{"investigation":{"slug":"riskonblast","entity_name":"RiskOnBlast","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":0.93,"status":"published","content_type":"investigation","summary":"RiskOnBlast was a GambleFi (gambling and exchange) platform launched on the Blast Layer-2 network in February 2024. Its anonymous team executed an exit scam (rug pull) on February 24, 2024, draining approximately 420 ETH (~$1.3 million) from over 750 investor wallets immediately after the IDO cap was reached. The project is linked by on-chain evidence to a serial fraud group responsible for more than $20 million in losses across multiple DeFi protocols.","sections":[{"content":"RiskOnBlast marketed itself as a GambleFi platform on the Blast Layer-2 network, offering crypto betting games and a RISK token. It participated in Blast's BIG BANG competition and received an 'Undeniable' rating, which lent it a degree of perceived legitimacy and helped attract investor confidence. The project held an uncapped Initial DEX Offering (IDO) beginning February 22, 2024, which closed the following day after raising its 420 ETH target. The team was fully anonymous and had no disclosed identities or verifiable track record prior to launch.","heading":"Overview","sources":[{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/279004/blast-gamblefi-platform-riskonblast-rugpull","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 24, 2024 at 14:35 UTC, the IDO creator called the contract's withdraw() function on the IDO contract (address: 0x25f8c342e430c85829ef5021c0720f0c60969840, created February 22, 2024) just 17 minutes after the 420 ETH threshold was reached, liquidating all investor funds in a single transaction. The IDO creator wallet is identified on-chain as 0x1eeb963133f657ed3228d04b8cd9a13280efc558. Immediately following the withdrawal, the team deleted their website and all social media accounts including their official X (formerly Twitter) account. Coinbase tech lead Andrew Choi issued a public alert on February 25 noting the sudden disappearance of the project's online presence. CertiK Alert confirmed the X account had gone dark shortly after funds were siphoned.","heading":"Exit Scam Mechanics","sources":[{"url":"https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/community/articles/65dc7184761bde6939a5fc4e/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to CertiK's on-chain analysis, the 420.50 ETH (~$1.3 million) was laundered through multiple routes to obscure the trail. Approximately $494,912 was sent to ChangeNow (a non-custodial swap service), $385,743 to MEXC exchange, $193,055 to Bybit, $125,000 to Railgun (a privacy protocol), $24,800 bridged via ThorChain to a Cosmos wallet (cosmos12alg6yvhz9ympry4h2zhsy0547t6llx8grnprd), $24,759 bridged via RangoBridge to an Arbitrum wallet (0x09c366e8ec6cc5c53454ac16d237cf7fa719783e) which aggregated $129,100 before routing to Binance, and additional funds via deBridge and SideShift. Blockchain researcher Amir Ormu reported that approximately $850,000 was laundered through ChangeNow as a mixer. On-chain researcher SomaXBT documented the full fund flow and confirmed funds were stolen from over 750 victim wallets, with individual losses including at least one investor reporting a loss exceeding $12,500.","heading":"Fund Flows and Laundering","sources":[{"url":"https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/blast-ecosystems-riskonblast-rug-pulls-1-3m-ether-in-apparent-scam/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/community/articles/65dc7184761bde6939a5fc4e/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT and other on-chain investigators identified RiskOnBlast as linked to a serial fraud group with alleged responsibility for more than $20 million in aggregate losses across multiple DeFi protocols and blockchain networks. According to ZachXBT's analysis published in April 2024, the same group allegedly responsible for RiskOnBlast subsequently moved approximately $1 million in laundered proceeds onto Blast to seed a new project called Leaper Finance. ZachXBT also flagged ZebraLending on Base as a suspected concurrent operation by the same group, which held $311,000 in TVL at the time of flagging. Other protocols attributed to this group include: Magnate Finance on Base (alleged losses of $6.5 million), Kokomo Finance ($4 million), Solfire Finance on Solana ($4.8 million), Lendora Protocol on Scroll, and several others including Hash DAO and Glori Finance. The group's alleged modus operandi involves forging KYC documents, engaging low-credibility audit firms to appear legitimate, seeding liquidity from prior scam proceeds to grow TVL toward