BTC $86,813.24 +3.51%
ETH $2,760.68 +2.25%
BNB $782.32 +1.60%
XRP $1.54 +3.15%
SOL $122.83 +4.30%
TRX $0.3347 +0.56%
DOGE $0.0971 +2.79%
ADA $0.2565 +3.80%
BCH $316.51 +2.69%
LINK $14.40 +0.28%
HYPE $91.02 +2.18%
AAVE $183.20 +11.35%
SUI $1.20 +4.18%
XLM $0.2249 +1.97%
ZEC $1,391.46 -0.33%
AAPL $331.74 +0.08%
AMZN $252.06 +1.15%
GOOGL $343.68 -0.20%
MSFT $516.38 -0.42%
META $730.21 +0.18%
NVDA $237.36 +2.41%
TSLA $368.93 +3.27%
SNDK $1,745.30 -0.03%
INTC $124.08 +4.50%
SPCX $155.97 +2.75%
MU $1,092.88 +4.60%
AMD $639.90 +5.68%
BTC $86,813.24 +3.51%
ETH $2,760.68 +2.25%
BNB $782.32 +1.60%
XRP $1.54 +3.15%
SOL $122.83 +4.30%
TRX $0.3347 +0.56%
DOGE $0.0971 +2.79%
ADA $0.2565 +3.80%
BCH $316.51 +2.69%
LINK $14.40 +0.28%
HYPE $91.02 +2.18%
AAVE $183.20 +11.35%
SUI $1.20 +4.18%
XLM $0.2249 +1.97%
ZEC $1,391.46 -0.33%
AAPL $331.74 +0.08%
AMZN $252.06 +1.15%
GOOGL $343.68 -0.20%
MSFT $516.38 -0.42%
META $730.21 +0.18%
NVDA $237.36 +2.41%
TSLA $368.93 +3.27%
SNDK $1,745.30 -0.03%
INTC $124.08 +4.50%
SPCX $155.97 +2.75%
MU $1,092.88 +4.60%
AMD $639.90 +5.68%

fraud

All
Article
Flash

GoPlus: Robinhood Chain exposes the Meme coin RUG factory again, with a flow exceeding 9 million USD

The GoPlus security team disclosed that a high-risk fraudulent Meme factory was recently discovered on the Robinhood Chain, with a transaction volume exceeding 9 million dollars in the past 30 days, involving hundreds of fraudulent Memes. The asset aggregation address is 0x8c3Bad30cc7563A2D0357F49509FFd063666bb00. As of September 28, 2026, the address balance is approximately 56.0635 ETH, equivalent to about 148,000 dollars; the address has a total of about 1,385 transactions, with the latest 400 transactions generating approximately 1,728.02 ETH in income and transferring out approximately 1,861.12 ETH; the two-way transaction volume is about 3,589.14 ETH, equivalent to about 9.49 million dollars.Direct evidence of "authorizing or selling tokens ---> liquidating ETH ---> transferring to the same aggregation address" was found in the high-risk associated Memes. The amount is the gross amount transferred into the aggregation system from the same project batch and does not represent net profit. The fraudulent Meme factory model mainly includes "new accounts shipping out ---> layered aggregation ---> fund recycling: 1. Creating Tokens based on industry hotspots; 2. Allocating Tokens to a large number of new EOAs with only 4 to 11 transactions; 3. Selling in segments through PonsV2Helper / UniversalRouter; 4. Emptying ETH to local aggregators or the main aggregation address (0x8c3bad); 5. Providing funds for the next round of projects, new wallets, and trading operations. The key to this fraud model is: 1. Using a large number of new wallets to hide the actual concentration of chips; 2. Segmentally selling by these wallets to create the illusion of multiple independent traders; 3. After the shipment is completed, funds flow into the same aggregation system; 4. Reinvesting the profits from old projects into the next round.On-chain researcher Wazz recently disclosed that a suspected continuous Rug gang initiated at least 53 Robinhood Chain Memes within about two months and extracted approximately 18.43 million dollars from them. Their main tactic is to control most of the token supply using 70 to 200 wallets, then reinvest the profits from the previous round into the next round. This case is similar to the fraudulent model in this case, but there is currently no evidence to indicate that it is the same gang.

first_img X sued two British users, accusing them of defrauding $277,000 in creator revenue

The social media platform X has filed a lawsuit in London against two British residents, accusing them of defrauding the company through the Creator Revenue Sharing program. X Internet Unlimited Company and X Corp. stated in the lawsuit that Vivek Kumar Sen, Zamyang Sherpa, and unidentified accomplices operated multiple X accounts in collaboration, using likes, retweets, and replies to create a false impression of genuine interaction to increase their share of revenue from the program. X was acquired last year by Elon Musk's artificial intelligence company xAI for $33 billion.The plaintiffs named a total of 9 accounts, including @Vivek4real_, @Bitcoin_Teddy, @saylordocs, @TrendingBitcoin, @Kalshibacktest, and @PolyBackTest. X accused several accounts of posting identical or highly similar cryptocurrency-related content within minutes of each other, with one post interval being only 11 seconds; at the same time, these accounts had overlapping financial and identity information, such as the Stripe account associated with @Bitcoin_Teddy being registered under the name "Stefan Mann," while the associated bank account and email both belonged to Sen.X claimed it suffered a loss of £207,384 (approximately $277,000) due to program expenditures and is seeking at least £75,000 (approximately $100,000) for investigation, analysis, remediation, and prevention of further violations.

first_img Fake AI trading robot tutorial deceives 224 victims into deploying malicious contracts

On September 14, blockchain intelligence company TRM Labs released a report revealing that fake YouTube tutorials lured 224 victims into deploying and funding malicious smart contracts under the guise of building AI-based crypto arbitrage bots, resulting in the theft of 274.6 ETH. TRM identified a total of 234 contracts deployed by the victims, with funds ultimately flowing into six collection addresses controlled by the operators. The stolen ETH was worth approximately $517,000 at the time of the transfer, with a median loss of 1 ETH per incident.Unlike common wallet theft attacks, this scam did not involve phishing links, spoofed domains, or malicious authorization prompts. Victims chose the tutorials themselves, copied the code, deployed the contracts, and funded them from their own wallets, with each step authorized by the victims themselves. As a result, wallet security warnings and phishing blacklists could not be triggered. TRM discovered nine nearly identical YouTube tutorials disguised as different creators, using AI-generated virtual hosts and voiceovers, promising to build fully automated crypto trading bots with Claude, and guiding victims to a compiler website controlled by the operators, some of which mimicked the commonly used Remix development environment.In one variant analyzed by TRM, a backend script would discard the source code pasted by the victims and retrieve another contract from the operator's server, with the clean code displayed on the screen never being on-chain. The replaced contract accepted deposits and transferred any balance over 0.05 ETH to the operators when the victims pressed Start or Withdraw, with no arbitrage logic or AI functionality included in the contract.
app_icon
ChainCatcher Building the Web3 world with innovations.