Galaxy Heroes BEP-20 Audit 10855744

Download as pdf or txt
Download as pdf or txt
You are on page 1of 21

G A LA XY HE RO E S C O I N (G HC ) / BE P- 2 0 PRO JE CT & CO NT RA CT A UDI T / A UDI T PE RF O RME D BY DE SSE RT F I N A N C E

Galaxy Heroes Coin (GHC)


BEP-20 Audit
Performed at block 10855744

PERFORMED BY DESSERT FINANCE


FOR CONTRACT ADDRESS: 0x683fae4411249Ca05243dfb919c20920f3f5bfE0

1
INITIAL DISCLAIMER
Dessert Finance provides due-diligence project audits for various BSC projects. Dessert Finance in no
way guarantees that a project will not remove liquidity, sell off team supply, or otherwise exit scam.
Dessert Finance does the legwork and provides public information about the project in an easy-to-
understand format for the common person.

Agreeing to a project audit can be seen as a sign of confidence and is generally the first sign of trust
for a project, but in no way guarantees that a team will not remove all liquidity (“Rug Pull”), sell off
tokens, or completely exit scam. There is also no way to prevent private sale holders from selling off
their tokens. It is ultimately your responsibility to read through all documentation, social media
posts, and contract code of each individual project to draw your own conclusions and set your own
risk tolerance.
Dessert Finance in no way takes responsibility for any losses, nor does Dessert Finance encourage
any speculative investments. The information provided in this audit is for information purposes only
and should not be considered investment advice.
BE P - 2 0 C O NT RA C T FI NA L T HO UG HT S

Dessert Finance ONLY audits for the vulnerabilities listed in this report. Any vulnerability outside the
scope of this report is not covered by this audit. Dessert Finance ONLY audits contracts provided to
us by the team, ALL contracts that have been audited will be listed in the report. If there is only one
contract address listed this means Dessert Finance has ONLY audited the main contract and any
additional contracts (NFT contracts, Game contracts, DividendDistributor, etc.) have not been
reviewed by Dessert Finance and we cannot guarantee any form of security related to anything not
listed within this report. Dessert Finance has ONLY audited contracts listed in this report.
2
DessertDoxxed
DessertDoxxed is a service offered by Dessert Finance that allows projects to do a
private face reveal matched with an I.D to allow founders / team members to privately
Doxx themselves to us. This allows an added layer of security to the projects team but
also allows an added layer of confident to project supporters.
T E A M O VE RVI E W

✓ The founder of this project has been DessertDoxxed


3
Table of Contents

1. Contract Code Audit – Token Overview


2. BEP-20 Contract Code Audit – Overview
3. BEP-20 Contract Code Audit – Vulnerabilities Checked
4. Contract Code Audit – Contract Ownership
5. Contract Code Audit – Mint Functions
6. Contract Transaction Fees
7. Website Overview
8. Social Media
9. Final Thoughts Web/Social
10. Top Token Holders/Wallets
11. Location Audit
12. Review of Team
13. Roadmap
T A BLE O F C O NT E NT S

14. Disclaimers

4
Contract Code Audit – Token Overview

Contract Name Contract Address


0x683fae4411249Ca05243dfb919c20920f3f5b
fE0
GHC

Compiler Version Total Supply

v0.8.7+commit.e28d00a7
1,000,000,000,000,000 GHC
C O NT RA C T C O DE A UDI T – T O K E N O VE RVI E W

Contract Deployer Address Current Owner Address

0x2E8598a5576B12E1610A46fA518d39C5c2c13088 0x8defd2d9d3693809164d769e30a1b215762f87f4

5
BEP-20 Contract Code Audit – Overview
Dessert Finance was commissioned to perform an audit on Galaxy Heroes Coin (GHC).

