đ Welcome to CFG Ninja Audit Portal
CFG Ninja Audit Portal is your comprehensive platform for blockchain security analysis, smart contract auditing, and token safety verification. Our platform combines advanced AI technology with industry-standard security practices to provide you with reliable and actionable insights.
đ¯ What Can You Do Here?
đ Token Scanner
Instantly analyze any token across 32+ blockchains. Get comprehensive security reports including honeypot detection, contract security, trading fees, and AI-powered risk assessment.
đĄī¸ Smart Contract Audits
Request professional security audits for your smart contracts. Our expert team performs thorough code reviews and vulnerability assessments to ensure your project's safety.
đ View Published Audits
Browse our collection of completed audits. Each audit includes detailed findings, security recommendations, and verification badges you can display on your project.
đ¤ Telegram Bot Integration
Access token scanning directly from Telegram. Use our bot to quickly check tokens, get real-time alerts, and stay informed about security risks.
⥠Quick Start Guide
Get started with CFG Ninja in just a few minutes:
1Navigate to Token Scanner
Click on "Token Scanner" in the main menu or use the search bar at the top of any page.
2Enter Token Details
Enter the token contract address and select the blockchain network. We support 32+ chains including Ethereum, BSC, Polygon, Arbitrum, Base, and more.
3Enable AI Analysis (Optional)
Toggle the AI analysis option for advanced risk scoring and intelligent insights about potential security concerns.
4Review Results
Get instant results including risk score, security flags, trading fees, liquidity analysis, and detailed contract information.
đ Token Scanner
Our Token Scanner is the most comprehensive free tool for analyzing token security across multiple blockchains. It provides real-time data and AI-powered insights to help you make informed decisions.
How to Use
- Go to the Token Scanner page from the main menu
- Paste the token contract address into the search field
- Select the blockchain network from the dropdown
- Optionally enable AI analysis for enhanced insights
- Click "Scan Token" and wait for results (usually 3-5 seconds)
What You'll Get
đ Risk Score (0-100)
An overall security rating based on multiple factors. Scores above 70 are generally considered safe, but always review the detailed findings.
đĄī¸ Honeypot Safety
- Honeypot Detection: Identifies if the token is a honeypot scam
- Transfer Pausable: Checks if transfers can be paused
- Cannot Buy: Detects if buying is restricted
- Trading Cooldown: Identifies if there are trading restrictions
- Blacklist Function: Checks for wallet blacklisting capabilities
đ Contract Security
- Source Code Verified: Contract code is publicly viewable
- Proxy Contract: Identifies upgradeable contracts
- Mint Function: Checks if new tokens can be created
- Owner Change Balance: Detects if owner can modify balances
- Hidden Owner: Identifies concealed ownership
- Self-Destruct: Checks if contract can be destroyed
- External Call: Identifies external contract interactions
đ¸ Trading Fees
- Buy Tax: Fee charged when purchasing tokens
- Sell Tax: Fee charged when selling tokens
- Anti-Whale Modifiable: Checks if limits can be changed
- Cannot Sell All: Detects if selling entire balance is restricted
â ī¸ Rugpull Safety
- Liquidity Lock: Status and duration of locked liquidity
- LP Holders: List of major liquidity providers
- Creator Holdings: Token percentage held by creator
- Owner Holdings: Token percentage held by owner
đĨ Top Holders
View the top 10 token holders with their balances and ownership percentages. High concentration in a few wallets can indicate risk.
đĄī¸ Request Audit
Professional smart contract audits are essential for any serious blockchain project. Our experienced security researchers perform comprehensive audits to identify vulnerabilities and recommend fixes.
Audit Process
1Submit Request
Fill out the audit request form with your project details, contract addresses, and specific concerns.
2Initial Review
Our team reviews your submission within 24-48 hours and provides a quote and timeline.
3Security Analysis
Expert auditors perform manual code review, automated testing, and security analysis of your smart contracts.
4Report Delivery
Receive a comprehensive audit report including findings, severity ratings, and recommendations for fixes.
5Fix Verification
After you implement fixes, we re-audit the contracts and issue a final verification report.
What's Included
- â Comprehensive security analysis
- â Manual code review by expert auditors
- â Automated security testing
- â Gas optimization recommendations
- â Detailed findings report with severity ratings
- â Fix verification and re-audit
- â Public audit badge for your website
- â Listing on our audits page
đ View Audits
Browse our complete collection of published security audits. Each audit is publicly accessible and demonstrates our commitment to transparency and security.
