{"id":43151,"date":"2021-05-25T16:21:56","date_gmt":"2021-05-25T13:21:56","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=43151"},"modified":"2025-08-31T02:23:14","modified_gmt":"2025-08-30T23:23:14","slug":"analysts-warn-of-safemoon-defi-bugs-enabling-20m-asset-drain","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/analysts-warn-of-safemoon-defi-bugs-enabling-20m-asset-drain\/","title":{"rendered":"Analysts warn of SafeMoon DeFi bugs enabling $20m asset drain"},"content":{"rendered":"<p>HashEx researchers, during a security audit, <a href=\"https:\/\/medium.com\/hashex-blog\/3-billion-backdoor-safemoon-security-analysis-5b74476698de\" target=\"_blank\" rel=\"noreferrer noopener\">\u0432\u044b\u044f\u0432\u0438\u043b\u0438<\/a> 12 vulnerabilities in the SafeMoon DeFi project&#8217;s smart contracts. The bugs detected could allow assets worth $20 million to be withdrawn and block transactions, analysts noted.<\/p>\n<p>SafeMoon runs on Binance Smart Chain. For every transfer, the project charges a 10% fee, half of which is then distributed among token holders. One of SafeMoon&#8217;s main ideas is to incentivise users to hold the asset and dampen its volatility.<\/p>\n<p>The project plans to issue a quadrillion tokens. Currently, according to <a href=\"https:\/\/www.coingecko.com\/en\/coins\/safemoon\" target=\"_blank\" rel=\"noreferrer noopener\">CoinGecko<\/a>, more than 583 trillion coins are in circulation. Since SafeMoon&#8217;s launch in March, its market capitalisation has surpassed $2 billion, and the number of investors has reached 2 million.<\/p>\n<p>HashEx warned of potential risks for investors. Among the bugs identified by the researchers, two are critical and three pose a high risk.<\/p>\n<p>According to the analysts, the SafeMoon smart contract is controlled by an external address whose balance stores liquidity pool tokens worth $20 million.<\/p>\n<p>Earlier, Certik specialists spoke about this. In their audit, the experts identified 13 distinct bugs, but there was no discussion of critical vulnerabilities at the time. SafeMoon has not fixed any of the discovered bugs.<\/p>\n<p>If the smart contract owner&#8217;s address is compromised, there is at any moment a risk of the so-called rug pull, HashEx researchers say. The term denotes the practice of inflating the value of a token in the liquidity pool with a subsequent sharp withdrawal of funds. Subsequently, other pool participants are left with devalued assets.<\/p>\n<p>SafeMoon said they are aware of the problem, but the team has &#8216;internal rules and procedures governing the contract&#8217;s operation to mitigate risks&#8217;.<\/p>\n<p>HashEx also found that some of the vulnerabilities could leave certain users without rewards or distribute them to a specific wallet.<\/p>\n<p>HashEx specialists note that attackers could exploit several bugs at once, creating a &#8216;chain perfectly suited for an attack&#8217;.<\/p>\n<p>In SafeMoon&#8217;s response to the HashEx audit, the project said that solving many of the identified problems would require a hard fork.<\/p>\n<p>Beyond the vulnerabilities, some users have other questions about the project. For example, it is often <a href=\"https:\/\/www.reddit.com\/r\/CryptoCurrency\/comments\/mx538h\/the_truth_about_safemoon_the_modern_day_crypto\/\" target=\"_blank\" rel=\"noreferrer noopener\">accused of running a Ponzi scheme<\/a>.<\/p>\n<p>Barstool Sports founder Dave Portnoy, who invested in SafeMoon, said that &#8216;this could be a Ponzi scheme.&#8217; He also stressed that &#8216;nobody has any idea how this works&#8217;.