SwapRum Rug Pull: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(30 minutes completed.)
(30 more minutes completed.)
Line 4: Line 4:
[[File:Swaprum.jpg|thumb|SwapRun Website]]SwapRum Finance offered a next generation decentralized exchange. They obtained an audit from CertiK but only partially resolved some of the issues in their project. Then they used one of those issues to execute a rug pull and withdraw all funds form the liquidity pool, which were then brought out through TornadoCash.
[[File:Swaprum.jpg|thumb|SwapRun Website]]SwapRum Finance offered a next generation decentralized exchange. They obtained an audit from CertiK but only partially resolved some of the issues in their project. Then they used one of those issues to execute a rug pull and withdraw all funds form the liquidity pool, which were then brought out through TornadoCash.


This is a global/international case not involving a specific country.<ref name="slowmisthackedarchive-10953" /><ref name="hackenclubtwitterarchive-10954" /><ref name="hackenclubtwitter-10955" /><ref name="arbiscan-10956" /><ref name="sebasti04989541twitter-10957" /><ref name="cryptoemprendetwitter-10958" /><ref name="lucas75831804twitter-10959" /><ref name="anciliainctwitter-10960" /><ref name="jessiedegenstwitter-10961" /><ref name="metasleuthtwitter-10962" /><ref name="damicalestwitter-10963" /><ref name="martiniguyyttwitter-10964" /><ref name="peckshieldalerttwitter-10965" /><ref name="damicalestwitter-10966" /><ref name="dedotfisecuritytwitter-10967" /><ref name="theblocktwitter-10968" /><ref name="musiclo62847240twitter-10969" /><ref name="saitopicknewstwitter-10970" /><ref name="jinyachao1999twitter-10971" /><ref name="takacryptotwitter-10972" /><ref name="huntershannohstwitter-10973" /><ref name="moffcointwitter-10974" /><ref name="whalecointalktwitter-10975" /><ref name="waleedmahmoud99twitter-10976" /><ref name="marcink88twitter-10977" /><ref name="mtomczakorgtwitter-10978" /><ref name="rnsahintwitter-10979" /><ref name="cyversalertstwitter-10980" /><ref name="cryptosavingexptwitter-10981" /><ref name="cryptokeretwitter-10982" /><ref name="damicalestwitter-10983" /><ref name="vadymnikolskyi1twitter-10984" /><ref name="mueb2ethtwitter-10985" /><ref name="cryptopotatotwitter-10986" /><ref name="esatoshiclubtwitter-10987" /><ref name="alabasimamountwitter-10988" /><ref name="brahmi1973twitter-10989" /><ref name="mnathu0105twitter-10990" /><ref name="numencybertwitter-10991" /><ref name="koinbultwitter-10992" /><ref name="0xepicatwitter-10993" /><ref name="lun68251148twitter-10994" /><ref name="becausebitcointwitter-10995" /><ref name="djkhileshrajtwitter-10996" /><ref name="cyversalertstwitter-10997" /><ref name="yunasmftwitter-10998" /><ref name="perseuscryptotwitter-10999" /><ref name="cryptaiatechtwitter-11000" /><ref name="becausebitcointwitter-11001" /><ref name="newsgagarintwitter-11002" /><ref name="majedmaddevtwitter-11003" /><ref name="juanpmarintwitter-11004" /><ref name="jurangcryptotwitter-11005" /><ref name="chainaegistwitter-11006" /><ref name="aloponaftwitter-11007" /><ref name="dariush72249709twitter-11008" /><ref name="beosinalerttwitter-11009" /><ref name="datedata51twitter-11010" /><ref name="dailynewsweb3twitter-11011" /><ref name="aryobagas9twitter-11012" /><ref name="blinanalyticstwitter-11013" /><ref name="ayodelesammyleetwitter-11014" /><ref name="tokenmetricsinctwitter-11015" /><ref name="hayatkhan6931twitter-11016" />
This is a global/international case not involving a specific country.<ref name="slowmisthackedarchive-10953" /><ref name="hackenclubtwitterarchive-10954" /><ref name="hackenclubtwitter-10955" /><ref name="arbiscan-10956" /><ref name="sebasti04989541twitter-10957" /><ref name="cryptoemprendetwitter-10958" /><ref name="lucas75831804twitter-10959" /><ref name="anciliainctwitter-10960" /><ref name="jessiedegenstwitter-10961" /><ref name="metasleuthtwitter-10962" /><ref name="damicalestwitter-10963" /><ref name="martiniguyyttwitter-10964" /><ref name="peckshieldalerttwitter-10965" /><ref name="damicalestwitter-10966" /><ref name="dedotfisecuritytwitter-10967" /><ref name="theblocktwitter-10968" /><ref name="musiclo62847240twitter-10969" /><ref name="saitopicknewstwitter-10970" /><ref name="jinyachao1999twitter-10971" /><ref name="takacryptotwitter-10972" /><ref name="huntershannohstwitter-10973" /><ref name="moffcointwitter-10974" /><ref name="whalecointalktwitter-10975" /><ref name="waleedmahmoud99twitter-10976" /><ref name="marcink88twitter-10977" /><ref name="mtomczakorgtwitter-10978" /><ref name="rnsahintwitter-10979" /><ref name="cyversalertstwitter-10980" /><ref name="cryptosavingexptwitter-10981" /><ref name="cryptokeretwitter-10982" /><ref name="damicalestwitter-10983" /><ref name="vadymnikolskyi1twitter-10984" /><ref name="mueb2ethtwitter-10985" /><ref name="cryptopotatotwitter-10986" /><ref name="esatoshiclubtwitter-10987" /><ref name="alabasimamountwitter-10988" /><ref name="brahmi1973twitter-10989" /><ref name="mnathu0105twitter-10990" /><ref name="numencybertwitter-10991" /><ref name="koinbultwitter-10992" /><ref name="0xepicatwitter-10993" /><ref name="lun68251148twitter-10994" /><ref name="becausebitcointwitter-10995" /><ref name="djkhileshrajtwitter-10996" /><ref name="cyversalertstwitter-10997" /><ref name="yunasmftwitter-10998" /><ref name="perseuscryptotwitter-10999" /><ref name="cryptaiatechtwitter-11000" /><ref name="becausebitcointwitter-11001" /><ref name="newsgagarintwitter-11002" /><ref name="majedmaddevtwitter-11003" />


