Quantum Audit Logo

Is WorldMobileToken Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

WorldMobileToken WMTX
0xdbb5…39d7
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 2d ago 1 audit on record
How is this score calculated? → Critical Risk
Executive SummaryAI Copilot

The WorldMobileToken contract is an ERC20 token utilizing OpenZeppelin's battle-tested libraries for capped supply, permit functionality, and role-based access control. While the code quality is high due to OpenZeppelin's foundation, significant centralization exists with the deployer holding all administrative roles. Additionally, the token uses a non-standard 6-decimal precision, which requires careful handling by integrators.

1 High1 Medium1 Low1 Informational
Volume 24h
$577.1K
Liquidity
$440.4K
Price
$0.01895
Token Age
10mo
Top 10 Holders
91.4%

Security Findings

High

Centralized Access Control and Single Point of Failure

H-01The contract's constructor grants the `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE` to the deployer's address (`_msgSender()`). This design centralizes significant power in a single entity. The `DEFAULT_ADMIN_ROLE` can grant or revoke any other role, including `MINTER_ROLE` and `BURNER_ROLE`. A compromise of the deployer's private key would allow an attacker to mint new tokens up to the cap, burn existing tokens, or manipulate roles, leading to severe economic impact and loss of trust (7.3 Access Control, 7.8 Operations).
IssueThe contract's constructor grants the `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE` to the deployer's address (`_msgSender()`). This design centralizes significant power in a single entity. The `DEFAULT_ADMIN_ROLE` can grant or revoke any other role, including `MINTER_ROLE` and `BURNER_ROLE`. A compromise of the deployer's private key would allow an attacker to mint new tokens up to the cap, burn existing tokens, or manipulate roles, leading to severe economic impact and loss of trust (7.3 Access Control, 7.8 Operations).
FixTransfer the `DEFAULT_ADMIN_ROLE` to a robust multi-signature wallet (e.g., Gnosis Safe) immediately after deployment. This distributes control and requires multiple approvals for critical administrative actions, significantly reducing the risk associated with a single point of failure.
StatusUnresolved
Medium

Non-Standard ERC20 Decimals

M-01The `decimals()` function is overridden to return 6, whereas the widely adopted standard for ERC20 tokens is 18 decimals. This deviation can lead to significant integration challenges, miscalculations, and user confusion across various platforms such as exchanges, wallets, block explorers, and DeFi protocols that often assume 18 decimals by default (7.1 Architecture, 7.4 Economic).
IssueThe `decimals()` function is overridden to return 6, whereas the widely adopted standard for ERC20 tokens is 18 decimals. This deviation can lead to significant integration challenges, miscalculations, and user confusion across various platforms such as exchanges, wallets, block explorers, and DeFi protocols that often assume 18 decimals by default (7.1 Architecture, 7.4 Economic).
FixEnsure all external systems and user interfaces interacting with the WorldMobileToken are explicitly aware of and correctly configured to handle 6 decimals. Provide clear documentation and communication regarding this non-standard precision to prevent errors and ensure accurate display of token amounts.
StatusUnresolved
Low

Lack of Dedicated `DEFAULT_ADMIN_ROLE` Transfer Function

L-01While the `AccessControl` contract allows for granting and revoking roles, there isn't a dedicated, explicit function to safely transfer the `DEFAULT_ADMIN_ROLE` to a new address or a multi-signature wallet in a single, atomic transaction. Transferring this critical role requires a multi-step process (granting to new admin, then revoking from old admin), which can be error-prone if not executed carefully (7.3 Access Control, 7.8 Operations).
IssueWhile the `AccessControl` contract allows for granting and revoking roles, there isn't a dedicated, explicit function to safely transfer the `DEFAULT_ADMIN_ROLE` to a new address or a multi-signature wallet in a single, atomic transaction. Transferring this critical role requires a multi-step process (granting to new admin, then revoking from old admin), which can be error-prone if not executed carefully (7.3 Access Control, 7.8 Operations).
FixImplement a custom `transferAdmin` function that allows the current `DEFAULT_ADMIN_ROLE` to transfer its role to a new address in a single, atomic transaction, or ensure a well-documented and tested procedure is followed for manual transfer. This reduces the risk of accidental loss of administrative control during the transfer process.
StatusUnresolved
Info

Contract Immutability (Non-Upgradeable)

I-01The `WorldMobileToken` contract is deployed as a standard implementation and does not incorporate any proxy patterns (e.g., UUPS, Transparent). This means the contract's logic is immutable once deployed to the blockchain. While this provides certainty regarding the contract's behavior, it also implies that any future bug fixes, security patches, or feature enhancements would necessitate deploying an entirely new contract and migrating all token holders (7.7 Upgrades).
IssueThe `WorldMobileToken` contract is deployed as a standard implementation and does not incorporate any proxy patterns (e.g., UUPS, Transparent). This means the contract's logic is immutable once deployed to the blockchain. While this provides certainty regarding the contract's behavior, it also implies that any future bug fixes, security patches, or feature enhancements would necessitate deploying an entirely new contract and migrating all token holders (7.7 Upgrades).
FixAcknowledge the immutability of the contract. For future projects, consider using upgradeable proxy patterns if flexibility for future updates or bug fixes is desired. For this contract, ensure thorough testing before deployment, as no post-deployment logic changes are possible.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract leverages battle-tested OpenZeppelin libraries for ERC20, ERC20Capped, ERC20Permit, and AccessControl, contributing to a solid foundation (7.2 Code Security). The implementation correctly overrides `_mint` and `decimals()`. However, the custom `decimals()` value of 6, instead of the common 18, introduces a potential for integration errors and user confusion across various platforms (7.1 Architecture).

GovernanceHigh1/10

The token design incorporates a fixed supply cap and explicit roles for minting and burning, providing controlled supply management (7.4 Economic). However, the `DEFAULT_ADMIN_ROLE`, `MINTER_ROLE`, and `BURNER_ROLE` are all initially granted to the deployer, creating a high degree of centralization (7.3 Access Control). This single point of failure means a compromise of the deployer's key could lead to unauthorized supply manipulation, impacting token economics (7.8 Operations).

UpgradesHigh3/10

The `WorldMobileToken` contract is deployed as a standard implementation and does not utilize any proxy patterns, meaning it is not upgradeable (7.7 Upgrades). This ensures immutability post-deployment, preventing any future changes to the contract logic. However, it also means that any discovered vulnerabilities or desired feature enhancements would necessitate a new contract deployment and a token migration process.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

33.4% in wallets58.0% in contracts
Effective Concentration56.6%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0xf4e5…c161
Unlocked LP Held By
0xa9f9…7dfd0xe803…d3cf

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 50% (91.4% total → 56.6% effective; 33.4% in EOAs, 58.0% in contracts — heavy)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • 1 High finding(s) from audit
  • 1 Medium finding(s) from audit
  • 1 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

金蟾 (JIN)Critical RiskbStocks Never Sleep (BSTOCKS)Critical RiskZypher Token (POP)Critical RiskSOLANA (SOL)Critical RiskSTBL_Token - STBL Governance Token (STBL)Critical RiskTartSwap (TART)Critical Risk

Would You Like a More Detailed Audit of WorldMobileToken?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit