
🚨 URGENT: QFL — Simple Safety Rules (READ NOW). Risk about random criptos..
CRITICAL — DO THIS FIRST
★ WHITELIST only audited tokens with OWNERSHIP RENOUNCED or MULTISIG + TIME-LOCK
★ BLOCK tokens with mint / burn / blacklist / admin privileges unless multisig+timelock+audit
★ NO RANDOM GRIDS — disable random selection across big pools; HUMAN REVIEW required for any non-whitelisted token
★ NO INFINITE APPROVE — enforce ALLOWANCE CAPS (no infinite approvals) and alert on approve() changes
★ REAL-TIME MONITORING + KILL-SWITCH — auto-pause on large mints, sudden liquidity removal, owner transfers or abnormal approvals
High priority (do next)
•MINIMUM LIQUIDITY & VOLUME — recomended $100k liquidity / $50k 24h volume (verify LP origin & lock proof)
•SLIPAGE, MAX TRADE SIZe
slippage ≤ 1.5% (≤0.5% for microcap); max trade 0.1%–0.5% of circ. supply (be conservative)
•STRONG KYC / AML for issuers and market makers — reject opaque teams
Extras (helpful, but secondary)
THREAT FEEDS / honeypot scanner: use PeckShield, CertiK, Chainalysis, honeypot.is for automatic flags
POST-LISTING MONITORING & RE-AUDIT (30/90 days), market-maker disclosure, multisig + timelock for treasury ops, user education (don’t sign unknown txs or airdrops).
For users (one-line rules)
Do NOT sign unknown transactions. Never approve infinite allowances. If token isn’t whitelisted + audited, don’t trade it.
Bottom line (paste-ready)
If you can’t enforce WHITELIST + BLOCK ADMIN PRIVILEGES + VERIFIED LP LOCK + HUMAN REVIEW + REAL-TIME MONITORING, STOP running random grid buys on low-cap or cross-chain tokens. Limits (0.1–0.5% trades, 1–1.5% slippage) help but they don’t stop honeypots, backdoors or dust tracking. You’re gambling with users’ money — act now.

THESE ARE REAL INCIDENTS, NOT HYPOTHETICAL. Links included so you can verify.
Below: case → MECHANISM → impact → RISK%. Short, spaced, easy to scan.
SQUID — Rug-pull after viral marketing.
MECHANISM: OWNER BACKDOOR + liquidity removal on DEX.
Impact: total loss for holders; platform reputation damaged.
RISK: 95.0%
Links: https://www.coindesk.com/search/?q=squid%20game%20token ; https://www.cointelegraph.com/search?query=squid%20game%20token
AnubisDAO — Contract with hidden mint/burn controls used to drain funds.
MECHANISM: MINT/BURN BACKDOOR + privileged roles.
Impact: holders drained; spread via listings/interfaces.
RISK: 92.0%
Links: https://www.cointelegraph.com/search?query=AnubisDAO ; https://peckshield.com/en/
Meerkat Finance — “Hack” suspected to be a rug that drained farm liquidity.
MECHANISM: centralized farming/treasury keys.
Impact: BSC liquidity collapse; user losses.
RISK: 88.0%
Links: https://www.coindesk.com/search/?q=Meerkat%20Finance
bZx Attacks — Flash-loan attacks manipulating on-chain prices.
MECHANISM: ORACLE MANIPULATION via AMM price abuse + flash loans.
Impact: protocol drains, mass liquidations.
RISK: 90.0%
Links: https://www.coindesk.com/search/?q=bzx%20attack
Harvest Finance — Stable/Curve pool manipulation → ~$30M loss.
MECHANISM: ORACLE / POOL MANIPULATION + flash loans.
Impact: large LP losses; trust erosion.
RISK: 89.0%
Links: https://www.coindesk.com/search/?q=Harvest%20Finance%20exploit
Cream Finance — Multiple exploits across 2021–2022.
MECHANISM: contract/integration vulnerabilities (oracles, bridges).
Impact: repeated big losses, solvency stress.
RISK: 90.0%
Links: https://www.coindesk.com/search/?q=Cream%20Finance%20exploit
HONEYPOT TOKENS (category) — Tokens you can BUY but cannot SELL.
MECHANISM: conditional transfer/transferFrom logic, blacklists or router checks.
Impact: buyers trapped, total losses.
RISK: 96.0%
Tools: https://honeypot.is/ ; https://www.cointelegraph.com/search?query=honeypot%20token
Evolved Apes (NFT rug) — Creators drained treasury and shut the marketplace.
MECHANISM: centralized marketplace/royalty control.
Impact: collectors lose ETH; platforms lose trust.
RISK: 85.0%
Links: https://www.cointelegraph.com/search?query=Evolved%20Apes
Wormhole Bridge Exploit — Bridge bug allowed minting → ~$320M stolen.
MECHANISM: faulty verification / mint logic in cross-chain bridge.
Impact: huge capital loss; cross-chain trust collapse.
RISK: 94.0%
Links: https://www.coindesk.com/search/?q=Wormhole%20exploit
DUSTING ATTACKS & RESIDUES — Tiny txs to trace and deanonymize wallets.
MECHANISM: on-chain correlation heuristics; malicious dust tokens/hooks.
Impact: privacy loss → targeted phishing/extortion.
RISK: 75.0%
Links: https://www.chainalysis.com ; https://www.blockchain.com/learning-portal/what-is-a-dusting-attack
TOKENS THAT TRAP / DEFORM WALLETS — Leftover residues or transfer taxes that break UX.
MECHANISM: blacklists, EIP-777 hooks, transfer taxes creating dust.
Impact: wallets stuck; security/UX nightmare.
RISK: 92.0%
Links: https://eips.ethereum.org/EIPS/eip-777
ORACLE MANIPULATION (category) — Manipulate reference prices to force liquidations.
MECHANISM: manipulate AMM prices that oracles ingest or feed bad data.
Impact: TVL losses, large reversals.
RISK: 91.0%
Links: https://blog.peckshield.com ; https://www.coindesk.com/search/?q=oracle%20manipulation
APPROVALS / API KEY & PRIVATE KEY LEAKS — Infinite approvals or leaked keys drain assets.
MECHANISM: unlimited approve() or compromised keys.
Impact: immediate full drain; costly recovery.
RISK: 98.0%
Links: https://consensys.net/blog ; https://etherscan.io
MALICIOUS TOKENOMICS / INFINITE MINT — Teams mint supply and dump.
MECHANISM: owner/multisig with mint() authority.
Impact: price collapse; investor losses.
RISK: 93.0%
Links: https://peckshield.com/en/
PHISHING VIA AIRDROPS / MALICIOUS UI — Users sign malicious txs and give approvals.
MECHANISM: social engineering + signature prompts.
Impact: wallets drained or compromised.
RISK: 90.0%
Links: https://www.coindesk.com/search/?q=airdrop%20phishing
BRIDGE / WRAPPED TOKEN MINT ABUSE — Wrapped assets minted without proper validation.
MECHANISM: weak cross-chain proofs / relayer compromise.
Impact: fake supply and integrator losses.
RISK: 94.0%
Links: https://www.coindesk.com/search/?q=bridge%20exploit
BATCHOVERFLOW & CONTRACT BUGS — Code bugs that mint/drain tokens.
MECHANISM: poor contract code / missing checks.
Impact: exploitable tokens, forced fixes.
RISK: 86.0%
Links: search “BatchOverflow ERC-20” on https://www.coindesk.com
SMALL EXCHANGES & MALICIOUS MARKET MAKERS — Permissive listings + fake liquidity.
MECHANISM: wash trading, bought listings, opaque MMs.
Impact: mass user losses; scrutiny of larger platforms.
RISK: 90.0%
Links: https://www.chainalysis.com ; https://www.cointelegraph.com/search?query=exchange%20listing%20scam

SHORT TECHNICAL JUSTIFICATIONS
Backdoors / privileged roles → RUG-PULL / MINT risks. Check ownership renounce.
Oracles on raw AMM prices → PRICE MANIPULATION via flash loans. Use TWAP / medians.
Infinite approvals / signed txs → IMMEDIATE DRAIN. Enforce allowance caps.
Honeypots / transfer hooks → buyable but unsellable tokens — inspect transfer() code.
Weak bridge proofs → ARBITRARY SUPPLY. Require strong cross-chain proofs.
Dust/residue → PRIVACY & TRACKING vectors — chain transparency enables deanonymization.
Listing without due diligence → distribution vector for scams.
MATERIALS / INTEL (full links)
News: https://www.coindesk.com — search each case.
Forensics: https://www.chainalysis.com
Threat intel / audits: https://peckshield.com/en/ ; https://certik.org/blog
Honeypot / contract scans: https://honeypot.is/ ; https://etherscan.io
Security guidance: https://consensys.net/blog