Security

What is enforced by the chain and what is still a promise, in plain terms. NIULAI is a classic SPL token with no custom program on the mint, so most of this is checkable in one command:

spl-token display <MINT>

Do that yourself rather than trusting this page.

What nobody can do, including us

Attack Why it's impossible
Mint more tokens Mint authority is revoked. There is no key that can create supply.
Freeze or seize your balance There is no freeze authority, and never was one. No account can be frozen.
Tax your trades Classic SPL Token program, no transfer-fee extension. A transfer moves exactly what you sent.
Rename the token or swap its image Metadata is set immutable after launch.
Pull the launch liquidity LP tokens are burned, not locked. There is no position to withdraw.
Change the rules later There is no program to upgrade. The mint is a standard account with no authorities.

Note what is not claimed: there is no "ownership renounced" line, because there is no owner construct to renounce. An empty mint authority and an empty freeze authority are the Solana equivalent, and unlike an announcement they are fields on the mint account that anyone can read.

The two got there by different routes, and the difference is worth stating rather than smoothing over. The mint authority was revoked — it existed, it was used once to mint the supply, and then it was set to null in a transaction linked from the landing page. The freeze authority was never set at all: spl-token create-token only creates one when asked with --enable-freeze, and the launch script never asks. So there is no freeze-revocation transaction to link, because there was never a freeze authority to revoke. That is the stronger of the two claims, and it would be a shame to describe it in weaker words than it deserves.

Verify before you buy, not after. Both authorities empty is the single check that separates this from the majority of tokens on Solana, and it takes ten seconds.

What is still trusted

Being honest about the parts that are not enforced by code:

The front end. This site publishes the mint address. If someone compromises the domain they could publish a different one — which is why the address is also on the explorer and the aggregators. This is the main thing you are trusting. Cross-check before a large buy.

That the pool holds what it says. 100% of supply going into liquidity is a claim about a transaction. It is checkable on the explorer, and you should check it rather than take the sentence above at face value.

That the burn actually happened. It is a transaction, so it is checkable, but it is checkable by you rather than guaranteed by the token. Look at it.

Note what is not on this list any more. There is no eligibility snapshot to trust, no merkle root to verify and no distributor program holding most of the supply — because there is no distribution at all. Those were the three largest items here, and removing the airdrop removed them rather than mitigating them.

There is no airdrop, so every airdrop is a scam

100% of supply goes into the liquidity pool at launch. There is no claim, no presale, no allowlist and no snapshot, and there never will be.

That makes one rule unusually simple: any $NIULAI airdrop, claim link, presale or allowlist is fraudulent. Not "probably". There is nothing for a legitimate one to distribute. Nobody from this project will DM you, and no page that asks you to connect a wallet to receive tokens is ours.

The threats this project cannot fix for you

Most people who lose money around a launch like this do not lose it to the token contract:

Deployment hardening

Audit status

Not audited, and there is nothing custom to audit — the mint is the standard SPL Token program, which is audited, and there is no distributor, vault or claim program of any kind. The part that would have most needed review was the distributor that used to hold the community allocation, and it no longer exists.

Do not read the absence of an audit as safety, and do not read a standard mint as a guarantee. Memecoins routinely go to zero for reasons that have nothing to do with the code.

Reporting something

Open a private security advisory on the repo, or contact the team directly. Please don't post an exploitable finding publicly before it is fixed.

This page is docs/SECURITY.md from the repository, rendered. There is no second copy of these numbers to go stale.