$3M worth of customer funds swiped via alleged Swaprum DEX rug pull

$3M worth of customer funds swiped via alleged Swaprum DEX rug pull


Arbitrum-based decentralized exchange (DEX) Swaprum has allegedly conducted a rug-pull on its users, with $3 million worth of customer deposits being swiped from the platform.

A rug-pull or exit scam occurs when a seemingly legitimate project ropes in a certain amount of investment or user deposits before promptly shutting everything down, pulling the capital and vanishing off into the distance — if they don’t adequately cover their tracks, of course.

According to May 19 tweet from the alerts-focused account of blockchain security firm Peck Shield, the bad actors swiped 1,628 Ether (ETH) — worth roughly $2.95 million at current prices — from Swaprum’s liquidity pools, bridged it to Ethereum, and then “laundered” almost all of those funds through crypto mixer Tornado Cash.

Following the incident, Swaprum’s Twitter, Telegram and Github accounts have all been deleted, however Swaprum’s website is still operational at the time of writing.

okex
Deleted socials. Source: Twitter

Adding extra context to the incident, fellow blockchain security firm Beosin claimed that the “deployer of Swaprum used the add() backdoor function to steal LP [liquidity provider] tokens staked by users, then removed liquidity from the pool for profit.”

This was apparently made possible due to the Swaprum developer team allegedly “upgrading the normal liquidity collateral reward contract to a contract containing backdoor functions.”

A keyword search for “Swaprum” on Twitter yields several tweets from people calling out smart contract auditors CertiK over the whole ordeal, as the firm had conducted an audit of the platform as recently as May 5.

Related: Can you recover stolen Bitcoin from crypto scams?

Their complaints essentially assert that CertiK signed off on the platform by auditing the platform, with the “audited by CertiK” logo still currently up on the Swaprum website.

However, it is worth noting that as per CertiK’s disclaimers, it “conducts security assessments on the provided source code exclusively,” and can’t guarantee that its recommendations are integrated. In the audit, CertiK flagged a “major” issue with how centralized Swaprum was.

While it also appears that the backdoor-related upgrades to the project’s smart contracts were conducted after the audit was completed.

As it stands, CertiK’s website has now flagged Swaprum as an “exit scam.”

Swaprum audit. Source: CertiK

Magazine: $3.4B of Bitcoin in a popcorn tin — The Silk Road hacker’s story





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

You have not selected any currency to display

Pin It on Pinterest

Crypto-Moon
Bybit
Crypto-Moon
$3M worth of customer funds swiped via alleged Swaprum DEX rug pull
okex
undefined
Ledger
US big banks hold early talks on joint crypto stablecoin: WSJ
Dubai regulator clarifies real-world asset tokenization rules: Lawyer
Theta Capital raises $175M to back early-stage blockchain startups
Genesis files dual lawsuits to claw back $3.3B from DCG, Barry Silbert
Vitalik wants to make Ethereum ‘as simple as Bitcoin’ in 5 years
The Public internet is a bottleneck for blockchain — DoubleZero CEO
Blockfi
TokenMetrics
Important Ripple (XRP) Developments, Cardano's (ADA) Bull Run Potential, and More: Bits Recap May 23
Unicoin Executive Who Put Bounty on Vladimir Putin’s Head Charged With $110M Fraud
Sharing More, Owning Less: How Arman Sarhaddar and ivault are Building a Sustainable Future with Blockchain
Cardano price
Ethereum (ETH) Price Action Shows Strength as Bulls Target $3,800 Mark
Important Ripple (XRP) Developments, Cardano's (ADA) Bull Run Potential, and More: Bits Recap May 23
Unicoin Executive Who Put Bounty on Vladimir Putin’s Head Charged With $110M Fraud
Sharing More, Owning Less: How Arman Sarhaddar and ivault are Building a Sustainable Future with Blockchain
Cardano price