Token Audit Study: 15,008 CoinGecko & CoinMarketCap Tokens

15,008
Tokens Audited
57.7%
High Risk
16.3%
Clean
7
Chains Covered

Background

CoinGecko and CoinMarketCap together list tens of thousands of EVM token contracts - the reference point most retail investors use when deciding whether a token is legitimate. Being listed carries an implicit signal of credibility. This study tests that assumption at scale.

ChainAware ran Token Audit across 15,008 deduplicated EVM contracts drawn from both platforms, covering Ethereum, BSC, Base, Polygon, Arbitrum, Optimism, and Avalanche. 127 security checks were applied across 11 modules. 97.3% of contracts in the dataset had verified source code.


Chain Distribution

Chain Tokens Share
Ethereum 5,572 37.1%
BSC 4,265 28.4%
Base 2,609 17.4%
Arbitrum 1,038 6.9%
Polygon 1,007 6.7%
Optimism 286 1.9%
Avalanche 231 1.5%

Risk Verdict Distribution

Verdict Count Share
High Risk 8,661 57.7%
Suspicious 3,740 24.9%
Honeypot 156 1.0%
Clean 2,451 16.3%

83.7% of listed tokens scored below Clean. The listing status of a token on CoinGecko or CoinMarketCap is not a security signal.


Risk by Chain

BSC had the worst risk profile of any chain in the dataset. Avalanche performed best, though even there less than 30% of tokens scored Clean.

Chain High Risk Clean
BSC 67.4% 7.5%
Optimism 63.3% 10.5%
Arbitrum 62.2% 14.3%
Ethereum 59.7% 19.9%
Polygon - -
Base - -
Avalanche 41.6% 29.9%

Primary Risk Drivers

No Mint Cap - 35.3% of Tokens

5,305 tokens (35.3%) have no cap on the total supply that can be minted. The deployer can expand supply without limit at any point after launch.

Zero tokens with this finding appeared in the Clean verdict bucket. No mint cap is the single strongest predictor of a High Risk verdict in the dataset.

No Timelock - 35.8% of Tokens

5,373 tokens (35.8%) have no timelock on administrative functions, allowing a single transaction to alter protocol parameters without advance notice to holders.


Liquidity Findings

Liquidity analysis revealed a significant share of listed tokens with no accessible market at all:

Finding Count Share
No Pool Found 4,343 28.9%
LP Unlocked 7,423 49.5%
Critical TVL (under $1,000) 3,911 26.1%
Low TVL (under $10,000) 3,051 20.3%
Partial LP Lock 271 1.8%

28.9% of listed tokens have no liquidity on any tracked DEX - they cannot be sold. 49.5% have LP controlled entirely by the deployer, who can drain the pool at will.


Proxy and Upgradeability

5,235 tokens (34.9%) are upgradeable proxy contracts - the underlying logic can be replaced after deployment. Of those:

  • EOA single-key controlled: 118 tokens - a single private key can rewrite the contract
  • Multisig controlled: 31 tokens
  • DAO / protocol governed: 1,324 tokens

Honeypots

156 confirmed honeypots were identified (1.0%). Common patterns among those 156:

Pattern Share of Honeypots
Custom transfer entry points 56%
Layered transfer delegation 51%
Unexpected events in transfers 47%
Obfuscated variable names 36%
Blacklist functions 29%
Excessive branching 28%

Additional High-Risk Patterns

Finding Count Share
Hidden mint functions 980 6.5%
Asymmetric pause patterns 718 4.8%
Fake burn functions 330 -
Currently paused tokens 30 -

Risk Score Distribution

Metric Score
Mean 102.2
Median 100.0
25th percentile 55.0
75th percentile 145.0
Maximum 1,375

Scores are additive - each triggered finding contributes its weighted severity to the total. A score of 1,375 represents a contract with critical findings across multiple modules simultaneously.


Products Used

  • Token Audit - 127 checks across 11 modules: Ownership, Supply, Liquidity, Transfer, Approve, Permit, Pausability, Reentrancy, Honeypot, and more
  • ChainAware Behavioral Database - 23M+ wallet profiles supporting deployer wallet analysis
  • Source: CoinGecko + CoinMarketCap combined, deduplicated

Audit a Token →    Token Audit Documentation →


Further Reading


Dataset: 15,008 EVM contracts from CoinGecko and CoinMarketCap, 97.3% source-verified. Full methodology →