seven-figure targets before executing an exit. Following exposure of Leaper Finance and Glori Finance by ZachXBT, both projects deactivated their social media accounts and websites went dark — consistent with the pattern observed in RiskOnBlast.","heading":"Linked Fraud Group and Serial Activity","sources":[{"url":"https://crypto.news/blockchain-fraud-group-strikes-again-launches-fresh-scheme-on-blast-network/","name":"crypto.news","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/blockchain-fraud-group-shifts-1m-to-blast-for-new-schemes","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://invezz.com/news/2024/04/15/blasts-leaper-finance-flagged-the-group-of-scammers-who-stole-8-figures/","name":"invezz.com","type":"other","credibility":3},{"url":"https://beincrypto.com/fraud-ethereum-layer-2-base-blast-arbitrum/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/warning-malicious-group-threatening-layer-2-networks-exposed/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"RiskOnBlast is widely cited as the first confirmed exit scam on the Blast network and ranks among the top three largest exit scams on token presale projects in 2024 by value lost. The incident occurred while Blast was still in its pre-mainnet testnet phase (mainnet was not launched until February 29, 2024), drawing attention to the absence of project vetting mechanisms. The rug pull raised questions about Blast's BIG BANG competition vetting standards, given the project had received a positive competition rating before executing the scam. No law enforcement actions or arrests related to the RiskOnBlast incident have been publicly reported as of May 2026. Stolen funds routed to centralized exchanges (MEXC, Bybit, Binance) have not been publicly reported as frozen or recovered.","heading":"Platform Context and Blast Network Response","sources":[{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/community/articles/65dc7184761bde6939a5fc4e/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.ccn.com/news/blasts-first-scam-riskonblast-suffers-rug-pull/","name":"ccn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple risk indicators were present before and during the RiskOnBlast incident: (1) Fully anonymous founding team with no disclosed identities or verifiable history. (2) No reputable security audit from a recognized firm prior to the IDO. (3) Uncapped IDO structure with an immediate withdrawal mechanism callable by the deployer. (4) The project was launched on a network still in pre-mainnet phase with limited safeguards. (5) Presale ran only two days (February 22-23, 2024) before closing, and funds were drained within 48 hours. (6) The project alleged a previous '$1 million seed round' which investigators have not independently verified and which may itself have been fabricated to inflate credibility. These factors are consistent with patterns identified by ZachXBT in the broader serial fraud group's operations across other protocols.","heading":"Red Flags and Risk Indicators","sources":[{"url":"https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"coindesk.com","type":"other","credibility":3},{"url":"https://crypto.news/blockchain-fraud-group-strikes-again-launches-fresh-scheme-on-blast-network/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-02-22","event":"RiskOnBlast IDO contract (0x25f8c342e430c85829ef5021c0720f0c60969840) deployed on Blast L2. RISK token presale opens.","source":""},{"date":"2024-02-23","event":"IDO closes after reaching 420 ETH (~$1.25 million) cap from over 750 investor wallets.","source":""},{"date":"2024-02-24","event":"At 14:35 UTC, IDO creator wallet (0x1eeb963133f657ed3228d04b8cd9a13280efc558) calls withdraw() on the IDO contract 17 minutes after cap is confirmed, draining all 420.50 ETH. Team deletes website and social media accounts.","source":""},{"date":"2024-02-25","event":"Coinbase tech lead Andrew Choi alerts the community to disappearance of project's website and X account. On-chain researchers SomaXBT and Amir Ormu begin documenting fund flows. Funds are distributed to ChangeNow (~$495k), MEXC (~$386k), Bybit (~$193k), Railgun (~$125k), and other services.","source":""},{"date":"2024-02-26","event":"CoinDesk and multiple crypto outlets report the incident as the first confirmed exit scam on Blast network. CertiK publishes on-chain incident analysis.","source":""},{"date":"2024-04-14","event":"ZachXBT publicly identifies Leaper Finance on Blast as a new project being funded by the same fraud group, with ~$1 million in laundered funds from prior scams (including alleged RiskOnBlast proceeds) seeded into the protocol.","source":""},{"date":"2024-04-15","event":"ZachXBT also flags ZebraLending on Base as a concurrent suspected operation by the same group (~$311k TVL). Following the exposure, Leaper Finance and Glori Finance deactivate social media and websites, consistent with the RiskOnBlast pattern.