🚀 Welcome to CFG Ninja Audit Portal

CFG Ninja Audit Portal is your comprehensive platform for blockchain security analysis, smart contract auditing, and token safety verification. Our platform combines advanced AI technology with industry-standard security practices to provide you with reliable and actionable insights.

đŸŽ¯ What Can You Do Here?

🔍 Token Scanner

Instantly analyze any token across 32+ blockchains. Get comprehensive security reports including honeypot detection, contract security, trading fees, and AI-powered risk assessment.

đŸ›Ąī¸ Smart Contract Audits

Request professional security audits for your smart contracts. Our expert team performs thorough code reviews and vulnerability assessments to ensure your project's safety.

📊 View Published Audits

Browse our collection of completed audits. Each audit includes detailed findings, security recommendations, and verification badges you can display on your project.

🤖 Telegram Bot Integration

Access token scanning directly from Telegram. Use our bot to quickly check tokens, get real-time alerts, and stay informed about security risks.

⚡ Quick Start Guide

Get started with CFG Ninja in just a few minutes:

1Navigate to Token Scanner

Click on "Token Scanner" in the main menu or use the search bar at the top of any page.

2Enter Token Details

Enter the token contract address and select the blockchain network. We support 32+ chains including Ethereum, BSC, Polygon, Arbitrum, Base, and more.

3Enable AI Analysis (Optional)

Toggle the AI analysis option for advanced risk scoring and intelligent insights about potential security concerns.

4Review Results

Get instant results including risk score, security flags, trading fees, liquidity analysis, and detailed contract information.

💡 Pro Tip: Share your scan results with others using the "Share Scan" button. The shareable link will auto-load the scan for anyone who opens it.

🔍 Token Scanner

Our Token Scanner is the most comprehensive free tool for analyzing token security across multiple blockchains. It provides real-time data and AI-powered insights to help you make informed decisions.

How to Use

  1. Go to the Token Scanner page from the main menu
  2. Paste the token contract address into the search field
  3. Select the blockchain network from the dropdown
  4. Optionally enable AI analysis for enhanced insights
  5. Click "Scan Token" and wait for results (usually 3-5 seconds)

What You'll Get

📊 Risk Score (0-100)

An overall security rating based on multiple factors. Scores above 70 are generally considered safe, but always review the detailed findings.

đŸ›Ąī¸ Honeypot Safety

  • Honeypot Detection: Identifies if the token is a honeypot scam
  • Transfer Pausable: Checks if transfers can be paused
  • Cannot Buy: Detects if buying is restricted
  • Trading Cooldown: Identifies if there are trading restrictions
  • Blacklist Function: Checks for wallet blacklisting capabilities

🔒 Contract Security

  • Source Code Verified: Contract code is publicly viewable
  • Proxy Contract: Identifies upgradeable contracts
  • Mint Function: Checks if new tokens can be created
  • Owner Change Balance: Detects if owner can modify balances
  • Hidden Owner: Identifies concealed ownership
  • Self-Destruct: Checks if contract can be destroyed
  • External Call: Identifies external contract interactions

💸 Trading Fees

  • Buy Tax: Fee charged when purchasing tokens
  • Sell Tax: Fee charged when selling tokens
  • Anti-Whale Modifiable: Checks if limits can be changed
  • Cannot Sell All: Detects if selling entire balance is restricted

âš ī¸ Rugpull Safety

  • Liquidity Lock: Status and duration of locked liquidity
  • LP Holders: List of major liquidity providers
  • Creator Holdings: Token percentage held by creator
  • Owner Holdings: Token percentage held by owner

đŸ‘Ĩ Top Holders

View the top 10 token holders with their balances and ownership percentages. High concentration in a few wallets can indicate risk.

â„šī¸ Note: The Token Scanner analyzes public blockchain data. While highly accurate, always conduct additional research before making investment decisions.

đŸ›Ąī¸ Request Audit

Professional smart contract audits are essential for any serious blockchain project. Our experienced security researchers perform comprehensive audits to identify vulnerabilities and recommend fixes.

Audit Process

1Submit Request

Fill out the audit request form with your project details, contract addresses, and specific concerns.