Contract Address
0x683fae4411249Ca05243dfb919c20920f3f5bfE0

TokenTracker
Galaxy Heroes Coin (GHC)

Contract Creator
0x2e8598a5576b12e1610a46fa518d39c5c2c13088

Source Code
Contract Source Code Verified (Exact Match)

Contract Name
GHC
BE P- 2 0 C O NT RA C T C O DE A UDI T – O VE RVI E W

Other Settings
default evmVersion, None

Compiler Version
0.8.7+commit.e28d00a7

Optimization Enabled
Yes with 200 runs

Code is truncated to fit the constraints of this document.


The code in its entirety can be viewed here.

6
The contract code is verified on BSCScan.
BEP-20 Contract Code Audit – Vulnerabilities Checked
Vulnerability Tested AI Scan Human Review Result

Integer Overflow Complete Complete ✓ Low / No Risk

Integer Underflow Complete Complete ✓ Low / No Risk

Correct Token Standards Implementation Complete Complete ✓ Low / No Risk

Timestamp Dependency for Crucial Functions Complete Complete ✓ Low / No Risk

Exposed _Transfer Function Complete Complete ✓ Low / No Risk

Transaction-Ordering Dependency Complete Complete ✓ Low / No Risk

Unchecked Call Return Variable Complete Complete ✓ Low / No Risk

Use of Deprecated Functions Complete Complete ✓ Low / No Risk

Unprotected SELFDESTRUCT Instruction Complete Complete ✓ Low / No Risk

State Variable Default Visibility (2+ found) Complete Complete ✓ Low / Min Risk

Deployer Can Access User Funds Complete Complete


✓ Low / No Risk

This report is for the contract listed in previous page.


The contract code is verified on BSCScan.
7 The vulnerabilities listed above were not found in the token’s Smart Contract.
Contract Code Audit – Contract Ownership
Contract Ownership has not been renounced at the time of Audit

We have reached out to the team for an


explanation on why they are retaining
ownership of the contract.

The project intends to retain ownership of the


project to ensure LP is maintained at a
percentage that isn't too rich.
C O NT RA C T C O DE A UDI T – C O NT RA CT O W NE RSHI P

We have placed the contract owner address


below for your viewing:

Owner Address: 0x76e3d5dd9933f062c94705941630e30d8059c68f

8
Contract Code Audit – Mint Functions
This Contract Cannot Mint New GHC Tokens.

We do understand that sometimes


mint functions are essential to the
functionality of the project. If a mint
function is ever listed we will have the
team clarify its use case for
transparency purposes.
A mint function was not found in
C O NT RA C T C O DE A UDI T – MI N T FUNCT I O NS

the contract code.

9
Contract Transaction Fees
At the time of Audit the transaction fees (“tax”) listed below are the fees associated with
trading. These fees are taken from every buy and sell transaction unless otherwise stated.

Buy Tax

3% 2% 2% 2% 1%
LIQUIDITY MARKETING BUYBACK DEV GHC
POOL WALLET WALLET WALLET REFLECTIONS

Sell Tax
C O NT RA C T T RA N SA C T I O N FE E S

10
Website Part 1 – Overview
www.galaxyheroescoin.com
W E BSI T E DE SK T O P A ND MO BI LE VI E W A UDI T

Above images are actual snapshots of the current live website of the project.
Website was registered on 08/27/2021, registration expires 08/27/2022.
✓ This exceeds the 3 year minimum we like to see on new projects.
Website Part 2 – Checklist

✓ Mobile Friendly

✓ No JavaScript Errors

✓ Spell Check

✓ SSL Certificate

The website contained no JavaScript errors. No typos, or grammatical errors were


W E BSI T E CHE C K LI ST

present, and we found a valid SSL certificate allowing for access via https.

No additional issues were found on the website.

12
Website Part 3 – Responsive HTML5 & CSS3

No issues were found on the Mobile


Friendly check for the website. All
elements loaded properly and browser
resize was not an issue. The team has put
a considerable amount of thought and
effort into making sure their website
looks great on all screens.

