Security
What is enforced by the chain and what is still a promise, in plain terms. NIULAI is a classic SPL token with no custom program on the mint, so most of this is checkable in one command:
spl-token display <MINT>
Do that yourself rather than trusting this page.
What nobody can do, including us
| Attack | Why it's impossible |
|---|---|
| Mint more tokens | Mint authority is revoked. There is no key that can create supply. |
| Freeze or seize your balance | There is no freeze authority, and never was one. No account can be frozen. |
| Tax your trades | Classic SPL Token program, no transfer-fee extension. A transfer moves exactly what you sent. |
| Rename the token or swap its image | Metadata is set immutable after launch. |
| Pull the launch liquidity | LP tokens are burned, not locked. There is no position to withdraw. |
| Change the rules later | There is no program to upgrade. The mint is a standard account with no authorities. |
Note what is not claimed: there is no "ownership renounced" line, because there is no owner construct to renounce. An empty mint authority and an empty freeze authority are the Solana equivalent, and unlike an announcement they are fields on the mint account that anyone can read.
The two got there by different routes, and the difference is worth stating rather than smoothing
over. The mint authority was revoked — it existed, it was used once to mint the supply, and
then it was set to null in a transaction linked from the landing page. The freeze authority was
never set at all: spl-token create-token only creates one when asked with --enable-freeze,
and the launch script never asks. So there is no freeze-revocation transaction to link, because
there was never a freeze authority to revoke. That is the stronger of the two claims, and it would
be a shame to describe it in weaker words than it deserves.
Verify before you buy, not after. Both authorities empty is the single check that separates this from the majority of tokens on Solana, and it takes ten seconds.
What is still trusted
Being honest about the parts that are not enforced by code:
The front end. This site publishes the mint address. If someone compromises the domain they could publish a different one — which is why the address is also on the explorer and the aggregators. This is the main thing you are trusting. Cross-check before a large buy.
That the pool holds what it says. 100% of supply going into liquidity is a claim about a transaction. It is checkable on the explorer, and you should check it rather than take the sentence above at face value.
That the burn actually happened. It is a transaction, so it is checkable, but it is checkable by you rather than guaranteed by the token. Look at it.
Note what is not on this list any more. There is no eligibility snapshot to trust, no merkle root to verify and no distributor program holding most of the supply — because there is no distribution at all. Those were the three largest items here, and removing the airdrop removed them rather than mitigating them.
There is no airdrop, so every airdrop is a scam
100% of supply goes into the liquidity pool at launch. There is no claim, no presale, no allowlist and no snapshot, and there never will be.
That makes one rule unusually simple: any $NIULAI airdrop, claim link, presale or allowlist is fraudulent. Not "probably". There is nothing for a legitimate one to distribute. Nobody from this project will DM you, and no page that asks you to connect a wallet to receive tokens is ours.
The threats this project cannot fix for you
Most people who lose money around a launch like this do not lose it to the token contract:
- Similarly named tokens. Anyone can create a token with any name on Solana in one command, and other unrelated projects already use this name on other chains. Ticker search cannot tell them apart. Paste the mint address from this site instead.
- Fake claim pages. Expect them anyway. A launch with no airdrop still attracts sites offering one, and they exist to drain the wallet you connect. See above: there is no real version to confuse them with.
- Malicious approvals. A swap moves the tokens you are swapping. It does not need blanket authority over your other token accounts. Read the transaction preview, and reject anything asking for more than the trade you asked for.
Deployment hardening
- Create the mint with a hardware wallet (
usb://ledger?key=0). No hot key should ever hold mint authority, even for the minutes between creation and revocation. - Revoke both authorities before anything trades, not after.
- Burn the LP in the same sitting as seeding the pool.
- Set metadata immutable. Mutable metadata is a rug that needs no key on the mint.
Audit status
Not audited, and there is nothing custom to audit — the mint is the standard SPL Token program, which is audited, and there is no distributor, vault or claim program of any kind. The part that would have most needed review was the distributor that used to hold the community allocation, and it no longer exists.
Do not read the absence of an audit as safety, and do not read a standard mint as a guarantee. Memecoins routinely go to zero for reasons that have nothing to do with the code.
Reporting something
Open a private security advisory on the repo, or contact the team directly. Please don't post an exploitable finding publicly before it is fixed.