2Initial Review

Our team reviews your submission within 24-48 hours and provides a quote and timeline.

3Security Analysis

Expert auditors perform manual code review, automated testing, and security analysis of your smart contracts.

4Report Delivery

Receive a comprehensive audit report including findings, severity ratings, and recommendations for fixes.

5Fix Verification

After you implement fixes, we re-audit the contracts and issue a final verification report.

What's Included

  • ✅ Comprehensive security analysis
  • ✅ Manual code review by expert auditors
  • ✅ Automated security testing
  • ✅ Gas optimization recommendations
  • ✅ Detailed findings report with severity ratings
  • ✅ Fix verification and re-audit
  • ✅ Public audit badge for your website
  • ✅ Listing on our audits page
âš ī¸ Important: Audits do not guarantee bug-free code. They significantly reduce risk but cannot eliminate all potential vulnerabilities.

📊 View Audits

Browse our complete collection of published security audits. Each audit is publicly accessible and demonstrates our commitment to transparency and security.

Audit Information

Each published audit includes:

  • Project Overview: Description and purpose
  • Contract Details: Addresses and network information
  • Security Findings: Detailed vulnerability reports
  • Severity Ratings: Critical, High, Medium, Low classifications
  • Recommendations: Suggested fixes and improvements
  • Fix Status: Whether issues have been resolved
  • Audit Badge: Verification badge with unique ID

Using Audit Badges

Projects that pass our audits receive a verification badge. This badge can be embedded on your website or documentation:

<a href="https://cfg.ninja/audits/[PROJECT_ID]" target="_blank">
  <img src="https://cfg.ninja/badge.png" alt="Audited by CFG Ninja" />
</a>

🤖 Telegram Bot

Access token scanning directly from Telegram with our powerful bot integration. Get instant security analysis without leaving your chat.

Getting Started

  1. Open Telegram and search for @CFGNinjaBot
  2. Start a chat and send /start
  3. Use commands to scan tokens and get security reports

Available Commands

/check [address] [chain]

Scan a token and get comprehensive security analysis. Example:

/check 0x1234...5678 bsc

/start

Start the bot and see available commands.

/help

Get detailed help about bot features and usage.

Supported Chains

The Telegram bot supports all major blockchains: bsc, eth,polygon, arbitrum, base, avalanche,optimism, fantom, and more.

Features

  • 🔍 Instant token security analysis
  • 📊 Risk score and safety ratings
  • 🔒 Contract security checks
  • 💰 Trading fee information
  • 🔗 PinkSale launchpad detection
  • âš ī¸ Critical security alerts
  • 📈 Holder concentration analysis
  • 🔐 Liquidity lock status

📖 Understanding Results

Learn how to interpret the security analysis results and make informed decisions.

Risk Score Interpretation

  • 90-100: Excellent - Very low risk, strong security
  • 70-89: Good - Acceptable risk, standard security
  • 50-69: Moderate - Some concerns, review carefully
  • 30-49: High Risk - Multiple red flags present
  • 0-29: Critical - Likely scam or severe vulnerabilities
âš ī¸ Important: Risk scores are capped at 90 for non-audited projects and 95 for audited projects without KYC. Perfect scores (100) are reserved for fully audited and KYC-verified projects.

Red Flags to Watch For

  • đŸšĢ Honeypot detected
  • đŸšĢ Cannot sell all tokens
  • đŸšĢ Hidden owner functions
  • đŸšĢ Self-destruct capability
  • đŸšĢ High buy/sell taxes (>15%)
  • đŸšĢ No liquidity lock
  • đŸšĢ High creator/owner holdings (>20%)
  • đŸšĢ Source code not verified

Positive Indicators

  • ✅ Source code verified
  • ✅ Liquidity locked for extended period
  • ✅ Low or no buy/sell taxes
  • ✅ No honeypot characteristics
  • ✅ Distributed holder base
  • ✅ Creator holdings renounced or low
  • ✅ Professional audit completed
  • ✅ Active development and community

🔗 Sharing Scans

Share your token scan results with others using shareable URLs. Anyone with the link can view the same analysis without running a new scan.

How to Share

  1. Complete a token scan
  2. Click the "Share Scan" button below the project name
  3. The shareable URL is automatically copied to your clipboard
  4. Paste and share the link anywhere

Shareable URL Format

https://cfg.ninja/token-scanner?address=0x...&chain=bsc

Auto-Scan Feature

When someone opens your shared link, the scanner automatically loads and displays the results. No manual input required!

Use Cases

  • 📱 Share on social media (Twitter, Telegram, Discord)
  • đŸ’Ŧ Send to friends and community members
  • 📧 Include in email communications
  • 📝 Embed in blog posts or articles
  • 🔗 Add to project documentation

â›“ī¸ Supported Blockchains

CFG Ninja Token Scanner supports 32+ blockchain networks, making it one of the most comprehensive multi-chain security tools available.

Major Networks

Ethereum (ETH)

The original smart contract platform

BNB Smart Chain (BSC)

High-performance Binance chain

Polygon (MATIC)

Ethereum scaling solution

Arbitrum

Ethereum Layer 2 rollup

Optimism

Optimistic rollup network

Base

Coinbase Layer 2 network

Avalanche (AVAX)

High-throughput blockchain

Fantom (FTM)

DAG-based smart contract platform

Additional Networks

  • Cronos (CRO)
  • Moonbeam (GLMR)
  • Moonriver (MOVR)
  • Metis
  • Boba Network
  • Aurora (NEAR)
  • Harmony (ONE)
  • Celo
  • OKC (OKX Chain)
  • Heco (Huobi ECO)
  • And many more...

Click "View all supported blockchains" on the Token Scanner page to see the complete list.

đŸ› ī¸ Security Tools

CFG Ninja provides 15 free security tools for smart contract developers, auditors, and researchers. Access all tools at /tools.

Contract Analysis Tools

🤖 AI Audit Assistant

Upload Solidity contracts for instant AI-powered security analysis. Identifies vulnerabilities, suggests fixes, and provides a security score — all without sharing your code externally.

Open Tool →

đŸ“Ĩ Contract Downloader

Download verified smart contract source code from any blockchain explorer. Supports Ethereum, BSC, Polygon, Arbitrum, and more. Outputs Solidity files ready for review.

Open Tool →

📋 Contract Flattener

Combine multi-file Solidity contracts into a single flat file. Essential for verification on block explorers and preparing contracts for audit tools like Slither.

Open Tool →

â›Ŋ Gas Optimizer

Paste Solidity code and get AI-powered gas optimization recommendations. Identifies expensive patterns and suggests cheaper alternatives with estimated savings.

Open Tool →

Transaction & Address Tools

🔐 Transaction Safety Checker

Simulate transactions before signing. See exactly what a transaction will do — token transfers, approvals, state changes — with AI-powered risk explanations.

Open Tool →

âš ī¸ Address Risk Scanner

Check any blockchain address for scam history, phishing activity, blacklist status, and malicious behavior. Powered by GoPlus Security API with AI risk assessment.

Open Tool →

đŸ’ŗ Wallet Health Scanner

Analyze your wallet for risky token approvals, suspicious holdings, and security vulnerabilities. Get actionable recommendations to secure your assets.

Open Tool →

đŸ–ŧī¸ NFT Security Scanner

Verify NFT collections and individual tokens for scams, fake metadata, malicious contracts, and wash trading. Supports ERC-721 and ERC-1155.

Open Tool →

Developer Utilities

🔧 ABI Encoder / Decoder

Encode and decode Ethereum ABI data. Paste function signatures and parameters to generate calldata, or decode raw transaction input data into readable format.

Open Tool →

📜 Event Log Decoder

Decode raw Ethereum event logs into human-readable format. Paste event topics and data to see the event name, parameters, and values.

Open Tool →

🔑 Function Signature Database

Look up function selectors (4-byte signatures) to identify unknown contract functions. Search by selector hash or function name.

Open Tool →

#ī¸âƒŖ Keccak256 Hash Generator

Generate Keccak256 hashes used throughout the Ethereum ecosystem. Hash text, function signatures, or arbitrary data for smart contract development.

