| Risk factor | Finding | Evidence | Date |
|---|---|---|---|
| Sellable | Yes | Transfer simulation | 11 Sept 2026 |
| Buy tax | No data | Contract | 11 Sept 2026 |
| Sell tax | No data | Contract | 11 Sept 2026 |
| Admin mint | Not present | Contract | 11 Sept 2026 |
| Transfers pausable | Not present | Contract | 11 Sept 2026 |
| Address blacklist | Not present | Contract | 11 Sept 2026 |
| Upgradeable proxy | No | Contract | 11 Sept 2026 |
| Source verified | Yes | Block explorer | 11 Sept 2026 |
| Top-10 holders | 47.2% | Holder distribution | 11 Sept 2026 |
| Liquidity locked | No | LP holders | 11 Sept 2026 |
| Holders | 219899 | Token contract | 11 Sept 2026 |
| Contract deployed | 4 Mar 2020 — 2,382 days ago |
| Deployment transaction | 0xe87715…3c4ed1 |
| Deployed by | 0x1449e0…6d9adb |
| Holders | 219,899 |
| Rank | Address | Share |
|---|---|---|
| #1 | 0x91d147…de3292 | 17.83% |
| #2 | 0x1d4896…030270 | 12.77% |
| #3 | 0xf97781…41acec | 5.00% |
| #4 | 0x27944b…2f7c80 | 2.47% |
| #5 | 0x841ed6…f13a34 | 2.20% |
This automated check looked at the COMP contract's code and current holder data on Ethereum and returned a score of 16 out of 18. In practical terms, the scan found no admin mint function, meaning nothing in the contract as read allows new tokens to be created on demand by an owner address. No transfer-pausing mechanism was detected, so there is no code path found that would let an owner freeze the token network-wide. No address blacklist function was found, meaning individual wallets do not appear to be blockable from moving or selling tokens through the contract itself. The contract is also not an upgradeable proxy, which means its core logic cannot be swapped out later by whoever controls it. A transfer simulation indicated the token is sellable, which is a basic check against so-called honeypot contracts that let you buy but not sell. Two things stand out as worth attention: top-10 wallets hold 47.2% of supply, a concentration level where large holders moving tokens could affect price significantly, and liquidity is not locked, meaning whoever provided the trading pool could withdraw it. Buy and sell tax data was not available from the contract at the time of the check.
It's worth being clear about what this does not cover. This is an automated read of contract mechanics only — it does not evaluate who is behind the project, how tokens are allocated or vested, whether marketing claims match reality, or whether any legal or regulatory obligations are being met. A contract can score well on code-level checks like this one while still carrying risks tied to team behaviour, business decisions, or how supply is distributed and controlled outside the contract's technical functions. This score reflects code and holder data only, not intent.
Before considering any transaction, it would be reasonable to look into who holds the top wallets and whether any are known exchange or treasury addresses rather than individual holders, check whether the liquidity pool address and its history are documented anywhere, review COMP's actual token distribution and vesting schedule from primary sources like Compound's own documentation or governance forum, and look at the contract's transaction history for any past behaviour that seems inconsistent with the code as currently read. Cross-referencing this with independent sources and forming your own view of the project's structure is a reasonable next step rather than relying on any single automated check.
Contracts change after they are checked. Tell us where to reach you and we will say when this one does. Free for three contracts, no account.
We checked 18 points out of 100.
The other 82 are where money is usually lost: who the team is, where the tokens sit, what the documents actually say, and what the project chose not to put on its front page.