KetchupSwap Deflationary Token Mishandling: Difference between revisions
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ketchupswapdeflationarytokenmishandling.php}} thumb|KetchupSwapKetchupSwap is a copy of PantherSwap. All funds are stored in a smart contract hot wallet. This contract had an error in the way deflationary tokens were handled, which caused extra rewards to be released. All investors lost their funds as the hacker cashed out and the price of the token plummeted to zero. The...") |
No edit summary |
||
| (One intermediate revision by the same user not shown) | |||
| Line 1: | Line 1: | ||
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ketchupswapdeflationarytokenmishandling.php}} | {{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ketchupswapdeflationarytokenmishandling.php}} | ||
{{Unattributed Sources}} | |||
[[File:Ketchupswap.jpg|thumb|KetchupSwap]]KetchupSwap is a copy of PantherSwap. All funds are stored in a smart contract hot wallet. This contract had an error in the way deflationary tokens were handled, which caused extra rewards to be released. | [[File:Ketchupswap.jpg|thumb|KetchupSwap]]KetchupSwap is a copy of PantherSwap. All funds are stored in a smart contract hot wallet. This contract had an error in the way deflationary tokens were handled, which caused extra rewards to be released. | ||
| Line 5: | Line 6: | ||
All investors lost their funds as the hacker cashed out and the price of the token plummeted to zero. The project has not relaunched. | All investors lost their funds as the hacker cashed out and the price of the token plummeted to zero. The project has not relaunched. | ||
This is a global/international case not involving a specific country. | This is a global/international case not involving a specific country.<ref name="openblocksecgithub-2342" /><ref name="thoreumfinancemedium-3371" /><ref name="ketchupfinance-3372" /><ref name="dappradar-3373" /><ref name="dappradar-3374" /><ref name="dappdotcom-3375" /><ref name="ketchupswaptelegram-3376" /><ref name="cafeswapfinancetwitter-3377" /><ref name="johndoughbulltwitter-3378" /><ref name="scryptoschooltwitter-3379" /><ref name="johndoughbulltwitter-3380" /><ref name="googledoc-3381" /><ref name="happy777thakurtwitter-3382" /><ref name="pacocaiotwitter-3383" /><ref name="enpitu1okutwitter-3384" /><ref name="facebook-3385" /><ref name="youtube-3386" /><ref name="advfn-3387" /><ref name="apeboard-3388" /><ref name="rugdoc-3389" /><ref name="ketchupfinancegithub-3390" /><ref name="jeuxvideo-3391" /><ref name="cottonfarmdocs-3392" /><ref name="bscscan-3393" /><ref name="poocoin-3394" /><ref name="watchpugtwitter-3395" /><ref name="dappradartwitter-3396" /><ref name="bscscan-3397" /><ref name="fxcryptonews-3398" /><ref name="yieldfarm-3399" /> | ||
== About KetchupSwap == | == About KetchupSwap == | ||
| Line 111: | Line 112: | ||
!Description | !Description | ||
|- | |- | ||
|June 16th, 2021 | |June 16th, 2021 | ||
|Main Event | |Main Event | ||
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. | |Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. | ||
| Line 119: | Line 120: | ||
| | | | ||
|} | |} | ||
== Technical Details == | |||
