Skip to content

02 · Token check ​

Paste a token address on BNB Chain. Nothing is signed, nothing is spent.

Static reads ​

  • Metadata: name, symbol, decimals, total supply, bytecode size.
  • Verified source on Sourcify, with the contract name.
  • Owner: owner() or getOwner(), and whether it is renounced (zero or dead address). An active owner is a wallet or a contract; the page says which.
  • Proxy: EIP-1967 implementation, beacon and legacy slots. If the token is a proxy, the capability scan runs on the implementation.

Capability scan ​

The dispatcher of an EVM contract pushes each function selector as a PUSH4 constant. Grub walks the bytecode, skips push data, collects every PUSH4 and matches them against a table of privileged selectors:

CapabilityExamplesLevel
mintmint(address,uint256), mint(uint256)danger
blacklistblacklist(address), setBots, isBlacklisteddanger
upgradeupgradeTo, upgradeToAndCalldanger
selfdestructthe SELFDESTRUCT opcode outside push datadanger
pause, trading switch, fee setters, fee exemptions, limits, whitelistpause(), openTrading(), setBuyFee, excludeFromFees, setMaxWallet…warn
ownable, renouncetransferOwnership, renounceOwnershipinfo

A capability is a possibility, not a verdict. Combined with an active owner it becomes a finding; with a renounced owner it is mostly history. Renamed functions evade this scan, which is why the replay below exists.

Liquidity ​

PancakeSwap V2 pair against WBNB (reserves) and PancakeSwap V3 pools at every fee tier (WBNB balance). Pools on other venues, including Uniswap V4, are not visible to this scan and the page says so.

Buy and sell replay ​

When a V2 pair holds at least 0.2 BNB, Grub replays, in one eth_simulateV1 request from a fresh account funded by a state override:

  1. buy 0.05 BNB of the token through the router (fee-on-transfer safe method);
  2. approve the router;
  3. transfer half of the received tokens to a third account;
  4. sell the other half.

From the logs it measures the buy tax (received versus the router quote), the sell tax (BNB received versus the quote), and whether the transfer and the sell revert. A token you cannot sell is a honeypot whatever its website says. Taxes above 30 % are danger, above 10 % warn.

Verdict ​

Worst level among the findings. A verified token with an active owner and a mint function is marked danger on purpose: the owner can change the rules. The page always shows the evidence next to the stamp so you can disagree with it.

Grub · @grubonchain on X · open tools, no account · contracts unaudited · the official $GRUB address is published on the Contracts page first, anything before that is a scam.