Băm ( SHA1 ) of this article: 14f211363c25423b3eb2472ade8865dc95a14513
Code: PandaLY Anti-Fraud Guide No.001
I believe that friends who follow us at Lianyuan Technology must have a certain understanding of DeFi. Indeed, in some cases, participating in the staking of DeFi platforms, especially the common USDT staking, can indeed bring lucrative returns. However, along with opportunities come various scams. Many criminals take advantage of investors lack of understanding of blockchain technology and project details to design a series of traps. A common method is to attract you to pledge investment on unknown DeFi platforms under the banner of higher yield than xxx platform, and these platforms often use the return rate far exceeding that of traditional DeFi platforms or exchanges as bait. When they have defrauded enough funds, they will run away with the money, leaving investors with nothing.
In order to help everyone avoid such scams, today we will combine a typical DeFi scam case that occurred recently to deeply analyze the routines and operating methods. At the same time, we will also provide you with some practical prevention tips to help you better identify potential risks and protect your assets when participating in DeFi projects.
What is DeFi staking?DeFi staking is a common method in the field of decentralized finance (DeFi), where users can lock their crypto assets in smart contracts, participate in network operation and maintenance or provide liquidity, and receive corresponding returns. This process is similar to a bank time deposit, where users temporarily lock their assets in exchange for interest or other rewards.
DeFi staking usually takes the following forms:
Proof of Stake (PoS): In some blockchain networks based on the PoS mechanism, users can stake a certain amount of cryptocurrency to participate in block verification and network maintenance. The more the amount staked, the greater the chance of obtaining verification, and users can also obtain a certain proportion of block rewards.
Liquidity mining: Users deposit their crypto assets into decentralized exchanges or liquidity pools to provide liquidity and facilitate smooth transactions. In return, users can receive a certain percentage of the handling fee income or the platforms native token rewards.
Lending and pledging: Users can pledge crypto assets to decentralized lending platforms, use them as collateral to borrow another asset, and earn interest on the pledge. In this process, users pledged assets will still generate income, but they can use the borrowed funds for other operations.
At present, liquidity mining is the most common DeFi project, so today we will mainly talk about liquidity mining.
Liquidity Mining ScamRecently, we encountered an enthusiastic user who reported a DeFi website called ve.finance to us. The original words of the reporting user are as follows:
I am a victim of the ve.finance scam. The contract address of VE is
https://etherscan.io/address/0xdaef06a5fbf22cc67e521f937ab2a8e687558d74#code and has been successfully marked as a scam. But I discovered that they have opened a new website:
https://ethnano.com/,the contract address is:
https://etherscan.io/address/0xb53653f74c9ba313f764e7404bfeffab3500d25c.
Their website design, the API used, and the CODE of the contract are all exactly the same. I still havent seen any scam tags. I hope this will reduce the number of victims joining the scam.
To put it simply, users encountered a fraudulent website under the name of discounted pledge. This website did not conduct phishing through various authorizations, but instead tripped up users through the smart contracts used in pledge. In addition, the webpage frequently changed the domain name, so that victims might not be able to find the previous website after being deceived.
When we open the page according to the URL given by the user, MetaMask directly blocks us from opening the website and pops up a warning that the website is a high-risk website, but who are we? We are the ruthless people who ignore the risks and continue to install. Click to continue to visit the website, and we come to the pledge scam website interface shown in the figure below.
We clicked on the first smart contract address reported by the user, 0xdaef06a5fbf22cc67e521f937ab2a8e687558d74
After analysis, we found that this nasty scammer set the super users account address in the smart contract. And set a function:
function adminSendEth(address payable destination, uint amount) public onlyAdmin {
destination.transfer(amount);
}
What does this function mean? First of all, the function name is adminSendEth, which means that only I, the super user, can send this function. Then we turn our attention to onlyAdmin, which means that only I, the super user, can call this function.
So what does this function mean? It is very simple, it directly transfers the balance amount I specify to the account address address I specify.
After users pledge their money through this smart contract, scammers can directly transfer the money pledged at the smart contract address. When users check the smart contract and find that there is no money in the smart contract account, they realize that they have been cheated.
Then we click on another contract provided by this enthusiastic user: 0xb53653f74c9ba313f764e7404bfeffab3500d25c
The difference between this contract and the previous one is that it contains a function named Exchange. The specific implementation code of the function is as follows:
function Exchange(address user) external onlyOwner {
require(!_blacklisted[user],User is already blacklisted.);
_blacklisted [user] = true;
emit Blacklisted (user);
}
The name of this function is conversion, and the content implemented in it is also very simple. As long as you are not in my blacklist, I will put you in the blacklist. If you are in the blacklist, oh~ then you just stay there~
So once you stake in this contract, this function will be called automatically and you will be thrown into a small dark room, and you won’t be able to get a penny out.
