Do not rug on me: Zero-dimensional Scam Detection
arxiv.org
arxiv.org
Users do not see these tokens unless they actively search them out. Uniswap uses the TokenList standard (https://tokenlists.org/) and by default users only see tokens such as the top 100 projects on CoinGecko. There are many lists created by reputable players such as Aave and Gemini which cover the entire gamut of projects users want to trade without exposing end users to scam tokens.
I believe this is a good system and has worked well as having any kind of listing process or even a DAO introduces subjectivity and provides points of capture for bad actors. With an open listing process and standards like TokenLists we can say that Uniswap is truly a public good and will be around as long as we need it which provides a guaranteed way to swap any asset for any other asset no matter who created it or how controversial it is which is a good primitive for humanity to be able to rely on.
If there's 100 tokens listed on the front page, and one of them is a scam, that may be near 0%, but it's equally near to 2%.
I'd be pretty confident that there's a >1% chance of being scammed on a platform like this. FTT wasn't thought to be a scam until it was proven to be.
Unless a token issuer does so with fully audited accounting with real assets backing their tokens, why should any token not be default assumed to be a scam, instead of default assumed to be valid?
Popularity and usage doesn't change this point. USDT may be incredibly popular, but it also lacks credibility.
Disclaimer: I still remain long BTC (lol@myself)
Ignoring anything else you might have gotten wrong, the comment you are responding to didn't say a 2.3% chance of being scammed, it said a 2.3% chance of NOT being scammed, which is nowhere near 0% or 2%, as it comes from abusing the 97.7% figure from the paper.
I think the majority of those top 100 tokens are not properly audited with tangible assets backing them.
FTT remains the most recent glowing example.
To fix your analogy, it's like a payment processor having thousands of fake storefronts able to accept payment. If 97% of their volume was to those fake entities then definitely shut them down but most of the volume would be Amazon and Walmart and the fake storefronts wouldn't even be a rounding error.
Volume info: https://info.uniswap.org/
Reminds me of "it either works or it doesn't, so there's a 50/50 chance"
And excluding users who haven't gone through that education hardly seems like the democratization of finance that these services advertise.
So uneducated users would really have to go out of their way to get scammed through there. Like having to go out of their way to follow up on a solicitation from something caught in a Gmail spam filter.
If you want to trade an unlisted token by adding the contract address manually, sure you can do that. But then it’s on you if you get scammed, like if you follow through on a solicitation from a spam email.
There's also the obvious case of the scammers getting a user to actually buy the token (perhaps through spam email or "pump groups" that give explicit instructions on how to perform the swap) which I'm not saying has never happened but I do claim is more rare. Even the obviously silly scam emails do have the occasional person click on them and lose their money. The upside is that getting scammed on Uniswap is actually harder as you need to manually bypass safety features.
It looks at transactions and attempts to classify coins as scam or not.
It doesn’t make any claims about the volume in scam coins. That’s more a clickbait headline and HN thread thing.
It’s most trying to contribute an algorithm for identifying scam coins.
See the appendix for features from the transactions that they used for their algorithm.
Uniswap filters the tokens available the same modern email providers filters email. If you go looking in the spam folder and fall pray to a scam there, it is your fault, not the fault of the email provider.
I am mainly wondering about Uniswap being described as safe.
I don't know anything about the space, but it sounds like a fact and statistic that should be front and centre in peoples face all the time.
What they'll conclude reading this is "wow, crypto is full of scams" and be right.
Email and Uniswap are both useful tools that are safe to use for even non-technical users. In fact Uniswap is safer as spam filters aren't 100% reliable but Uniswap's lists nearly are.
> “97% of the tokens are scams so Uniswap is unsafe to use"
People are likely to draw the unsafe assumption.
Sargos attempted to clarify that some safety is created with filtering via a trusted list.
My conclusion reading it was, crypto tokens are 98% scams. Uniswap is an exchange. It's a utility, using an open protocol. It's makeup reflects the makeup of the domain.
I told you.
