← All posts
GUIDES

How to check a BEP-20 token contract before you buy

TT
Tirio Team · 7 min read

Anyone can deploy a token with any name. A BNB Chain checklist: the right address, verified source, owner powers, proxies, taxes, holders and liquidity.

On BNB Chain a token is just a contract. Its name and symbol are whatever its deployer typed. There can be dozens of tokens called USDT, and only one of them is the one you want. Most losses on new tokens do not come from clever hacks. They come from buying the wrong contract, or a contract that was built to take your money.

This checklist takes about ten minutes per token. It will not make a bad project good, but it catches most of the traps that are visible in the code and on chain.

1. Get the address from the source

The address is the token's identity. Everything else can be copied.

  • Take it from the project's own channels, such as its website or documentation, and cross-check it with a well-known tracker. CoinGecko's swap guide points out that many tokens share a name and suggests confirming the contract address on its vetted token pages.
  • Compare the whole address, character by character. Matching the first and last few characters proves little.
  • Be suspicious of tokens that simply arrive in your wallet. PancakeSwap's troubleshooting guide warns that a token coming from an airdrop that then fails to swap is most likely a scam, and that you should not approve it or follow its links.

2. Open the contract on BscScan

BscScan is the main explorer for BNB Smart Chain. On the token's address page, the Contract tab tells you whether the source code is verified.

Verification means the explorer compiled the published source and confirmed it matches the bytecode on chain. It is important to know what that does and does not prove. Etherscan's guide to interacting with contracts safely, written by the team that also builds BscScan, says "verified" does not mean the contract is safe. It only means the code you can read is the code that runs.

An unverified token is a much bigger warning. If you cannot read the code, you cannot know what a transaction will do, including approvals it might grant. GoPlus Security's token risk documentation calls closed-source contracts extremely risky.

3. Read what the owner can do

Many tokens have an owner, an address with special powers. Under Read Contract, the owner function shows who it is. Then look through the source for functions marked onlyOwner or similar. These are the ones that matter most:

Owner powerWhy it matters
mintnew supply can be created and sold into the pool
set fee or taxbuy or sell tax can be raised, sometimes to 100 %
blacklistchosen addresses can be blocked from selling
pause tradingeveryone except privileged addresses can be frozen
max transaction or walletlimits can be tightened until trades fail
change balancesyour balance can be rewritten

GoPlus describes each of these in its risk documentation and treats most of them as serious red flags.

What "ownership renounced" really means

A common reassurance is that ownership has been renounced. In the widely used OpenZeppelin Ownable contract, renounceOwnership leaves the contract without an owner and disables every owner-only function. That helps, but it is not the end of the story:

  • Settings made before renouncing stay. A blacklist or a high tax set earlier keeps working.
  • Some contracts hide a second owner or include a way to reclaim ownership. GoPlus flags both patterns.
  • Renouncing does not freeze an upgradeable contract if the upgrade rights sit somewhere else. That is the next check.

4. Check whether it is a proxy

Some tokens are proxies: the address you hold forwards every call to a separate implementation contract, which can be replaced. Etherscan's explanation of proxy contracts notes the purpose is to upgrade logic without changing the address.

On the Contract tab, a proxy shows Read as Proxy and Write as Proxy sections with the implementation's functions. The explorer's "Is this a proxy?" prompt is a heuristic and can be wrong, and Etherscan itself warns that it does not verify that the code shown under those tabs is what actually runs.

Upgradeable tokens are not automatically bad. Some of the largest stablecoins are upgradeable. But it means the rules can change after you buy, so ask who controls upgrades.

5. Find out about taxes before you trade

A token with a transfer tax gives you less than the pool output every time it moves, and it is the most common reason swaps fail. Look for tax variables and setter functions in the source, and read the project's documentation. PancakeSwap's FAQ asks traders to check a project's website for a transaction fee before swapping.

A practical shortcut: paste the token address into a swap interface that measures taxes and look at the quote before you sign anything. On tirio.io, an unlisted token is read on chain and marked as unlisted, taxes are probed before routing, and the quote says which side is taxed and by how much, or says plainly when the tax could not be measured. Our guide to taxed tokens explains what the numbers mean and how much slippage they need.

6. Look at holders and liquidity

The Holders tab on the token page lists addresses by balance. A few things to look for:

  • Concentration. If a handful of wallets that are not pools, burn addresses or known contracts hold most of the supply, they can move the price at will.
  • Where the liquidity is. Find the main pool and how much it holds. A pool with a few thousand dollars of depth cannot absorb a large sale.
  • Whether liquidity is locked. CoinMarketCap's glossary entry on rug pulls suggests checking both the pool's liquidity and whether it is locked, since a rug pull is the creators withdrawing the pool.
  • A chart with only buys. CertiK's honeypot guide calls an all-green chart with almost no sells a good indication that holders cannot sell.

For tokens that started on a launchpad, it also helps to know whether the token has graduated and where its liquidity went. Our post on bonding-curve launchpads covers four.meme, Flap and Genius.fun.

7. Use scanners as a second opinion

Explorers now show third-party risk cards. Etherscan's guide mentions cards from GoPlus and Token Sniffer that can flag unverified code, fake tokens or buy taxes, and BscScan shows a token reputation label that it explicitly says is not an endorsement. These tools are useful for catching obvious problems quickly. They are not a guarantee in either direction, so treat a clean result as one input and not as permission.

The checklist

  1. Address from the project's own source, cross-checked, compared in full.
  2. Verified source on BscScan. Unverified means stop.
  3. Owner powers: mint, tax, blacklist, pause, limits, balance changes.
  4. Renounced? Check what was set before, hidden owners and reclaim functions.
  5. Proxy? Then find out who can upgrade it.
  6. Tax on buys and sells, measured or documented.
  7. Holders, liquidity and locks, and a chart that has sells in it.
  8. A small test before a large trade, if you still want to go ahead.

None of these steps needs special tools, and together they filter out most of the tokens that are designed to trap buyers. When you do trade, read the quote carefully. Our guide to reading a swap quote shows what each line means.

KEEP READING