CONTRACT ANALYSIS

FiatTokenV2_2

Scanned August 11, 2026 · Check a different contract →

Code review

FiatTokenV2_2

Ethereum · 0xA0b869913606eB48
View source →
3
capabilities present
4
undetermined
7
checks run
Warn someone before they buy:Share on XShare on RedditShare on LinkedIn
🪤

How the owner could rug you

3 owner powers found that could be used against holders. Each is a capability the code grants — not proof of intent.

🟡Transfers or selling can be blocked/paused/toggled
Yes

The owner could pause transfers, preventing you from selling or transferring your tokens

Code: The `whenNotPaused` modifier is used in multiple functions, indicating that transfers can be paused

🟡Specific addresses can be frozen/blocked from transferring
Yes

The owner could blacklist your address, preventing you from transferring your tokens

Code: The `_setBlacklistState` function allows the owner to blacklist addresses

🔴The contract is a proxy and can have its logic swapped by an admin
Yes · high

The owner could swap the contract's logic, potentially introducing malicious code

Code: The contract is a proxy, as indicated by the note in the problem statement

Owner can mint new tokens
Undetermined

Code: No explicit mint function found in the provided code, but contract is a proxy and the implementation may be incomplete

A fee/tax can be changed, and is uncapped or settable very high
Undetermined

Code: No explicit fee-changing function found in the provided code, but contract is a proxy and the implementation may be incomplete

An owner/admin can move or withdraw user funds/reserves
Undetermined

Code: No explicit privileged withdrawal function found in the provided code, but contract is a proxy and the implementation may be incomplete

A privileged owner/admin still holds these powers
Undetermined

Code: No explicit information about ownership or admin roles found in the provided code, but contract is a proxy and the implementation may be incomplete

This checks only what the code can do. It cannot see whether liquidity is locked, how concentrated holders are, or what the team intends — those need live on-chain data. Absence of these mechanisms is not proof a token is safe.

What this could cost you

How much money would you put into this? We'll show you what you could actually lose — in dollars, not just a scary word like "risk."

$

Enter an amount above to see it in real dollars instead of just labels.

Scope of this review

This is a proxy contract. The findings below describe the implementation at 0x43506849d7c04f9138d1a2050bbf3a0c054402dd. The implementation can be swapped for different code by whoever controls the upgrade mechanism.

This contract's source is characters — only the first were analyzed, so parts of it were not examined. That's the real reason, not a vague size limit: NaN characters were cut off the end.

What the code allows

Transfer restrictions
Present

Evidence: The `whenNotPaused` modifier and the `_setBlacklistState` function indicate that transfers can be restricted

This allows: Transfer restrictions can affect your ability to sell or transfer your tokens

Upgradeability
Present

Evidence: The contract is a proxy, as indicated by the note in the problem statement

This allows: Upgradeability determines whether the contract's logic can be changed, and under what conditions

Pausability
Present

Evidence: The `whenNotPaused` modifier is used in multiple functions, indicating that the contract can be paused

This allows: Pausability determines whether the contract's functionality can be temporarily suspended

Mint authority
Undetermined

Evidence: No explicit mint authority found in the provided code, but contract is a proxy and the implementation may be incomplete

This allows: The mint authority determines who can mint new tokens, and under what conditions

Owner privileges
Undetermined

Evidence: No explicit information about owner privileges found in the provided code, but contract is a proxy and the implementation may be incomplete

This allows: The owner's privileges determine what actions they can take, and how they can affect the contract's state

Fees on transfer
Undetermined

Evidence: No explicit information about fees on transfer found in the provided code, but contract is a proxy and the implementation may be incomplete

This allows: Fees on transfer can affect the cost of selling or transferring your tokens

Ownership status
Undetermined

Evidence: No explicit information about ownership status found in the provided code, but contract is a proxy and the implementation may be incomplete

This allows: The ownership status determines who has control over the contract, and what actions they can take

Worth reading yourself

  • The contract is a proxy, as indicated by the note in the problem statement
  • The `whenNotPaused` modifier is used in multiple functions, indicating that transfers can be paused
  • The `_setBlacklistState` function allows the owner to blacklist addresses

What this did not check

  • The provided code is truncated, and may not contain all relevant information
  • The contract is a proxy, and the implementation may be incomplete
  • Liquidity lock, holder concentration, and actual on-chain balances are not visible in the source code and were not checked

Automated review of verified source only. Not an audit. Does not cover on-chain state, holder distribution, liquidity, or deployer behavior. It cannot tell you whether a token is safe or whether to buy it. Absence of a finding is not evidence that a contract is sound — it may mean the relevant code was not readable, not verified, or not reached.

Want more than the free read?

A real security researcher personally reads this contract's verified source — not an automated re-run of the free check.

What's checked

The same 7 owner-power categories as the free check — mint authority, ability to disable trading, blacklist power, mutable fees, upgradeability, privileged withdrawal, and whether ownership is still active — plus 4 categories the free tier doesn't cover: exact current fee values and where they're set, whether ownership itself can be transferred (and to whom), any hardcoded or owner-settable exceptions to fees/limits/blacklist, and external contracts this one calls out to and trusts.

How it's done

I read the contract's actual verified source directly — no token-window truncation, since a person isn't limited by an LLM's context size the way the free tier is. Every finding cites the specific function or modifier it comes from; if the code doesn't determine something, the report says so instead of guessing.

What you get

A written report emailed to you within 24 hours: a plain-English summary, every finding with its evidence, and what the review could not determine from source alone.

Disclaimer: this is a capability review of verified source code, not a formal security audit and not investment advice. It reports what the contract's owner/admin technically CAN do — it does not check on-chain state, liquidity depth, holder concentration, or deployer behavior, and it does not certify a contract as safe.

Building something that needs this programmatically?

By purchasing, you agree to our Terms of Service and Privacy Policy.

This is a surface read

It reports capabilities visible in source. It does not model economics, test exploit paths, or reason about how contracts interact. A real review does — with runnable proofs for anything it claims.

Request a security review →

Paid reviews go further than this free scan: every finding is signed, timestamped, and hash-chained into a record — self-scored 16/20 against an independent standard →

✉️Email us