Worked example · 2023-11
PulseChain ecosystem fake-audit-claim token launches — PulseChain — 2023-11 to 2024-02
Summary
PulseChain launched in May 2023 as an Ethereum fork with a native PLS token and a community airdrop to PulseChain sacrificers. The chain's DeFi ecosystem grew rapidly through Q3-Q4 2023, with DEXs, lending protocols, and token projects deploying to capture the new chain's liquidity. The PulseChain community — predominantly retail investors who had participated in the sacrifice phase — had a strong appetite for early-stage DeFi projects.
From November 2023 through February 2024, a cohort of approximately 15-20 token projects launched on PulseChain with a recurring trust-signal pattern: each project's marketing materials prominently displayed "Audit Pending — CertiK" or "Security Audit in Progress — Hacken" badges. The language varied ("currently undergoing CertiK audit," "audit scheduled Q1 2024," "working with Hacken Security"), but the structural pattern was identical: a named-audit-firm association that did not exist.
The projects' lifecycle followed a consistent arc:
- Pre-launch: Announce token launch on PulseChain Telegram channels and X/Twitter PulseChain community accounts. Display "audit pending" badge prominently on the project website.
- Launch: Deploy token contract with hidden-mint capability (
mint()function behindonlyOwner), seed LP on PulseX (PulseChain's dominant DEX) with operator-controlled liquidity, lock or burn a portion of LP tokens as a trust signal. - Holder-capture: Accumulate user deposits into the LP through organic and bot-amplified social-media promotion, sustained over 1-4 weeks. The "audit pending" claim served as the primary objection-handler: when community members questioned the token's security, the team pointed to the "pending audit" as evidence of good-faith engagement.
- Exit: Drain the LP via the
onlyOwnerfunctions, remove the project website and social-media presence, and disappear. The "audit pending" claim evaporated with the project — no follow-up, no audit delivered, no firm-side artefact.
Both CertiK and Hacken published statements in February 2024 clarifying that none of the named projects had engagements with their firms. CertiK's statement noted that the "audit pending" framing was the most commonly-encountered brand-misuse pattern in the PulseChain ecosystem during the Q4 2023–Q1 2024 window, exceeding outright fake completed-audit claims (T6.002). The forward-looking nature of the claim — "audit pending" rather than "audit completed" — made verification structurally harder for individual users: the firm's completed-audit registry (which beats T6.002) could not confirm or deny a pending engagement, and the firm's engagement-tracking surface was not publicly exposed.
Aggregate losses across the cohort are estimated at $4-7 million, distributed across PLS and bridged-stablecoin (USDC, USDT) pairs on PulseX. No individual project within the cohort has been forensically documented at the per-incident named-case level; the T6.004 classification anchors the cohort as a class-level pattern within the PulseChain ecosystem's startup-phase T6.004 surface.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2023-05 | PulseChain mainnet launches; DeFi ecosystem begins forming; PulseX DEX deployed | (ecosystem genesis) |
| 2023-11 to 2024-02 | ~15-20 token projects launch with "audit pending / in progress / scheduled" badges citing CertiK or Hacken; no engagement exists at either firm | T6.004 deployment (fabricated forward-looking audit claims) |
| 2023-11 to 2024-02 | Projects accumulate deposits through audit-claim-backed marketing; operator-side LP drains and hidden-mint dilution execute per project | T6.004 → T2.001 → T5.001 (composed attack chain) |
| 2024-02 | CertiK and Hacken publish statements clarifying no engagement with named PulseChain projects; community discussion of per-firm engagement-verification | (audit-firm-side denial — canonical T6.004 detection signal) |
| 2024-02 onward | Several projects' deployer addresses identified through funder-graph clustering analysis; 3-5 operator clusters tentatively mapped | (attribution surface — pseudonymous-cohort) |
Realised extraction
Aggregate $4-7 million across the cohort in PLS and bridged stablecoins. Per-project extraction ranged from ~$50,000 to ~$800,000, with the median around $200,000. The LP-drain and hidden-mint extraction primitives varied by project. Proceeds were routed through PulseChain-native DEXs (PulseX) and, where bridged stablecoins were involved, bridged back to Ethereum. No funds were recovered; no operator identities were established.
Public references
- Cross-reference: T6.004 at
techniques/T6.004-audit-pending-marketing-claim.md. - Cross-reference: T6.002 at
techniques/T6.002-fake-audit-claim.md. - Cross-reference:
examples/2025-08-hypervault-finance-exit-scam.md— canonical T6.004 anchor (forward-looking audit claim with firm-side denial). - Cross-reference:
examples/2020-12-compounder-finance.md— early T6.004 boundary case (Timelock-queued malicious strategy with active audit claim). [certikpulsechain2024]— CertiK, "PulseChain Ecosystem — Audit-Claim Verification Advisory" (2024-02).[hackenpulsechain2024]— Hacken, "PulseChain Projects Brand-Misuse Advisory" (2024-02).
Public References
See citations in corresponding technique file.