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited? | |||
== Total Amount Lost == | == Total Amount Lost == | ||
| Line 132: | Line 136: | ||
== Total Amount Recovered == | == Total Amount Recovered == | ||
There do not appear to have been any funds recovered in this case. | |||
What funds were recovered? What funds were reimbursed for those affected users? | What funds were recovered? What funds were reimbursed for those affected users? | ||
| Line 138: | Line 142: | ||
== Ongoing Developments == | == Ongoing Developments == | ||
What parts of this case are still remaining to be concluded? | What parts of this case are still remaining to be concluded? | ||
== Individual Prevention Policies == | |||
{{Prevention:Individuals:Placeholder}} | |||
{{Prevention:Individuals:End}} | |||
== Platform Prevention Policies == | |||
{{Prevention:Platforms:Placeholder}} | |||
{{Prevention:Platforms:End}} | |||
== Regulatory Prevention Policies == | |||
{{Prevention:Regulators:Placeholder}} | |||
{{Prevention:Regulators:End}} | |||
== References == | == References == | ||
[https://github.com/openblocksec/blocksec-incidents/blob/main/defi/2021.md blocksec-incidents/2021.md at main · openblocksec/blocksec-incidents · GitHub] (Aug | <references><ref name="openblocksecgithub-2342">[https://github.com/openblocksec/blocksec-incidents/blob/main/defi/2021.md blocksec-incidents/2021.md at main · openblocksec/blocksec-incidents · GitHub] (Aug 11, 2021)</ref> | ||
[https://thoreum-finance.medium.com/what-exploit-happened-today-for-gocerberus-and-garuda-also-for-lokum-ybear-piggy-caramelswap-3943ee23a39f | <ref name="thoreumfinancemedium-3371">[https://thoreum-finance.medium.com/what-exploit-happened-today-for-gocerberus-and-garuda-also-for-lokum-ybear-piggy-caramelswap-3943ee23a39f What exploit happened today for GoCerberus and Garuda, also for KetchupSwap, Lokum, YBear, Piggy, CaramelSwap and our rough compensation plan | by Thoreum Finance | Medium] (Aug 29, 2021)</ref> | ||
[https://ketchupfinance.com/ KetchupFinance] (Sep | <ref name="ketchupfinance-3372">[https://ketchupfinance.com/ KetchupFinance] (Sep 15, 2021)</ref> | ||
[https://dappradar.com/binance-smart-chain/defi/ketchupswap KetchupSwap | DappRadar] (Sep | <ref name="dappradar-3373">[https://dappradar.com/binance-smart-chain/defi/ketchupswap KetchupSwap | DappRadar] (Sep 15, 2021)</ref> | ||
[https://dappradar.com/blog/ketchupswap-attracts-3000-unique-wallets-within-9-days | <ref name="dappradar-3374">[https://dappradar.com/blog/ketchupswap-attracts-3000-unique-wallets-within-9-days Ketchupswap Attracts 3000 Unique Wallets Within 9 Days] (Sep 23, 2021)</ref> | ||
[https://www.dapp.com/app/ketchupswap KetchupSwap | Dapp.com] (Sep | <ref name="dappdotcom-3375">[https://www.dapp.com/app/ketchupswap KetchupSwap | Dapp.com] (Sep 23, 2021)</ref> | ||
[https://t.me/KetchupSwap Telegram: Contact @KetchupSwap] (Sep | <ref name="ketchupswaptelegram-3376">[https://t.me/KetchupSwap Telegram: Contact @KetchupSwap] (Sep 23, 2021)</ref> | ||
[https://twitter.com/CafeSwapFinance/status/1400530540839641088 @CafeSwapFinance Twitter] (Sep | <ref name="cafeswapfinancetwitter-3377">[https://twitter.com/CafeSwapFinance/status/1400530540839641088 @CafeSwapFinance Twitter] (Sep 23, 2021)</ref> | ||