== About SwapRum ==
== About SwapRum ==
Line 10: Line 10:


"Swaprum is a next-generation decentralized exchange with a range of trading tools and potential earnings of up to 100% APY. Explore limitless possibilities in the world of DeFi with Swaprum."
"Swaprum is a next-generation decentralized exchange with a range of trading tools and potential earnings of up to 100% APY. Explore limitless possibilities in the world of DeFi with Swaprum."
The Swaprum application was promoted as a way that one could obtain free Arbitrum tokens<ref name="aryobagas9twitter-11012" />.<blockquote>Claim Tokens For Free
Free ARB tokens for everyone
Join Swaprum Free Pool and get free ARB tokens every day! Become a part of the platform's community and earn cool rewards with your friends. Read the detailed terms below.</blockquote>


"Swaprum (@Swaprum) on Arbitrum rugged by its founders for ~$3M"
"Swaprum (@Swaprum) on Arbitrum rugged by its founders for ~$3M"
Line 49: Line 56:
The interface provided users with a balance in ARB, and claimed that withdrawals would be processed after 0.5 ARB were accumulated<ref name="sanjeev08818841twitter-11025" /><ref name="blmcryptotwitter-11018" />.
The interface provided users with a balance in ARB, and claimed that withdrawals would be processed after 0.5 ARB were accumulated<ref name="sanjeev08818841twitter-11025" /><ref name="blmcryptotwitter-11018" />.


Multiple users on Twitter expressed support and excitement for the project<ref name="parhan235twitter-11021" />, while others helped to promote it<ref name="blmcryptotwitter-11018" />.
Multiple users on Twitter expressed support and excitement for the project<ref name="parhan235twitter-11021" /><ref name="aloponaftwitter-11007" />, while others helped to promote it<ref name="blmcryptotwitter-11018" /><ref name="datedata51twitter-11010" />. In fact, it was reported that the Telegram account of the project was full<ref name="ayodelesammyleetwitter-11014" />.


<blockquote>good project...and good investasi.....bravo @Swaprum</blockquote>
<blockquote>good project...and good investasi.....bravo @Swaprum</blockquote>
Line 62: Line 69:


=== Limitations of Interface ===
=== Limitations of Interface ===
There were multiple reports prior to the rug pull of issues with the provided Swaprum interface<ref name="khuongeyelesstwitter-11031" /><ref name="sanjeev08818841twitter-11025" />, including a reported inability to withdraw funds<ref name="mohsencngtwitter-11028" />.<blockquote>Why does the claim not accumulate in the balance section?</blockquote><blockquote>Why hasn't the token been deposited into my wallet after a few days of requesting a withdrawal?</blockquote>
There were multiple reports prior to the rug pull of issues with the provided Swaprum interface<ref name="khuongeyelesstwitter-11031" /><ref name="sanjeev08818841twitter-11025" />, including failures to load the website<ref name="aryobagas9twitter-11012" /> and a reported inability to withdraw funds<ref name="ayodelesammyleetwitter-11014" /><ref name="mohsencngtwitter-11028" /><ref name="hayatkhan6931twitter-11016" /><ref name="dariush72249709twitter-11008" />.<blockquote>Why does the claim not accumulate in the balance section?</blockquote><blockquote>Why hasn't the token been deposited into my wallet after a few days of requesting a withdrawal?</blockquote><blockquote>I want you to help, even in withdrawing, there is a pending order.</blockquote><blockquote>Bro dont pay scam site withdrawal transaction dont work 100% scam</blockquote>


== What Happened ==
== What Happened ==
Line 71: Line 78:
!Event
!Event
!Description
!Description
|-
|May 17th, 2023 10:44:00 AM MDT
|Telegram Reportedly Full
|Twitter user AyodeleSammylee reports that the Telegram account of the Swaprum project is full. The majority of messages visible appear to be users attempting to withdraw their funds<ref name="ayodelesammyleetwitter-11014" />.
|-
|-
|May 17th, 2023 7:52:00 PM MDT
|May 17th, 2023 7:52:00 PM MDT
|
|
|
|
|-
|May 17th, 2023 3:45:00 PM MDT
|Website Bad Request Reported
|Twitter user Aryo Bagas reports that the mobile application is giving a "Error Bad request, check internet" code<ref name="aryobagas9twitter-11012" />.
|-
|-
|May 18th, 2023 9:52:12 AM MDT
|May 18th, 2023 9:52:12 AM MDT
Line 87: Line 102:
|Twitter Account Deactivation
|Twitter Account Deactivation
|It's reported that Swaprum Finance has deactivated their Twitter account<ref name="lamarziaatwitter-11027" />.
|It's reported that Swaprum Finance has deactivated their Twitter account<ref name="lamarziaatwitter-11027" />.
|-
|May 19th, 2023 12:22:00 AM MDT
|ChainAegis Reports Rug Pull
|A ChainAegis alert is generated on Twitter to report on the rug pull<ref name="chainaegistwitter-11006" />.
|-
|May 19th, 2023 2:10:00 AM MDT
|Blin Analytics Report
|Blin Analytics reports on the situation on Twitter<ref name="blinanalyticstwitter-11013" />.
|-
|May 19th, 2023 2:53:00 AM MDT
|Beosin Alert Published
|Beosin publishes an alert on Twitter about the situation<ref name="beosinalerttwitter-11009" />.
|-
|-
|May 19th, 2023 4:01:00 AM MDT
|May 19th, 2023 4:01:00 AM MDT
Line 94: Line 121:
|May 19th, 2023 4:36:00 AM MDT
|May 19th, 2023 4:36:00 AM MDT
|The Block Article
|The Block Article
|The Block publishes an article on the situation<ref name="theblock-11033" />. TBD get summary.
|The Block publishes an article on the situation<ref name="theblock-11033" />. TBD get summary. This is crossposted by Token Metrics<ref name="tokenmetricsinctwitter-11015" />.
|-
|May 19th, 2023 6:20:00 AM MDT
|CryptoPolitan Article
|Crossposted by Daily Web3 News<ref name="dailynewsweb3twitter-11011" />.
|-
|May 19th, 2023 8:11:00 AM MDT
|Majed Summary Published
|TBD expand<ref name="majedmaddevtwitter-11003" />.
|-
|May 19th, 2023 9:01:00 AM MDT
|Wisper Crypto Summary Published
|Wisper Crypto publishes a summary on Twitter<ref name="jurangcryptotwitter-11005" />.
|-
|-
|May 19th, 2023 10:34:00 AM MDT
|May 19th, 2023 10:34:00 AM MDT
Line 105: Line 144:


<ref name="skynet-11032" />
<ref name="skynet-11032" />
=== Beosin Alert Analysis ===
Beosin published an alert about the situation on Twitter<ref name="beosinalerttwitter-11009" />.<blockquote>Swaprum on Arbitrum rugged for ~$3M.
The deployer of Swaprum used the add() backdoor function to steal LP tokens staked by users, then removed liquidity from the pool for profit.
2/ The project has upgraded the the normal liquidity collateral reward contract to a contract containing backdoor functions.
3/ The backdoor function add() will transfer LP tokens from the contract to the _devadd address. By querying the _devadd address, it will return the ‘Swaprum:Deployer’ address.
4/ The Swaprum: Deployer uses the stolen LP tokens in the previous step to remove liquidity.
1,620 $ETH has already sent to Tornado Cash.</blockquote>
=== WisperCrypto Summary ===
WisperCrypto published a summary of the situation<ref name="jurangcryptotwitter-11005" />.<blockquote>Breaking News!
#Swaprum DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%
In a shocking turn of events, the decentralized exchange #Swaprum operating on Ethereum Layer 2 network #Arbitrum has orchestrated a treacherous exit scam, leaving users devastated and questioning the safety of the crypto industry.
The Swaprum team slyly removed the liquidity tied to their native coin, SAPR, causing a significant drop in its price. Unsuspecting investors were left holding worthless tokens, resulting in a loss of approximately 1,628 ETH ($3M) in user deposits.
To further obfuscate the stolen funds, the Swaprum team transferred them to Ethereum and employed the notorious ETH mixer service Tornado Cash. This service masks the transaction trail, making it difficult for authorities to trace the flow of funds
The deceitful team swiftly deleted their social media presence on Twitter, Telegram, and GitHub, leaving users without any means of contact. However, the project's official website, which served as the interface for the protocol, is still accessible.
Subsequent investigations by Beosin's security analysts revealed that Swaprum's smart contract contained a covert backdoor mechanism, raising concerns about the project's intentions from the start.
This incident adds to the growing list of crypto scams, highlighting the urgent need for increased security and regulation within the industry. Investors must remain vigilant and exercise caution when engaging with decentralized platforms.</blockquote>


== Total Amount Lost ==
== Total Amount Lost ==
Line 115: Line 184:


