Several Critical Issues Found
Simply get in touch with us and get a detailed security report for your smart contract with in-depth bug descriptions and security recommendations. We're eager to hear from you!
The minting authority is an address or entity granted permission to create new tokens within a token's ecosystem.
Based on the on-chain analysis, the mint authority is not set, meaning that no additional tokens can be minted beyond the current supply.
The freeze authority is a control mechanism within some token ecosystems that allows the designated authority to prevent specific accounts from transferring tokens.
Based on the on-chain analysis, since the freeze authority is not set, there is no central entity or mechanism in place to block or freeze token transfers between accounts.
Metadata provides detailed information about the token, including its name, symbol, and other descriptive elements that help users and programs identify and interact with the token.
The Bonk Token's metadata can be viewed on the Solana Explorer Website.
The update authority, identified by the account 9AhKqLR67hwapvG8SA2JFXaCshXc9nALJjpKaHZrsbkw for Bonk Token, holds the privilege to modify this metadata. This role has the ability to maintain the token's relevance and accuracy of information over time.
Token extensions refer to additional features or capabilities that can be integrated into a token's design, beyond the standard functionalities.
The Bonk token does not use the Token 2022 program, there are no extra features or extensions beyond the basic SPL token functionalities implemented.
The project Bonk Token uses the pre-built SPL token program on the Solana chain to generate fungible tokens. Unlike on the EVM-based chain, the built-in SPL token program eliminates the need to create an individual token contract/program.
Note: The SPL token program is a component of the Solana blockchain and its security ought to be ensured by Solana. Additionally, the SPL token program is an integral part of the Solana blockchain and is secured by the Solana network.
This inspection detailed the findings from a preliminary fast-track behavior and security analysis of a token that utilizes Solana's built-in program including Solana Token Program and Solana Token Program 2022. The scan aimed to verify various aspects of the token, including deployment configuration, real-time transactions, token holder distribution, and adherence to a memecoin security checklist, which may interest stakeholders looking to understand potential risks.
This document outlines the results of a preliminary fast-track behavior and security analysis and does not constitute an official security assessment. Stakeholders should proceed with a full-scale audit to understand and evaluate the token's security posture.
The scan employed automated tools capable of quickly analyzing the token based on predefined metrics and checklists. The focus was on identifying overt issues that could be readily apparent without in-depth testing.
This scanned result reflects the findings from a fast-track behavior and security analysis and should not be interpreted as a comprehensive security audit. The inspection result is limited to the following:
ID | Title | Severity |
---|---|---|
No Data |
Severity: Medium
Category: Centralization
Based on onchain analysis, the update authority exists (9AhKqLR67hwapvG8SA2JFXaCshXc9nALJjpKaHZrsbkw) and the isMutable
option is set to True
.
Unauthorized changes to metadata could mislead users and platforms, disrupting ecosystem operations based on incorrect token information. https://developers.metaplex.com/token-metadata/update
Severity: Medium
Category: Centralization
Based on onchain analysis, the update authority exists (9AhKqLR67hwapvG8SA2JFXaCshXc9nALJjpKaHZrsbkw) and the isMutable
option is set to True
.
Unauthorized changes to metadata could mislead users and platforms, disrupting ecosystem operations based on incorrect token information. https://developers.metaplex.com/token-metadata/update
Severity: Medium
Category: Centralization
Based on onchain analysis, the update authority exists (9AhKqLR67hwapvG8SA2JFXaCshXc9nALJjpKaHZrsbkw) and the isMutable
option is set to True
.
Unauthorized changes to metadata could mislead users and platforms, disrupting ecosystem operations based on incorrect token information. https://developers.metaplex.com/token-metadata/update
This document outlines the results of a preliminary fast-track behavior and security analysis and does not constitute an official security assessment. Stakeholders should proceed with a full-scale audit to understand and evaluate the token's security posture.