Check Point Research reported that scammers and attackers used fraudulent crypto tokens and misconfigured smart contracts to steal funds from investors and liquidity pools. The activity included tokens with hidden or adjustable buy and sell fees, owner-controlled anti-sell mechanisms, and minting functions that let creators manipulate supply or trap holders. Examples included the M3 token’s concealed fee logic and the MINI BASKETBALL token’s owner-controlled restrictions that could prevent users from selling.
The report also detailed exploits tied to weak contract design and operational failures. In one case, the Levyathan contract was compromised after an exposed private key and flawed emergencyWithdraw logic were abused, while the Zenon Network incident involved an externally callable burn function that was exploited to drain about $814,570. Researchers urged users to rely on established exchanges and tokens and to verify marketplace URLs carefully to reduce exposure to token fraud, phishing, and smart-contract abuse.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published an analysis describing fraudulent token patterns and smart-contract misconfigurations used to steal investor funds, including the M3, MINI BASKETBALL, Levyathan, and Zenon Network cases.
The report states that scammers obtained $14 billion in cryptocurrency in 2021, providing broader context for the scale of crypto fraud.
The report states that the Zenon Network lost approximately $814,570 after an attacker abused an externally callable burn function, manipulated the token's internal pricing logic, and drained the liquidity pool.
Check Point Research found that Levyathan also had an emergencyWithdraw flaw using rewardDebt instead of user.amount, and said attackers exploited it multiple times with more than 57 observed calls.
After obtaining the exposed MasterChef private key, an attacker minted millions of tokens and later withdrew all funds from the Levyathan contract.
According to the report, a Levyathan developer mistakenly uploaded the MasterChef contract private key to the project's GitHub repository, exposing control of the contract.
The report identified MINI BASKETBALL as a token whose transfer logic initially prevented anyone from selling and later allowed only two addresses to sell. Check Point said the token had more than 3,500 buyers and over 14,000 transactions.
Check Point Research said the M3 token contract contained a hidden fee mechanism and that its operators initially set the fee parameter to 8 before later changing it to 99 after blockchain tools had scanned the contract.
The article references the SQUID token scam, which BBC reported stole $3.38 million from crypto investors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.