Audit Information
Each published audit includes:
- Project Overview: Description and purpose
- Contract Details: Addresses and network information
- Security Findings: Detailed vulnerability reports
- Severity Ratings: Critical, High, Medium, Low classifications
- Recommendations: Suggested fixes and improvements
- Fix Status: Whether issues have been resolved
- Audit Badge: Verification badge with unique ID
Using Audit Badges
Projects that pass our audits receive a verification badge. This badge can be embedded on your website or documentation:
<a href="https://cfg.ninja/audits/[PROJECT_ID]" target="_blank">
<img src="https://cfg.ninja/badge.png" alt="Audited by CFG Ninja" />
</a>đ¤ Telegram Bot
Access token scanning directly from Telegram with our powerful bot integration. Get instant security analysis without leaving your chat.
Getting Started
- Open Telegram and search for
@CFGNinjaBot - Start a chat and send
/start - Use commands to scan tokens and get security reports
Available Commands
/check [address] [chain]
Scan a token and get comprehensive security analysis. Example:
/check 0x1234...5678 bsc/start
Start the bot and see available commands.
/help
Get detailed help about bot features and usage.
Supported Chains
The Telegram bot supports all major blockchains: bsc, eth,polygon, arbitrum, base, avalanche,optimism, fantom, and more.
Features
- đ Instant token security analysis
- đ Risk score and safety ratings
- đ Contract security checks
- đ° Trading fee information
- đ PinkSale launchpad detection
- â ī¸ Critical security alerts
- đ Holder concentration analysis
- đ Liquidity lock status
đ Understanding Results
Learn how to interpret the security analysis results and make informed decisions.
Risk Score Interpretation
- 90-100: Excellent - Very low risk, strong security
- 70-89: Good - Acceptable risk, standard security
- 50-69: Moderate - Some concerns, review carefully
- 30-49: High Risk - Multiple red flags present
- 0-29: Critical - Likely scam or severe vulnerabilities
Red Flags to Watch For
- đĢ Honeypot detected
- đĢ Cannot sell all tokens
- đĢ Hidden owner functions
- đĢ Self-destruct capability
- đĢ High buy/sell taxes (>15%)
- đĢ No liquidity lock
- đĢ High creator/owner holdings (>20%)
- đĢ Source code not verified
Positive Indicators
- â Source code verified
- â Liquidity locked for extended period
- â Low or no buy/sell taxes
- â No honeypot characteristics
- â Distributed holder base
- â Creator holdings renounced or low
- â Professional audit completed
- â Active development and community
đ Sharing Scans
Share your token scan results with others using shareable URLs. Anyone with the link can view the same analysis without running a new scan.
How to Share
- Complete a token scan
- Click the "Share Scan" button below the project name
- The shareable URL is automatically copied to your clipboard
- Paste and share the link anywhere
Shareable URL Format
https://cfg.ninja/token-scanner?address=0x...&chain=bscAuto-Scan Feature
When someone opens your shared link, the scanner automatically loads and displays the results. No manual input required!
Use Cases
- đą Share on social media (Twitter, Telegram, Discord)
- đŦ Send to friends and community members
- đ§ Include in email communications
- đ Embed in blog posts or articles
- đ Add to project documentation
âī¸ Supported Blockchains
CFG Ninja Token Scanner supports 32+ blockchain networks, making it one of the most comprehensive multi-chain security tools available.
Major Networks
Ethereum (ETH)
The original smart contract platform
BNB Smart Chain (BSC)
High-performance Binance chain
Polygon (MATIC)
Ethereum scaling solution
Arbitrum
Ethereum Layer 2 rollup
Optimism
Optimistic rollup network
Base
Coinbase Layer 2 network
Avalanche (AVAX)
High-throughput blockchain
Fantom (FTM)
DAG-based smart contract platform
Additional Networks
- Cronos (CRO)
- Moonbeam (GLMR)
- Moonriver (MOVR)
- Metis
- Boba Network
- Aurora (NEAR)
- Harmony (ONE)
- Celo
- OKC (OKX Chain)
- Heco (Huobi ECO)
- And many more...
Click "View all supported blockchains" on the Token Scanner page to see the complete list.
đ ī¸ Security Tools
CFG Ninja provides 15 free security tools for smart contract developers, auditors, and researchers. Access all tools at /tools.