No JavaScript errors were found. No


issues with loading elements, code, or
W E BSI T E RE SPO NI SVE HT ML5 /CSS T E ST

stylesheets.
Website Part 4 (GWS) – General Web Security

SSL CERTIFICATE CONTACT EMAIL SPAM / MALWARE / POPUPS


A valid SSL certificate was No malware found
found. Details are as follows: A valid contact email was
found on the official No injected spam found
Offered to: galaxyheroescoin.com website. Contact email is
listed as shown below: No internal server errors
Issued by: R3
Contact No popups found
Valid Until: 11/27/2021 [email protected]
Domain is marked clean by
Google, McAfee, Sucuri
Labs, & ESET
✓ ✓ ✓
G W S RE PO RT

14
Social Media

We were able to locate a Social Media networks for the project.


All links have been conveniently placed below.
SO C I A L ME DI A RE PO RT

Twitter Telegram Reddit Discord Facebook Instagram

✓ At least 3 social media networks were found.


15
Top Token Holders
The entire supply was in one wallet at the time of audit. We expect this to change as the
project goes through initial distribution phases. Please use the link below to view the most
up-to-date holder information.
Click here to view the most up-to-date list of holders
T O P T O K E N HO LDE RS

16
Location Audit
We were unable to identify a primary location for the project at this
time or a location has not been declared.

?
PRO JE C T LO C A T I O N

17
Team Overview

We are unable to find any


information about the team on the
website at this time. Projects may
choose to stay anonymous for a
myriad of reasons.
T E A M O VE RVI E W

✓ The Founder of this team has been DessertDoxxed


18
Roadmap
A roadmap was not found on the official website at the time of audit.
RO A DMA P

19
Disclaimer

The opinions expressed in this document are for general informational


purposes only and are not intended to provide specific advice or
recommendations for any individual or on any specific investment. It is only
intended to provide education and public knowledge regarding BSC projects.
This audit is only applied to the type of auditing specified in this report and the
scope of given in the results. Other unknown security vulnerabilities are beyond
responsibility. Dessert Finance only issues this report based on the attacks or
vulnerabilities that already existed or occurred before the issuance of this
report. For the emergence of new attacks or vulnerabilities that exist or occur in
the future, Dessert Finance lacks the capability to judge its possible impact on
the security status of smart contracts, thus taking no responsibility for them.
The smart contract analysis and other contents of this report are based solely
on the documents and materials that the contract provider has provided to
Dessert Finance or was publicly available before the issuance of this report
(issuance of report recorded via block number on cover page), if the documents
and materials provided by the contract provider are missing, tampered, deleted,
concealed or reflected in a situation that is inconsistent with the actual
situation, or if the documents and materials provided are changed after the
issuance of this report, Dessert Finance assumes no responsibility for the
resulting loss or adverse effects. Due to the technical limitations of any
organization, this report conducted by Dessert Finance still has the possibility
that the entire risk cannot be completely detected. Dessert Finance disclaims
any liability for the resulting losses.

Dessert Finance provides no guarantees against the sale of team tokens or the
removal of liquidity by the project audited in this document. Even projects with a
low risk score have been known to pull liquidity, sell all team tokens, or exit-
scam. Please exercise caution when dealing with any cryptocurrency related
platforms.

The final interpretation of this statement belongs to Dessert Finance.


DI SC LA I ME R

Dessert Finance highly advises against using cryptocurrencies as speculative


investments and they should be used solely for the utility they aim to provide.

20
Thank
You
T HA NK YO U!

DESSERT FINANCE PROJECT AUDIT HAS BEEN COMPLETED FOR GALAXY HEROES COIN (GHC) 1 DSRT HAS BEEN SENT TO
AUDITED PROJECT’S CONTRACT ADDRESS FOR VERIFICATION OF THIS AUDIT AT BLOCK NUMBER: 10855744

www.dessertswap.finance
21
https://t.me/dessertswap

You might also like