D100Token
Scanned September 9, 2026 · Check a different contract →
D100Token
How the owner could rug you
None of the common owner-side rug mechanisms were found in the code. That is not a clean bill of health — see the limits below.
Code: No mint function or role is visible in the provided snippet; the contract body where minting could be defined is not included
Code: No pausable flag, modifier, or transfer‑gate logic appears in the visible code; such logic may be defined later in the truncated part
Code: No blacklist mapping or check in the shown code; could be introduced later
Code: No fee calculation or setter function is present in the excerpt; may exist in omitted sections
Code: No proxy pattern (e.g., ERC1967, TransparentUpgradeableProxy) is visible; the rest of the contract is not shown
Code: No function that moves tokens/BNB from the contract to an arbitrary address is visible; such a function could be defined later
Code: Ownable is inherited, providing an owner variable and onlyOwner modifier, but we cannot see whether ownership has been renounced or transferred in the omitted code
This checks only what the code can do. It cannot see whether liquidity is locked, how concentrated holders are, or what the team intends — those need live on-chain data. Absence of these mechanisms is not proof a token is safe.
What this could cost you
How much money would you put into this? We'll show you what you could actually lose — in dollars, not just a scary word like "risk."
None of the common rug mechanisms were found, so there's nothing to calculate against here. That's not the same as "safe" — see the limits above.
This contract's source is 39,717 characters — only the first 9,000 were analyzed, so parts of it were not examined. That's the real reason, not a vague size limit: 30,717 characters were cut off the end.
What the code allows
Evidence: No mint() or _mint() calls are present in the excerpt; the token’s supply‑changing logic may be in the missing part
This allows: Presence would allow the owner or a privileged role to increase total supply
Evidence: Only the Ownable base contract is shown; specific onlyOwner functions are not visible in the truncated code
This allows: Owner‑only functions can modify token behavior, fees, or access controls
Evidence: No pause flag, tradingEnabled variable, or blacklist check appears in the visible portion
This allows: Such restrictions can block or limit token transfers
Evidence: No fee calculation or deduction logic is present in the snippet
This allows: Transfer fees can be used to siphon value from holders
Evidence: No proxy or upgrade function is visible; could be defined later
This allows: Upgradeability lets an admin replace contract logic after deployment
Evidence: No Pausable import or onlyWhenNotPaused modifier is seen
This allows: A pause can freeze all token transfers
Evidence: Ownable sets an initial owner, but we cannot see any renounceOwnership or transferOwnership calls in the truncated code
This allows: If ownership is still held, privileged actions remain possible
Worth reading yourself
- ›The contract imports OpenZeppelin Ownable, providing an owner variable and onlyOwner modifier.
- ›Only interface definitions (IERC20) and libraries (SafeMath) are visible; the actual token implementation (state variables, constructor, transfer logic) is missing due to truncation.
What this did not check
- ›Source code was truncated at 9000 characters; the missing tail may contain minting, pausing, blacklist, fee, upgradeability, or withdrawal logic.
- ›Liquidity lock status, holder concentration, and actual on‑chain balances are NOT visible in the source and were not checked.
Automated review of verified source only. Not an audit. Does not cover on-chain state, holder distribution, liquidity, or deployer behavior. It cannot tell you whether a token is safe or whether to buy it. Absence of a finding is not evidence that a contract is sound — it may mean the relevant code was not readable, not verified, or not reached.
Want more than the free read?
A real security researcher personally reads this contract's verified source — not an automated re-run of the free check.
What's checked
The same 7 owner-power categories as the free check — mint authority, ability to disable trading, blacklist power, mutable fees, upgradeability, privileged withdrawal, and whether ownership is still active — plus 4 categories the free tier doesn't cover: exact current fee values and where they're set, whether ownership itself can be transferred (and to whom), any hardcoded or owner-settable exceptions to fees/limits/blacklist, and external contracts this one calls out to and trusts.
How it's done
I read the contract's actual verified source directly — no token-window truncation, since a person isn't limited by an LLM's context size the way the free tier is. Every finding cites the specific function or modifier it comes from; if the code doesn't determine something, the report says so instead of guessing.
What you get
A written report emailed to you within 24 hours: a plain-English summary, every finding with its evidence, and what the review could not determine from source alone.
Disclaimer: this is a capability review of verified source code, not a formal security audit and not investment advice. It reports what the contract's owner/admin technically CAN do — it does not check on-chain state, liquidity depth, holder concentration, or deployer behavior, and it does not certify a contract as safe.
Building something that needs this programmatically?
By purchasing, you agree to our Terms of Service and Privacy Policy.
This is a surface read
It reports capabilities visible in source. It does not model economics, test exploit paths, or reason about how contracts interact. A real review does — with runnable proofs for anything it claims.
Request a security review →Paid reviews go further than this free scan: every finding is signed, timestamped, and hash-chained into a record — self-scored 16/20 against an independent standard →