=== Reactions on Twitter ===
=== Reactions on Twitter ===
The news was widely reported on Twitter<ref name="lamarziaatwitter-11027" /><ref name="beyondkartotwitter-11023" /><ref name="web3wisertwitter-11017" /><ref name="winnerilltwitter-11026" /><ref name="beyondbitcoin1twitter-11029" /><ref name="defivisionarytwitter-11024" /><ref name="kirill186186twitter-11022" />.<blockquote>swaprum finance deactivate their twitter account?</blockquote><blockquote>Important Alert! Crypto traders, beware! Swaprum, an exchange on Arbitrum network, has been exposed as a decentralized scam. The team behind it has shamelessly withdrawn approximately $3 million from customer deposits </blockquote><blockquote>Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%</blockquote><blockquote>Just got rugged on Swaprum. Site and discord is still up. A lot of work for 1 million</blockquote><blockquote>JUST IN: Swaprum, a decentralized exchange (DEX) built on @arbitrum ruggpulls with $3 million users deposit.  According to blockchain security firm PeckShield, the team has already laundered part of the funds on Tornado Cash.</blockquote><blockquote>The #Swaprum rug pull has left investors devastated with a jaw-dropping $3 million loss in this #defi scam. As a social media marketer, I urge everyone to stay vigilant while investing in the crypto market. Like and retweet to spread the word!</blockquote><blockquote>@Swaprum he deceived us all, we fulfilled all the conditions, but they threw us .. do not believe this is ophirists</blockquote>
The news was widely reported on Twitter<ref name="lamarziaatwitter-11027" /><ref name="beyondkartotwitter-11023" /><ref name="web3wisertwitter-11017" /><ref name="winnerilltwitter-11026" /><ref name="beyondbitcoin1twitter-11029" /><ref name="defivisionarytwitter-11024" /><ref name="kirill186186twitter-11022" /><ref>[https://twitter.com/rotcivegaf/status/1660032640332832768 Rotciv - "A week ago I reported a bug, which they never paid for, it was obvious from afar that it was a trap.  the truth is that they made a well-organized trap" - Twitter] (May 25, 2023)</ref><ref>[https://twitter.com/Ero___Gamer/status/1659759290922483717 Rean Schwarzer - "I know from the start Swaprum was a scam project just after visiting their token page on @CoinMarketCap since it clearly had a warning sign of a rugged token. Ironically I joined their group to get free ARB but after I posted about their token they kicked me out lol." - Twitter] (May 25, 2023)</ref>.<blockquote>swaprum finance deactivate their twitter account?</blockquote><blockquote>Important Alert! Crypto traders, beware! Swaprum, an exchange on Arbitrum network, has been exposed as a decentralized scam. The team behind it has shamelessly withdrawn approximately $3 million from customer deposits </blockquote><blockquote>Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%</blockquote><blockquote>Just got rugged on Swaprum. Site and discord is still up. A lot of work for 1 million</blockquote><blockquote>JUST IN: Swaprum, a decentralized exchange (DEX) built on @arbitrum ruggpulls with $3 million users deposit.  According to blockchain security firm PeckShield, the team has already laundered part of the funds on Tornado Cash.</blockquote><blockquote>The #Swaprum rug pull has left investors devastated with a jaw-dropping $3 million loss in this #defi scam. As a social media marketer, I urge everyone to stay vigilant while investing in the crypto market. Like and retweet to spread the word!</blockquote><blockquote>@Swaprum he deceived us all, we fulfilled all the conditions, but they threw us .. do not believe this is ophirists</blockquote><blockquote>A week ago I reported a bug, which they never paid for, it was obvious from afar that it was a trap.  the truth is that they made a well-organized trap</blockquote><blockquote>I know from the start Swaprum was a scam project just after visiting their token page on @CoinMarketCap since it clearly had a warning sign of a rugged token. Ironically I joined their group to get free ARB but after I posted about their token they kicked me out lol.</blockquote>
 
=== Backlash Against CertiK Auditor ===
There was considerable backlash against CertiK for approving the team's smart contract<ref name="juanpmarintwitter-11004" />.<blockquote>Wtf @CertiK ? Did they bought the audit?</blockquote>