It's preposterous to call a marketplace where less then 3% of the offerings are "legit" a safe market to use.
Its a digital marketplace. The digital space is full of attempted scams that never come to fruition, and their presence is no indication of engagement. Is that really that hard to wrap your head around?
I’m sure the AOL walled garden had much higher quality content than the internet at large.
[1] or whatever they are using now
85% of all email is spam[1]. But that's not a value judgment on the technology--Humanity can still get value from email.
Sturgeon's law says 90% of everything is crap. If you deal with other humans, you need a way to sift through that crap. In the case of email, that means use a spam filter. In the case of crypto, it means don't buy shitcoins.
People can and do spam Uniswap with fake tokens, because it is wide open and anyone can interact with it. That doesn't necessarily mean that large amounts are being lost trading these scam tokens. I don't know the numbers myself, but if 99% percent of Uniswap trades are WBTC, ETH, LINK, USDC, DAI, and other big-name tokens, and 1% are scams, then the scale of the problem is not at all what is implied by the headline.
If someone is serious about measuring fraud on UniSwap, they would look into the percentage of value traded accounted for by these scam tokens.
This question matters from a policy perspective because headlines like this disparage one of the best things to emerge from crypto in recent years (DeFi) and deflect criticism away from where it is deserved (centralization).
DeFi apps like Uniswap are safer than centralized exchanges because you can see everything that is happening on-chain, and maintain custody of your own tokens yourself. Most people who were relying of FTX have been screwed by the exchange itself, regardless of the market value of the token that they thought they owned. If you lose money on Uniswap it's not because the exchange did something wrong, but because the issuer of the token did something wrong, or simply because the token you purchased fell in value.
If you are trading ETH, WBTC, LINK, USDC on Uniswap, you are better protected than if you are trading these same tokens on any of the centralized exchanges.
Reputable how? like ftx a couple weeks ago? Gemini holds an F rating by the BBB and a massive amount of complaints on trust pilot.[1][2]
This is their marketing message "Put your crypto to work. With Gemini Earn, you can receive up to 8.05% APY on your cryptocurrency." This is done by buying and holding stablecoins. Just curious how do you suppose they return such high APY on stablecoins without doing the exact same scam as FTX?
[1]https://www.bbb.org/us/ny/new-york/profile/cryptocurrency-ex...
[2]https://www.trustpilot.com/review/gemini.com
[edit] added quote for clarity
I hope this irony was intended!
The only scams possible in the _logic_ of Uniswap are those which would be considered bugs in the code.
Obviously, as this article points out — that’s not a panacea for _all_ scams. But I am surprised that people on a forum about hacking can’t see why eliminating an entire class of bugs could be useful.
No true crypto enthusiasts would use a centralized exchange. If they’re using an exchange, they must not be a true crypto enthusiast.
To say that centralized exchanges whom you trust to keep your assets in their custody run counter to the spirit of a system conceived with trustlessness as the defining feature is not rhetorical voodoo or fallacious reasoning.
Is there a “Every Man a Scotsman” saying?
The comment didn’t say “you’re not a crypto enthusiast _unless_ you believe X”. It just made an assertion (which, for what it’s worth, I think is incorrect) that the majority have a certain belief.
It really doesn’t matter to the meaning of my comment whether the first sentence exists or not. You can simply remove it if you like, the rest of the comment is still comprehensible. And, most importantly, its main point - to differentiate between the kind of exchange the gp was referencing and the kind the post is about, still stands.
This is all just a case of nitpicking some small detail that is so common and annoying. It’s the “your battery is dying” to a screenshot.
Even disregarding that, are we really posting wikipedia links to No True Scotsman in 2022? Has anyone not heard of NTS? It just comes across as pedantic.
Finally, you’re all hung up on the definition of “crypto enthusiast” — but it doesn’t even have meaning in the specific context. It’s just an attempt to shorten a much longer comment (like this one).
In my head, crypto enthusiast was just the 15 character version of “that group of people who are very interested in the programming and theory of decentralized economies. They tend to attend crypto conferences, program solidity or other smart contract dsls, and use phrases like ‘not your keys, not your crypto’”.
