CryptoReal
CASE FILE — May 20, 2023

Backdoored Upgrade Lets Swaprum Team Drain $3M From Arbitrum DEX

Swaprum, a decentralized exchange built on Arbitrum, disappeared with roughly $3 million in user funds on Thursday. The team wiped its social media accounts and GitHub repositories in the aftermath, yet the project's website stayed online — still displaying a Certik audit badge in its banner.

The exit comes less than a month after Merlin DEX made off with $1.8 million in a similar fashion, reviving questions about whether a Certik seal actually signals safety or should instead be treated as a warning sign. Swaprum marks the fourth rug pull above $1 million tracked so far in 2023, and every one of those projects had passed some form of audit — a reminder that not all reviews carry the same weight.

Credit for surfacing the incident goes to Beosin.

01How the funds were taken

The exploit itself was not sophisticated. Swaprum's reward contract was upgraded to a new implementation that quietly introduced a function called add(). This function routed users' LP tokens to the team's own deployer wallet, giving the operators a way to strip out the underlying liquidity at will.

The deployer address behind the theft is identified as 0xf2744e1fe488748e6a550677670265f664d96627, and a sample transaction shows the mechanism in action. From there, the stolen assets were bridged over to an Ethereum address, where a combined 1,620 ETH was ultimately funneled into Tornado Cash.

Sums referenced in this case file

02What the audit did and didn't catch

Notably, the malicious upgraded contract was never part of what Certik actually reviewed. Still, the underlying design flaw — the ability to swap out a contract holding user funds for any arbitrary new deployment — existed from day one, audit or not.

To its credit, Certik's report did flag centralization concerns, noting that the contract owner retained outsized authority over parts of the protocol. But the language framed the risk almost entirely around external attackers rather than the team itself:

Any compromise to the _owner account may allow the hacker to take advantage of this authority…

If an attacker compromises the account, he can change the implementation of the contract and drain tokens from the contract.

Given how often this pattern has repeated across the industry, auditors arguably owe users clearer language about the possibility of malicious insiders, not just hypothetical external hacks. Something like a straightforward "ruggability" rating could convey that risk far more directly to everyday users — though it's unlikely that projects looking to rubber-stamp a scam would welcome such a metric being attached to their report.

Certik has since revised Swaprum's status on its platform to "Exit Scam."

ArbitrumRugpullSwaprum
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.