{"id":97171,"date":"2023-05-20T02:15:33","date_gmt":"2023-05-20T02:15:33","guid":{"rendered":"https:\/\/dripp.zone\/news\/index.php\/2023\/05\/20\/3m-worth-of-customer-funds-swiped-via-alleged-swaprum-dex-rug-pull-crypto-news\/"},"modified":"2023-05-20T02:15:35","modified_gmt":"2023-05-20T02:15:35","slug":"3m-worth-of-customer-funds-swiped-via-alleged-swaprum-dex-rug-pull-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/3m-worth-of-customer-funds-swiped-via-alleged-swaprum-dex-rug-pull-crypto-news\/","title":{"rendered":"$3M worth of customer funds swiped via alleged Swaprum DEX rug pull\n &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div data-v-2f4c2c70=\"\">\n<p>Arbitrum-based decentralized exchange (DEX) Swaprum has allegedly conducted a rug-pull on its users, with $3 million worth of customer deposits being swiped from the platform.<\/p>\n<p>A <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/blockchain-security-firm-freezes-160k-stolen-in-merlin-dex-rugpull\">rug-pull or exit scam<\/a> occurs when a seemingly legitimate project ropes in a certain amount of investment or user deposits before promptly shutting everything down, pulling the capital and vanishing off into the distance \u2014 if they don&#8217;t adequately <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/kucoin-meme-coin-daily-rug-pull-confirmation\">cover their tracks<\/a>Ofcourse. <\/p>\n<p>According to a May 19 tweet from the alerts-focused account of blockchain security firm Peck Shield, the bad actors swiped 1,628 Ether (<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/ethereum-price\">eth<\/a>) \u2014 worth roughly $2.95 million at current prices \u2014 from Swaprum&#8217;s liquidity pools, bridged it to Ethereum, and then \u201claundered\u201d almost all of those funds through crypto mixer Tornado Cash. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/PeckShieldAler?src=hash&#038;ref_src=twsrc%5Etfw\">#PeckShieldAler<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/rugpull?src=hash&#038;ref_src=twsrc%5Etfw\">#rugpull<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Swaprum?ref_src=twsrc%5Etfw\">@Swaprum<\/a> on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/Arbitrum?src=hash&#038;ref_src=twsrc%5Etfw\">#arbitrum<\/a> rugged ~$3M, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24SAPR&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$SAPR<\/a> has dropped -100%. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Swaprum?ref_src=twsrc%5Etfw\">@Swaprum<\/a> already deleted its social accounts\/groups. <br \/>The scammers have bridged ~1,628 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24ETH&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$ETH<\/a> to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/Ethereum?src=hash&#038;ref_src=twsrc%5Etfw\">#Ethereum<\/a> and laundered 1,620 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24ETH&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$ETH<\/a> to Tornado Cash<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/tUNgbwGQCd\">https:\/\/t.co\/tUNgbwGQCd<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/UH8V9RyFHy\">pic.twitter.com\/UH8V9RyFHy<\/a><\/p>\n<p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1659404608685604864?ref_src=twsrc%5Etfw\">May 19, 2023<\/a><\/p><\/blockquote>\n<p>Following the incident, Swaprum&#8217;s Twitter, Telegram and Github accounts have all been deleted, however Swaprum&#8217;s website is still operational at the time of writing.<\/p>\n<figure><figcaption style=\"text-align: center;\"><em>Deletedsocials.  Source: Twitter<\/em><\/figcaption><\/figure>\n<p>Adding extra context to the incident, fellow blockchain security firm Beosin claimed that the \u201cdeployer of Swaprum used the add() backdoor function to steal LP [liquidity provider] tokens staked by users, then removed liquidity from the pool for profit.\u201d<\/p>\n<p>This was apparently made possible due to the Swaprum developer team allegedly &#8220;upgrading the normal liquidity collateral reward contract to a contract containing backdoor functions.&#8221; <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">3\/ The backdoor function add() will transfer LP tokens from the contract to the _devadd address.  By querying the _devadd address, it will return the &#8216;Swaprum:Deployer&#8217; address. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/Z1rZmFSf5R\">pic.twitter.com\/Z1rZmFSf5R<\/a><\/p>\n<p>\u2014 Beosin Alert (@BeosinAlert) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/BeosinAlert\/status\/1659482292614725635?ref_src=twsrc%5Etfw\">May 19, 2023<\/a><\/p><\/blockquote>\n<p>A keyword search for &#8220;Swaprum&#8221; on Twitter yields several tweets from people calling out. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/april-s-crypto-scams-exploits-and-hacks-lead-to-103m-lost-certik\">smart contract auditors<\/a> CertiK over the whole ordeal, as the firm had conducted an audit of the platform as recently as May 5. <\/p>\n<p><strong><em>Related: <\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/can-you-recover-stolen-bitcoin-from-crypto-scams\"><strong><em>Can you recover stolen Bitcoin from crypto scams?<\/em><\/strong><\/a><\/p>\n<p>Their complaints essentially assert that CertiK signed off on the platform by auditing the platform, with the &#8220;audited by CertiK&#8221; logo still <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/swaprum.finance\/swap#\">currently<\/a> up on the Swaprum website. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">well done <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/CertiK?ref_src=twsrc%5Etfw\">@certiK<\/a> Another rug that&#8217;s coming from your audits.<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/swaprum?src=hash&#038;ref_src=twsrc%5Etfw\">#swaprum<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Swaprum?ref_src=twsrc%5Etfw\">@Swaprum<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/certik?src=hash&#038;ref_src=twsrc%5Etfw\">#certik<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/scam?src=hash&#038;ref_src=twsrc%5Etfw\">#scam<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/rug?src=hash&#038;ref_src=twsrc%5Etfw\">#rogue<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/cPlyx3GMU6\">pic.twitter.com\/cPlyx3GMU6<\/a><\/p>\n<p>\u2014 Crypto Emprende YT (@cryptoemprende_) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/cryptoemprende_\/status\/1659228098427068417?ref_src=twsrc%5Etfw\">May 18, 2023<\/a><\/p><\/blockquote>\n<p>However, it is worth noting that as per CertiK&#8217;s disclaimers, it &#8220;conducts security assessments on the provided source code exclusively,&#8221; and cannot guarantee that its recommendations are integrated.  In the audit, CertiK flagged a &#8220;major&#8221; issue with how centralized Swaprum was. <\/p>\n<p>While it also appears that the backdoor-related upgrades to the project&#8217;s smart contracts were conducted after the audit was completed.<\/p>\n<p>As it stands, CertiK&#8217;s website has now flagged Swaprum as an &#8220;exit scam.&#8221;<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-05\/e524567d-1b65-4e35-8924-2ffbf5a9c732.png\"\/><figcaption style=\"text-align: center;\"><em>To install Swaprumaudit.  Source: CertiK<\/em><\/figcaption><\/figure>\n<p><strong><em>Magazine: <\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/3-4-billion-bitcoin-popcorn-tin-silk-road-hacker\/\"><strong><em>$3.4B of Bitcoin in a popcorn tin \u2014 The Silk Road hacker&#8217;s story<\/em><\/strong><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\"\/><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Arbitrum-based decentralized exchange (DEX) Swaprum has allegedly conducted a rug-pull on its users, with $3 million worth of customer deposits being swiped from the platform. A rug-pull or exit scam occurs when a seemingly legitimate project ropes in a certain amount of investment or user deposits before promptly shutting everything down, pulling the capital and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":97172,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[235,203,210,234,231,232,237,238,236,233],"class_list":["post-97171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-bitcoin","tag-crypto-currency","tag-elon-musk","tag-ethereum","tag-hyperledger","tag-ibm","tag-mining","tag-nodes","tag-spacex","tag-tesla"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/97171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=97171"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/97171\/revisions"}],"predecessor-version":[{"id":97173,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/97171\/revisions\/97173"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/97172"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=97171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=97171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=97171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}