In that context the statement was mostly tautological stage setting for the rest of the comment, so for the whole thing to get derailed by low effort, kind of rude, attempts “but it’s an almost, but not quite logical fallacy (well, NTS isn’t actually a logical fallacy, but I am going to snarkily imply it is one)” sniping is not only wasted space … it’s boring.
Not addressing the argument, but pointing out a fallacy on Wikipedia.
It's just neutral infrastructure. Trying to think of an analogy, I thought... "It would be like saying 98% of transactions in $USD are scams, that wouldn't mean $USD are unsafe to use."
But once i said that in my head... it would definitely say something about a traditional currency if 98% of transactions were scams. (I know uniswap isn't a currency, that just came out of my attempt at an analogy). Something not good. About something. Maybe it doesn't mean uniswap is unsafe to use, but wow, it means something is a mess.
If it just means that there are a crazy ton of people trying scams with tokens, that sure seems like something to be aware of.
If 98% of Uniswap trades were scams then I definitely wouldn't be here discussing it.
The same applies to your USD analogy. It doesn't matter if 98% of transactions are scams if these 98% are worth a few dollars only. A scammer could make a million transaction worth a cent each. That's very different from a trillion dollars being used in a few big scam transactions.
Finally, somewhere I can sell my slaves easily!
These trading pairs are more akin to spam, to show up in the search results (somewhere else, do not show up on Uniswap). Other research find the scam volume is way less than 1% of the total trading volume. Only looking this number does not reflect the true health of the market or the controls Uniswap has in place to prevent trading these tokens.
We also do not call fake Viagram advertising email rug pull, even if it is clearly intended to steal your money without making your dick hard.
You do. If Gmail, Yahoo, or Microsoft block your sends, you might as well give up sending email.
it's the same with uniswap. you can list without permission, but you won't have any credibility unless your actions build them.
I don’t see how that’s any different that an unsuspecting/ native user rushing head first into some random scam coin they have no business paying for and getting rugged.
Some people are stupid. That will always be the case. And there will always be dirtbags trying to take advantage of them. That’s a part of life. Has nothing to do with the underlying technology of crypto.
I think that the parent makes a fair point. I'm willing to go so far as to agree that suddenly yanking support for a coin you created and put up for sale on a public marketplace can be described as pulling the rug on that coin. I don't think I would assume, though, that doing so necessarily constitutes a deliberate attempt to scam people.
Is it irresponsible? Perhaps. Though that's a somewhat subjective judgment, and I recognize that the crypto community's culture around these things runs in sharp contrast to how I think about public marketplaces, so perhaps it wouldn't be fair of me to make a value judgment.
Is it worrying? I suppose I can appreciate arguments that the kinds of regulation necessary to prevent such behavior are themselves harmful, and that this sort of thing is acceptable or even desirable insofar as it indicates the market's level of freedom. I can't bring myself to agree, though. I personally would not want to participate in a securities exchange where such behavior is rampant.
But not all worrying or irresponsible behavior is a scam.
It's a bit like saying most startups go belly-up in the first years, so we shouldn't do startups anymore.
I'm about as much of an NFT hater as you can be.
But people spend money on lots of "dumb" stuff.
So why is an NFT a scam if Pokemon cards aren't?
Both of them are artificially scarce. Both of them are mainly about buying cute pictures. And at least for a lot of the buyers, it's about speculating the price will go up in the future.
Quantity matters.
