Verify every token before you buy Unlimited checks · $3.99/wk · Cancel anytime
Get Unlimited
Swap on Verixia
[ on-chain  ·  solana + evm ]

Token Risk Check

Paste any contract address for an instant on-chain risk assessment -- honeypot detection, liquidity analysis, holder concentration, and contract permissions.

Read the contract before the contract reads you. Honeypot, rug, and scam detection from on-chain state — not market data.

⚠️ Token Risk Check
✓ On-Chain Analysis
🔒 No Signup
⚡ Results in Seconds
🔍 Honeypot detection
💧 LP lock status
👥 Holder concentration
⚡ Solana + EVM
4.6 / 5 from 2,383 users Direct on-chain reads 🔐 Non-custodial — no wallet connect required Sub-5-second scan 🔗 Solana · Ethereum · Base · Arbitrum · BNB · Polygon · Avalanche 📊 50,231 risk checks run
Live
🔍 On-chain read ⚡ Seconds ✓ No signup
>_
Enter the full token contract address for the most accurate on-chain analysis
No address? Try a popular check:
1 free check · Unlimited from $3.99/wk
No signup required · Results in seconds
Unlimited checks from $3.99 / week · Cancel anytime
Use the same email entered during checkout to restore access
Unlimited token checks active

Unlimited Token Risk Checks

Verify every contract before buying. Honeypot detection, LP lock analysis, and holder concentration reviews across Solana and EVM.
$5.6BFBI crypto losses 2023
$1B+FTC losses 2023
<5sper contract scan
Best Value -- Save 80%
Yearly Access
$39.99 / yr  ·  $3.33/mo
Popular
Monthly Access
$11.99 / month
Try it -- no commitment
Weekly Access
$3.99 / week · cancel anytime
SSL Secured Stripe Cancel anytime No hidden fees
Live Detections
127 scans today
49K+Scans Run
6Chains
15+Risk Signals
FreeFirst Check
What the checker detects
Example signals · run a scan to see live results
⚠️Sell TaxDETECTED
💧LP LockUNLOCKED
🔑Mint AuthorityACTIVE
OwnershipRENOUNCED
🐋Whale Wallet42%
📅Token Age3 DAYS
🚨Approval RiskHIGH
CooldownACTIVE
🔄Last Update48H AGO
📉Liquidity 24h-12%
🚫Transfer LockENCODED
Freeze AuthENABLED
📋ContractVERIFIED
💰LP Depth$48K
🔗Blacklist FnPRESENT
🔍
Honeypot Detection
Simulates sell transactions to detect transfer locks, fee traps, and whitelist-only exit conditions before you buy in. Reads the contract directly — not market data. Works across Solana SPL tokens and all major EVM chains.
💧
Liquidity & Holders
Reviews pool depth, LP lock status, and top wallet percentages. Surfaces unlocked pools and concentrated wallets before the price collapses.
Results in Seconds
On-chain read — no API delays, no market data lag. Raw contract analysis returned in under 5 seconds.
Token verified? Swap at best price.
Route across Raydium, Orca, Meteora & 50+ DEXes — non-custodial, no KYC
Swap on Verixia →
SOL ETH BASE ARB BNB AVAX Powered by Verixia

Token Risk Analysis -- Contract, Liquidity & Holders

🔗 TL;DR

A token's risk lives in three places: contract permissions (can the dev mint, freeze, or block sells?), liquidity structure (is the LP locked and deep enough to exit?), and holder distribution (can a handful of wallets dump the entire float?). The checker above reads all three directly on-chain in under five seconds.

Scan time< 5 sec
Signals checked15+
Cost (first check)Free

Malicious function detectors serve as a vital tool in the analysis of smart contracts, honing in on specific segments of code that may enable behaviors detrimental to token holders and the broader ecosystem. These functions often encompass capabilities such as unauthorized fund transfers, privilege escalations, or the unilateral alteration of contract state—operations that, if misused, can lead to financial losses or erosion of trust. However, the detection of such functions is far from straightforward. Many of these code segments can superficially resemble standard administrative or utility methods, making it challenging to discern their true nature without a nuanced, context-aware examination. Automated detection systems can flag these functions based on patterns or keywords, yet the complexity of smart contract design means that some flagged functions are in fact integral to legitimate contract operation, while genuinely harmful functionalities may be obfuscated or embedded within convoluted logic flows that evade easy detection.

At the core of evaluating malicious functions lies the question of contract control—specifically, how mutability and permissions are architected within the contract’s code. Functions that permit the contract owner or a privileged address to mint additional tokens, freeze transfers, or withdraw funds represent concentrated points of control that introduce structural risk. These capabilities can be perfectly valid for operational reasons such as token supply management or regulatory compliance, but they simultaneously create vectors through which malicious actions might be executed. The risk profile shifts significantly depending on whether these permissions are permanently assigned or can be modified over time. Contracts employing proxy patterns or upgradeable logic introduce an additional layer of uncertainty, as the ability to alter contract behavior post-deployment can mask potential malicious intentions. In such scenarios, assessing who holds the authority to invoke these functions, and under what constraints, becomes a critical focus. Without this understanding, the mere presence of owner-only functions does not automatically equate to danger, but it does warrant heightened scrutiny.

The practical implications of malicious functions are also shaped by the operational environment in which they exist, particularly the interplay between network transaction fees and governance mechanisms like multisignature (multisig) wallets. On blockchains with low transaction fees, attackers might find it economically feasible to repeatedly invoke malicious functions or launch spam attacks that exploit vulnerabilities. This economic accessibility can amplify the threat posed by dangerous functions, as the cost barrier for exploitation is reduced. Conversely, networks with higher fees inherently impose friction that can dissuade attackers from frequent or large-scale exploit attempts, although this does not eliminate risk altogether. Multisig wallets add another dimension by requiring multiple independent approvals before privileged functions can be executed. This layer of operational complexity can significantly mitigate the risk associated with a single compromised key or insider threat, effectively diffusing control and enhancing resilience against malicious actions. The dynamic interaction between these factors influences not only the likelihood of exploitation but also the potential speed and scale at which damage can occur.

It is critical to emphasize that the detection of potentially malicious functions alone does not provide definitive evidence of exploitative intent or impending loss. Many smart contracts intentionally include privileged functions to facilitate legitimate administrative tasks, contract upgrades, or compliance with evolving regulatory standards. The context in which these functions operate—such as the transparency of ownership, the presence or absence of multisig controls, and the nature of any upgrade mechanisms—greatly impacts their risk profile. When such functions exist alongside opaque ownership structures or mechanisms that enable unchecked code changes, the combination can be particularly concerning, as it raises the possibility of covert or retrospective malicious behavior. On the other hand, when these elements are subject to clear, community-driven governance and robust multisig safeguards, the same functions may be benign or even essential for the healthy evolution of the protocol. This duality highlights the importance of examining the broader permission architecture and governance context to accurately interpret the implications of any flagged malicious function.

Further analytical depth arises when considering the strategic behavior of actors controlling these functions. In some cases, the concentration of privileged permissions may reflect a deliberate trade-off between decentralization and operational efficiency, particularly in early-stage projects where active management is needed to stabilize token economics or respond to unforeseen technical issues. However, this concentration inherently carries the risk of abuse, whether intentional or accidental, and can undermine user confidence. The capacity for future upgrades or dynamic changes to permissions introduces an additional layer of unpredictability, as it can allow for the introduction of new malicious functions or the enhancement of existing ones without community consent. Consequently, a comprehensive risk assessment must consider not only the static presence of certain functions but also the contract’s upgradeability framework and the transparency of the governance process that oversees such changes.

Moreover, the complexity of smart contract code can itself be a tool for obfuscation. Malicious functions may be hidden behind intricate logic, conditional checks, or unusual function signatures that evade detection by simplistic pattern-matching tools. This necessitates a deeper, often manual, code review by skilled analysts who can trace execution paths and understand subtle interactions between functions. Without such analysis, automated malicious function detectors may generate false positives or false negatives, potentially misguiding stakeholders. Therefore, while these detectors provide valuable initial signals, their findings must be contextualized within a thorough understanding of the contract’s architecture and governance dynamics.

In summary, malicious function detection is a nuanced field that extends beyond binary identification of suspicious code. It requires integrating knowledge of access controls, upgradeability, network economics, and governance structures to discern whether flagged functions pose genuine threats. Recognizing that the pattern of permissions alone does not confirm malicious intent is essential, as is appreciating how different operational environments and governance models can shape the risk landscape. Only through this layered and context-rich analysis can the true nature of potentially harmful functions be understood and properly managed.

Pre-buy on-chain checklist

  • Mint authority renouncedConfirms supply is capped — no new tokens can be issued post-launch.
  • LP locked or burnedLiquidity cannot be removed in a single transaction. Lock duration and locker contract are both verifiable on-chain.
  • !Top 10 holders under 40%Lower concentration means coordinated dumps are mechanically harder. Above 40% is a structural caution.
  • !No active freeze authorityActive freeze means wallets can be paused at the contract level — no exit possible during a freeze.
  • ×No transfer restrictionsThe transfer function should accept any holder selling. Encoded sell blocks, whitelist exits, and hidden tax functions are honeypot signatures.

Frequently asked questions

Verify the contract address before you buy in. Paste it into the scanner above for the full on-chain breakdown.

Why on-chain signals matter

🔒
Non-custodial Your wallet keys never leave your device. Funds move directly between wallets through the smart contract — Verixia holds nothing.
No account required No sign-up, no KYC, no email. Connect your wallet and swap. Disconnect at any time — no ongoing permissions required.
Solana + EVM Checks SPL tokens and EVM contracts across Ethereum, Base, Arbitrum, BNB Chain, Polygon, and Avalanche.
⚙ Methodology
Every risk verdict is generated from three on-chain reads run in parallel: (1) direct contract bytecode analysis for honeypot patterns, mint/freeze authority, and blacklist functions; (2) liquidity pool inspection for LP lock status, depth, and removable percentage; (3) holder distribution from token-account snapshots. No editorial opinion is layered on the output. Read the full methodology →