Worked example · 2020-09
Yfdexf.Finance liquidity-mining exit scam — Ethereum — 2020-09-08 to 2020-09-10
Summary
Yfdexf.Finance launched on approximately September 8, 2020, during the peak of the "DeFi Summer" yield-farming wave that saw dozens of new yield-farming protocols deploy on Ethereum. The protocol presented itself as a liquidity-mining / yield-farming platform with a native token, YFDEX. The operator ran a two-day advertising blitz on Twitter, Telegram, and Medium, promoting the protocol with giveaways to Twitter users for retweets and hashtags.
The protocol's promotional materials claimed it was "the FIRST and LEGIT protocol to get rewarded on your TrippleStaking" and advertised a four-hour pre-sale window "until the hard cap is reached" with unsold tokens to be burned. The compressed pre-sale window and aggressive urgency framing were structural features of the exit-scam design: they concentrated deposits into a short window, minimising the window during which community scrutiny might surface warning signals.
Approximately two days after launch — on or around September 10, 2020 — the team simultaneously deleted the protocol's official website, Medium story, Twitter account, and Telegram channel. The deposited funds ($20M) were no longer accessible to depositors. The YFDEX token, which had traded on Uniswap at a peak of 0.1 ETH ($36.06 per token), collapsed to effectively zero; the final recorded trade was 10 YFDEX for 0.002 ETH (~$0.73).
The case is one of the largest pure exit scams of the 2020 DeFi wave and is structurally distinct from contemporaneous 2020 cases: Harvest Finance (October 2020) was an oracle-manipulation exploit by an external attacker, not an operator exit; Compounder Finance (December 2020) was a strategy-contract swap by the operator team that drained LP but left an on-chain forensic trail; UniCats (October 2020) was an approval-backdoor exploit embedded in a yield-farming contract. Yfdexf is the cleanest 2020 anchor for the deposit-collection then simultaneous surface-deletion exit pattern.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2020-09-08 | Yfdexf.Finance launches on Ethereum; pre-sale and liquidity-mining campaign begins; Twitter, Telegram, Medium surfaces active | T1 (Token Genesis — extraction-substrate deployment) |
| 2020-09-08 to 2020-09-10 | Users deposit ETH, stablecoins, and other assets into Yfdexf's liquidity-mining pools across ~200+ Uniswap transactions; YFDEX token trades at peak |
T5.001 (deposit collection phase) |
| 2020-09-10 (~2 days post-launch) | Team simultaneously deletes website, Medium, Twitter, and Telegram; deposited funds (~$20M) disappear with the operator | T5.001 execution (Hard LP Drain); T6.001 (surface deletion as deception-infrastructure confirmation) |
| 2020-09-10 (post-exit) | YFDEX collapses to |
(post-exit price impact) |
| 2020-09 onward | No operator attribution established; case sits in the pseudonymous-attribution category | (attribution gap) |
What defenders observed
- Pre-event (social-media blitz): The protocol's compressed ~2-day promotional blitz on Twitter, Telegram, and Medium used giveaway incentives (retweets, hashtags) to drive deposit velocity. The compressed window was a structural signal — legitimate protocols do not typically concentrate their entire marketing campaign into a 48-hour window with a four-hour pre-sale hard-cap claim.
- At-event (deposit collection): User deposits flowed into Yfdexf's pools; the YFDEX token traded actively on Uniswap (~200 transactions). The deposit contract gave the operator team control over the pooled funds with no timelock, multisig, or withdrawal-delay mechanism. The absence of these safeguards was the load-bearing structural defect.
- At-event (surface deletion): The simultaneous deletion of all operator surfaces (website, Medium, Twitter, Telegram) at the exit moment is the distinctive T6.001 signal: the surfaces were deception infrastructure, not genuine community infrastructure. The simultaneity of the deletion is itself a forensic signal — it confirms coordinated operator action rather than a gradual project abandonment.
- Post-event (token collapse): YFDEX collapsed from ~0.1 ETH to near-zero in the final recorded Uniswap trade. The 49 addresses holding the worthless token represent the residual victim set. No fund-recovery or operator-attribution progress was publicly documented.
What this example tells contributors writing future Technique pages
- Yfdexf is the cleanest 2020 anchor for the short-window liquidity-mining exit scam sub-pattern of T5.001. The compressed pre-sale window, the aggressive social-media campaign, and the simultaneous surface deletion are the three structural features that distinguish this sub-pattern from the longer-window operator exits (Compounder Finance December 2020, SushiSwap Chef Nomi September 2020). Future T5.001 worked examples covering operator-side exit scams should record the deposit-window duration as a structural feature — shorter windows correlate with higher operator intent but narrower defender-observation windows.
- The absence of timelock/multisig on the deposit contract is the load-bearing structural defect. Yfdexf's deposit-collection mechanism gave the operator unilateral control over pooled funds with no withdrawal delay. A timelock on fund withdrawals, a multisig on the deposit contract, or a withdrawal-cap mechanism would have closed the exit surface. Future T5.001 detection guidance should flag deposit contracts where the operator retains unilateral withdrawal authority without a timelock.
- The simultaneous surface deletion is a T6.001 forensic signal. When an operator deletes all public surfaces simultaneously, the surfaces were deception infrastructure. This is a post-hoc forensic signal that confirms T6.001, but it is only observable after the exit. Pre-event detection requires examining the deployer-to-community-surface mismatch — anonymous team + no audit + no timelock + compressed marketing window — rather than waiting for the surface deletion itself.
- Yfdexf sits in the 2020 exit-scam cohort but is structurally distinct from its contemporaries. Harvest Finance was an external-attacker oracle manipulation (T9.001); Compounder Finance was an operator-side strategy-swap drain with an on-chain forensic trail (T5.001 + T5.003); UniCats was an approval-backdoor exploit (T4.004). Yfdexf is the purest operator-side deposit-collection-then-disappear case in the 2020 corpus. Future technique pages covering the operator-side exit-scam class should distinguish the deposit-collection sub-pattern (Yfdexf) from the strategy-swap sub-pattern (Compounder) and the treasury-swap sub-pattern (SushiSwap Chef Nomi).
Public references
[cointelegraphyfdexf2020]— CoinTelegraph, "Another DeFi exit scam just made off with $20M in investor funds" (2020-09): reporting on the Yfdexf exit scam, $20M figure, 2-day campaign, surface deletion.[quadrigayfdexf2020]— Quadriga Initiative, "YFDexF Finance Exit Scam — $20m" (casestudy database entry): project launch date, mechanism, token address, peak price.[zycryptoyfdexf2020]— ZyCrypto, "Crypto Whale Warns Of Growing DeFi Scams As Another Protocol Exits Market With Funds Worth $20M" (2020-09).
Citations
[cointelegraphyfdexf2020]— primary contemporaneous press; $20M figure, 2-day campaign window, surface deletion sequence, token price trajectory.[quadrigayfdexf2020]— casestudy database entry; launch date, mechanism summary, token address, peak price (0.1 ETH).
Discussion
Yfdexf.Finance is the canonical 2020 anchor for the short-window liquidity-mining exit scam sub-pattern of T5.001. The case demonstrates the recurring structural property that launch-window deposit concentration + anonymous operator + unilateral withdrawal authority = T5.001-exposed by construction. The compressed ~2-day deposit window was both the operator's operational advantage (minimising the window for community scrutiny) and the defender's detection challenge (the window was too short for organic community vetting to surface warning signals before deposits were collected).
The case is structurally the purest operator-side exit scam in the 2020 corpus. Harvest Finance was an external-attacker oracle manipulation (T9.001) — the Harvest team remained and cooperated with the post-mortem. Compounder Finance was an operator-side strategy-swap drain (T5.001 + T5.003) where the team used a timelock to swap in malicious strategy contracts — the on-chain forensic trail was preserved. SushiSwap Chef Nomi was a treasury-swap exit (T5.005) where the operator swapped the dev-fund allocation against community LP and later returned the funds. Yfdexf is distinct from all three: the operator collected user deposits into a protocol they controlled, then deleted all surfaces and disappeared with the funds, leaving no on-chain forensic trail beyond the deposit-flow pattern and no operator to engage in post-mortem.
The attribution surface is the case's principal limitation at v0.1. The operator team is completely unknown — no named individuals, no funder-graph cluster identification, no exchange-KYC linkage. The case sits in the pseudonymous-attribution category as a representative of the broader 2020 exit-scam cohort where operator anonymity was the norm. Future named-attribution cases in the short-window exit-scam sub-pattern (if any emerge through retrospective blockchain forensics or exchange-KYC de-anonymisation) can build on the Yfdexf structural template.
For defenders, the case reinforces the standing lesson that pre-deposit due diligence must include verification of timelock/multisig on the deposit contract, operator identity verification, and scrutiny of compressed marketing windows. The 48-hour campaign-to-exit window was too short for community vetting to function — the vetting must occur at the pre-deposit design-review layer, not at the community-discussion layer. The simultaneous surface deletion is the post-hoc confirmation of T6.001 but arrives too late for depositor protection.