Greed for Blur airdrop, turns out Blast L2 is all fake? Developer exposes exit scam risk
The profit-sharing L2 network Blast recently launched by Blur is gaining popularity as locked assets continue to rise, with the media touting record-breaking numbers. However, research by a Polygon developer has revealed that the L2 mentioned by Blur is simply a multi-signature control contract that can be abandoned with just 3 out of 5 signatures.
Exploring Blur's profit-sharing L2 network Blast: on-chain native interest rates, sustainable NFT contracts, and more.
Table of Contents
Developer: Blast is not L2
Polygon developer Jarrod Watts first explained many common centralized technical issues found in L2 solutions like Arbitrum, OP, Linea, Base, Scroll, Polygon zkEVM, and zkSync. However, he emphasized the key difference: "Blast is not L2."
He stated, "Blast is a smart contract:
1/ Accepts user funds.
2/ Stakes user funds in protocols like LIDO."
There is no testnet, no transactions, no bridging, no Rollup, and no sending of transaction data to Ethereum. It is not L2.
"Blast is just a 3/5 multisig…"
I spent the past few days diving into the source code to see if this statement is actually true.
Here's everything I learned:
— Jarrod Watts (@jarrodWattsDev) November 23, 2023
Blast, the airdrop sought after by crypto traders, is just a smokescreen
Cybersecurity company SlowMist founder Yu Xian commented that when testing the Blast contract, he found that Blast is indeed controlled by a 3/5 multisig, can be upgraded and changed, and has no time lock, making it easy to exit scam.
Yu Xian commented that this so-called L2, apart from the contracts deployed on Ethereum, is essentially a centralized Web2 gimmick, endorsed by a bunch of well-known institutions.
"So, do you still believe in the technology? What are you really believing in? You believe in those institutions, how can you not believe? Even any random dog has a bunch of believers... There's no need to talk about decentralization anymore in the future, don't talk about any technical architecture, just deploy a contract on Ethereum first (at least some code that can be verified), and take it from there."
At the time of submission, Blast and Pacman had not issued an official response.
测试 Blast 时,就简单过了一遍其合约安全:
– 是个可升级合约,Owner 3/5 多签(不知道都是谁),没时间锁
– 如果要跑路,要么多签升级个恶意的逻辑合约,要么 enableTransition 设置个恶意的 mainnetBridge这个所谓的 L2 目前除了发在以太坊上的合约,其他都是中心化 Web2… https://t.co/AR3y4ply0d
— Cos(余弦)😶🌫️ (@evilcos) November 23, 2023