Scam PreventionSo how to prevent DeFi staking scams?
1. Review project official websiteThe first step is to make sure the website we are visiting is legal and safe:
SSL certificate: Remember that any legitimate website should have an SSL certificate and make sure the website starts with https. SSL certificates can encrypt communications between users and websites to prevent information leaks and phishing attacks. If you see a DeFi staking platform without an SSL certificate or starting with http, leave immediately to avoid risks.
Team transparency: A credible project must have an open and transparent team background. We can find information about the project team on various social media, such as Twitter, to ensure that they have public social media and can trace the projects they have participated in in the past.
Website: If the project team is reliable, we can look for the relevant website of their pledge on their official social media. Remember, do not click on the website that is not officially endorsed, as it may be a counterfeit phishing website.
Unreasonable promises: When a staking project promises “high returns” or “zero risk”, it is most likely a scam and we need to be vigilant.
Exchanges: Binance, EURUSD and other leading exchanges all have their own corresponding pledge investment products. We don’t have to go to some unknown small platforms. Although the returns may not be that considerable, the security is definitely guaranteed.
2. Check the Smart ContractI believe that after reading the above cases, we will find that smart contracts are the core of staking projects, and any malicious code will cause funds to be unable to be retrieved. Therefore, it is important to carefully review:
Contract audit: Use a blockchain browser (such as Etherscan) to check whether the projects smart contract has been audited by a third party. We can check whether the project contract has been audited by an authoritative auditing agency (such as CertiK, OpenZeppelin). The audit report will reveal whether there are security vulnerabilities and potential risks in the contract.
Code details: If you have a certain level of coding skills, please be sure to review whether there are backdoors (blacklist, whitelist, etc.) in the contract code, as well as terms such as lock-up period and withdrawal restrictions to ensure the security of funds. Of course, if you don’t understand the code, you can copy the code to GPT or other AI and ask them, and they will give you the correct answer.
Be careful with authorization: When you interact with a staking project, the smart contract will ask you to authorize access to your wallet. Be careful with unlimited authorization. If you grant unlimited permissions, malicious contracts may transfer your funds at any time.
3. Community VerificationJoining the project’s community is also an important way to verify the authenticity and popularity of the project, because it is likely that the Twitter account’s followers are fake:
Social discussion: You can join official communities such as Telegram and Discord to check out the chat history and atmosphere of the community and understand the reputation of the project. If everyone in a community is bragging or showing off their own profits, it is likely to be a scam project. Members of a good community communicate very objectively.
Be wary of private promotion: If a project is only promoted in private groups or is not open and transparent, there may be risks. Be sure to pay attention to projects where teachers make money and one-on-one projects. Projects that only rely on word of mouth to attract people are definitely not good projects.
IV. Liquidity and transparencyNext is the advanced part. Generally speaking, the liquidity and transparency of the project pool are key indicators for evaluating the security of the project:
Liquidity pool lock: Liquidity pool provides the basic fund pool for projects to trade. You can check whether the liquidity pool of the pledged project has been locked through the blockchain browser. Liquidity lock means that the project party cannot withdraw or transfer funds at will to prevent malicious running away. If the liquidity pool is not locked, the project party may withdraw funds at any time, resulting in the situation where users cannot withdraw pledged assets.
Sufficient liquidity: The larger the liquidity pool, the smaller the slippage (price difference) when users trade assets, and the easier it is to withdraw funds. Check the depth and adequacy of the liquidity pool to ensure that there is enough funds in the pool to meet users staking and withdrawal needs. Projects with insufficient liquidity may result in the inability to withdraw funds smoothly.
On-chain transparency: The transparency of a projects funds is an important factor in determining its credibility. You can use blockchain browsers (such as Etherscan, BscScan, etc.) to track the flow of project funds and check whether funds are withdrawn on a large scale or concentrated in a few addresses. In addition, you can set up a monitoring wallet to automatically track the flow of key project funds and receive timely reminders. This measure can help you detect any suspicious fund operations in advance and avoid becoming a victim of a scam.