"Target stores around the country have pre-sunrise lines around the block, and the trading card sections look like bread aisles before a snowstorm or toilet paper aisles at the start of the COVID-19 pandemic as fans, collectors, and resellers are trying to arbitrage tins of Pokémon cards that can be resold for an easy profit."[1]
"The intense demand for Pokémon trading cards, which steadily rose in recent years then rocketed up even more during the pandemic, has caused Target to temporarily suspend sales of the cards, citing a threat to the safety of customers and workers."[2]
"You can probably guess what happened next. Thanks to the increased visibility of card collecting on social media, along with a surge in grading services pricing out high-value collectibles, folks are practically camping out of stores just to get the latest Pokémon card shipment. Everyone wants to find a rare card that they can flip for thousands of dollars, just like they’ve seen in the news."[3]
"YouTuber Logan Paul (USA) has recently acquired a coveted PSA Grade 10 Pikachu Illustrator card following a record-breaking trade worth $5,275,000 (£3,862,424 / €4,477,146)."[4]
[1]: https://www.vice.com/en/article/7kv9dd/target-is-prepared-to...
[2]: https://www.nytimes.com/2021/05/14/business/pokemon-cards-ta...
[3]: https://www.nytimes.com/2021/05/14/business/pokemon-cards-ta...
[4]: https://www.guinnessworldrecords.com/news/2022/4/logan-paul-...
https://www.youtube.com/watch?v=z-fxfuWhff0
I was a fan of Fate/Extra and Fate/Extella, so I was curious about Fate/Grand Order and found it very hard to run on any Android emulators, the NVIVIA Shield, AMZN Fire tablets and the other off-brand Android devices I have a huge collection of. Eventually I got it running and found the English translations make no sense at all, but it is moe-driven more than story driven and it wouldn't bother fans at all.
I guess the test token I put on Uniswap is a scam then.
Pokemon cards technically have a use case.
So do crypto kitties and smooth love potion - even if it's somehow slightly "dumber".
If I simply create a meme token and sell it to someone who speculates that it will increase in value, I don’t see how that can be considered a scam.
It’s fun for people to own and trade AMC, GameStop, Magic: The Gathering, Ethereum, NFTs, etc.
The difference is when I buy a Pokémon card, I own the physical item.
When I buy an NFT I buy a digital claim on some item, but you don’t actually own the item, you own the claim that you own the item.
And, we know that Ethereum has changed history in the past (DAO failure in 2016), and they can do it again anytime a majority of the stakeholders think it ought to be done.
I think rule-of-law property rights are more robust, or simply owning bitcoin, as its just a protocol without a group of people in change.
Pokemon cards were sold for kids to have fun, and in the end they actually are valuable, whereas NFTs were marketed as valuable, and in the end kids make fun of people buying them.
And the vast number of collectors sure as hell aren't playing games with the valuable cards they collected the past few years. Logan Paul didn't spend $5 million on a Pokemon card just so he had it to play in a Pokemon tournament, especially since it's just an illustrator promo card anyway, doesn't even have a function in the game (at least as far as I can tell, I don't follow this closely, I did have a Magic The Gathering phase, though, which was the OG TCG and also has its own craziness).
From their paper, I think sympathetic to your POV:
> For example, it is not clear that cryptocurrencies such as Doge or Shiba have any use case or intrinsic value, but they are among the most popular meme-coins. In our framework, we say that a token has no intrinsic value or use case if the developer knows that the trading price with respect to USD will eventually be zero. In other words, a tradable malicious token in Uniswap induces a zero-sum game between the users and the developers, i.e. the incentives for the investors are not aligned with those of the token creators. Therefore, the main difference between malicious and non-malicious tokens is the developer’s intentionality towards the token. One of the main problems of these definitions is that it is unfeasible to distinguish between scam tokens and under-performing or abandoned projects without accurate off-chain data.
They didn’t measure how much value was stolen by rug-pull maneuvers. Did 10,000 ‘fake’ tokens start up, run a while, and rug-pull taking $1 with them? I’d guess that’s just ‘debugging’. Did a few big rug pulls run away with a million dollars? Can we detect _those_ better?
This article is about fraud detection. The conversation should really be about the machine learning techniques used, and the actual conclusion, which is using those techniques, ” This implies that new malicious tokens can be detected prior to the malicious act,and, on the other hand, tokens supported by a strong project can also detected at an early stage.”