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">My shitcoin announcement. Invest at your own risk. I have no idea how this works <a href=\"https:\/\/t.co\/G1iW8iZTWG\">pic.twitter.com\/G1iW8iZTWG<\/a><\/p>\n<p>\u2014 Dave Portnoy (@stoolpresidente) <a href=\"https:\/\/twitter.com\/stoolpresidente\/status\/1394379356487757834?ref_src=twsrc%5Etfw\">May 17, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Popular cryptocurrency blogger Lark Davis compared SafeMoon to the controversial Bitconnect project.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Bitconnect was for a brief moment a top 10 <a href=\"https:\/\/twitter.com\/hashtag\/crypto?src=hash&#038;ref_src=twsrc%5Etfw\">#crypto<\/a>, the people making money did not want to accept it was a ponzi, they made every excuse to justify it, and attacked anyone who stated the obvious. <\/p>\n<p>Then it rug pulled and everyone lost big time. <a href=\"https:\/\/twitter.com\/hashtag\/safemoon?src=hash&#038;ref_src=twsrc%5Etfw\">#safemoon<\/a> is no different.<\/p>\n<p>\u2014 Lark Davis (@TheCryptoLark) <a href=\"https:\/\/twitter.com\/TheCryptoLark\/status\/1384664238371704832?ref_src=twsrc%5Etfw\">April 21, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00ab\u0422\u043e, \u0447\u0442\u043e \u0432\u044b \u0437\u0430\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u0442\u0435 \u0434\u0435\u043d\u044c\u0433\u0438 \u043d\u0430 [\u0441\u0445\u0435\u043c\u0435] \u041f\u043e\u043d\u0446\u0438, \u043d\u0435 \u043c\u0435\u043d\u044f\u0435\u0442 \u0442\u043e\u0433\u043e \u0444\u0430\u043a\u0442\u0430, \u0447\u0442\u043e \u044d\u0442\u043e \u041f\u043e\u043d\u0446\u0438\u00bb, \u2014 <a href=\"https:\/\/twitter.com\/TheCryptoLark\/status\/1384664527229231107\" target=\"_blank\" rel=\"noreferrer noopener\">\u043d\u0430\u043f\u0438\u0441\u0430\u043b<\/a> \u043e\u043d.<\/p>\n<\/blockquote>\n<p>Despite the criticism, SafeMoon&#8217;s developers plan to develop the project further. According to the roadmap for the year, the company intends to release a SafeMoon app and wallet, launch its own exchange, expand the team, and open offices in the United Kingdom or Ireland.<\/p>\n<p>Security is of paramount importance for DeFi projects, which are often targeted by hacks.<\/p>\n<p>As reported in May, DeFi protocols <a href=\"https:\/\/forklog.com\/en\/news\/hacker-drains-30-million-in-spartan-protocol-tokens-from-defi-protocol\">Spartan<\/a>, Rari Capital, <a href=\"https:\/\/forklog.com\/en\/news\/defi-protocol-xtoken-loses-25-million-in-hack\">xToken<\/a>, <a href=\"https:\/\/forklog.com\/en\/news\/defi-protocol-bearn-fi-loses-11-million-in-a-hack\">bEarn Fi<\/a> and <a href=\"https:\/\/forklog.com\/en\/news\/hacker-crashes-pancakebunny-token-price\">PancakeBunny<\/a> were affected by attacks.<\/p>\n<p>Read ForkLog&#8217;s bitcoin-news in our Telegram \u2014 cryptocurrency news, prices and analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>HashEx researchers, during the audit, identified 12 vulnerabilities in the SafeMoon DeFi project&#8217;s smart contracts. The detected bugs could allow assets worth $20 million to be withdrawn and block transactions, analysts noted.<\/p>\n","protected":false},"author":1,"featured_media":43152,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[967,1301,1093],"class_list":["post-43151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-audit","tag-blockchain-vulnerabilities","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"48","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/43151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=43151"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/43151\/revisions"}],"predecessor-version":[{"id":43153,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/43151\/revisions\/43153"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/43152"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=43151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=43151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=43151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}