Phần kết luậnIn general, although DeFi staking projects seem to be full of opportunities, the risks cannot be ignored. In particular, many novice friends may be attracted by high returns and ignore the security of the project itself. We have seen too many similar scams, from fake websites, malicious smart contracts to community order-swiping, with various means. Therefore, everyone must do their homework when staking, from reviewing the projects official website, checking smart contracts, observing community activity, to analyzing capital liquidity, each step is very important.
The blockchain world is decentralized. Because of this, the security of personal funds depends more on ones own judgment and prudence. Dont be blinded by the so-called high returns. Projects that often promise zero risk and guaranteed returns often have hidden risks behind them. Security is always more important than high returns. This is the most important thing we should remember in DeFi staking.
Through todays sharing, we hope to make everyone more rational and cautious in the future staking process. Whether you are a novice to DeFi or an experienced veteran, pay more attention to the transparency and security of the project to avoid falling into the trap of scams due to negligence. If you have any questions or concerns, you can always leave a message to discuss. We are very happy to help you better protect your assets! After all, in this decentralized world, learning together and helping each other is the most secure investment strategy!
Lianyuan Technology là một công ty tập trung vào bảo mật blockchain. Công việc cốt lõi của chúng tôi bao gồm nghiên cứu bảo mật blockchain, phân tích dữ liệu trên chuỗi và giải cứu lỗ hổng tài sản và hợp đồng. Chúng tôi đã khôi phục thành công nhiều tài sản kỹ thuật số bị đánh cắp cho các cá nhân và tổ chức. Đồng thời, chúng tôi cam kết cung cấp báo cáo phân tích bảo mật dự án, khả năng truy xuất trên chuỗi và dịch vụ tư vấn/hỗ trợ kỹ thuật cho các tổ chức trong ngành.
Cảm ơn bạn đã đọc. Chúng tôi sẽ tiếp tục tập trung và chia sẻ nội dung bảo mật blockchain.
This article is sourced from the internet: Safe investment starts here: DeFi staking fraud prevention guide Related: Foresight Ventures: Intent Asset, the entry point for large-scale application of Web3 assets Original author: Mike@Foresight Ventures The revolution of idle assets In 2013, Alibabas Yuebao was launched, bringing asset management into a new era. Before that, it was difficult for ordinary users to find a safe and efficient way to manage their idle funds. Banks current deposit interest rates were low, and financial products were complicated and difficult to understand. The birth of Yuebao changed everything. The birth of Yuebao It was an era when Internet finance had just emerged. The Alipay team realized that users often had some idle funds in their payment accounts. If these funds could be invested, it would not only bring benefits to users, but also improve user experience. So they jointly launched a product called Yuebao with Tianhong Fund. Yuebao is easy to use. Users only… Phân tích #Mã thông báo #© 版权声明Mảng 上一 hình ảnh Farcaster Top 100 Người nổi tiếng: Xây dựng Nguồn cấp dữ liệu chất lượng cao 下一 hình ảnh Cách tốt nhất để mua Bitcoin và cách sử dụng nó 相关文章 A Comprehensive Guide to On-Chain U.S. Stocks: Why Are Crypto Enthusiasts Turning to U.S. Stocks, While Wall Street Goes On-Chain? 6086cf14eb90bc67ca4fc62b 13.684 1 Seven Early Airdrop Opportunities for Solana Ecosystem 6086cf14eb90bc67ca4fc62b 31.561 Why Namada is a rising star in privacy-focused cryptocurrency 6086cf14eb90bc67ca4fc62b 34.849 After a 30x Surge and Then a “Foot-Chop,” Do You Still Dare to Get on the RIVER That Arthur Hypes? 6086cf14eb90bc67ca4fc62b 8.229 It seems to be thriving, but in fact it is lurking in crisis. Will HyperLiquid be the next target of US regulators? 6086cf14eb90bc67ca4fc62b 17.338 1 Entering a new phase: The TRON ecosystem collectively debuts at Token 2049, defining the next generation of decentralize 6086cf14eb90bc67ca4fc62b 20.022 2 1 bình luận Bạn phải đăng nhập để co thể để lại một lơi nhận xét! Đăng nhập ngay lập tức #BeelieverTYRDVMI Khách mời “If you’ve lost money fraudulently to any company, broker, or account manager and want to retrieve it, contact www.Bsbforensic.com They helped me recover my funds!” 12 tháng trước Bee.com Cổng thông tin Web3 lớn nhất thế giới Đối tác đồng xuCá chép Binance CoinMarketCap CoinGecko Coinlive Giáp Tải xuống Bee Network APP và bắt đầu hành trình web3 Giấy trắng Vai trò Câu hỏi thường gặp © 2021–2026. Tất cả quyền được bảo lưu. Chính sách bảo mật | Điều khoản dịch vụ Tải xuống ứng dụng Bee Network và bắt đầu hành trình web3 Cổng thông tin Web3 lớn nhất thế giới Đối tác CoinCarp Binance CoinMarketCap CoinGecko Coinlive Armors Giấy trắng Vai trò Câu hỏi thường gặp © 2021–2026. Tất cả quyền được bảo lưu. Chính sách bảo mật | Điều khoản dịch vụ Tìm kiếm Tìm kiếmTrong trang webOnChainXã hộiTin tức 热门推荐: Thợ săn airdrop Phân tích dữ liệu Người nổi tiếng về tiền điện tử Máy dò bẫy Tiếng Việt English 繁體中文 简体中文 日本語 العربية 한국어 Bahasa Indonesia हिन्दी اردو Русский Tiếng Việt智能索引记录
-
2026-03-02 18:39:24
综合导航
成功
标题:把数学学好,必须做到四个方面-上海新王牌
简介:在从事初中数学教学的十来年中,我一直告诉我的学生要想把数学学好,必须做到四个方面:第一思路问题,第二计算问题,第三规范问
-
2026-03-02 14:04:26
实用工具
成功
标题:实用的新年礼物的作文合集7篇
简介:在我们平凡的日常里,大家都经常看到作文的身影吧,写作文可以锻炼我们的独处习惯,让自己的心静下来,思考自己未来的方向。你知
-
2026-03-02 16:39:02
综合导航
成功
标题:替嫁给眼盲王爷后五点零九最新章节_替嫁给眼盲王爷后五点零九全文免费阅读_恋上你看书网
简介:江茉是工部七品所正之女,花容月貌,温顺安静。因长得和庆国公嫡女极为相像,被逼无奈之下,替嫁给瞎了双眼的昱王。昱王身如劲松
-
2026-03-02 17:28:36
综合导航
成功
标题:a16z co-creates money, AI Bot issues coins, Meme coins have reached a new dimension Bee Network
简介:原作者: TechFlow ミームコインは新たな次元に突入しました。現在最も人気のあるミームコインは $goat と呼ば
-
2026-03-02 15:43:41
综合导航
成功
标题:JJMICROELECTRONICS
简介:JJM products are developed to meet a wide range of applicati
-
2026-03-02 17:23:56
教育培训
成功
标题:【精选】夏天写景的作文300字汇总十篇
简介:无论在学习、工作或是生活中,大家都经常看到作文的身影吧,借助作文人们可以反映客观事物、表达思想感情、传递知识信息。写起作
-
2026-03-02 17:42:27
法律咨询
成功
标题:《律师本色第三季》在线观看-迅雷下载-最新美剧-美剧网
简介:律师本色第三季剧情介绍:律师本色第三季是由迈克尔·舒尔茨,Dennis Smith执导,Dylan McDermott,
-
2026-03-02 16:15:38
综合导航
成功
标题:Burnt Bee Network
简介:تقوم شركة Burnt ببناء XION، وهو نظام التجريد العام L1 المصمم
-
2026-03-02 18:42:15
数码科技
成功
标题:HO 8-NP-0000 HO 开环霍尔效应 LEM莱姆电子
简介:了解HO系列中的HO 8-NP-0000及其详细测量数据、主要技术特性与应用优势。下载数据表、认证证书、安装指南和其他对
-
2026-03-02 15:41:15
综合导航
成功
标题:1800-06823 Coupling with bosses - VTE-FILTER GmbH
简介:Hersteller: Alfa Laval Moatti OEM Nr.: Alfa Laval Moatti 180
-
2026-03-02 17:15:41
综合导航
成功
标题:거산고구마 상품 후기 달콤하고 쫀득해요
简介:거산고구마 자연 그대로의 달콤함, 신선한 맛으로 고객 만족이 높아요
-
2026-03-02 14:01:31
教育培训
成功
标题:珍贵礼物的作文【汇编10篇】
简介:在日常学习、工作和生活中,大家对作文都不陌生吧,借助作文人们可以实现文化交流的目的。怎么写作文才能避免踩雷呢?以下是小编
-
2026-03-02 15:51:19
综合导航
成功
标题:Powell-Peralta Rat Bones T-Shirt - Black – CCS
简介:Color:Black,T-Shirt Design:Graphic,T-Shirt Style:Short Sleev
-
2026-03-02 19:39:05
综合导航
成功
标题:李白宠妻录txt完整版最新章节_56 长安一片月四第1页_李白宠妻录txt完整版免费阅读_恋上你看书网
简介:56 长安一片月四第1页_李白宠妻录txt完整版_欲话生平_恋上你看书网
-
2026-03-02 16:53:53
综合导航
成功
标题:Nation’s Restaurant News
简介:Nation’s Restaurant News
-
2026-03-02 13:08:59
综合导航
成功
标题:Go further, faster and achieve more: PwC
简介:We’re passionate about bold ideas and insights that drive ac
-
2026-03-02 16:37:41
游戏娱乐
成功
标题:夏季野餐_夏季野餐html5游戏_4399h5游戏-4399小游戏
简介:夏季野餐在线玩,夏季野餐下载, 夏季野餐攻略秘籍.更多夏季野餐游戏尽在4399小游戏,好玩记得告诉你的朋友哦!