Contract Analysis Tools
đ¤ AI Audit Assistant
Upload Solidity contracts for instant AI-powered security analysis. Identifies vulnerabilities, suggests fixes, and provides a security score â all without sharing your code externally.
đĨ Contract Downloader
Download verified smart contract source code from any blockchain explorer. Supports Ethereum, BSC, Polygon, Arbitrum, and more. Outputs Solidity files ready for review.
đ Contract Flattener
Combine multi-file Solidity contracts into a single flat file. Essential for verification on block explorers and preparing contracts for audit tools like Slither.
âŊ Gas Optimizer
Paste Solidity code and get AI-powered gas optimization recommendations. Identifies expensive patterns and suggests cheaper alternatives with estimated savings.
Transaction & Address Tools
đ Transaction Safety Checker
Simulate transactions before signing. See exactly what a transaction will do â token transfers, approvals, state changes â with AI-powered risk explanations.
â ī¸ Address Risk Scanner
Check any blockchain address for scam history, phishing activity, blacklist status, and malicious behavior. Powered by GoPlus Security API with AI risk assessment.
đŗ Wallet Health Scanner
Analyze your wallet for risky token approvals, suspicious holdings, and security vulnerabilities. Get actionable recommendations to secure your assets.
đŧī¸ NFT Security Scanner
Verify NFT collections and individual tokens for scams, fake metadata, malicious contracts, and wash trading. Supports ERC-721 and ERC-1155.
Developer Utilities
đ§ ABI Encoder / Decoder
Encode and decode Ethereum ABI data. Paste function signatures and parameters to generate calldata, or decode raw transaction input data into readable format.
đ Event Log Decoder
Decode raw Ethereum event logs into human-readable format. Paste event topics and data to see the event name, parameters, and values.
đ Function Signature Database
Look up function selectors (4-byte signatures) to identify unknown contract functions. Search by selector hash or function name.
#ī¸âŖ Keccak256 Hash Generator
Generate Keccak256 hashes used throughout the Ethereum ecosystem. Hash text, function signatures, or arbitrary data for smart contract development.
đ Bytecode Disassembler
Disassemble EVM bytecode into human-readable opcodes. Analyze deployed contract bytecode to understand low-level execution flow.
đŗ Merkle Proof Generator
Generate and verify Merkle trees and proofs for whitelists, airdrops, and on-chain verification. Supports address lists and custom leaf data.
Web3 Safety Tools
đ URL Safety Checker
Check any URL for phishing, malware, and scam indicators. Verifies SSL certificates, domain age, and cross-references against known malicious site databases.
đ How to Read an Audit Report
CFG Ninja audit reports follow a standardized format designed for both technical and non-technical readers. Here's how to navigate and interpret each section.
Report Structure
1Project Overview
The top section shows the project name, logo, contract addresses, blockchain network, and a brief description. The security score (out of 100) is displayed prominently â this is the overall safety rating.
2Security Score Breakdown
The score is calculated by deducting points for each finding based on severity:
- Critical (-15 pts): Funds at immediate risk, exploitable vulnerabilities, or complete loss of control
- High (-10 pts): Significant security issues that could lead to fund loss under certain conditions
- Medium (-5 pts): Issues that don't immediately threaten funds but weaken overall security
- Low (-2 pts): Minor issues, best practice violations, or code quality improvements
- Informational (-1 pt): Suggestions, gas optimizations, or style recommendations
đĸ 90-100: Excellent â minimal or no issues found
đĩ 80-89: Good â minor improvements recommended
đĄ 70-79: Fair â some issues need attention
đ´ Below 70: Poor â significant security concerns
3Findings Table
Each finding includes:
- ID: Unique identifier (e.g., CFG-001)
- Title: Brief description of the issue
- Severity: Critical, High, Medium, Low, or Informational
- Category: Type of issue (Reentrancy, Access Control, Logic Error, Gas Optimization, etc.)
- Status: Open, Acknowledged, or Resolved
- Description: Detailed explanation of the vulnerability
- Recommendation: Suggested fix or mitigation
4Scope & Methodology
Lists which contracts and functions were audited, the tools used (Slither, Mythril, manual review), and the audit methodology. This helps you understand the depth and coverage of the review.
5GoPlus Security Data
If available, the report includes on-chain security data from GoPlus API: honeypot checks, trading tax analysis, holder distribution, liquidity lock status, and contract permission analysis.
