Source: https://x.com/SlorgoftheSlugs/status/1830769369049375204
Scammers have found a way to burn tokens inside your Solana wallet
But with a little awareness you can avoid becoming their next victim.
๐งต(1/8)
https://preview.redd.it/9oz43j42xmmd1.png?width=679&format=png&auto=webp&s=14514c1a37a9656a886cc2785473a686eb58c798
Imagine you swap for a token and the wallet history confirms that you received it.
But then you look inside and nothing shows up.
You begin to panic, but you assume the network is just being slow.
โ
Time passes and no tokens, so you do some digging and reach out to someone who might know what’s going on.
This was the reality for a Jupiter Community Member 4 days ago.
So where did they go?
โ
After the Moderation Staff looked into it, something stood out on the Solscan page:
There was a burn transaction only 7 seconds after the user had received the tokens.
They swapped, but then were almost immediately burned.
How?
https://preview.redd.it/9td74p56xmmd1.png?width=680&format=png&auto=webp&s=09f8f3e77b269f48d55a42781334f7775665d320
The token had a ‘Permanent Delegate’.
This is a token extension that gives an address authority over a supply, allowing any token to be burnt at will.
The idea behind it is to allow for things like Sanctions to be enforceable, but scammers are using it cleverly.
https://preview.redd.it/5ubpgjk7xmmd1.png?width=680&format=png&auto=webp&s=c371469a1016ea090e93f3bed6be5b63ed884474
Luckily, certain entities like @JupiterExchange & @Rugcheckxyz are aware and have spun up indicators for when this extension is turned on. But not every site does this at the moment.
https://preview.redd.it/rz55e4f9xmmd1.png?width=680&format=png&auto=webp&s=6b51665b89f394705cb1c36d1f15e860f747e51c
And even so, having a permanent delegate doesn’t prevent something from being swapped.
After all, it is a legitimate token extension and meant to be used by real tokens.
โ
Regardless, practicing due diligence with any token is crucial.
Always have a routine that you don’t deviate from, and take your time to read all the text when making a swap.
If not, it could end up costing you some day โ especially as new token capabilities are developed.
โ
And if you enjoyed the thread:
Make sure to retweet the initial post to help spread awareness of this scam
https://preview.redd.it/r6ugzd4gxmmd1.png?width=504&format=png&auto=webp&s=3854c2c1f0fd31f7658f0427591849e54d4d8d09