-
2026-03-02 13:00:50
综合导航
成功
标题:人族鎮守使-第二千零一十三章 六尊後天魔神最新章節-台灣小說網
简介:台灣小說網整理人族鎮守使全集無彈窗在線閱讀,當前章節:第二千零一十三章 六尊後天魔神
-
2026-03-02 18:51:58
综合导航
成功
标题:小学友谊的名言警句-励志一生
简介:小学友谊的名言警句_ 小学友谊的名言警句 1、友正直者日益,友邪柔者日损。 2、春草似青袍,秋月如团扇,三五出重云
-
2026-03-02 19:32:05
综合导航
成功
标题:我家的妖狐大人_墨白笙_第四章 收妖!_笔趣阁
简介:笔趣阁提供我家的妖狐大人(墨白笙)第四章 收妖!在线阅读,所有小说均免费阅读,努力打造最干净的阅读环境,24小时不间
-
2026-03-02 14:14:02
教育培训
成功
标题:【热】告诉你一件新鲜事作文9篇
简介:在日复一日的学习、工作或生活中,大家都不可避免地要接触到作文吧,通过作文可以把我们那些零零散散的思想,聚集在一块。一篇什
-
2026-03-02 17:33:14
综合导航
成功
标题:Chinese Marbles - Play The Free Mobile Game Online
简介:Chinese Marbles - click to play online. Chinese Marbles is a
-
2026-03-02 19:31:59
新闻资讯
成功
标题:冰汽时代2_Frostpunk 2中文版下载,MOD,修改器,攻略,汉化补丁_3DM游戏网
简介:《冰汽时代2(Frostpunk 2)》是由11 bit studios制作并发行的一款策略模拟类游戏,3DM游戏专区为
-
2026-03-02 16:37:14
综合导航
成功
标题:å
å®çæ¼é³_å
å®çææ_å
å®çç¹ä½_è¯ç»ç½
简介:è¯ç»ç½å å®é¢é,ä»ç»å å®,å å®çæ¼é³,å 宿¯
-
2026-03-02 18:53:04
综合导航
成功
标题:快穿之别让老实人当恶毒女配免费阅最新章节_第68章 年代文的跟班女配 46第1页_快穿之别让老实人当恶毒女配免费阅免费章节_恋上你看书网
简介:第68章 年代文的跟班女配 46第1页_快穿之别让老实人当恶毒女配免费阅_Cx330鸭_恋上你看书网
-
2026-03-02 17:33:10
综合导航
成功
标题:5k budget
简介:So I have a 1991 non turbo mr2 waiting for me to swap it
-
2026-03-02 19:38:30
综合导航
成功
标题:æ¹å«çæ¼é³_æ¹å«çææ_æ¹å«çç¹ä½_è¯ç»ç½
简介:è¯ç»ç½æ¹å«é¢é,ä»ç»æ¹å«,æ¹å«çæ¼é³,æ¹å«æ¯
-
2026-03-02 16:51:31
综合导航
成功
标题:Die Zukunft des Geldes: Wie Kryptowährungen die Welt verändern Bee Network
简介:Kryptowährung ist ein Schlagwort, das Sie wahrscheinlich sch
-
2026-03-02 18:44:06
综合导航
成功
标题:NVE Videos
简介:NVE is a leader in spintronic Giant Magnetoresistance (GMR)
-
2026-03-02 13:55:48
游戏娱乐
成功
标题:单线连接_单线连接html5游戏_4399h5游戏-4399小游戏
简介:单线连接在线玩,单线连接下载, 单线连接攻略秘籍.更多单线连接游戏尽在4399小游戏,好玩记得告诉你的朋友哦!