Swaprum Hack
Incident Overview
Swaprum, an Arbitrum-based DEX project, experienced a rugpull by the deployer. The total funds lost reached 2,915,567 $USD.
Swaprum is a decentralized exchange (DEX) on the Arbitrum network with its token $SAPR. An investigation revealed that Swaprum was subjected to a rugpull by its own deployer who had privileged access to LPs in multiple pools and $SAPR token minting.
The exitscam consisted of two main parts:
1) Liquidity removals on various pools such as USDT/WETH ($241k), USDT/USDC ($280k), ARB/WETH ($280k), ARB/USDC($126K), WOM/USDT($49K) and etc.
2) Liquidity removal related to $SAPR token where initially 800k $SAPR were minted directly into scammer's wallet address followed by direct liquidity draining from SAPR/WETH pool for another 500K $SAPR tokens plus ~$94K USD worth of WETH.
Later the attacker deployed a malicious upgrade for the SAPR Controller Proxy contract which allowed to create additional 200M new $SAPR tokens out of thin air via two separate transactions.
Finally, all available liquidity in Swaprum's SAPR/WETH pool was drained using newly created tokens leaving it empty.
The total funds lost reached 2,915,567 $USD and were transferred to another EOA address in two transactions for 1,617.7 $ETH. Consequently, all the stolen funds were transferred through TornadoCash or bridged via Celer Network and Multichain Bridge.
Scammer address:
https://arbiscan.io/address/0xf2744e1f…d96627
Funds holder address:
https://arbiscan.io/address/0xaaf8b443…ef5e1c
Liquidity removal transaction examples:
https://arbiscan.io/tx/0x0ebc5f91…f0c3be
https://arbiscan.io/tx/0xcb64a40d…747edf
https://arbiscan.io/tx/0x45b911b9…d081d0
https://arbiscan.io/tx/0x33020fdf…74796a
https://arbiscan.io/tx/0x9d66bda0…3662b1
SAPR mint transactions:
https://arbiscan.io/tx/0x972dc40a…c6f541
https://arbiscan.io/tx/0x821b2e98…60168e
SAPR liquidity drain transaction example:
https://arbiscan.io/tx/0x982cc3b2…b33502
TornadoCash transfer example:
https://arbiscan.io/tx/0x8424b157…eb4eff
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Swaprum, these are the critical security checks that could have prevented this incident (May 2023).
- Verify all logic paths related to Drained Contracts / Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Certik Report
Sources & References
- 01
-
02
Web Archive https://archive.ph/M8R0h
- 03
Learn to Prevent the Next Swaprum
The Swaprum hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.