Open Tool →

🔍 Bytecode Disassembler

Disassemble EVM bytecode into human-readable opcodes. Analyze deployed contract bytecode to understand low-level execution flow.

Open Tool →

đŸŒŗ Merkle Proof Generator

Generate and verify Merkle trees and proofs for whitelists, airdrops, and on-chain verification. Supports address lists and custom leaf data.

Open Tool →

Web3 Safety Tools

🌐 URL Safety Checker

Check any URL for phishing, malware, and scam indicators. Verifies SSL certificates, domain age, and cross-references against known malicious site databases.

Open Tool →

💡 Tip: All tools are free and don't require an account. Access the full tools collection at /tools.

📑 How to Read an Audit Report

CFG Ninja audit reports follow a standardized format designed for both technical and non-technical readers. Here's how to navigate and interpret each section.

Report Structure

1Project Overview

The top section shows the project name, logo, contract addresses, blockchain network, and a brief description. The security score (out of 100) is displayed prominently — this is the overall safety rating.

2Security Score Breakdown

The score is calculated by deducting points for each finding based on severity:

  • Critical (-15 pts): Funds at immediate risk, exploitable vulnerabilities, or complete loss of control
  • High (-10 pts): Significant security issues that could lead to fund loss under certain conditions
  • Medium (-5 pts): Issues that don't immediately threaten funds but weaken overall security
  • Low (-2 pts): Minor issues, best practice violations, or code quality improvements
  • Informational (-1 pt): Suggestions, gas optimizations, or style recommendations
Score Thresholds:
đŸŸĸ 90-100: Excellent — minimal or no issues found
đŸ”ĩ 80-89: Good — minor improvements recommended
🟡 70-79: Fair — some issues need attention
🔴 Below 70: Poor — significant security concerns

3Findings Table

Each finding includes:

  • ID: Unique identifier (e.g., CFG-001)
  • Title: Brief description of the issue
  • Severity: Critical, High, Medium, Low, or Informational
  • Category: Type of issue (Reentrancy, Access Control, Logic Error, Gas Optimization, etc.)
  • Status: Open, Acknowledged, or Resolved
  • Description: Detailed explanation of the vulnerability
  • Recommendation: Suggested fix or mitigation

4Scope & Methodology

Lists which contracts and functions were audited, the tools used (Slither, Mythril, manual review), and the audit methodology. This helps you understand the depth and coverage of the review.

5GoPlus Security Data

If available, the report includes on-chain security data from GoPlus API: honeypot checks, trading tax analysis, holder distribution, liquidity lock status, and contract permission analysis.

6Audit Badge & Verification

The bottom of each report shows the official CFG Ninja audit badge with the score, date, and a unique verification ID. Projects can embed this badge on their own website.

Common Finding Categories

🔄 Reentrancy

Functions that can be called recursively before state updates, potentially draining funds.

🔐 Access Control

Missing or incorrect permission checks that allow unauthorized users to call privileged functions.

🧮 Integer Overflow

Arithmetic operations that wrap around, producing unexpected values (mitigated in Solidity 0.8+).

💱 Oracle Manipulation

Price feeds that can be manipulated through flash loans or low-liquidity attacks.

⚡ Front-Running

Transactions that can be exploited by miners or MEV bots observing the mempool.

🔓 Centralization Risk

Excessive admin privileges or single points of failure that could compromise the protocol.

What to Do After Reading

  • For investors: Check the overall score and severity of open findings. A score above 80 with no critical/high issues is generally a positive signal.
  • For developers: Review each finding's recommendation and prioritize fixes by severity. Request a re-audit after implementing changes.
  • For projects: Share the audit report with your community. Embed the badge on your website and social media. Address all findings publicly.
âš ī¸ Remember: An audit is a point-in-time assessment. It does not guarantee bug-free code. Contract upgrades, new dependencies, or changed configurations after the audit may introduce new vulnerabilities.

✨ What's New

Stay up to date with the latest features and improvements to CFG Ninja Audit Portal.

