OAK — OnChain Attack Knowledge

Worked example · 2020-09

Yfdexf.Finance liquidity-mining exit scam — Ethereum — 2020-09-08 to 2020-09-10

Loss
approximately $20 million in user-deposited funds (ETH, stablecoins, and other assets deposited into Yfdexf.Finance's liquidity-mining pools across a ~2-day campaign). The protocol collected deposits during a four-hour pre-sale window and a post-launch staking/liquidity-mining window, then the team deleted the official website, Medium story, Twitter account, and Telegram channel and disappeared with the deposited funds.
OAK Techniques observed
OAK-T11.005 (Operator-Side Fake Platform Fraud — the YfdexF.Finance project was a wholly fabricated DeFi protocol; the website, Twitter, Telegram, and Medium presence were deception infrastructure deleted simultaneously at the exit moment, confirming the platform had no genuine operational intent). OAK-T2.001 (Single-Sided Liquidity Plant — the YfdexF liquidity-mining pools were structurally single-sided deposit traps from genesis; the operator seeded the pools with the YFDEX token as the dominant side, and user deposits of ETH and stablecoins into the paired side constituted the extraction target; the pools had no genuine liquidity-provision function and existed solely to collect user deposits for the exit) + OAK-T5.001 (Hard LP Drain — primary; the operator team controlled the deposit-collection mechanism and withdrew user-deposited funds from the protocol's pools, converting the yield-farming deposit flow into a single-operator exit) + OAK-T6.001 (Source-Verification Mismatch — the project presented as a legitimate DeFi protocol with a Twitter presence, Telegram community, Medium articles, and a professional website; the operator deleted all of these surfaces simultaneously at the exit moment, confirming they were deception infrastructure rather than genuine community surfaces) + OAK-T1.003 (onlyOwner / Proxy Rug — the YFDEX token was created as the extraction substrate; the pre-sale and liquidity-mining token distribution was the access-acquisition channel through which user deposits were collected, and the deployer retained full control over the deposit-collection mechanism).
Attribution
pseudonymous — the Yfdexf.Finance team operated under completely unknown identities. No named individuals or entities have been publicly linked to the operation. The team's social-media surfaces (Twitter, Telegram, Medium) were deleted at the exit moment, and the domain registration and hosting details were insufficient to establish attribution. The case sits in the pseudonymous-attribution category with no public attribution to named individuals at v0.1.
Key teaching point
Yfdexf.Finance is the canonical 2020 anchor for the short-window liquidity-mining exit scam sub-pattern: the operator deploys a yield-farming protocol during a DeFi hype window (the "DeFi Summer" of 2020), runs an aggressive social-media campaign promising high APY and "legitimacy" claims, collects deposits over a compressed window (~2 days), then deletes all operator surfaces simultaneously and disappears with the deposited funds. The structural lesson is that launch-window deposit concentration + anonymous operator + no timelock or multisig on the fund-collection contract = T5.001-exposed by construction.

Summary

Yfdexf.Finance launched on approximately September 8, 2020, during the peak of the "DeFi Summer" yield-farming wave that saw dozens of new yield-farming protocols deploy on Ethereum. The protocol presented itself as a liquidity-mining / yield-farming platform with a native token, YFDEX. The operator ran a two-day advertising blitz on Twitter, Telegram, and Medium, promoting the protocol with giveaways to Twitter users for retweets and hashtags.

The protocol's promotional materials claimed it was "the FIRST and LEGIT protocol to get rewarded on your TrippleStaking" and advertised a four-hour pre-sale window "until the hard cap is reached" with unsold tokens to be burned. The compressed pre-sale window and aggressive urgency framing were structural features of the exit-scam design: they concentrated deposits into a short window, minimising the window during which community scrutiny might surface warning signals.

Approximately two days after launch — on or around September 10, 2020 — the team simultaneously deleted the protocol's official website, Medium story, Twitter account, and Telegram channel. The deposited funds ($20M) were no longer accessible to depositors. The YFDEX token, which had traded on Uniswap at a peak of 0.1 ETH ($36.06 per token), collapsed to effectively zero; the final recorded trade was 10 YFDEX for 0.002 ETH (~$0.73).

The case is one of the largest pure exit scams of the 2020 DeFi wave and is structurally distinct from contemporaneous 2020 cases: Harvest Finance (October 2020) was an oracle-manipulation exploit by an external attacker, not an operator exit; Compounder Finance (December 2020) was a strategy-contract swap by the operator team that drained LP but left an on-chain forensic trail; UniCats (October 2020) was an approval-backdoor exploit embedded in a yield-farming contract. Yfdexf is the cleanest 2020 anchor for the deposit-collection then simultaneous surface-deletion exit pattern.

Timeline (UTC)

When Event OAK ref
2020-09-08 Yfdexf.Finance launches on Ethereum; pre-sale and liquidity-mining campaign begins; Twitter, Telegram, Medium surfaces active T1 (Token Genesis — extraction-substrate deployment)
2020-09-08 to 2020-09-10 Users deposit ETH, stablecoins, and other assets into Yfdexf's liquidity-mining pools across ~200+ Uniswap transactions; YFDEX token trades at peak 0.1 ETH ($36.06) T5.001 (deposit collection phase)
2020-09-10 (~2 days post-launch) Team simultaneously deletes website, Medium, Twitter, and Telegram; deposited funds (~$20M) disappear with the operator T5.001 execution (Hard LP Drain); T6.001 (surface deletion as deception-infrastructure confirmation)
2020-09-10 (post-exit) YFDEX collapses to 0.002 ETH ($0.73) in final Uniswap trade; 49 addresses hold the now-worthless token (post-exit price impact)
2020-09 onward No operator attribution established; case sits in the pseudonymous-attribution category (attribution gap)

What defenders observed

  • Pre-event (social-media blitz): The protocol's compressed ~2-day promotional blitz on Twitter, Telegram, and Medium used giveaway incentives (retweets, hashtags) to drive deposit velocity. The compressed window was a structural signal — legitimate protocols do not typically concentrate their entire marketing campaign into a 48-hour window with a four-hour pre-sale hard-cap claim.
  • At-event (deposit collection): User deposits flowed into Yfdexf's pools; the YFDEX token traded actively on Uniswap (~200 transactions). The deposit contract gave the operator team control over the pooled funds with no timelock, multisig, or withdrawal-delay mechanism. The absence of these safeguards was the load-bearing structural defect.
  • At-event (surface deletion): The simultaneous deletion of all operator surfaces (website, Medium, Twitter, Telegram) at the exit moment is the distinctive T6.001 signal: the surfaces were deception infrastructure, not genuine community infrastructure. The simultaneity of the deletion is itself a forensic signal — it confirms coordinated operator action rather than a gradual project abandonment.
  • Post-event (token collapse): YFDEX collapsed from ~0.1 ETH to near-zero in the final recorded Uniswap trade. The 49 addresses holding the worthless token represent the residual victim set. No fund-recovery or operator-attribution progress was publicly documented.

What this example tells contributors writing future Technique pages

  • Yfdexf is the cleanest 2020 anchor for the short-window liquidity-mining exit scam sub-pattern of T5.001. The compressed pre-sale window, the aggressive social-media campaign, and the simultaneous surface deletion are the three structural features that distinguish this sub-pattern from the longer-window operator exits (Compounder Finance December 2020, SushiSwap Chef Nomi September 2020). Future T5.001 worked examples covering operator-side exit scams should record the deposit-window duration as a structural feature — shorter windows correlate with higher operator intent but narrower defender-observation windows.
  • The absence of timelock/multisig on the deposit contract is the load-bearing structural defect. Yfdexf's deposit-collection mechanism gave the operator unilateral control over pooled funds with no withdrawal delay. A timelock on fund withdrawals, a multisig on the deposit contract, or a withdrawal-cap mechanism would have closed the exit surface. Future T5.001 detection guidance should flag deposit contracts where the operator retains unilateral withdrawal authority without a timelock.
  • The simultaneous surface deletion is a T6.001 forensic signal. When an operator deletes all public surfaces simultaneously, the surfaces were deception infrastructure. This is a post-hoc forensic signal that confirms T6.001, but it is only observable after the exit. Pre-event detection requires examining the deployer-to-community-surface mismatch — anonymous team + no audit + no timelock + compressed marketing window — rather than waiting for the surface deletion itself.
  • Yfdexf sits in the 2020 exit-scam cohort but is structurally distinct from its contemporaries. Harvest Finance was an external-attacker oracle manipulation (T9.001); Compounder Finance was an operator-side strategy-swap drain with an on-chain forensic trail (T5.001 + T5.003); UniCats was an approval-backdoor exploit (T4.004). Yfdexf is the purest operator-side deposit-collection-then-disappear case in the 2020 corpus. Future technique pages covering the operator-side exit-scam class should distinguish the deposit-collection sub-pattern (Yfdexf) from the strategy-swap sub-pattern (Compounder) and the treasury-swap sub-pattern (SushiSwap Chef Nomi).

Public references

  • [cointelegraphyfdexf2020] — CoinTelegraph, "Another DeFi exit scam just made off with $20M in investor funds" (2020-09): reporting on the Yfdexf exit scam, $20M figure, 2-day campaign, surface deletion.
  • [quadrigayfdexf2020] — Quadriga Initiative, "YFDexF Finance Exit Scam — $20m" (casestudy database entry): project launch date, mechanism, token address, peak price.
  • [zycryptoyfdexf2020] — ZyCrypto, "Crypto Whale Warns Of Growing DeFi Scams As Another Protocol Exits Market With Funds Worth $20M" (2020-09).

Citations

  • [cointelegraphyfdexf2020] — primary contemporaneous press; $20M figure, 2-day campaign window, surface deletion sequence, token price trajectory.
  • [quadrigayfdexf2020] — casestudy database entry; launch date, mechanism summary, token address, peak price (0.1 ETH).

Discussion

Yfdexf.Finance is the canonical 2020 anchor for the short-window liquidity-mining exit scam sub-pattern of T5.001. The case demonstrates the recurring structural property that launch-window deposit concentration + anonymous operator + unilateral withdrawal authority = T5.001-exposed by construction. The compressed ~2-day deposit window was both the operator's operational advantage (minimising the window for community scrutiny) and the defender's detection challenge (the window was too short for organic community vetting to surface warning signals before deposits were collected).

The case is structurally the purest operator-side exit scam in the 2020 corpus. Harvest Finance was an external-attacker oracle manipulation (T9.001) — the Harvest team remained and cooperated with the post-mortem. Compounder Finance was an operator-side strategy-swap drain (T5.001 + T5.003) where the team used a timelock to swap in malicious strategy contracts — the on-chain forensic trail was preserved. SushiSwap Chef Nomi was a treasury-swap exit (T5.005) where the operator swapped the dev-fund allocation against community LP and later returned the funds. Yfdexf is distinct from all three: the operator collected user deposits into a protocol they controlled, then deleted all surfaces and disappeared with the funds, leaving no on-chain forensic trail beyond the deposit-flow pattern and no operator to engage in post-mortem.

The attribution surface is the case's principal limitation at v0.1. The operator team is completely unknown — no named individuals, no funder-graph cluster identification, no exchange-KYC linkage. The case sits in the pseudonymous-attribution category as a representative of the broader 2020 exit-scam cohort where operator anonymity was the norm. Future named-attribution cases in the short-window exit-scam sub-pattern (if any emerge through retrospective blockchain forensics or exchange-KYC de-anonymisation) can build on the Yfdexf structural template.

For defenders, the case reinforces the standing lesson that pre-deposit due diligence must include verification of timelock/multisig on the deposit contract, operator identity verification, and scrutiny of compressed marketing windows. The 48-hour campaign-to-exit window was too short for community vetting to function — the vetting must occur at the pre-deposit design-review layer, not at the community-discussion layer. The simultaneous surface deletion is the post-hoc confirmation of T6.001 but arrives too late for depositor protection.

Techniques demonstrated (5)