[https://twitter.com/JohnDoughBull/status/1405159533828247553 @JohnDoughBull Twitter] (Sep | <ref name="johndoughbulltwitter-3378">[https://twitter.com/JohnDoughBull/status/1405159533828247553 @JohnDoughBull Twitter] (Sep 23, 2021)</ref> | ||
[https://twitter.com/SCryptoschool/status/1404085033472724998 @SCryptoschool Twitter] (Sep | <ref name="scryptoschooltwitter-3379">[https://twitter.com/SCryptoschool/status/1404085033472724998 @SCryptoschool Twitter] (Sep 23, 2021)</ref> | ||
[https://twitter.com/JohnDoughBull/status/1406164342530248705 @JohnDoughBull Twitter] (Sep | <ref name="johndoughbulltwitter-3380">[https://twitter.com/JohnDoughBull/status/1406164342530248705 @JohnDoughBull Twitter] (Sep 23, 2021)</ref> | ||
[https://docs.google.com/forms/d/e/1FAIpQLSe6U7eNy3z1a9oGlowxsK_zcubyEK69ACsXoLlpAarNVbPOQw/closedform Lokum finance & Ketchup swap] (Sep | <ref name="googledoc-3381">[https://docs.google.com/forms/d/e/1FAIpQLSe6U7eNy3z1a9oGlowxsK_zcubyEK69ACsXoLlpAarNVbPOQw/closedform Lokum finance & Ketchup swap] (Sep 24, 2021)</ref> | ||
[https://twitter.com/happy777thakur/status/1405155988110405639 @happy777thakur Twitter] (Sep | <ref name="happy777thakurtwitter-3382">[https://twitter.com/happy777thakur/status/1405155988110405639 @happy777thakur Twitter] (Sep 24, 2021)</ref> | ||
[https://twitter.com/pacoca_io/status/1404538831962058752 @pacoca_io Twitter] (Sep | <ref name="pacocaiotwitter-3383">[https://twitter.com/pacoca_io/status/1404538831962058752 @pacoca_io Twitter] (Sep 24, 2021)</ref> | ||
[https://twitter.com/enpitu1oku/status/1405241146175938561 @enpitu1oku Twitter] (Sep | <ref name="enpitu1okutwitter-3384">[https://twitter.com/enpitu1oku/status/1405241146175938561 @enpitu1oku Twitter] (Sep 24, 2021)</ref> | ||
[https://www.facebook.com/ketchupswap/ | <ref name="facebook-3385">[https://www.facebook.com/ketchupswap/ Ketchupswap - Facebook] (Sep 24, 2021)</ref> | ||
[https://www.youtube.com/watch?v=9TWl6IKJZYw How to Migrate Pancake LP to Cafe LP on KetchupSwap - YouTube] (Sep | <ref name="youtube-3386">[https://www.youtube.com/watch?v=9TWl6IKJZYw How to Migrate Pancake LP to Cafe LP on KetchupSwap - YouTube] (Sep 24, 2021)</ref> | ||
[https://uk.advfn.com/crypto/Ketchup-Token-KETCHUP Ketchup Token (KETCHUP) Fundamentals and Technical Info | ADVFN] (Sep | <ref name="advfn-3387">[https://uk.advfn.com/crypto/Ketchup-Token-KETCHUP Ketchup Token (KETCHUP) Fundamentals and Technical Info | ADVFN] (Sep 24, 2021)</ref> | ||
[https://apeboard.hellonext.co/b/Integrations/p/ketchupswap KetchupSwap | Ape Board] (Sep | <ref name="apeboard-3388">[https://apeboard.hellonext.co/b/Integrations/p/ketchupswap KetchupSwap | Ape Board] (Sep 24, 2021)</ref> | ||
[https://rugdoc.io/project/ketchup-finance/ Ketchup Finance – RugDoc] (Sep | <ref name="rugdoc-3389">[https://rugdoc.io/project/ketchup-finance/ Ketchup Finance – RugDoc] (Sep 24, 2021)</ref> | ||
[https://github.com/KetchupFinance KetchupFinance · GitHub] (Sep | <ref name="ketchupfinancegithub-3390">[https://github.com/KetchupFinance KetchupFinance · GitHub] (Sep 24, 2021)</ref> | ||
