Quantum Audit Logo

Is zipcoin a Scam?

Early-stage security check — honeypot & rug-pull analysis

zipcoin ZC
0x0f43…0389
Base
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.
Last checked today 1 audit on record New Launch · 2d old
Executive SummaryAI Copilot

This report is based on an audit request for contract 0x0f43374670bd7533cdb9d0b9d8294a8820350389 on the Base network. No source code was provided for analysis, therefore a comprehensive security assessment could not be performed. The risk levels and findings are placeholders reflecting the lack of information and the inherent risk of interacting with unverified contracts.

1 High9 Informational
! Early-stage analysis. This token has limited on-chain history (2d old). New tokens carry elevated risk — data may change rapidly. Always verify independently before investing.
Volume 24h
$585.2K
Liquidity
$231.8K
Price
$0.000000771
Token Age
2d
Top 10 Holders
40.7%

Security Findings

High

Liquidity withdrawable by the owner/deployer

QA-LIQUIDITY0.0% of the pool's LP is burned or time-locked. 99.6% is held, unlocked, by the token's owner/deployer (0x218e…04e2) — they can pull that liquidity at any moment. This is the rug-pull path. 0.4% is held, unlocked, by 1 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool.
Issue0.0% of the pool's LP is burned or time-locked. 99.6% is held, unlocked, by the token's owner/deployer (0x218e…04e2) — they can pull that liquidity at any moment. This is the rug-pull path. 0.4% is held, unlocked, by 1 address(es) other than the owner/deployer. No single one holds a majority: their exits thin the market rather than hand anyone the pool.
FixCheck the lock's end date and beneficiary on the locker's own page before relying on it.
StatusAcknowledged
Info

No Source Code Provided for Analysis

I-01The audit request did not include the source code for the contract at 0x0f43…0389. This prevents any form of static or dynamic analysis.
IssueThe audit request did not include the source code for the contract at . This prevents any form of static or dynamic analysis.
FixProvide the complete and verified Solidity source code for the contract to enable a comprehensive security audit.
StatusUnresolved
Info

Inability to Assess Technical Security

I-02Without the contract's source code, it is impossible to assess technical security aspects such as reentrancy, integer overflows/underflows, access control flaws, logic errors, or gas optimizations (7.2 Code Security, 7.3 Access Control).
IssueWithout the contract's source code, it is impossible to assess technical security aspects such as reentrancy, integer overflows/underflows, access control flaws, logic errors, or gas optimizations (7.2 Code Security, 7.3 Access Control).
FixSubmit the contract's source code for a detailed technical security review.
StatusUnresolved
Info

Inability to Assess Economic and Governance Risks

I-03The absence of source code prevents the evaluation of economic models, governance mechanisms, oracle dependencies, or potential for flash loan attacks (7.4 Economic, 7.5 Governance).
IssueThe absence of source code prevents the evaluation of economic models, governance mechanisms, oracle dependencies, or potential for flash loan attacks (7.4 Economic, 7.5 Governance).
FixProvide the source code to allow for an assessment of economic and governance risks.
StatusUnresolved
Info

Inability to Assess Upgradeability and Operational Risks

I-04Without source code, it is impossible to determine if the contract is upgradeable, what proxy pattern is used, or to assess any upgrade safety issues (7.7 Upgrades). Operational risks (7.8 Operations) related to administrative functions or emergency procedures also cannot be evaluated.
IssueWithout source code, it is impossible to determine if the contract is upgradeable, what proxy pattern is used, or to assess any upgrade safety issues (7.7 Upgrades). Operational risks (7.8 Operations) related to administrative functions or emergency procedures also cannot be evaluated.
FixSubmit the contract's source code to enable a review of its upgradeability and operational aspects.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 40.7% of supply. Of that, 15.6% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 25.1% in wallets, 0.0% in other contracts. 1,104 holders in total.
IssueThe ten largest holders own 40.7% of supply. Of that, 15.6% in DEX pools — not holders that can sell, so excluded from the concentration score. What remains: 25.1% in wallets, 0.0% in other contracts. 1,104 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Not listed by any independent source

QA-IDENTITY1,104 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
Issue1,104 holders. Not listed by CoinGecko or any exchange GoPlus tracks. Nothing independent confirms who is behind this token, so every power its contract grants is scored at face value.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $232K (DexScreener, all pools). 24h trading volume $585K (DexScreener, all pools).
IssueLiquidity $232K (DexScreener, all pools). 24h trading volume $585K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $232K of DEX liquidity across 1 pools. Launch: 2 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: mint capability could not be read. Control: an owner that could not be resolved. Code: not upgradeable (no proxy). Fees: no buy or sell tax. Market: $232K of DEX liquidity across 1 pools. Launch: 2 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — 2 days of market history

QA-RECENTThe token's oldest DEX pool is 2 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 2 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalMedium6/10

Without access to the contract's source code, a detailed technical security analysis (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) cannot be conducted. Potential vulnerabilities such as reentrancy, integer overflows, or logic errors cannot be identified. Therefore, no strengths or issues can be reported in this section.

GovernanceHigh1/10

The economic and governance aspects (7.4 Economic, 7.5 Governance) of the contract cannot be evaluated without the underlying source code. This prevents assessment of tokenomics, fee structures, oracle dependencies, or governance mechanisms. Consequently, no specific economic or governance risks or strengths can be determined.

UpgradesMedium5/10

The upgradeability model (7.7 Upgrades) of the contract cannot be determined without the source code. It is unknown if the contract is upgradeable, what proxy pattern it might use, or if there are any upgrade safety mechanisms in place. Therefore, no assessment of upgrade-related risks or benefits is possible.

Security Checklist

Contract VerifiedFail
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

25.1% in wallets0.0% in contracts
Effective Concentration25.1%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder99.6%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x218e…04e2
Unlocked LP Held By
0x218e…04e20x9bd2…168c0xe95d…7bc9

A privileged address — the deployer, the owner, or the token contract itself — is among these holders, so that party can withdraw liquidity.

What Raised This Score

  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — withdrawable by the owner/deployer — rug-pull risk
  • Top-10 concentration > 20% (40.7% total → 25.1% effective; 25.1% in EOAs, 0.0% in contracts; 15.6% burned, locked or in pools excluded)
  • Contract source NOT verified — its logic cannot be read

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Cysic (CYS)High RiskWrapped L1coin (WL1)High RiskFLock.io (FLOCK)Critical RiskCoinbase Wrapped MEGA (CBMEGA)Critical Riskbasedpad.fun (BPAD)Critical RiskSuperfluid Token (SUP)High Risk

Would You Like a More Detailed Audit of zipcoin?

This token is brand new. Run a deeper AI-powered analysis of the contract code — free and instant.

Get Detailed Audit