Snowflake Floki Hack

TOTAL LOST $70K
Low Honeypot

Summarize with AI

Affected Chain 2021 Incident surface
Recovered - No recovery reported
All-Time Rank #1632 By amount stolen
Protocol Type Exit Scam/Honeypot Target category

Incident Overview

The Snowflake Floki smart contract contained a transfer tax component that allowed the project deployer to ramp up the transfer fee of each transaction up to 100%, netting the deployer approx. $ 70k in ill-gotten funds.

The Snowflake Floki project was practically an imitation of the meme coin Floki Inu but promised to develop a metaverse casino. The $SFF token would have played the role of the in-game currency used for bets in Poker, Blackjack and Roulette. In order to make the $SFF token tradable, the contract deployer added initial liquidity in the below transaction:

https://bscscan.com/tx/0x371a142d…02fd57

A closer look at the $SFF smart contract should have alerted investors since the transfer taxes were adjustable by the contract deployer. This empowered the contract deployer to set fees up to 100% for each transaction, sending the tokens to his address:

https://bscscan.com/address/0x78cd0ea1…b67570#code#L1092

The deployer took advantage of the changeable transfer fee set it to 95% for selling SFF token:

https://bscscan.com/tx/0xe8e6680e…f678e5

In order to squeeze as much as possible out of the project, the deployer also removed liquidity several times :

https://bscscan.com/tx/0x18168c04…f73957

https://bscscan.com/tx/0xd9018a15…1cee15

https://bscscan.com/tx/0xd3ddc09b…126e04

https://bscscan.com/tx/0x3cbb6a94…06144a

https://bscscan.com/tx/0x555b7329…46f65b

The website and social media have been taken down.

Contract Deployer Address:

https://bscscan.com/address/0x731e5bb9…fbf44c

Incident Report

Protocol / Project Snowflake Floki
Date of Incident
Attack Technique Honeypot
Classification Token
Primary Source View Post-Mortem

Protocol Information

Protocol Type Exit Scam/Honeypot
Affected Token SFF
Official Website snowflakefloki.finance/
Protocol Twitter/X @snowflakefloki
Team Anonymous
Source Code Unverified

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of honeypot and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Snowflake Floki's contract logic - root cause: token
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Honeypot audit checklist and test coverage

If you're auditing a protocol with similar architecture to Snowflake Floki, these are the critical security checks that could have prevented this incident (December 2021).

  • Verify all logic paths related to Honeypot are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Sources & References

Learn to Prevent the Next Snowflake Floki

The Snowflake Floki hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial