Snowflake Floki Honeypot Scam

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search

Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Snowflake Floki Homepage

Snowflake Floki claimed to be launching a new metaverse casino, and investors flocked in to participate. In reality, the house always wins. Token purchasers were unable to sell due to deliberate limitations in the smart contract. Only the smart contract owner could sell. Significant funds were spent on the tokens, and lost as the contract owners sold into the liquidity. It does not seem like any funds were recovered.

This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9][10][11][12]

About Snowflake Floki

[13][14]

"SnowFlakeFloki is the Iced Out Metaverse Casino on the Binance Smart Chain. The token is making you a shareholder in the biggest Metaverse Casino where you are profiting from all gambling that is done around the clock. SnowFlakeFloki is a token used for in-game bets and plays such as slot machines, Poker, Blackjack, Roulette and more."

"SnowFlakeFloki is the Iced Out Metaverse Casino on the Binance Smart Chain. The token is making you a shareholder in the biggest Metaverse Casino where you are profiting from all gambling that is done around the clock. SnowFlakeFloki is a token used for in-game bets and plays such as slot machines, Poker, Blackjack, Roulette and more. As a token holder you are receiving more tokens on every transaction made simply by holding the token. Gambling and Lottery are the world biggest and most profitable industries which allow you to make a lot of money. Either by playing yourself or by passively earning from other people playing. The Crypto Casino Industry is known to be highly unfair towards players, with the odds heavily stacked agains them. It is very frustrating to always loose in a Casino. Greedy Casino Dealers who take adavantge of players is unfair and depressing. SnowFlakeFloki can afford to have a high winning odds algorithm based on fair gameplays with winnings and profits. As the user base grows and more players join the casino, they have to buy SnowFlakeFloki tokens which increases the demand which results in a massive increase in the token price."

"This Monday 5pm UTC 27th December on Pancakeswap V2 there will be the launch of the $SFF token. You have the chance to be one of the first buyers. (Imagine you would have been one of the first investors in Shiba Inu) You have to set up your MetaMask or Trustwallet with BNB on the Binance Smart Chain and connect it with Pancakeswap. Please follow this videos for instruction: (Depending on the wallet you prefer)."


The launch of Snowflake Floki was announced in the morning of December 27th[7].

WE ARE LIVE

Contract Address: 0x78cd0ea1108a146dc493b086170e2d9771b67570

You can copy and paste the contract address on Pancakeswap and swap BNB for SFF (SnowFlake Floki) Pancakeswap : https://exchange.pancakeswap.finance/#/swap?inputCurrency=0xB8c77482e45F1F44dE1745F52C74426C631bDD52&outputCurrency=0x78cd0ea1108a146dc493b086170e2d9771b67570

Turn the slippage to 11-12%

The Reality

"A honeypot is a spoof that traps users into buying tokens while disabling the ability to sell them. The buyer’s funds are stuck in the contract because all withdrawals are disconnected. Usually, scammers blacklist all wallets other than their own."

"Many unscrupulous people also try to take advantage of legitimate coin memes such as Floki Inu and Shiba Inu."


Snowflake Floki, a cryptocurrency presented as an imitation of the popular Floki Inu meme coin, has been exposed as a honeypot scam. Honeypot scams involve enticing users to purchase tokens while preventing them from selling those tokens. This is achieved by locking users' funds into the contract and disconnecting all withdrawal capabilities, essentially trapping their money. These scams often blacklist all wallets except the one of the scammer[15].

This type of scam is not new and has been a concern within the Ethereum community for some time. However, due to the lower issuance costs on the Binance Smart Chain (BSC), such scams have become increasingly common on this blockchain platform[15].

Snowflake Floki was launched on PancakeSwap, a decentralized exchange on the Binance Smart Chain. Users quickly identified red flags indicating its fraudulent nature. There are now methods, such as honeypot detectors, to identify these scams by simulating transactions to determine whether a cryptocurrency project is legitimate or a scam[15].

In the past, token projects inspired by mainstream media trends, like the Squid Game-themed token, have attracted attention by showing rapid price increases. However, these tokens often include mechanisms that prevent users from selling them, leading to significant financial losses for buyers. Unscrupulous actors are also exploiting the popularity of legitimate meme coins like Floki Inu and Shiba Inu for fraudulent purposes[15].

What Happened

Snowflake Floki launched a smart contract which would allow users to buy the token but not allow any sales from users. Many users bought the token and were unable to sell it.

Key Event Timeline - Snowflake Floki Honeypot Scam
Date Event Description
December 27th, 2021 10:38:00 AM MST Snowflake Floki Announcement The Snowflake Floki smart contract is announced in a tweet, and it appears that many users start to buy the token immediately[7][16].
December 27th, 2021 7:54:00 PM MST PeckShield Warning On Twitter PeckShield shares a warning on Twitter to notify that "[s]ell is diabled" and advising users to "[s]tay [away] from it!"[17].
December 28th, 2021 7:43:44 AM MST PortalCripto Article PortalCripto reports that Snowflake Floki has been exposed as a honeypot scam[15]. This type of scam is not new and has been a concern within the Ethereum community for some time. There are now methods, such as honeypot detectors, to identify these scams by simulating transactions to determine whether a cryptocurrency project is legitimate or a scam. Unscrupulous actors have been exploiting the popularity of legitimate meme coins like Floki Inu and Shiba Inu for fraudulent purposes.

Technical Details

Contract Address: 0x78cd0ea1108a146dc493b086170e2d9771b67570[7]

Total Amount Lost

The total amount lost is unknown.

Immediate Reactions

Users Purchasing Snowflake Floki

Users Warning About Issues

Warning From PeckShield

PeckShield shares a warning on Twitter to notify that "[s]ell is diabled" and advising users to "[s]tay [away] from it!"[17].

#SCAM PeckShield has detected that @snowflakefloki is a #honeypot! Sell is disabled. People are constantly being trapped into buying. Stay *AWAY* from it!


"On Monday, Snowflake Floki debuted on PancakeSwap, a decentralized platform powered by the Binance Smart Chain, with some fans recognizing the red flag right away."

"In another development, Snowflake Floki, a parody of the Floki Inu Coin Meme, was released by blockchain security firm PeckShield. [Snowflake Floki] is a honeypot scam. It starts users buying tokens while deactivating the ability to sell them. The buyer’s money gets stuck in the contract because all withdrawals are segregated, usually because scammers blacklist all other wallets except their own."

Ultimate Outcome

"This type of scam is not new. Ethereum users have been dealing with honeypots for years. Since Binance Smart Chain is a much cheaper token issuing platform, such scams are commonplace in the smart contract chain."

"Now there is an easy way to spot honeypot, if not an easy way. A honeypot detector simulates a buy and sell transaction to determine if a project is a scam."

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

Ongoing Developments

TBD

Individual Prevention Policies

Individuals need to exercise caution with the smart contracts they choose to interact with. While it is possible to detect honeypot smart contracts easily, there are other threats which can only be uncovered through a third party security audit.

Avoid the use of smart contracts unless necessary. Minimize the level of exposure by removing or withdrawing assets whenever possible. Aim to choose smart contracts which have obtained third party security audits, preferably having been audited by at least three separate reputable firms. Pay attention to the audit reports, which smart contracts are covered, and whether the smart contract has been upgraded or modified since the report. Ensure that any administrative functions with the ability to remove funds from the smart contract are under the authority of a multi-signature wallet which is controlled by at least three separate and reputable entities.

Store the majority of funds offline. By offline, it means that the private key and/or seed phrase is exclusively held by you and not connected to any networked device. Examples of offline storage include paper wallets (seed phrase or key written down and deleted from all electronic media), hardware wallets, steel wallet devices, etc...