[https://www.jeuxvideo.com/forums/42-3011927-66614522-1-0-1-0-farm-ketchup-finance.htm <nowiki>[FARM] Ketchup Finance sur le forum Finance - 26-05-2021 10:22:34 - jeuxvideo.com</nowiki>] (Sep | <ref name="jeuxvideo-3391">[https://www.jeuxvideo.com/forums/42-3011927-66614522-1-0-1-0-farm-ketchup-finance.htm <nowiki>[FARM] Ketchup Finance sur le forum Finance - 26-05-2021 10:22:34 - jeuxvideo.com</nowiki>] (Sep 24, 2021)</ref> | ||
[https://docs.cottonfarm.app/security/recent-hacks https://docs.cottonfarm.app/security/recent-hacks] (Sep | <ref name="cottonfarmdocs-3392">[https://docs.cottonfarm.app/security/recent-hacks https://docs.cottonfarm.app/security/recent-hacks] (Sep 24, 2021)</ref> | ||
[https://bscscan.com/token/0x6a0be09db6e9626789cf3f01361e985bc011daa6?a=0x983a0b9f829b89e23fbf0d0bdfdd2c702c0f975f KetchupSwap Finance Token (KETCHUP) Token Tracker | BscScan] (Sep | <ref name="bscscan-3393">[https://bscscan.com/token/0x6a0be09db6e9626789cf3f01361e985bc011daa6?a=0x983a0b9f829b89e23fbf0d0bdfdd2c702c0f975f KetchupSwap Finance Token (KETCHUP) Token Tracker | BscScan] (Sep 24, 2021)</ref> | ||
[https://poocoin.app/tokens/0x714a84632ed7edbbbfeb62dacf02db4beb4c69d9 | <ref name="poocoin-3394">[https://poocoin.app/tokens/0x714a84632ed7edbbbfeb62dacf02db4beb4c69d9 PooCoin BSC Charts] (Sep 24, 2021)</ref> | ||
[https://twitter.com/WatchPug_/status/1409475302493810689 @WatchPug_ Twitter] (Sep | <ref name="watchpugtwitter-3395">[https://twitter.com/WatchPug_/status/1409475302493810689 @WatchPug_ Twitter] (Sep 23, 2021)</ref> | ||
[https://twitter.com/DappRadar/status/1405502990094536710 @DappRadar Twitter] (Sep | <ref name="dappradartwitter-3396">[https://twitter.com/DappRadar/status/1405502990094536710 @DappRadar Twitter] (Sep 23, 2021)</ref> | ||
[https://bscscan.com/address/0xe959d028728a58bc794dbd025e36d558cdc439d2 Address 0xe959d028728a58bc794dbd025e36d558cdc439d2 | BscScan] (Sep | <ref name="bscscan-3397">[https://bscscan.com/address/0xe959d028728a58bc794dbd025e36d558cdc439d2 Address 0xe959d028728a58bc794dbd025e36d558cdc439d2 | BscScan] (Sep 24, 2021)</ref> | ||
[https://www.fxcryptonews.com/binance-smart-chain-defi-protocol-exploited-and-token-drained-to-0-00-by-hackers/ Binance Smart Chain DeFi Protocol Exploited and Token Drained to $0.00 by Hackers - Fxcryptonews] (Sep | <ref name="fxcryptonews-3398">[https://www.fxcryptonews.com/binance-smart-chain-defi-protocol-exploited-and-token-drained-to-0-00-by-hackers/ Binance Smart Chain DeFi Protocol Exploited and Token Drained to $0.00 by Hackers - Fxcryptonews] (Sep 24, 2021)</ref> | ||
[https://yieldfarm.gitbook.io/yieldfarm/ | <ref name="yieldfarm-3399">[https://yieldfarm.gitbook.io/yieldfarm/ Welcome to Yield Farm Library - Yield Farm] (Sep 24, 2021)</ref></references> | ||
Latest revision as of 17:54, 2 May 2023
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
KetchupSwap is a copy of PantherSwap. All funds are stored in a smart contract hot wallet. This contract had an error in the way deflationary tokens were handled, which caused extra rewards to be released.
All investors lost their funds as the hacker cashed out and the price of the token plummeted to zero. The project has not relaunched.
