VegaSec / Trust report
Token AuditAVOID

Thin Liquidity Token Audit

THIN · SOLANA · Report VS-SOLANA-THIN

0

Score / 100

Verdict

Block from promotion

Multiple public-data risk signals detected. Do not rely on this without a manual review.

Surface analyzed
Token Audit
Scan source confidence
38%

Elevated

Methodology
Public sources · v0

Automated, not analyst-reviewed

Generated
May 25, 2026, 3:00 PM UTC

Upgrade path

Need a private evidence memo?

Turn this public artifact into an operator-reviewed Private Review memo. Paid review stays separate from the public score.

Request Private Review

Share this report

Ready

Public-source signals. Not a substitute for a formal audit. No buy/sell recommendation.

Critical signal

Liquidity

94/100

Critical signal

Owner control

92/100

Critical signal

Holder concentration

88/100

Elevated signal

Trading behavior

73/100

THIN

Asset identity

THIN / SOLANA

Thin Liquidity Token Audit identity preserved in the saved public report and Trust Index entry.

Generated May 25, 2026, 3:00 PM

Scanned target address

So1anaDangerDemo1111111111111111111111111111

Liquidity

$9.1K

24h volume

$62K

Pair source

UNKNOWN

VegaSec summary

This fixture shows an AVOID token case: owner control, fragile liquidity and extreme holder concentration make the risk incompatible with public promotion without manual review.

Risk exposure

Risk exposure by category

Each row is a public-data dimension the audit scored. Higher values mean more signal worth investigating before relying on this asset.

  • Liquidity

    Critical signal

    94/100
  • Owner control

    Critical signal

    92/100
  • Holder concentration

    Critical signal

    88/100
  • Trading behavior

    Elevated signal

    73/100
  • Deployer

    Elevated signal

    68/100
  • Contract surface

    Elevated signal

    67/100
  • Social proof

    Elevated signal

    58/100

Token risk checklist

Market-standard token controls mapped from VegaSec evidence. Higher risk scores mean more signals to review before relying on the asset.

  • Honeypot detection

    Can holders exit? Trading simulation and public evidence flag trapped-funds risk.

  • Transfer / tax behavior

    Fee or transfer rules that can drain holders or make exits expensive.

  • Mint authority

    Owner or role-controlled mint paths that could dilute supply.

  • Owner powers

    Pause, blacklist, transfer restriction, or admin controls that can block exits.

  • Proxy / upgradability

    Whether deployed logic can be replaced after launch without clear operator review.

  • Holder concentration

    Top-wallet dominance and concentration signals from public holder data.

  • Liquidity depth

    Pool depth and volume evidence used only as risk context, not a market call.

  • Source verification

    Verified source improves auditability; missing source stays a limitation.

  • Deployer track record

    Public deployer history and prior-contract context where available.

  • !

    Social & website signals

    Website, social, and public metadata gaps that affect evidence confidence.

Pass! Caution Fail Unknown

Audit pack

Token posture + provenance

Per-dimension reasoning over the public token surface (DexScreener pair + explorer verified source). Control markers only — never a market position recommendation.

  • Source verificationadequate

    Evidence

    • Contract source is verified on an approved explorer.

    Caveats

    • Verified source proves the on-chain bytecode matches the published Solidity; it does not prove the code is secure.

    Next step

    • Pair with the Solidity audit pack for the actual security analysis.
  • Contract provenanceadequate

    Evidence

    • Contract address: So1anaDangerDemo1111111111111111111111111111 on solana.

    Caveats

    • Provenance only confirms identity; it does not prove the contract is secure.

    Next step

    • Cross-reference the address with the project's official channels before treating it as canonical.
  • Pool liquidityunknown

    Caveats

    • Liquidity figure was not exposed by the public pair adapter at scan time.

    Next step

    • Operator review required to gather this dimension before a verdict can be issued.
  • Holder distributionunknown

    Caveats

    • Holder count and concentration were not exposed at scan time.

    Next step

    • Operator review required to gather this dimension before a verdict can be issued.
  • Market ageunknown

    Caveats

    • Pair creation timestamp was not exposed at scan time.

    Next step

    • Operator review required to gather this dimension before a verdict can be issued.
  • Deployer signalsunknown

    Caveats

    • Deployer prior-contract history was not exposed at scan time.

    Next step

    • Operator review required to gather this dimension before a verdict can be issued.

Evidence

Evidence that explains the verdict

Each row is one public-data signal pulled from automated sources. Use it as a starting point for review, not as a final answer.

  • Liquidity is fragile compared with observed market attention
  • Holder concentration and owner control require manual review
  • Source confidence is too weak for public promotion

Baseline source confidence

0%

Methodology baseline used by the verdict engine. Higher baseline reduces the penalty for ambiguous data; low baseline pushes the verdict toward UNKNOWN/WATCH. May differ from the scan source confidence shown at the top when the live scan supplied a fresher signal.

Badges

manual-review-requiredpublic-data-only

How to read this report

Score, confidence, ranking — four moving parts, no hand-tuning.

Generated 2026-05-25T12:00:00.000-03:00 · Token · THIN

Score bands

  • 019

    AVOID-style triage · this report

    Multiple high or critical findings, low source confidence, or unverified context. Public action should pause until a Private Review or a re-scan with better evidence.

  • 2049

    High caution

    Notable findings or thin evidence. Worth a Private Review before relying on the artifact.

  • 5069

    Watch

    Mixed signals: some evidence, some gaps. Re-scan after material changes to the target.

  • 7089

    Clear surface (automated)

    No critical or high findings via static analysis. Not a safety claim — human review still recommended for diligence work.

  • 90100

    Strong surface (automated)

    No critical or high findings, verified source, and high source confidence. Not a safety claim — human review still recommended for diligence work.

Score
Deterministic 0–100 derived from severity counts. Same formula across every report. Lower means more risk.
Confidence
Separate axis. Measures how much VegaSec trusts the input data. Low confidence pushes the verdict toward UNKNOWN; the two are never collapsed into one number.
Ranking / percentile
Only meaningful within the eligible Trust Index set. Shown on /trust-index when the eligible pool is large enough. Today the public index is a controlled preview.

Private Review is separate

A paid Private Review does not raise the public score on this report. Public score reflects public-source evidence only. Private Review adds operator attestation and a confidential memo, never a score bump.

Export and share

  • · Shareable public URL: copy from the report actions panel.
  • · Markdown export: every export carries the report id, target, verdict, generated timestamp, and the public-data disclaimer.
  • · PDF export: not in this MVP. Tracked as a follow-up — the Markdown export contains the same content and prints cleanly to PDF from a browser today.

Community artifact

Report ready to share, copy or export.

This link preserves the scanned target, route, confidence and Scan ID. Example report links are marked as public samples; live Token Audit and Repository Audit links require submitted context and fail closed to UNKNOWN when evidence is missing.

Ready

VegaSec is intelligence and triage. It is not financial advice, does not promise returns and does not replace manual due diligence.