Anatomy of a GhostScore verdict.
Every contract on every chain produces this card. One score, one tier, one action, one analyst line. Shareable, permanent, verifiable. Below is the real format using live data from Binance-Peg ETH on BSC.
Every element, explained.
A 6-eyed security guard watches the contract. The result is a single card. Here is what each part means and why it matters.
GhostLabs Profile and Socials
- The verified GhostScore ID ties this card to a permanent public record
- Social links let anyone verify the issuing organization independently
- QR code links directly to the on-chain verdict page
Token Asset Identification
- This is not native ETH. It is a bridged "pegged" version on BSC
- The ticker $ETH creates brand confusion with the L1 asset
- Contract address and chain are shown for independent verification
Aggregate Risk Score (out of 100)
- Composite of 5 weighted pillars: Security, Team, Tokenomics, Value, Health
- 29/100 indicates severe risk across multiple categories
- Critical failures trigger an amplifier that accelerates the score downward
Asset Classification and Vulnerability Type
- "Literary Fiction" is Tier 3. The name itself signals a project that tells a better story than its code delivers
- Ten tiers map score bands to behavioral archetypes, from Total Asymmetry (Tier 1) to The Gold Standard (Tier 10)
- The action pill "Evacuate" is the recommended next step for holders
Key Vulnerability Detail (Verified and Quoted)
- The analyst line is generated from verified on-chain findings, not marketing copy
- It names the specific risk: one admin key controlling total supply
- Written in plain language so non-technical holders can act immediately
Detailed Findings Summary and Call to Action
- 8 critical findings out of 100 checks gives immediate context on severity
- The bottom bar works as a standalone summary when the card is shared on social
- Token logo and chain identifier make the asset unmistakable at a glance
This is what every free read produces. A single card. The score, the tier, the action, and the analyst line. Shareable, permanent, verifiable. Every card lives at a public URL that anyone can check without asking the project for a PDF.
Want more than the card?Share your email. Get the full report.
The card is the headline. The email report is the story. One address, no spam, no drip sequence. We send the Tier 1 report and notify you if the contract changes. That is it.
Binance-Peg ETH uses the same ticker as native Ethereum but operates under entirely different trust assumptions. A single admin key controls the total supply. Source code is unverified on the block explorer. No liquidity lock exists. The combination of brand confusion and centralized control places this asset in the bottom 30% of all contracts scored by GhostLabs.
| Finding | Severity |
|---|---|
| Admin key controls entire supply. A single EOA can mint, burn, and pause the contract at any time without governance approval or timelock. | Critical |
| Unverified source code. The deployed bytecode does not match any verified source on BscScan. Independent review of the contract logic is not possible. | Critical |
| No liquidity lock. LP tokens are held in a standard wallet with no lock contract, timelock, or multisig protection. | Critical |
| Centralized minting function. The mint function is callable by the owner address without a supply cap or rate limit. | Critical |
| Same ticker as native ETH. The $ETH ticker creates brand confusion with Ethereum L1. Holders may not understand they hold a bridged, custodial asset. | High |
- Any transaction from the admin wallet that calls the mint or pause functions. This would indicate an immediate change to the supply or accessibility of the asset.
- Movement of LP tokens out of the current holding wallet. Without a lock contract, these tokens can be withdrawn at any time.
- Changes to the proxy implementation address, if the contract uses an upgradeable pattern. An upgrade could alter core behavior without holder consent.
GhostScore evaluates 100 checks across 5 weighted pillars: Security (30.5%), Team (30.4%), Tokenomics (16.6%), Value (13.8%), and Health (8.7%). Each pillar contains 20 questions scored individually. Critical failures trigger a nonlinear amplifier that accelerates the score downward. With 8 critical failures, the amplifier applied a penalty of 25.1 points to the raw composite. Hard overrides can also force the score to a fixed value for known threats such as sanctioned addresses or confirmed active exploits.
Go deeper. The Deep Audit ($98) adds line-level code citations, exploit path narratives, 5-pillar weighted breakdowns, and a signed PDF you can share with investors, partners, and exchanges.
Get the Deep AuditOne email. No spam. We send the full Tier 1 report and update you if the contract changes. That is it.
See it on your own contract.
Paste any contract address from any of the 35 supported chains. The free read takes under 60 seconds. No account required.