6Audit Badge & Verification
The bottom of each report shows the official CFG Ninja audit badge with the score, date, and a unique verification ID. Projects can embed this badge on their own website.
Common Finding Categories
đ Reentrancy
Functions that can be called recursively before state updates, potentially draining funds.
đ Access Control
Missing or incorrect permission checks that allow unauthorized users to call privileged functions.
đ§Ž Integer Overflow
Arithmetic operations that wrap around, producing unexpected values (mitigated in Solidity 0.8+).
đą Oracle Manipulation
Price feeds that can be manipulated through flash loans or low-liquidity attacks.
⥠Front-Running
Transactions that can be exploited by miners or MEV bots observing the mempool.
đ Centralization Risk
Excessive admin privileges or single points of failure that could compromise the protocol.
What to Do After Reading
- For investors: Check the overall score and severity of open findings. A score above 80 with no critical/high issues is generally a positive signal.
- For developers: Review each finding's recommendation and prioritize fixes by severity. Request a re-audit after implementing changes.
- For projects: Share the audit report with your community. Embed the badge on your website and social media. Address all findings publicly.
⨠What's New
Stay up to date with the latest features and improvements to CFG Ninja Audit Portal.
Version 3.29.1
Security hardening, emblem badges, and production readiness
- đĄī¸ Security Hardening: Admin authentication enforced on TrustBlock, Upload, and Project admin routes
- đ Emblem Badge System: Backend emblem API for project badge cards, sections, and logos
- đ§ Wizard Parity: 4naly3er, AI Explain, Test Suite Gen, and STRIDE Threat Model in Audit Wizard
- đ Contract Visualization: Metrics graph and inheritance diagrams in AI Audit Assistant
- đ GeckoTerminal Fallback: CoinGecko proxy with GeckoTerminal as automatic fallback
- đ CSP Hardened: Removed unsafe-eval, moved API secrets to environment variables
- đ Bug Fixes: GoPlus proxy 404, slug fallback for token names, badge 404 silence
Version 3.24.0
Major UI overhaul and enhanced PinkSale detection
- đ¨ New Card-Based Layout: Side-by-side information cards for better space utilization
- đ Shareable URLs: Share scan results with others via shareable links
- đ Auto-Scan: Scans automatically load from URL parameters
- đ Enhanced PinkSale Detection: Added HTML scraping fallback for better reliability
- đ¯ Improved Layout: Project name and share button now above risk score
- đ Bug Fixes: Fixed SSR prerender errors and removed duplicate fields
Version 3.23.0
Social media automation and Twitter integration
- đ¤ AI Security Tips: Automated blockchain security tips powered by Gemini 2.0
- đĻ Twitter Integration: Post security tips directly to Twitter/X
- đą Telegram Channel: Automated tips in Telegram channels
- đ Engagement Tracking: Monitor impressions, likes, and retweets
Version 3.21.0
Telegram bot enhancements
- đ Contract Age: Shows days since deployment
- đ Liquidity Lock: Displays lock status and duration
- đĨ Holder Analysis: Creator percentage and concentration metrics
- đ¨ Critical Flags: Enhanced security warning system
- đ Better Organization: Reorganized /check message structure
đ Full Changelog
Complete version history with all changes, improvements, and bug fixes.
