1 Medium1 Informational
Volume 24h
$305.0K
Liquidity
$397.1K
Price
$0.02439
Token Age
4mo
Top 10 Holders
71.1%

Security Findings

High

Centralized Control of Critical Roles

H-01The constructor of the WorldMobileToken contract grants the `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE` to the deployer address (`_msgSender()`). This design centralizes complete control over token supply management (minting up to the cap, burning tokens) and the ability to assign/revoke other roles to a single external owned account (EOA). A compromise of this single EOA's private key would allow an attacker to mint new tokens (up to the cap), burn existing tokens, and arbitrarily reassign roles, leading to significant economic damage and loss of trust. (7.3 Access Control, 7.8 Operations)
IssueThe constructor of the WorldMobileToken contract grants the `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE` to the deployer address (`_msgSender()`). This design centralizes complete control over token supply management (minting up to the cap, burning tokens) and the ability to assign/revoke other roles to a single external owned account (EOA). A compromise of this single EOA's private key would allow an attacker to mint new tokens (up to the cap), burn existing tokens, and arbitrarily reassign roles, leading to significant economic damage and loss of trust. (7.3 Access Control, 7.8 Operations)
FixTransfer the `DEFAULT_ADMIN_ROLE` to a multi-signature wallet (e.g., Gnosis Safe) immediately after deployment. This will require multiple trusted parties to approve any administrative actions, significantly reducing the risk of a single point of failure or malicious activity. Consider also assigning the `MINTER_ROLE` and `BURNER_ROLE` to separate, controlled addresses or multi-sigs if their operations are distinct.
StatusUnresolved
Medium

Economic Impact of Minting/Burning Authority

M-01The `MINTER_ROLE` and `BURNER_ROLE` provide the capability to dynamically increase or decrease the token supply within the defined cap. While the cap limits the maximum supply, the discretion to mint new tokens or burn existing ones can have a significant impact on the token's economic value and stability if not managed transparently and predictably. Without clear governance policies, the exercise of these powers could lead to unexpected inflation or deflation, potentially harming token holders. (7.4 Economic, 7.5 Governance)
IssueThe `MINTER_ROLE` and `BURNER_ROLE` provide the capability to dynamically increase or decrease the token supply within the defined cap. While the cap limits the maximum supply, the discretion to mint new tokens or burn existing ones can have a significant impact on the token's economic value and stability if not managed transparently and predictably. Without clear governance policies, the exercise of these powers could lead to unexpected inflation or deflation, potentially harming token holders. (7.4 Economic, 7.5 Governance)
FixEstablish and publicly communicate a clear policy for when and how minting and burning operations will be conducted. Consider implementing additional governance mechanisms, such as time-locks for large mints/burns or requiring community proposals for significant supply adjustments, to enhance transparency and predictability. This will help mitigate the risk of economic manipulation and build community confidence.
StatusUnresolved
Info

Non-Upgradeable Contract Design

I-01The WorldMobileToken contract is deployed directly without utilizing an upgradeable proxy pattern. This means that the contract's logic is immutable and cannot be modified or updated after deployment. While this eliminates risks associated with upgrade mechanisms (e.g., proxy vulnerabilities, improper upgrade paths), it also means that any future bug fixes, security patches, or feature enhancements would necessitate deploying an entirely new contract and migrating all token holders. (7.7 Upgrades, 7.1 Architecture)
IssueThe WorldMobileToken contract is deployed directly without utilizing an upgradeable proxy pattern. This means that the contract's logic is immutable and cannot be modified or updated after deployment. While this eliminates risks associated with upgrade mechanisms (e.g., proxy vulnerabilities, improper upgrade paths), it also means that any future bug fixes, security patches, or feature enhancements would necessitate deploying an entirely new contract and migrating all token holders. (7.7 Upgrades, 7.1 Architecture)
FixThis is a design choice. Ensure that the current implementation has undergone thorough testing and auditing to minimize the likelihood of needing future changes. If future flexibility is desired, consider a migration plan to an upgradeable contract in the long term, or accept the immutability as a feature that guarantees unchanging contract behavior.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract demonstrates strong technical foundations by inheriting from battle-tested OpenZeppelin contracts for ERC20, capping, permit functionality, and access control (7.2 Code Security). The override of the `decimals()` function is correctly implemented, ensuring the cap calculation is accurate. No complex custom logic is present, which reduces the attack surface and potential for novel vulnerabilities (7.1 Architecture). The use of Solidity 0.8.19 inherently mitigates common integer overflow/underflow issues.

GovernanceHigh1/10

The token incorporates a fixed supply cap of 2 billion tokens (with 6 decimals), providing predictability for token holders (7.4 Economic). However, the `MINTER_ROLE` and `BURNER_ROLE` grant significant power to adjust the token supply within this cap. Initially, the deployer holds `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE`, centralizing control over these critical economic levers (7.5 Governance). This single point of failure introduces a substantial risk if the controlling address is compromised or misused (7.8 Operations).

UpgradesHigh3/10

The WorldMobileToken contract is deployed as a standard, non-upgradeable implementation (7.7 Upgrades). This design choice eliminates the complexities and potential risks associated with upgrade mechanisms, such as proxy pattern vulnerabilities or improper upgrade paths. While it ensures immutability and predictability, it also means that no future bug fixes or feature enhancements can be implemented without a new contract deployment and token migration.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

27.0% in wallets44.1% in contracts
Effective Concentration44.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder50.5%
Top-3 Unlocked97.2%

Key Addresses

Deployer
0xf4e5…c161
Unlocked LP Held By
0x73e5…91ad0xfa2b…52bb0x3662…ba860xf867…b511

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 30% (71.1% total → 44.6% effective; 27.0% in EOAs, 44.1% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 50.5% (independent LP — depth risk, pool = 97% of DEX liquidity)
  • LP top3 unlocked holders = 97.2% (independent LP — depth risk, pool = 97% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

ether.fi governance token (ETHFI)High RiskCluster Protocol (CP)High RiskResearchCoin (RSC)High RiskFren PetHigh RiskBaseStonk (BSTONK)High RiskVoice of the Gods by Virtuals (ADM)High Risk

Would You Like a More Detailed Audit of WorldMobileToken?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit