Voorsie Profile picture
Apr 12, 2022 ā€¢ 21 tweets ā€¢ 9 min read ā€¢ Read on X
How to recognize scam coins?
While there are 101 ways to rugpull and scam people, I'm going to lay out one of the most obvious ways in this thead šŸ§µ Read on :-)
Using @oklgio's brand new product #Alpha as a Service, stumbled on this new contract with a pretty big liquidity add. A good amount of liquidity -can- be an indicator of a legit project, but this is no guarantee as you will find out later in this thread.. Image
First I used a quick #honeypot check on the page to see if the coin in question is buyable and sellable, it passed the test. It would be a big red flag šŸšØ if this test failed, meaning the contract prevents selling the coin.
After I tend to open @DEXToolsApp, to quickly look if their are any trades happening. This is the page for the coin; dextools.io/app/bsc/pair-eā€¦

I spotted some pretty big buys early on, could be an indicator for a legit launch... or is it? šŸ§ Image
Clicking on the first two buyers' addresses:
bscscan.com/address/0xc73bā€¦
bscscan.com/address/0x6bc3ā€¦

I quickly noticed similarities, these were both brand new and funded from the same address, namely;
bscscan.com/address/0x5bbdā€¦
This address first received many left-over BNB's from various temporary addresses, to then send it over to brand new one's to make the fake buys.

The final transfer, is a 63 BNB transfer to fund the initial liquidity (which is 100% burned);
bscscan.com/tx/0x80c4d9690ā€¦ Image
When you follow the money, you will encounter a rinse-and-repeat method of funding, collecting dust and refunding liquidity for the next scam coin. Happening 1 or 2 times per hour. Next to CATFORCE, you will see the previous coins CAMELCOIN, UNISALE, FUTUREDAO, and so on...
Anyway, back on topic, CATFORCE receiving more buys, even some (partial) sells to show people the token is sellable and 'people' making profits.

It's easy to click on each buyers address and open it in a new tab, you would quickly spot the funding from the same account. Image
Two addresses seem to be outsiders, but luckily, they made very small buys (less than a dollar). Either they know or they only check for honeypots, but luckily this round no victims were made.
The turnaround time seems to be like ~34 minutes from token contract creation until the script sells all and drains liquidity and starts the game all over.

This scam only needs one person to #FOMO in and either the liquidity will be pulled immediately, or ...
... just before the first real buyer tries to take profit. He would then be #frontrunned by the massive sell off.

So how is the rugpull exactly performed? I'll explain!
1 million tokens were created, half was burned and the other half was used for liquidity (and also burned) like a fair launch, nothing odd about this, right?

Well, the contract is verified (other trust indicator) but shows something funny... Image
The contract is using an interface of an external (unverified) contract which is used for 'accounting'.

This is where the magic (malicious activity) is really happening. While we can't read what the contract exactly does, we can see the result! Image
The malicious 'balanceOf()' function returns an insane amount of balance for the scammer, allowing him to sell these tokens that, according to @bscscan don't even exist! This allows him to drain ALL liquidity and retrieving his #BNB and that of potential victims. Image
Besides this, the accounting contract also tampers with the 'transfer()' function by putting its own 'doTransfer()' function in between. This would never allow you to transfer coins to @PancakeSwap for making a decent sell with your tokens.
I hope this thread helps you understand at least one of the ways these scammers operate. Many green ticks are placed with this one, and still it's a scam.
āœ… Verified contract
āœ… Passes honeypot checks on various sites
āœ… Burned coins
āœ… Sufficient liquidity
āœ… Locked (burned) liquidity
āœ… Renounced ownership
āœ… Big buys
āœ… Decent volume
āœ… Some successful sells
āŒ Rugpull
As said, this one is easily recognized when you click a few of the fake buys and you will see the same source of funding for these addresses. This can be disguised as well with just a little more advanced script! Always stay alert and never ape in too big. Stay safe friends!
Oh and beware... the next scam of this scammer is SquishiVerse (SLIME)
bscscan.com/address/0xc107ā€¦

Rugging in ~32 minutes...

Tag your friends to warn them for this scamming method!
@themoontography I challenge you to recognize this scamming method and include it in @oklgio's Alpha as a Service

ā€¢ ā€¢ ā€¢

Missing some Tweet in this thread? You can try to force a refresh
怀

Keep Current with Voorsie

Voorsie Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(