== Ultimate Outcome ==
== Ultimate Outcome ==
Line 197: Line 269:
<ref name="becausebitcointwitter-11001">[https://twitter.com/BecauseBitcoin/status/1659513274029703168 @BecauseBitcoin Twitter] (May 19, 2023)</ref>
<ref name="becausebitcointwitter-11001">[https://twitter.com/BecauseBitcoin/status/1659513274029703168 @BecauseBitcoin Twitter] (May 19, 2023)</ref>
<ref name="newsgagarintwitter-11002">[https://twitter.com/NewsGagarin/status/1659544949514289152 @NewsGagarin Twitter] (May 19, 2023)</ref>
<ref name="newsgagarintwitter-11002">[https://twitter.com/NewsGagarin/status/1659544949514289152 @NewsGagarin Twitter] (May 19, 2023)</ref>
<ref name="majedmaddevtwitter-11003">[https://twitter.com/MajedMaddev/status/1659562337378918400 @MajedMaddev Twitter] (May 19, 2023)</ref>
<ref name="majedmaddevtwitter-11003">[https://twitter.com/MajedMaddev/status/1659562337378918400 MajedMaddev - "Swaprum, a decentralized exchange on the Ethereum Layer 2 network Arbitrum, appears to have executed an "exit scam" commonly referred to as a "rug pull," absconding with an estimated $3 million in user deposits." - Twitter] (May 19, 2023)</ref>
<ref name="juanpmarintwitter-11004">[https://twitter.com/JuanP_marin/status/1659273873085407261 @JuanP_marin Twitter] (May 19, 2023)</ref>
<ref name="juanpmarintwitter-11004">[https://twitter.com/JuanP_marin/status/1659273873085407261 JuanP_marin - "Wtf @CertiK ? Did they bought the audit?" -Twitter] (May 19, 2023)</ref>
<ref name="jurangcryptotwitter-11005">[https://twitter.com/JurangCrypto/status/1659575115259195393 @JurangCrypto Twitter] (May 19, 2023)</ref>
<ref name="jurangcryptotwitter-11005">[https://twitter.com/JurangCrypto/status/1659575115259195393 Wisper Crypto - "Breaking News! #Swaprum DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%" - Twitter] (May 19, 2023)</ref>
<ref name="chainaegistwitter-11006">[https://twitter.com/ChainAegis/status/1659444425179938816 @ChainAegis Twitter] (May 19, 2023)</ref>
<ref name="chainaegistwitter-11006">[https://twitter.com/ChainAegis/status/1659444425179938816 ChainAegis - "According to the security monitoring of @ChainAegis, an analysis platform on the SharkTeam, Rug Pull occurred in the Arbitrum ecological Swaprum project" - Twitter] (May 19, 2023)</ref>
<ref name="aloponaftwitter-11007">[https://twitter.com/aloponaf/status/1658979516096876545 @aloponaf Twitter] (May 19, 2023)</ref>
<ref name="aloponaftwitter-11007">[https://twitter.com/aloponaf/status/1658979516096876545 aloponaf - "@Swaprum amazing payment" - Twitter] (May 19, 2023)</ref>
<ref name="dariush72249709twitter-11008">[https://twitter.com/dariush72249709/status/1659502503942139904 @dariush72249709 Twitter] (May 19, 2023)</ref>
<ref name="dariush72249709twitter-11008">[https://twitter.com/dariush72249709/status/1659502503942139904 dariush72249709 - "Bro dont pay scam site withdrawal transaction dont work 100% scam" - Twitter] (May 19, 2023)</ref>
<ref name="beosinalerttwitter-11009">[https://twitter.com/BeosinAlert/status/1659482287422193664 @BeosinAlert Twitter] (May 19, 2023)</ref>
<ref name="beosinalerttwitter-11009">[https://twitter.com/BeosinAlert/status/1659482287422193664 Beosin Alert - "Swaprum on Arbitrum rugged for ~$3M. The deployer of Swaprum used the add() backdoor function to steal LP tokens staked by users, then removed liquidity from the pool for profit." - Twitter] (May 19, 2023)</ref>
<ref name="datedata51twitter-11010">[https://twitter.com/datedata51/status/1659019451457748992 @datedata51 Twitter] (May 19, 2023)</ref>
<ref name="datedata51twitter-11010">[https://twitter.com/datedata51/status/1659019451457748992 datedata51 - "Join the best Yield #Farming pools and earn high APR" - Twitter] (May 19, 2023)</ref>
<ref name="dailynewsweb3twitter-11011">[https://twitter.com/DailyNewsWeb3/status/1659534539306471425 @DailyNewsWeb3 Twitter] (May 19, 2023)</ref>
<ref name="dailynewsweb3twitter-11011">[https://twitter.com/DailyNewsWeb3/status/1659534539306471425 DailyNewsWeb3 - "Decentralized Exchange Platform Loses $3 Million in Scam" - Twitter] (May 19, 2023)</ref>
<ref name="aryobagas9twitter-11012">[https://twitter.com/AryoBagas9/status/1658951836026679297 @AryoBagas9 Twitter] (May 19, 2023)</ref>
<ref name="aryobagas9twitter-11012">[https://twitter.com/AryoBagas9/status/1658951836026679297 AryoBagas9 - "funny" "Error Bad request, check internet" - Twitter] (May 19, 2023)</ref>
<ref name="blinanalyticstwitter-11013">[https://twitter.com/BlinAnalytics/status/1659471606706495489 @BlinAnalytics Twitter] (May 19, 2023)</ref>
<ref name="blinanalyticstwitter-11013">[https://twitter.com/BlinAnalytics/status/1659471606706495489 Blin Analytics - "@Swaprum was rugged on @arbitrum network. 1620 $ETH (~ $2.7M) was bridged to Ethereum network and deposited to @TornadoCash." - Twitter] (May 19, 2023)</ref>
<ref name="ayodelesammyleetwitter-11014">[https://twitter.com/AyodeleSammylee/status/1658876053266264064 @AyodeleSammylee Twitter] (May 19, 2023)</ref>
<ref name="ayodelesammyleetwitter-11014">[https://twitter.com/AyodeleSammylee/status/1658876053266264064 AyodeleSammylee - "Telegram account is full" - Twitter] (May 19, 2023)</ref>
<ref name="tokenmetricsinctwitter-11015">[https://twitter.com/tokenmetricsinc/status/1659514780116307968 @tokenmetricsinc Twitter] (May 19, 2023)</ref>
<ref name="tokenmetricsinctwitter-11015">[https://twitter.com/tokenmetricsinc/status/1659514780116307968 Token Metrics - "BREAKING: Swaprum DEX Team Absconds with $3M: Suspected Exit Scam on Arbitrum Network" - Twitter] (May 19, 2023)</ref>
<ref name="hayatkhan6931twitter-11016">[https://twitter.com/hayatkhan6931/status/1658915324660523025 @hayatkhan6931 Twitter] (May 19, 2023)</ref>
<ref name="hayatkhan6931twitter-11016">[https://twitter.com/hayatkhan6931/status/1658915324660523025 hayatkhan6931 - "I want you to help, even in withdrawing, there is a pending order." - Twitter] (May 19, 2023)</ref>
<ref name="web3wisertwitter-11017">[https://twitter.com/web3wiser/status/1659540574767120386 web3wiser - "Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%" - Twitter] (May 19, 2023)</ref>
<ref name="web3wisertwitter-11017">[https://twitter.com/web3wiser/status/1659540574767120386 web3wiser - "Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%" - Twitter] (May 19, 2023)</ref>
<ref name="blmcryptotwitter-11018">[https://twitter.com/blm_crypto/status/1658986244133748737 blm_crypto - "$SAPR stakeしてたから1.5 $ARB /hになった" - Twitter] (May 19, 2023)</ref>
<ref name="blmcryptotwitter-11018">[https://twitter.com/blm_crypto/status/1658986244133748737 blm_crypto - "$SAPR stakeしてたから1.5 $ARB /hになった" - Twitter] (May 19, 2023)</ref>

Revision as of 14:10, 25 May 2023

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

SwapRun Website

SwapRum Finance offered a next generation decentralized exchange. They obtained an audit from CertiK but only partially resolved some of the issues in their project. Then they used one of those issues to execute a rug pull and withdraw all funds form the liquidity pool, which were then brought out through TornadoCash.