This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21][22][23][24][25][26][27][28][29][30]
About KetchupSwap
"KetchupFinance is an automated market maker (AMM) — a decentralized finance (DeFi) application that allows users to exchange tokens, providing liquidity via farming and earning fees in return." "That means that users can trade digital assets without permission from a third-party. Instead the platform uses liquidity pools, which are filled by users themselves. In return users receive the native token, in this case KETCHUP."
"KetchupSwap launched its smart contracts on May 24th, but didn’t find an audience until the 26th. After that the protocol slowly grew its daily unique active wallets, reaching 391 on May 30th and 789 on May 31st."
"The first real moment of growth happened on June 1st, when KetchupSwap attracted 3,000 unique active user wallets. A partnership with Lokum Finance seems to have given the platform a boost."
"The newly launched DeFi protocol KetchupSwap on Binance Smart Chain has attracted exactly 3,000 unique active user wallets in 9 days. These user wallets brought $5,43 million in trading volume, now placing the dapp on the 12th spot in the DeFi Rankings on DappRadar." "The 3,000 unique active wallets on June 1st enjoyed a nice APY on their investments, as the platform offers 29,000% APY on for example the KETCHUP-BNB LP tokens."
"It's a decentralized exchange for swapping BEP20 tokens on Binance Smart Chain. KetchupFinance uses an automated market maker model where users trade against a liquidity pool. These pools are filled by users who deposit their funds into the pool and receive liquidity provider (LP) tokens in return."
"These tokens can later be used to reclaim their share of the pool, as well as a portion of the trading fees."
"KetchupFinance allows users to trade BEP20 tokens, provide liquidity to the exchange and earn fees, stake LP tokens to earn KETCHUP, stake KETCHUP to earn more KETCHUP and stake KETCHUP to earn tokens of other projects."
"KetchupFinance uses a referral program. With a referral link, you can earn 1% of rewards forever."
"KetchupFinance uses also automatic liquidity and burn system. In every transfer 4% go to LP BNB to avoid price impact, and 1% go to burn."
"Next up, on #CafeSwap's menu full of goodies, we're adding our new partner, @KetchupSwap. Soon you'll be able to enjoy everyone's favorite sauce at your beloved Café."
"When users put their tokens into liquidity pools and stake their LP tokens in a farm, they put their crypto tokens in a bank. But this time the bank is a protocol created by someone anonymous. Especially users that move between the high-APY yield farms are at risk."
"Thoreum is TRUE hyper deflationary token, the best coin for HODLING. Built to be Safemoon 2.0, Thoreum has many innovative features that help users earn & win bigger."
"Today, June 16th, multiple farms their native tokens were exploited all the way to $0.00. KetchupSwap, Lokum, YBear, Piggy, CaramelSwap. Sadly enough GoCerberus and Garuda were exploited as well." "A major exploit has affected multiple BSC farms by driving their native token prices to 0." "Cerberus, Garuda, KetchupSwap, Piggy, CaramelSwap, and a few more projects got exploited at the same time, because of mishandling of tokens with transfer tax."
"As you know, an unfortunate event took place on the 16th of June. Along with us, many DeFi platforms were hacked, causing investors and project owners to suffer great losses. We could drop all of this and leave but we knew we would lose sleep over the harm done to everyone, even though sleep is crucial to human health."
"All non-native funds in our contracts are safe, and you are able to withdraw them without a problem. The exploit limits itself specifically to the native token only, and when executed it allowed the exploiter to amplify their rewards by a massive amount to effectively mint as many tokens as they want."
"The exploit is not inherent to our contract. Most of the yield farms use a trusted contract called a MasterChef, which is used even by PancakeSwap themselves to distribute rewards. The problem is that the MasterChef was never designed for all these special tokens, it was designed specifically to receive rewards for LP tokens."
"But, yield farms kept popping up and adding non-LP tokens and everything was fine. Until recently tokens with a transfer fee became more popular. Most of our tokens have a transfer fee as well, it’s how we can have our tokenomics. But the problem is that the MasterChef was not designed for this."
