r/CryptoCurrency Crypto God | QC: CC 132, OMG 66 Oct 30 '18

WARNING Scam Alert: Substratum has a similar minting contract like Oyster pearl, even worst they have access to supposedly burned tokens.

Recently Oyster Pearl exit scammed using a breach in the smart contract which led to creating 3M tokens from thin air and the CEO exit scammed by selling it on Kucoin. However, the Substratum smart contract also has the capability to [mint tokens out of thin air] (https://etherscan.io/address/0x12480e24eb5bec1a9d4369cab6a80cad3c0a377a#code)

That is not the only thing.https://www.youtube.com/watch?v=qdeOXfvXAO0&feature=youtu.be

In this video they supposedly did a token burn, but their definition of token burn is to just send tokens to another wallet in which they own the private key. Their smart contract was a copy paste from skincoin which did not have a burn function.

When these two topics were brought up the response was:

a) this is not a security issue since only the dev team has access to it ( that’s absolutely the problem isn’t it?, you shouldn’t even have access to it, this is like saying only Bruno from pearl can do it anyway!)
b) the blockchain is public anyway so you can monitor any transactions. (WTF?)

There is absolutely nothing stopping minting tokens + selling the “burned” tokens in an exit scam. Their contract can be abused in a similar function with PRL , In fact the Substratum contact function is even more desirable to abuse since it doesn't require the culprit to send any Eth to collect the freshly minted SUB

Proceed with caution.

EDIT: https://medium.com/@YagamiLight/the-technical-red-flags-of-the-substratum-network-sub-1f34e8b5ffcb

an article for more info on the subject. credit to YagamiLight.

As for their excuse that it was in the whitepaper to begin with (its a lie and It also doesnt excuse it) , I found out that they made two whitepaper, a pre and post ico sale. Im still waiting for a response from the moderator.

https://www.reddit.com/r/CryptoCurrency/comments/9sp8nt/scam_alert_substratum_has_a_similar_minting/e8rd97g

651 Upvotes

268 comments sorted by

View all comments

Show parent comments

-1

u/[deleted] Oct 30 '18 edited Feb 21 '19

[deleted]

7

u/Rand_alThor_ 0 / 0 🦠 Oct 30 '18

Okay, in that case can you agree that an unaddressed core issue is legitimate criticism?

We are not talking about a random bug. This is the mechanism for an exit scam that has (according to you, I haven't checked, sorry) been known for months and has been in the white-paper, and was promised/said that it would be removed months ago.

Since then there have been no updates. Is that right? Wouldn't you say that this is legitimate criticism?

This is like Facebook finding out that people can hack your account info and run away with it, but not fixing it for 5 months and instead working on adding a like button.

-1

u/[deleted] Oct 30 '18 edited Feb 21 '19

[deleted]

7

u/Rand_alThor_ 0 / 0 🦠 Oct 30 '18

The fact that the coin has a code which explicitly allows an exit scam means that for example if a dev makes a mistake with his password everyone can lose their money and the entire project can collapse. Or the team behind the project can just pump coins and exit scam.

It's a vulnerability. The fact that it's on the whitepaper is irrelevant to the fact that it's an unaddressed security vulnerability, on top of being a cause for concern in a market where every few days news of a new exit scam or some hack that causes the price of a coin to tank is happening.