Projects presented fake security-audit reports claiming zero-vulnerability contracts. Retail investors bought heavily. The team exploited contract backdoors to steal user assets.