"Due to the design of the masterchef if you stake 100 tokens (with a 5% transaction fee) in a MasterChef, you are still able to withdraw 100 tokens from the MasterChef. But due to the transfer fee, only 95 tokens actually arrived in the contract. We actually figured that this would happen with our native token GoCerberus, and we updated the masterchef to deduct the transaction fee from the balance, eliminating the issue."
"But sadly enough we did not add this code to our non-native pools. This wasn’t such an issue, none of the non-native tokens have a transaction fee… Except for the Garuda token. Earlier today we noticed that the Garuda pool balance was getting smaller and some users reported that they could no longer withdraw. We had disabled depositing to this pool and started to think about a compensation plan. We understood that the issue had to do with the transaction fees at this time but did not know that this could be further exploited."
"Due to the inner workings of the Masterchef, once user balances grow larger then the total token balance in the pool, they effectively get a multiplier on their rewards. Anyone that was still in the Garuda pool was getting way larger harvests then they should. Until the point came that so much Garuda was withdrawn from the Garuda pool, that this multiplier became so large that a single harvest harvested all GoCerberus in the masterchef, about 40 million tokens (worth $190k at the time)."
"In the masterchef, the rewards per staked token are actually calculated by dividing the pool emissions by the total tokens in the contract." "[I]f there is 1 token remaining in the masterchef, the rewards per token are equal to the total emissions of that pool. So what happens in our previous case when there may only be 0.001 token in the pool and users still have a balance of thousands of tokens? Their harvests are thousands of times larger then what they should be."
"We believe that after KetchupSwap was exploited today, quickly some people realized this and got the balance in the pool so low that they could take all the tokens out of the masterchef in one go."
"So at this point all GoCerberus tokens were out of the masterchef, we quickly noticed this and took the actions we could. We started thinking of action plans to compensate the users. For some reason, after the initial drain, GoCerberus was still worth $0.005, so the damage was large but still limited."
"We believed that once the MasterChef was out of tokens, there were no more coins to steal. The issue lies with the referral systems of the MasterChef. When you do a simple harvest, the reward is transferred from the MasterChef to you, so you cannot take more tokens than the tokens present in the MasterChef, this is because we have a function safeCerberusTransfer that does not allow to return more." "But, the referral system of the MasterChef sadly enough does not use safeCerberusTransfer. Instead, it mints tokens directly to the referral."
"[W]e believe someone figured this out and was able to mint an unimaginable large amount of tokens to their referral, all because of the transaction fee on one single pool, the Garuda pool… The whole MasterChef was secure but it relied on the assumption that the total tokens in the contract would always be equal to the total sum of deposits. An assumption which many protocols did not know about. Today, many of these protocols, including ourselves, got exploited."
"After the initial drain, we realized what was happening and we noticed that there was still over $500k in value in the LPs. We quickly setup an emergency team to figure out a way to secure that money so it could be used for compensation. As we understood at this time that it was only a matter of time before these LPs would become worthless."
"After discussing with our engineers, we thought about a method to ‘whitehat’ these funds and had actually started developing and deploying the contracts for this (essentially they would use the referral method above to mint a large amount of tokens). Although we believed we would have been able to secure these funds given a bit more time, we were not able to deploy and execute the whitehat contract our devs developed within time and at some point we were informed that it was ‘too late’. A very stressful call where everyone on the team was doing everything they could became silent. We did what we could. Sadly enough so many other projects today were vulnerable to the same exploit. It is a novel exploit and nobody was ready for it. We did our absolute best to salvage the remaining funds."
"So, we rolled up our sleeves and started working towards recompensation. The whole team put all their efforts and sleepless nights into launching our new project: Simurgh. We have taken care of every little aspect of it, down to the smallest detail."
"In our THOREUM masterchef, every token with transaction fee will be checked and calculated exactly from the time they deposit so this will not happen ( Rugdoc.io have a scan on this and can confirm this). But in the near future we will double safe by not add pool for any deflationary token before we can confirm that their transaction fee is a fixed number that cannot be changed."