February 12, 2026

Version 3.29.1

Security hardening, emblem badges, and production readiness

  • đŸ›Ąī¸ Security Hardening: Admin authentication enforced on TrustBlock, Upload, and Project admin routes
  • 🏅 Emblem Badge System: Backend emblem API for project badge cards, sections, and logos
  • 🔧 Wizard Parity: 4naly3er, AI Explain, Test Suite Gen, and STRIDE Threat Model in Audit Wizard
  • 📊 Contract Visualization: Metrics graph and inheritance diagrams in AI Audit Assistant
  • 🔗 GeckoTerminal Fallback: CoinGecko proxy with GeckoTerminal as automatic fallback
  • 🔒 CSP Hardened: Removed unsafe-eval, moved API secrets to environment variables
  • 🐛 Bug Fixes: GoPlus proxy 404, slug fallback for token names, badge 404 silence
January 19, 2026

Version 3.24.0

Major UI overhaul and enhanced PinkSale detection

  • 🎨 New Card-Based Layout: Side-by-side information cards for better space utilization
  • 🔗 Shareable URLs: Share scan results with others via shareable links
  • 🔄 Auto-Scan: Scans automatically load from URL parameters
  • 🔍 Enhanced PinkSale Detection: Added HTML scraping fallback for better reliability
  • đŸŽ¯ Improved Layout: Project name and share button now above risk score
  • 🐛 Bug Fixes: Fixed SSR prerender errors and removed duplicate fields
January 16, 2026

Version 3.23.0

Social media automation and Twitter integration

  • 🤖 AI Security Tips: Automated blockchain security tips powered by Gemini 2.0
  • đŸĻ Twitter Integration: Post security tips directly to Twitter/X
  • 📱 Telegram Channel: Automated tips in Telegram channels
  • 📊 Engagement Tracking: Monitor impressions, likes, and retweets
January 2026

Version 3.21.0

Telegram bot enhancements

  • 📊 Contract Age: Shows days since deployment
  • 🔒 Liquidity Lock: Displays lock status and duration
  • đŸ‘Ĩ Holder Analysis: Creator percentage and concentration metrics
  • 🚨 Critical Flags: Enhanced security warning system
  • 📋 Better Organization: Reorganized /check message structure

📅 Full Changelog

Complete version history with all changes, improvements, and bug fixes.

v3.29.1 - February 12, 2026

New Features

  • Backend emblem API route for project badge cards and logos
  • Wizard parity: 4naly3er, AI Explain, Test Suite Gen, STRIDE Threat Model
  • Contract visualization with metrics graph and inheritance diagrams
  • GeckoTerminal fallback when CoinGecko is unavailable
  • Shared MobileMenu component across all 25 pages

Security

  • Added requireAuth + requireAdmin to TrustBlock publish routes
  • Added requireAuth + requireAdmin to Upload routes
  • Added requireAdmin to project admin PUT/DELETE/PATCH
  • Removed hardcoded API keys (TrustBlock, DexView)
  • Removed unsafe-eval from CSP scriptSrc
  • Reduced parameterLimit to prevent parameter pollution
  • Removed hardcoded Etherscan API key and dead debug files

Bug Fixes

  • GoPlus fetch-goplus proxy 404 and backend env var standardization
  • Slug fallback for letter-number boundary variants
  • Emblem page crash on 404 and AdSense data-nscript warning
  • CoinGecko proxy returning 200 with empty data instead of forwarding 404
  • Badge 404 console.error silenced for expected missing emblems
  • Backend URL normalization in next.config.js rewrites

Improvements

  • Console.log cleanup: 66 removed from frontend, logger migration in backend
  • Helmet CSP, CORS wildcard removed, error boundaries added
  • Sitemap expanded with emblem and distribution pages

v3.24.0 - January 19, 2026

New Features

  • Side-by-side card layout with responsive grid
  • Shareable URLs with URL parameters
  • Auto-scan functionality from shared links
  • Share button with clipboard integration
  • PinkSale HTML scraping fallback

Improvements

  • Moved project title and share button above risk score
  • Grouped related information cards together
  • Enhanced visual hierarchy
  • Improved mobile responsiveness