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","name":"CoinDesk: Blast Ecosystem Sees First Apparent Scam as RiskOnBlast Rug Pulls $1.3M Ether","type":"news_article","archive_url":"http://web.archive.org/web/20260311012502/https://www.coindesk.com/markets/2024/02/26/blast-ecosystem-sees-first-apparent-scam-as-riskonblast-rug-pulls-13m-ether","credibility":1,"archive_timestamp":"2026-03-11T01:25:02+00:00"},{"url":"https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","name":"CertiK: Risk On Blast Incident Analysis","type":"research","archive_url":"http://web.archive.org/web/20260220020347/https://www.certik.com/resources/blog/risk-on-blast-incident-analysis","credibility":2,"archive_timestamp":"2026-02-20T02:03:47+00:00"},{"url":"https://www.theblock.co/post/279004/blast-gamblefi-platform-riskonblast-rugpull","name":"The Block: Blast-based GambleFi platform RiskOnBlast allegedly rugpulled presale participants for $1.3 million","type":"news_article","archive_url":null,"credibility":1,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/blockchain-fraud-group-strikes-again-launches-fresh-scheme-on-blast-network/","name":"crypto.news: Blockchain fraud group strikes again, launches fresh scheme on Blast network","type":"news_article","archive_url":"http://web.archive.org/web/20260521044108/https://crypto.news/blockchain-fraud-group-strikes-again-launches-fresh-scheme-on-blast-network/","credibility":2,"archive_timestamp":"2026-05-21T04:41:08+00:00"},{"url":"https://cointelegraph.com/news/blockchain-fraud-group-shifts-1m-to-blast-for-new-schemes","name":"CoinTelegraph: Blockchain fraud group shifts $1M to Blast for new schemes","type":"news_article","archive_url":"http://web.archive.org/web/20260724163442/https://cointelegraph.com/news/blockchain-fraud-group-shifts-1m-to-blast-for-new-schemes","credibility":1,"archive_timestamp":"2026-07-24T16:34:42+00:00"},{"url":"https://cryptonews.com/news/blast-ecosystems-riskonblast-rug-pulls-1-3m-ether-in-apparent-scam/","name":"CryptoNews: Blast Ecosystem RiskOnBlast Rug Pulls $1.3M Ether in Apparent Scam","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://invezz.com/news/2024/04/15/blasts-leaper-finance-flagged-the-group-of-scammers-who-stole-8-figures/","name":"Invezz: Blast's Leaper Finance flagged; the group of scammers who stole 8 figures","type":"news_article","archive_url":"http://web.archive.org/web/20260726032436/https://invezz.com/news/2024/04/15/blasts-leaper-finance-flagged-the-group-of-scammers-who-stole-8-figures/","credibility":2,"archive_timestamp":"2026-07-26T03:24:36+00:00"},{"url":"https://beincrypto.com/fraud-ethereum-layer-2-base-blast-arbitrum/","name":"BeInCrypto: Fraud Syndicate Targets Ethereum Layer 2 Base Blast Arbitrum","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptopotato.com/warning-malicious-group-threatening-layer-2-networks-exposed/","name":"CryptoPotato: Warning Malicious Group Threatening Layer-2 Networks Exposed","type":"news_article","archive_url":"http://web.archive.org/web/20260605230938/https://cryptopotato.com/warning-malicious-group-threatening-layer-2-networks-exposed/","credibility":2,"archive_timestamp":"2026-06-05T23:09:38+00:00"},{"url":"https://coinmarketcap.com/community/articles/65dc7184761bde6939a5fc4e/","name":"CoinMarketCap Community: RiskOnBlast Team Disappeared With Over 420 ETH In A RISK Token Rugpull","type":"community_report","archive_url":"http://web.archive.org/web/20260724170629/https://coinmarketcap.com/community/articles/65dc7184761bde6939a5fc4e/","credibility":3,"archive_timestamp":"2026-07-24T17:06:29+00:00"},{"url":"https://www.ccn.com/news/blasts-first-scam-riskonblast-suffers-rug-pull/","name":"CCN: Blast's First Scam RiskOnBlast Suffers Rug Pull","type":"news_article","archive_url":"http://web.archive.org/web/20250901162805/https://www.ccn.com/news/blasts-first-scam-riskonblast-suffers-rug-pull/","credibility":2,"archive_timestamp":"2025-09-01T16:28:05+00:00"},{"url":"https://crypto.news/blast-network-layer-2-project-prey-500-eth-rug-pull/","name":"crypto.news: Blast network layer 2 project falls prey to 500 ETH rug pull","type":"news_article","archive_url":"http://web.archive.org/web/20251114085541/https://crypto.news/blast-network-layer-2-project-prey-500-eth-rug-pull/","credibility":2,"archive_timestamp":"2025-11-14T08:55:41+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:34.828379+00:00","updated_at":"2026-08-29T01:32:58.209+00:00"}}