Yes, they built a fraud detection system... and with it discovered that 97.7% of tokens were rug pulls
"Based on this theoretical foundation, we provided a methodology to find rug pulls that had already been executed. Not surprisingly, we found that more than the 97,7% of the tokens labelled were rug pulls."
We should be talking about the techniques described in the paper, and the fact that they determined it is possible to detect early on with some confidence if a project is solid, or a scam.
This should be a positive for the “crypto bad” folks if you ask me. But this is getting lost.
Reminder that 85%+ of all email sent is spam.
They suggest that this doesn't look like an organic collapse because it happens all at once, in a coordinated manner. I don't have the expertise to evaluate that claim, but it at least seems plausible.
What seems more problematic to me is that I'm not convinced that all of these events can be considered malicious. I would think that me just dicking around on the blockchain looks the same. Maybe I try making a coin, realize getting it off the ground is not going to be worth the effort or otherwise lose interest, and then abandon the project even before it really sells much. If so, then what percentage of these coins can be explained that way? Quite a large one, I'm guessing.
Perhaps there's another argument to be made, though, that that is not a good defense of the health/safety of the market for general consumers. Lots of coins that nobody should be touching because they aren't serious perhaps doesn't look much different from lots of legitimate scams from a consumer perspective. Either way, the story for consumers is a rather rigid formulation of "caveat emptor".
Transaction fees are one reason. Speed and account UX is another. L2 development is on track to solve some of these problems.
FTX/centralized exchange: deposit your gold, counterparty deposits silver. FTX possesses the physical quantities and gives you both receipts. You agree to you exchange rate and FTX issues new receipts for what you hold, old receipts are void. You can use the new receipt to withdraw your gold and silver[0].
Uniswap: You take the amount of gold you want to trade to a building. You get to the building and exchange your physical gold for physical silver directly. You leave with your physical silver. You spent a little gold on the way to afford gasoline for the trip.
These are technically inaccurate but give an overall correct idea of the difference.
[0]most crypto users don't understand how to possess their own crypto (control private keys) so they skip the last step and leave the 'gold/silver' (crypto) in the physical custody of the exchange.
Prevents things like FTX in theory right?
Of the remaining tokens it’s likely that a large portion will rug in the future.
My biggest problem with crypto is that most people who buy and hold it are not truly libertarians looking to scale up usability in the space. They're really just gamblers who want their investment to go to $1M per bitcoin so they can convert to fiat (the irony) and retire to the Bahamas and life the big life.
Otherwise, why does the entire industry keep banging on about $100K EOY?
And I won't begrudge you that, after all, it's your money, isn't it?
But until crypto makes a hard pivot from being a speculative investment to an ecosystem encouraging day-to-dy usage, I just don't believe it has any long-term usage.
In addition, I think Zuckerberg had an extremely brilliant idea when he wanted to make a stablecoin tied to a basket of currencies - it's be stable enough to use on a day-to-day basis, and it'd still be a crypto, at least theoretically.
The only difference is that they focused on shipping products people actually wanted to buy.
All I'm saying is that the gambling should be backed up by a significant amount of work aimed at usability, call it a high signal-to-noise ratio, if you will.
So, of course they'll be gamblers in crypto and every new field - what matters is for there to be a critical mass of builders making things that can be used on a day-to-day basis vs. those trying to hitch a ride on the bandwagon.
It's exactly the same effect as evaporative cooling of online social groups: if you don't set boundaries, trolls kicked out of places that do gather in your space and people who don't like being in such a space leave, until your space is nearly all trolls and one morning you wake up to find you've made a *chan again.
Otherwise you can be taken to the cleaners by scammers wash-trading piles of dirt.
Forgive me, but isn't it only useful to detect scams before they happen?
Yesterday over $2.1B in volume cleared on Uniswap [0]. It's certainly useable by someone. If you want cheaper fees, try it on Arbitrum or Optimism.
Of course the system may still be used for the types of transactions that cannot be easily replaced by mainstreem methods (crypto scams, fraud payments, pump/dump tokens etc) but I believe in the end it will die because the number of white sheeps will get thinner.
Fees from https://l2fees.info/