This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21][22][23][24][25][26][27][28][29][30][31][32][33][34][35][36][37][38][39][40][41][42][43][44][45][46][47][48][49][50][51]

About SwapRum

"Next Generation Decentralized Exchange"

"Swaprum is a next-generation decentralized exchange with a range of trading tools and potential earnings of up to 100% APY. Explore limitless possibilities in the world of DeFi with Swaprum."


The Swaprum application was promoted as a way that one could obtain free Arbitrum tokens[52].

Claim Tokens For Free

Free ARB tokens for everyone

Join Swaprum Free Pool and get free ARB tokens every day! Become a part of the platform's community and earn cool rewards with your friends. Read the detailed terms below.

"Swaprum (@Swaprum) on Arbitrum rugged by its founders for ~$3M"

"The deployer of Swaprum utilized a backdoor function, add(), to steal LP tokens staked by users

Following the theft, liquidity was swiftly stolen from the pool by the deployer"

"Then, the deployer of Swaprum transferred all the funds to Ethereum network using cross chain bridges such as @MultichainOrg, @AcrossProtocol, and @CelerNetwork. After successfully bridging 1620 $ETH through these platforms, he funneled it into @TornadoCash."

"At this time @Swaprum has deleted all their social media accounts and groups."

"As a result of this rugpull, the token $SAPR has plummeted by 100%. The scammers managed to escape with approximately 1,628 ETH, equivalent to around $2.95 million."

"CertiK AGAIN! Why in the hell are these degens giving such "projects" money? It's frustrating to see all these scammers since 2010, hello braincell."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.


The interface provided users with a balance in ARB, and claimed that withdrawals would be processed after 0.5 ARB were accumulated[53][54].

Multiple users on Twitter expressed support and excitement for the project[55][56], while others helped to promote it[54][57]. In fact, it was reported that the Telegram account of the project was full[58].

good project...and good investasi.....bravo @Swaprum

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

Limitations of Interface

There were multiple reports prior to the rug pull of issues with the provided Swaprum interface[59][53], including failures to load the website[52] and a reported inability to withdraw funds[58][60][61][62].

Why does the claim not accumulate in the balance section?

Why hasn't the token been deposited into my wallet after a few days of requesting a withdrawal?

I want you to help, even in withdrawing, there is a pending order.

Bro dont pay scam site withdrawal transaction dont work 100% scam

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - SwapRum Rug Pull
Date Event Description
May 17th, 2023 10:44:00 AM MDT Telegram Reportedly Full Twitter user AyodeleSammylee reports that the Telegram account of the Swaprum project is full. The majority of messages visible appear to be users attempting to withdraw their funds[58].
May 17th, 2023 7:52:00 PM MDT
May 17th, 2023 3:45:00 PM MDT Website Bad Request Reported Twitter user Aryo Bagas reports that the mobile application is giving a "Error Bad request, check internet" code[52].
May 18th, 2023 9:52:12 AM MDT Liquidity Drained Transaction to drain liquidity.
May 18th, 2023 9:48:00 PM MDT PeckShield Alert Triggered A PeckShield alert is triggered. The alerts is retweeted by the Web3 Watchdog[63] and pSquare_Daily[64]. TBD get actual alert.
May 19th, 2023 12:05:00 AM MDT Twitter Account Deactivation It's reported that Swaprum Finance has deactivated their Twitter account[65].
May 19th, 2023 12:22:00 AM MDT ChainAegis Reports Rug Pull A ChainAegis alert is generated on Twitter to report on the rug pull[66].
May 19th, 2023 2:10:00 AM MDT Blin Analytics Report Blin Analytics reports on the situation on Twitter[67].
May 19th, 2023 2:53:00 AM MDT Beosin Alert Published Beosin publishes an alert on Twitter about the situation[68].
May 19th, 2023 4:01:00 AM MDT Report on Twitter Describe the event.
May 19th, 2023 4:36:00 AM MDT The Block Article The Block publishes an article on the situation[69]. TBD get summary. This is crossposted by Token Metrics[70].
May 19th, 2023 6:20:00 AM MDT CryptoPolitan Article Crossposted by Daily Web3 News[71].
May 19th, 2023 8:11:00 AM MDT Majed Summary Published TBD expand[51].
May 19th, 2023 9:01:00 AM MDT Wisper Crypto Summary Published Wisper Crypto publishes a summary on Twitter[72].
May 19th, 2023 10:34:00 AM MDT Crypto Purity Article Crypto Purity reports on the situation[73]. TBD more summary[74].

Technical Details

This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?

[75]

Beosin Alert Analysis

Beosin published an alert about the situation on Twitter[68].

Swaprum on Arbitrum rugged for ~$3M.

The deployer of Swaprum used the add() backdoor function to steal LP tokens staked by users, then removed liquidity from the pool for profit.

2/ The project has upgraded the the normal liquidity collateral reward contract to a contract containing backdoor functions.

3/ The backdoor function add() will transfer LP tokens from the contract to the _devadd address. By querying the _devadd address, it will return the ‘Swaprum:Deployer’ address.

4/ The Swaprum: Deployer uses the stolen LP tokens in the previous step to remove liquidity.

1,620 $ETH has already sent to Tornado Cash.

WisperCrypto Summary

WisperCrypto published a summary of the situation[72].

Breaking News!

  1. Swaprum DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%

In a shocking turn of events, the decentralized exchange #Swaprum operating on Ethereum Layer 2 network #Arbitrum has orchestrated a treacherous exit scam, leaving users devastated and questioning the safety of the crypto industry.

The Swaprum team slyly removed the liquidity tied to their native coin, SAPR, causing a significant drop in its price. Unsuspecting investors were left holding worthless tokens, resulting in a loss of approximately 1,628 ETH ($3M) in user deposits.

To further obfuscate the stolen funds, the Swaprum team transferred them to Ethereum and employed the notorious ETH mixer service Tornado Cash. This service masks the transaction trail, making it difficult for authorities to trace the flow of funds

The deceitful team swiftly deleted their social media presence on Twitter, Telegram, and GitHub, leaving users without any means of contact. However, the project's official website, which served as the interface for the protocol, is still accessible.

Subsequent investigations by Beosin's security analysts revealed that Swaprum's smart contract contained a covert backdoor mechanism, raising concerns about the project's intentions from the start.

This incident adds to the growing list of crypto scams, highlighting the urgent need for increased security and regulation within the industry. Investors must remain vigilant and exercise caution when engaging with decentralized platforms.

Total Amount Lost

The total amount lost has been estimated at $2,950,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Reactions on Twitter

The news was widely reported on Twitter[65][76][77][78][79][80][81][82][83].

swaprum finance deactivate their twitter account?

Important Alert! Crypto traders, beware! Swaprum, an exchange on Arbitrum network, has been exposed as a decentralized scam. The team behind it has shamelessly withdrawn approximately $3 million from customer deposits

Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%

Just got rugged on Swaprum. Site and discord is still up. A lot of work for 1 million

JUST IN: Swaprum, a decentralized exchange (DEX) built on @arbitrum ruggpulls with $3 million users deposit. According to blockchain security firm PeckShield, the team has already laundered part of the funds on Tornado Cash.

The #Swaprum rug pull has left investors devastated with a jaw-dropping $3 million loss in this #defi scam. As a social media marketer, I urge everyone to stay vigilant while investing in the crypto market. Like and retweet to spread the word!

@Swaprum he deceived us all, we fulfilled all the conditions, but they threw us .. do not believe this is ophirists

A week ago I reported a bug, which they never paid for, it was obvious from afar that it was a trap. the truth is that they made a well-organized trap

I know from the start Swaprum was a scam project just after visiting their token page on @CoinMarketCap since it clearly had a warning sign of a rugged token. Ironically I joined their group to get free ARB but after I posted about their token they kicked me out lol.

Backlash Against CertiK Auditor

There was considerable backlash against CertiK for approving the team's smart contract[84].

Wtf @CertiK ? Did they bought the audit?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Audit Security Score Updated

The security score of the Swaprum project on CertiK was updated to "Exit Scam" status[75].