"We are aware of this logic and completely eliminated it in our THOREUM masterchef. THOREUM already has more rigid logics to check for all possibility before transfer and make sure no one can transfer if supply is zero or less. (detail will be published in another article)."
"We designed Thoreum with safety in mind and we are the first Masterchef contract that take deflationary token , token with transaction fee, in consideration. This exploit cannot be happen in our Thoreum contracts as we have many safety check function. We will give details about Thorum contracts in another article when we have time."
"No idea about this yet but something called Ketchupswap says they were hacked and some other Pantherswap clones are next like Caramel, Cerberus... You might want to get out if you're in one of these."
"The exact value that hackers stole is still unclear. However, hackers may have gotten away with an amount equal to the market cap of these projects."
"If you were in @KetchupSwap or @FinanceLokum before they got exploited, you can fill out [a] form to receive some compensation."
This is a global/international case not involving a specific country.
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| June 16th, 2021 | Main Event | Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
Total Amount Lost
The total amount lost is unknown.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ blocksec-incidents/2021.md at main · openblocksec/blocksec-incidents · GitHub (Aug 11, 2021)
- ↑ What exploit happened today for GoCerberus and Garuda, also for KetchupSwap, Lokum, YBear, Piggy, CaramelSwap and our rough compensation plan | by Thoreum Finance | Medium (Aug 29, 2021)
- ↑ KetchupFinance (Sep 15, 2021)
- ↑ KetchupSwap | DappRadar (Sep 15, 2021)
- ↑ Ketchupswap Attracts 3000 Unique Wallets Within 9 Days (Sep 23, 2021)
- ↑ KetchupSwap | Dapp.com (Sep 23, 2021)
- ↑ Telegram: Contact @KetchupSwap (Sep 23, 2021)
- ↑ @CafeSwapFinance Twitter (Sep 23, 2021)
- ↑ @JohnDoughBull Twitter (Sep 23, 2021)
- ↑ @SCryptoschool Twitter (Sep 23, 2021)
- ↑ @JohnDoughBull Twitter (Sep 23, 2021)
- ↑ Lokum finance & Ketchup swap (Sep 24, 2021)
- ↑ @happy777thakur Twitter (Sep 24, 2021)
- ↑ @pacoca_io Twitter (Sep 24, 2021)
- ↑ @enpitu1oku Twitter (Sep 24, 2021)
- ↑ Ketchupswap - Facebook (Sep 24, 2021)
- ↑ How to Migrate Pancake LP to Cafe LP on KetchupSwap - YouTube (Sep 24, 2021)
- ↑ Ketchup Token (KETCHUP) Fundamentals and Technical Info | ADVFN (Sep 24, 2021)
- ↑ KetchupSwap | Ape Board (Sep 24, 2021)
- ↑ Ketchup Finance – RugDoc (Sep 24, 2021)
- ↑ KetchupFinance · GitHub (Sep 24, 2021)
- ↑ [FARM] Ketchup Finance sur le forum Finance - 26-05-2021 10:22:34 - jeuxvideo.com (Sep 24, 2021)
- ↑ https://docs.cottonfarm.app/security/recent-hacks (Sep 24, 2021)
- ↑ KetchupSwap Finance Token (KETCHUP) Token Tracker | BscScan (Sep 24, 2021)
- ↑ PooCoin BSC Charts (Sep 24, 2021)
- ↑ @WatchPug_ Twitter (Sep 23, 2021)
- ↑ @DappRadar Twitter (Sep 23, 2021)
- ↑ Address 0xe959d028728a58bc794dbd025e36d558cdc439d2 | BscScan (Sep 24, 2021)
- ↑ Binance Smart Chain DeFi Protocol Exploited and Token Drained to $0.00 by Hackers - Fxcryptonews (Sep 24, 2021)
- ↑ Welcome to Yield Farm Library - Yield Farm (Sep 24, 2021)