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Wallets and exchanges can help educate users on the risks of interacting with unaudited smart contracts, and provide easier ways to detect common scams or untrusted projects. An industry insurance fund can assist users who are affected by honey pot smart contracts.

Never take for granted the limited knowledge of users of your service and their tendency to skip past provided information. It is recommended to design a simple tutorial and quiz for new users which explains the basics of seed phrases, strong password generation, secure two-factor authentication, common fraud schemes, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space. This tutorial and quiz should ensure their understanding and be a standard part of the sign-up or download process which is difficult or impossible to skip.

Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

Regulators can help educate their citizens on the risks of interacting with unaudited smart contracts. They can also ensure that all smart contracts registered officially obtain a smart contract audit. An industry insurance fund can assist users who are affected by honey pot smart contracts.

Create a standard tutorial and quiz for all new cryptocurrency participants, which is required to be completed once per participant. This tutorial and quiz should cover the basics of proper seed phrase protection, strong password generation, secure two-factor authentication, common fraud schemes, how to detect and guard against phishing attacks, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space.

All platforms should undergo published security and risk assessments by independent third parties. Two assessments are required at founding or major upgrade, one after 3 months, and one every 6 months thereafter. The third parties must not repeat within the past 14 months. A risk assessment needs to include what assets back customer deposits and the risk of default from any third parties being lent to. The security assessment must include ensuring a proper multi-signature wallet, and that all signatories are properly trained. Assessments must be performed on social media, databases, and DNS security.

Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. Almost 400 ETH holders defrauded by counterfeit MetaMask tokens - CoinCu News (Feb 16, 2022)
  2. SnowFlake Floki – SnowFlakeFloki the Iced Out Metaverse Casino (Feb 20, 2022)
  3. https://poocoin.app/tokens/0x78cd0ea1108a146dc493b086170e2d9771b67570 (Feb 21, 2022)
  4. https://bscscan.com/token/0x7a286B3f582897Eb36F13990F01b65F2C4567bC5#balances (Feb 21, 2022)
  5. https://bscscan.com/address/0x78cd0ea1108a146dc493b086170e2d9771b67570#code (Feb 21, 2022)
  6. $SFF - Snowflake Floki Price, Charts, All-Time High, Volume & Markets - In USD, EUR, CNY etc. | Nomics (Feb 21, 2022)
  7. 7.0 7.1 7.2 7.3 Snowflake Floki - "WE ARE LIVE You can copy and paste the contract address on Pancakeswap and swap BNB for SFF (SnowFlake Floki)" - Twitter Archive December 27th, 2021 10:43:35 AM MST (Feb 21, 2022)
  8. Floki Inu Knock-Off Ends Up Being Honeypot Scam (Feb 21, 2022)
  9. Snowflake Floki Ends Up Being A Honeypot Scam (Feb 21, 2022)
  10. Honeypot Detector for BSC (Feb 21, 2022)
  11. Snowflake Floki SCAM | Video deleted by Youtubers Open4Profit & Pushpendra Singh - YouTube (Feb 21, 2022)
  12. Snowflake Floki, a knock-off of the Floki Inu meme coin, is a honeypot scam - AZCoin News (Feb 21, 2022)
  13. Snowflake Floki Whitepaper Archive December 27th, 2021 4:00:06 PM MST (Feb 21, 2022)
  14. Snowflake Floki (SFF) Price, Chart, Value & Market Cap | CoinCodex (Feb 21, 2022)
  15. 15.0 15.1 15.2 15.3 15.4 Snowflake Floki turns out to be a Honeypot scam - PortalCrypto (Feb 21, 2022)
  16. Nazmul Hussain Barbhuiya "drar admin finally i am buy 0.5 BNB SFF token & hold 100X" - Twitter (Aug 31, 2023)
  17. 17.0 17.1 PeckShieldAlert - "#SCAM PeckShield has detected that @snowflakefloki is a #honeypot! Sell is disabled. People are constantly being trapped into buying. Stay *AWAY* from it!" - Twitter (Feb 21, 2022)