Token Audit Study: 15,008 CoinGecko & CoinMarketCap Tokens

Key Takeaways
- 57.7% of listed tokens scored High Risk; only 16.3% scored Clean - being listed on CoinGecko or CoinMarketCap is not a security signal
- 35.3% of tokens have no mint cap (unlimited supply inflation possible) and 49.5% have unlocked LP (deployer can drain the pool at will)
- BSC is the highest-risk chain in the dataset: 67.4% High Risk, 7.5% Clean; Avalanche performed best with 29.9% Clean
- 156 confirmed honeypots (1.0%) were identified; the most common patterns were custom transfer entry points (56%) and layered transfer delegation (51%)

15,008
Tokens Audited
57.7%
High Risk
16.3%
Clean
7
Chains Covered

Background

CoinGecko and CoinMarketCap together list tens of thousands of EVM token contracts - the reference point most retail investors use when deciding whether a token is legitimate. Being listed carries an implicit signal of credibility. This study tests that assumption at scale.

ChainAware ran Token Audit across 15,008 deduplicated EVM contracts drawn from both platforms, covering Ethereum, BSC, Base, Polygon, Arbitrum, Optimism, and Avalanche. 127 security checks were applied across 11 modules. 97.3% of contracts in the dataset had verified source code.


Chain Distribution

Chain Tokens Share
Ethereum 5,572 37.1%
BSC 4,265 28.4%
Base 2,609 17.4%
Arbitrum 1,038 6.9%
Polygon 1,007 6.7%
Optimism 286 1.9%
Avalanche 231 1.5%

Risk Verdict Distribution

Verdict Count Share
High Risk 8,661 57.7%
Suspicious 3,740 24.9%
Honeypot 156 1.0%
Clean 2,451 16.3%

83.7% of listed tokens scored below Clean. The listing status of a token on CoinGecko or CoinMarketCap is not a security signal.


Risk by Chain

BSC had the worst risk profile of any chain in the dataset. Avalanche performed best, though even there less than 30% of tokens scored Clean.

Chain High Risk Clean
BSC 67.4% 7.5%
Optimism 63.3% 10.5%
Arbitrum 62.2% 14.3%
Ethereum 59.7% 19.9%
Polygon - -
Base - -
Avalanche 41.6% 29.9%

Primary Risk Drivers

No Mint Cap - 35.3% of Tokens

5,305 tokens (35.3%) have no cap on the total supply that can be minted. The deployer can expand supply without limit at any point after launch.

Zero tokens with this finding appeared in the Clean verdict bucket. No mint cap is the single strongest predictor of a High Risk verdict in the dataset.

No Timelock - 35.8% of Tokens

5,373 tokens (35.8%) have no timelock on administrative functions, allowing a single transaction to alter protocol parameters without advance notice to holders.


Liquidity Findings

Liquidity analysis revealed a significant share of listed tokens with no accessible market at all:

Finding Count Share
No Pool Found 4,343 28.9%
LP Unlocked 7,423 49.5%
Critical TVL (under $1,000) 3,911 26.1%
Low TVL (under $10,000) 3,051 20.3%
Partial LP Lock 271 1.8%

28.9% of listed tokens have no liquidity on any tracked DEX - they cannot be sold. 49.5% have LP controlled entirely by the deployer, who can drain the pool at will.


Proxy and Upgradeability

5,235 tokens (34.9%) are upgradeable proxy contracts - the underlying logic can be replaced after deployment. Of those:

  • EOA single-key controlled: 118 tokens - a single private key can rewrite the contract
  • Multisig controlled: 31 tokens
  • DAO / protocol governed: 1,324 tokens

Honeypots

156 confirmed honeypots were identified (1.0%). Common patterns among those 156:

Pattern Share of Honeypots
Custom transfer entry points 56%
Layered transfer delegation 51%
Unexpected events in transfers 47%
Obfuscated variable names 36%
Blacklist functions 29%
Excessive branching 28%

Additional High-Risk Patterns

Finding Count Share
Hidden mint functions 980 6.5%
Asymmetric pause patterns 718 4.8%
Fake burn functions 330 -
Currently paused tokens 30 -

Risk Score Distribution

Metric Score
Mean 102.2
Median 100.0
25th percentile 55.0
75th percentile 145.0
Maximum 1,375

Scores are additive - each triggered finding contributes its weighted severity to the total. A score of 1,375 represents a contract with critical findings across multiple modules simultaneously.


Products Used

  • Token Audit - 127 checks across 11 modules: Ownership, Supply, Liquidity, Transfer, Approve, Permit, Pausability, Reentrancy, Honeypot, and more
  • ChainAware Behavioral Database - 23M+ wallet profiles supporting deployer wallet analysis
  • Source: CoinGecko + CoinMarketCap combined, deduplicated

Audit a Token →    Token Audit Documentation →


Frequently Asked Questions

Does being listed on CoinGecko or CoinMarketCap mean a token is safe?
No. This study found 83.7% of listed tokens scored below Clean - 57.7% scored High Risk alone. Listing status reflects market metrics (trading volume, holder count, market cap) not security. Neither platform performs smart contract auditing as a listing condition.

What is the most common reason tokens score High Risk?
No mint cap (35.3% of all tokens) is the single strongest predictor of a High Risk verdict in the dataset - zero tokens with this finding appeared in the Clean verdict bucket. No timelock (35.8%) is the second most common finding. Both indicate that the deployer retains unconstrained control over critical protocol parameters after launch.

How does the 15,008-token study differ from auditing a single token?
A single token audit produces a complete security assessment for one contract. The 15,008-token study was designed to establish a statistical baseline for the listed token ecosystem - identifying which risk patterns are endemic, which chains have the worst profiles, and how far "legitimacy" by listing standards diverges from contract-level safety.

What should a retail investor do with this information?
The base rate finding (57.7% High Risk among listed tokens) means that checking a token's listing status is insufficient before investing. Running a Token Audit on the contract address before buying costs nothing and takes seconds - and for a token in the High Risk majority, it may be the only signal that protects against a loss.

Further Reading


Dataset: 15,008 EVM contracts from CoinGecko and CoinMarketCap, 97.3% source-verified. Full methodology →

Last updated: