What a Contract Reader report looks like
This is the actual, unedited report the free Contract Reader produced for Tether (USDT) on Ethereum, the most widely held stablecoin there is. We picked it on purpose: a trusted token can still give its owner serious powers, and the report's job is to show those powers, not to call the token good or bad.
Each finding is something the owner can do, like mint or freeze wallets. There's no safety rating.
Every finding cites the function that grants it, so you can check it yourself on the explorer.
The scope box says what wasn't read, such as proxies or very large contracts.
Generated September 28, 2026 · verify against the source
TetherToken
How the owner could rug you
7 owner powers found that could be used against holders. Each is a capability the code grants — not proof of intent.
The owner can increase total supply at any time, diluting all existing holders.
Code: function issue(uint amount) public onlyOwner { ... _totalSupply += amount; balances[owner] += amount; }
The owner can halt all token transfers, effectively freezing the market.
Code: function pause() onlyOwner whenNotPaused public { paused = true; } and modifier whenNotPaused used in transfer/transferFrom.
The owner can freeze specific accounts, preventing them from sending or receiving tokens.
Code: function addBlackList(address _evilUser) public onlyOwner { isBlackListed[_evilUser] = true; } and transfer functions require !isBlackListed[msg.sender].
The owner can raise the fee taken on each transfer (up to the coded caps), reducing the amount you receive.
Code: function setParams(uint newBasisPoints, uint newMaxFee) public onlyOwner { require(newBasisPoints < 20); require(newMaxFee < 50); basisPointsRate = newBasisPoints; maximumFee = newMaxFee.mul(10**decimals); }
The owner can point the token to a new contract with arbitrary logic, potentially changing balances or rules.
Code: function deprecate(address _upgradedAddress) public onlyOwner { deprecated = true; upgradedAddress = _upgradedAddress; } and transfer logic forwards to UpgradedStandardToken when deprecated.
If an address is blacklisted, the owner can delete its token balance, effectively confiscating those tokens.
Code: function destroyBlackFunds(address _blackListedUser) public onlyOwner { require(isBlackListed[_blackListedUser]); uint dirtyFunds = balanceOf(_blackListedUser); balances[_blackListedUser] = 0; _totalSupply -= dirtyFunds; }
The original deployer keeps control over minting, pausing, blacklisting, fee changes, and upgrades.
Code: owner is set in Ownable constructor and never renounced; onlyOwner modifiers protect privileged functions.
This checks only what the code can do. It cannot see whether liquidity is locked, how concentrated holders are, or what the team intends — those need live on-chain data. Absence of these mechanisms is not proof a token is safe.
What this could cost you
How much money would you put into this? We'll show you what you could actually lose — in dollars, not just a scary word like "risk."
Enter an amount above to see it in real dollars instead of just labels.
What the code allows
Evidence: function issue(uint amount) public onlyOwner { ... }
This allows: Allows the owner to create additional tokens after deployment.
Evidence: onlyOwner modifiers on pause, unpause, addBlackList, removeBlackList, destroyBlackFunds, setParams, deprecate, issue, redeem.
This allows: Owner can change core token behavior, fees, and user access.
Evidence: whenNotPaused modifier on transfer/transferFrom and blacklist checks require(!isBlackListed[msg.sender]).
This allows: Transfers can be globally paused or blocked for specific addresses.
Evidence: uint fee = (_value.mul(basisPointsRate)).div(10000); in transfer and transferFrom.
This allows: A portion of each transfer is taken and sent to the owner.
Evidence: function deprecate(address _upgradedAddress) public onlyOwner { deprecated = true; upgradedAddress = _upgradedAddress; }
This allows: Future logic can be swapped by the owner.
Evidence: function pause() onlyOwner whenNotPaused public { paused = true; } and whenNotPaused modifier.
This allows: Owner can halt all token activity.
Evidence: owner set in constructor of Ownable; no renounceOwnership function present.
This allows: Privileged powers remain with the deployer.
Worth reading yourself
- ›destroyBlackFunds can erase a blacklisted address balance
- ›deprecate enables a full contract upgrade via an external UpgradedStandardToken
- ›setParams caps fees at <20 basis points and <50 * 10**decimals, but still mutable
- ›issue/redeem let owner expand or shrink total supply at will
What this did not check
- ›Liquidity lock status, holder concentration, and actual on‑chain balances are NOT visible in the source and were not checked.
Automated review of verified source only. Not an audit. Does not cover on-chain state, holder distribution, liquidity, or deployer behavior. It cannot tell you whether a token is safe or whether to buy it. Absence of a finding is not evidence that a contract is sound — it may mean the relevant code was not readable, not verified, or not reached.
Want more than the free read?
A real security researcher personally reads this contract's verified source — not an automated re-run of the free check.
What's checked
The same 7 owner-power categories as the free check — mint authority, ability to disable trading, blacklist power, mutable fees, upgradeability, privileged withdrawal, and whether ownership is still active — plus 4 categories the free tier doesn't cover: exact current fee values and where they're set, whether ownership itself can be transferred (and to whom), any hardcoded or owner-settable exceptions to fees/limits/blacklist, and external contracts this one calls out to and trusts.
How it's done
I read the contract's actual verified source directly — no token-window truncation, since a person isn't limited by an LLM's context size the way the free tier is. Every finding cites the specific function or modifier it comes from; if the code doesn't determine something, the report says so instead of guessing.
What you get
A written report emailed to you within 24 hours: a plain-English summary, every finding with its evidence, and what the review could not determine from source alone.
Disclaimer: this is a capability review of verified source code, not a formal security audit and not investment advice. It reports what the contract's owner/admin technically CAN do — it does not check on-chain state, liquidity depth, holder concentration, or deployer behavior, and it does not certify a contract as safe.
Building something that needs this programmatically?
By purchasing, you agree to our Terms of Service and Privacy Policy.
This is a surface read
It reports capabilities visible in source. It does not model economics, test exploit paths, or reason about how contracts interact. A real review does — with runnable proofs for anything it claims.
Request a security review →Paid reviews go further than this free scan: every finding is signed, timestamped, and hash-chained into a record — self-scored 16/20 against an independent standard →
Check any token the same way
2 free checks a day. Attempts that fail don't count.
Open the Contract Reader