v3.29.1 - February 12, 2026
New Features
- Backend emblem API route for project badge cards and logos
- Wizard parity: 4naly3er, AI Explain, Test Suite Gen, STRIDE Threat Model
- Contract visualization with metrics graph and inheritance diagrams
- GeckoTerminal fallback when CoinGecko is unavailable
- Shared MobileMenu component across all 25 pages
Security
- Added requireAuth + requireAdmin to TrustBlock publish routes
- Added requireAuth + requireAdmin to Upload routes
- Added requireAdmin to project admin PUT/DELETE/PATCH
- Removed hardcoded API keys (TrustBlock, DexView)
- Removed unsafe-eval from CSP scriptSrc
- Reduced parameterLimit to prevent parameter pollution
- Removed hardcoded Etherscan API key and dead debug files
Bug Fixes
- GoPlus fetch-goplus proxy 404 and backend env var standardization
- Slug fallback for letter-number boundary variants
- Emblem page crash on 404 and AdSense data-nscript warning
- CoinGecko proxy returning 200 with empty data instead of forwarding 404
- Badge 404 console.error silenced for expected missing emblems
- Backend URL normalization in next.config.js rewrites
Improvements
- Console.log cleanup: 66 removed from frontend, logger migration in backend
- Helmet CSP, CORS wildcard removed, error boundaries added
- Sitemap expanded with emblem and distribution pages
v3.24.0 - January 19, 2026
New Features
- Side-by-side card layout with responsive grid
- Shareable URLs with URL parameters
- Auto-scan functionality from shared links
- Share button with clipboard integration
- PinkSale HTML scraping fallback
Improvements
- Moved project title and share button above risk score
- Grouped related information cards together
- Enhanced visual hierarchy
- Improved mobile responsiveness
Bug Fixes
- Fixed SSR prerender errors with useSearchParams
- Fixed TypeScript onClick handler type errors
- Removed duplicate owner information
v3.23.0 - January 16, 2026
New Features
- AI-powered security tip generation with Gemini 2.0
- Twitter/X API integration for automated posting
- Telegram channel integration for security tips
- Category-based tip rotation system
- Engagement metrics tracking
v3.21.0 - January 2026
New Features
- Contract age display in Telegram bot
- Liquidity lock status and duration
- Holder concentration analysis
- Critical security flag detection
Improvements
- Reorganized /check message structure
- Enhanced security warnings
- Better mobile display
â Frequently Asked Questions
Is the Token Scanner free to use?
Yes! The Token Scanner is completely free. We believe everyone should have access to basic security analysis tools.
How accurate is the Token Scanner?
The scanner analyzes real-time blockchain data and uses industry-standard security checks. While highly accurate, it should be used as one of multiple research tools.
What's the difference between the free scanner and paid audit?
The Token Scanner provides automated analysis of public blockchain data. Professional audits include manual code review by expert security researchers, comprehensive testing, and detailed vulnerability reports.
How long does an audit take?
Standard audits typically take 1-2 weeks. Complex projects may require additional time. We provide a timeline estimate during the initial review.
Can I use the scanner for any blockchain?
We support 32+ major blockchains. If your chain isn't supported, contact us - we're constantly adding new networks.
Why is my risk score capped at 90?
Non-audited projects are capped at 90/100. Professional audits can increase the cap to 95, and KYC verification enables perfect 100 scores. This ensures users know which projects have been professionally verified.
How do I report a bug or request a feature?
Contact us on Telegram (@CFGNinja) or email support@cfg.ninja. We actively respond to user feedback and suggestions.
Is my data private?
We only analyze public blockchain data. We don't store scan results or track individual users. See our Privacy Policy for complete details.
đ Audit Badges
Official CFG Ninja Verified Badges are premium emblem widgets that allow audited projects to showcase their security credentials directly on their websites.

Badge Types
đˇī¸ Logo Badge
280 Ã 60px - Compact header element perfect for navigation bars, footers, and sidebars. Shows audit score at a glance.
đ Card Badge
380 Ã 480px - Detailed score card with CFG Ninja branding, security score, findings summary, and project info.
đ Section Badge
100% width - Full-width comprehensive audit display with complete findings breakdown and call-to-actions.
How to Get Your Badge
- Visit your audit page at
https://cfg.ninja/[your-project-slug] - Click the "Request Emblem" button in the audit actions section
- Choose your badge style (Logo, Card, or Section)
- Select your theme (Dark or Light)
- Preview the badge and copy the embed code
Installation Methods
import BadgeCard from '@/components/BadgeCard';
<BadgeCard slug="your-project-slug" theme="dark" /><iframe
src="https://cfg.ninja/emblem/your-project-slug?type=card&theme=dark"
width="380"
height="480"
frameborder="0"
scrolling="no"
></iframe>Score Calculation
Your security score is calculated from audit findings:
- Critical: -15 points
- High: -10 points
- Medium: -5 points
- Low: -2 points
- Informational: -1 point
Base Score: 100 points | Status Thresholds:Excellent (90+), Good (80-89), Fair (70-79), Poor (<70)
đ Contact Support
Need help? Have questions? We're here to assist you.
Get in Touch
đŦ Telegram
Join our community: @CFGNinjaAudits
đĻ Twitter/X
Follow us: @CFGNinja
đ§ Email
Business inquiries: support@cfg.ninja
đģ GitHub
Open source: CFG-Ninja
Response Times
- Telegram: Usually within 1-2 hours during business hours
- Email: Within 24-48 hours
- Twitter: Within 24 hours for DMs