Bug Fixes

  • Fixed SSR prerender errors with useSearchParams
  • Fixed TypeScript onClick handler type errors
  • Removed duplicate owner information

v3.23.0 - January 16, 2026

New Features

  • AI-powered security tip generation with Gemini 2.0
  • Twitter/X API integration for automated posting
  • Telegram channel integration for security tips
  • Category-based tip rotation system
  • Engagement metrics tracking

v3.21.0 - January 2026

New Features

  • Contract age display in Telegram bot
  • Liquidity lock status and duration
  • Holder concentration analysis
  • Critical security flag detection

Improvements

  • Reorganized /check message structure
  • Enhanced security warnings
  • Better mobile display

❓ Frequently Asked Questions

Is the Token Scanner free to use?

Yes! The Token Scanner is completely free. We believe everyone should have access to basic security analysis tools.

How accurate is the Token Scanner?

The scanner analyzes real-time blockchain data and uses industry-standard security checks. While highly accurate, it should be used as one of multiple research tools.

What's the difference between the free scanner and paid audit?

The Token Scanner provides automated analysis of public blockchain data. Professional audits include manual code review by expert security researchers, comprehensive testing, and detailed vulnerability reports.

How long does an audit take?

Standard audits typically take 1-2 weeks. Complex projects may require additional time. We provide a timeline estimate during the initial review.

Can I use the scanner for any blockchain?

We support 32+ major blockchains. If your chain isn't supported, contact us - we're constantly adding new networks.

Why is my risk score capped at 90?

Non-audited projects are capped at 90/100. Professional audits can increase the cap to 95, and KYC verification enables perfect 100 scores. This ensures users know which projects have been professionally verified.

How do I report a bug or request a feature?

Contact us on Telegram (@CFGNinja) or email support@cfg.ninja. We actively respond to user feedback and suggestions.

Is my data private?

We only analyze public blockchain data. We don't store scan results or track individual users. See our Privacy Policy for complete details.

🏆 Audit Badges

Official CFG Ninja Verified Badges are premium emblem widgets that allow audited projects to showcase their security credentials directly on their websites.

CFG Ninja Verified Badge

Badge Types

đŸˇī¸ Logo Badge

280 × 60px - Compact header element perfect for navigation bars, footers, and sidebars. Shows audit score at a glance.

🃏 Card Badge

380 × 480px - Detailed score card with CFG Ninja branding, security score, findings summary, and project info.

📄 Section Badge

100% width - Full-width comprehensive audit display with complete findings breakdown and call-to-actions.

How to Get Your Badge

  1. Visit your audit page at https://cfg.ninja/[your-project-slug]
  2. Click the "Request Emblem" button in the audit actions section
  3. Choose your badge style (Logo, Card, or Section)
  4. Select your theme (Dark or Light)
  5. Preview the badge and copy the embed code

Installation Methods

React / Next.js
import BadgeCard from '@/components/BadgeCard';

<BadgeCard slug="your-project-slug" theme="dark" />
HTML / iframe
<iframe
  src="https://cfg.ninja/emblem/your-project-slug?type=card&theme=dark"
  width="380"
  height="480"
  frameborder="0"
  scrolling="no"
></iframe>

Score Calculation

Your security score is calculated from audit findings:

  • Critical: -15 points
  • High: -10 points
  • Medium: -5 points
  • Low: -2 points
  • Informational: -1 point

Base Score: 100 points | Status Thresholds:Excellent (90+), Good (80-89), Fair (70-79), Poor (<70)

💡 Tip: Place badges prominently on your homepage or tokenomics page to maximize trust and transparency with your community.

📞 Contact Support

Need help? Have questions? We're here to assist you.

Get in Touch

đŸ’Ŧ Telegram

Join our community: @CFGNinjaAudits

đŸĻ Twitter/X

Follow us: @CFGNinja

📧 Email

Business inquiries: support@cfg.ninja

đŸ’ģ GitHub

Open source: CFG-Ninja

Response Times

  • Telegram: Usually within 1-2 hours during business hours
  • Email: Within 24-48 hours
  • Twitter: Within 24 hours for DMs
💡 Tip: For fastest support, reach out on Telegram where our team is most active.