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. SlowMist Hacked - SlowMist Zone (May 19, 2023)
  2. @hackenclub Twitter (May 19, 2023)
  3. @hackenclub Twitter (May 19, 2023)
  4. Arbitrum Transaction Hash (Txhash) Details | Arbiscan (May 19, 2023)
  5. @Sebasti04989541 Twitter (May 19, 2023)
  6. @cryptoemprende_ Twitter (May 19, 2023)
  7. @Lucas75831804 Twitter (May 19, 2023)
  8. @AnciliaInc Twitter (May 19, 2023)
  9. @Jessiedegens Twitter (May 19, 2023)
  10. @MetaSleuth Twitter (May 19, 2023)
  11. @Damicale_s Twitter (May 19, 2023)
  12. @MartiniGuyYT Twitter (May 19, 2023)
  13. @PeckShieldAlert Twitter (May 19, 2023)
  14. @Damicale_s Twitter (May 19, 2023)
  15. @DeDotFiSecurity Twitter (May 19, 2023)
  16. @TheBlock__ Twitter (May 19, 2023)
  17. @Musiclo62847240 Twitter (May 19, 2023)
  18. @saito_pickNEWS Twitter (May 19, 2023)
  19. @jinyachao1999 Twitter (May 19, 2023)
  20. @taka__crypto Twitter (May 19, 2023)
  21. @huntershannoHS Twitter (May 19, 2023)
  22. @moff_coin Twitter (May 19, 2023)
  23. @WhaleCoinTalk Twitter (May 19, 2023)
  24. @waleedmahmoud99 Twitter (May 19, 2023)
  25. @Marcin_K88 Twitter (May 19, 2023)
  26. @MTomczak_org Twitter (May 19, 2023)
  27. @rnsahin Twitter (May 19, 2023)
  28. @CyversAlerts Twitter (May 19, 2023)
  29. @CryptoSavingExp Twitter (May 19, 2023)
  30. @cryptokere Twitter (May 19, 2023)
  31. @Damicale_s Twitter (May 19, 2023)
  32. @vadymnikolskyi1 Twitter (May 19, 2023)
  33. @mueb2eth Twitter (May 19, 2023)
  34. @Crypto_Potato Twitter (May 19, 2023)
  35. @esatoshiclub Twitter (May 19, 2023)
  36. @AlabasiMamoun Twitter (May 19, 2023)
  37. @Brahmi1973 Twitter (May 19, 2023)
  38. @MNAThu0105 Twitter (May 19, 2023)
  39. @numencyber Twitter (May 19, 2023)
  40. @_Koinbul_ Twitter (May 19, 2023)
  41. @0xEpica Twitter (May 19, 2023)
  42. @Lun68251148 Twitter (May 19, 2023)
  43. @BecauseBitcoin Twitter (May 19, 2023)
  44. @djkhileshraj Twitter (May 19, 2023)
  45. @CyversAlerts Twitter (May 19, 2023)
  46. @YunasMF Twitter (May 19, 2023)
  47. @Perseus_Crypto_ Twitter (May 19, 2023)
  48. @CryptaiaTech Twitter (May 19, 2023)
  49. @BecauseBitcoin Twitter (May 19, 2023)
  50. @NewsGagarin Twitter (May 19, 2023)
  51. 51.0 51.1 MajedMaddev - "Swaprum, a decentralized exchange on the Ethereum Layer 2 network Arbitrum, appears to have executed an "exit scam" commonly referred to as a "rug pull," absconding with an estimated $3 million in user deposits." - Twitter (May 19, 2023)
  52. 52.0 52.1 52.2 AryoBagas9 - "funny" "Error Bad request, check internet" - Twitter (May 19, 2023)
  53. 53.0 53.1 Sanjeev08818841 - "What is this" - Twitter (May 19, 2023)
  54. 54.0 54.1 blm_crypto - "$SAPR stakeしてたから1.5 $ARB /hになった" - Twitter (May 19, 2023)
  55. Parhan235 - "good project...and good investasi.....bravo @Swaprum" - Twitter (May 19, 2023)
  56. aloponaf - "@Swaprum amazing payment" - Twitter (May 19, 2023)
  57. datedata51 - "Join the best Yield #Farming pools and earn high APR" - Twitter (May 19, 2023)
  58. 58.0 58.1 58.2 AyodeleSammylee - "Telegram account is full" - Twitter (May 19, 2023)
  59. Khuongeyeless - "Why does the claim not accumulate in the balance section?" - Twitter (May 19, 2023)
  60. mohsencng - "Why hasn't the token been deposited into my wallet after a few days of requesting a withdrawal?" - Twitter (May 19, 2023)
  61. hayatkhan6931 - "I want you to help, even in withdrawing, there is a pending order." - Twitter (May 19, 2023)
  62. dariush72249709 - "Bro dont pay scam site withdrawal transaction dont work 100% scam" - Twitter (May 19, 2023)
  63. web3_watchdog - "PeckShieldAlert: #PeckShieldAler #rugpull @Swaprum on #Arbitrum rugged ~$3M, $SAPR has dropped -100%" - Twitter (May 19, 2023)
  64. pSquare_Daily - "Swaprum (Arbitrum DEX) Pulls Exit Scam, Team Disappears With $3 Million, Twitter Account Deleted" - Twitter (May 19, 2023)
  65. 65.0 65.1 la_marziaa - "swaprum finance deactivate their twitter account?" - Twitter (May 19, 2023)
  66. ChainAegis - "According to the security monitoring of @ChainAegis, an analysis platform on the SharkTeam, Rug Pull occurred in the Arbitrum ecological Swaprum project" - Twitter (May 19, 2023)
  67. Blin Analytics - "@Swaprum was rugged on @arbitrum network. 1620 $ETH (~ $2.7M) was bridged to Ethereum network and deposited to @TornadoCash." - Twitter (May 19, 2023)
  68. 68.0 68.1 Beosin Alert - "Swaprum on Arbitrum rugged for ~$3M. The deployer of Swaprum used the add() backdoor function to steal LP tokens staked by users, then removed liquidity from the pool for profit." - Twitter (May 19, 2023)
  69. Swaprum DEX team disappears with $3 million in apparent exit scam - The Block (May 19, 2023)
  70. Token Metrics - "BREAKING: Swaprum DEX Team Absconds with $3M: Suspected Exit Scam on Arbitrum Network" - Twitter (May 19, 2023)
  71. DailyNewsWeb3 - "Decentralized Exchange Platform Loses $3 Million in Scam" - Twitter (May 19, 2023)
  72. 72.0 72.1 Wisper Crypto - "Breaking News! #Swaprum DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%" - Twitter (May 19, 2023)
  73. TheCryptopurity - "$3 million Crypto Rugpull Drains Swaprum DEX" - Twitter (May 19, 2023)
  74. $3 million Crypto Rugpull Drains Swaprum DEX - Crypto Purity (May 24, 2023)
  75. 75.0 75.1 Swaprum - CertiK Skynet Project Insight (May 19, 2023)
  76. Beyond_Karto - "Important Alert! Crypto traders, beware! Swaprum, an exchange on Arbitrum network, has been exposed as a decentralized scam. The team behind it has shamelessly withdrawn approximately $3 million from customer deposits" - Twitter (May 19, 2023)
  77. web3wiser - "Breaking: Swaprum #DEX On #Arbitrum Rug Pulls $3M, SAPR Token Crashes 100%" - Twitter (May 19, 2023)
  78. winnerill - "Just got rugged on Swaprum. Site and discord is still up. A lot of work for 1 million" - Twitter (May 19, 2023)
  79. Beyond_bitcoin1 - "JUST IN: Swaprum, a decentralized exchange (DEX) built on @arbitrum ruggpulls with $3 million users deposit." - Twitter (May 19, 2023)
  80. DeFiVisionary - "The #Swaprum rug pull has left investors devastated with a jaw-dropping $3 million loss in this #defi scam." - Twitter (May 19, 2023)
  81. Kirill186186 - "@Swaprum he deceived us all, we fulfilled all the conditions, but they threw us .. do not believe this is ophirists" - Twitter (May 19, 2023)
  82. Rotciv - "A week ago I reported a bug, which they never paid for, it was obvious from afar that it was a trap. the truth is that they made a well-organized trap" - Twitter (May 25, 2023)
  83. Rean Schwarzer - "I know from the start Swaprum was a scam project just after visiting their token page on @CoinMarketCap since it clearly had a warning sign of a rugged token. Ironically I joined their group to get free ARB but after I posted about their token they kicked me out lol." - Twitter (May 25, 2023)
  84. JuanP_marin - "Wtf @CertiK ? Did they bought the audit?" -Twitter (May 19, 2023)