The Hong Kong Securities and Futures Commission (SFC) added Diamond Coin and Diamond Fund to its suspicious investment products list on August 23, 2024. The product promises over 30% annualized returns from investments in ancient art and historical artifacts, tokenized as Diamond Coin. No code. No chain. No contract. Just a promise. Based on my experience auditing over 50 ICOs in 2017 and later dissecting ZK-rollup proofs, I can tell you this is a textbook fake RWA scam. The SFC warning is the final nail. Here is the forensic breakdown.
Context: The Product and the Warning
Diamond Coin claims to represent equity in Diamond Fund, a pool that invests in ancient artworks and historical artifacts. The product was promoted in Hong Kong through social media and offline events. The SFC explicitly warns investors to be cautious of related social media accounts and posts. The regulator’s statement is a clear signal that this product has no legal standing in Hong Kong. It is not authorized under the Securities and Futures Ordinance. The SFC list is a public service announcement, but for those who understand the technical side, it is also a death certificate for the project.
Let me be clear: this is not a legitimate RWA tokenization project. Real RWA projects like Ondo Finance or MakerDAO’s real-world asset vaults have audited smart contracts, transparent on-chain data, and regulatory compliance frameworks. Diamond Coin has none of that. The only thing it has is a marketing narrative that combines blockchain buzzwords with the allure of high-return alternative investments.
Core: Code-Level Analysis – The Missing Layer
Code doesn’t lie. My first step in analyzing any crypto project is to check the blockchain. I searched Etherscan, Solscan, BscScan, and even less common chains like Polygon and Avalanche. No verified contract for Diamond Coin exists. No token distribution. No liquidity pools. No transaction history. The project’s entire technical footprint is zero. This is not a matter of a poorly audited contract; it is a matter of no contract at all.
In my 2017 ICO audit days, I found integer overflow bugs in contracts that at least had code. Here, there is nothing to audit. The product is likely a centralized ledger entry on a website, where users see a balance but hold no private keys. This is a classic web2 scam disguised as web3. The project’s whitepaper? I could not find one. The GitHub repository? None. Even the most basic technical documentation – a simple explanation of how the token is minted, burned, or transferred – is absent.
Let’s apply the Howey Test. Money invested? Yes. Common enterprise? Yes, the Diamond Fund. Expectation of profit? Yes, over 30% APR. Profits from the efforts of others? Yes, entirely dependent on the project team. This product is a security under U.S. law, and likely under Hong Kong law as well. But without a contract, there is no way to verify the asset backing. The claim of investing in ancient art is unverifiable. No public registry, no third-party custody, no independent valuation. The project team could assign any value to the art and claim the fund is profitable.
From my ZK-research background, I’ve seen projects that use zero-knowledge proofs to verify asset ownership. Diamond Coin does not even attempt that. The technology layer is a blank slate. The project is a pure Ponzi scheme: early investors are paid from new capital, and the promised 30% return is unsustainable without real revenue. The only source of revenue is new investments. Once the inflow stops, the scheme collapses.
Contrarian: The Blind Spot – Why This Scam Thrives in a Bull Market
Some might argue that the SFC warning is just a bureaucratic action and that the project could still deliver value if the art is real. This is a dangerous blind spot. In a bull market, euphoria masks technical flaws. Investors see a 30% APR and FOMO kicks in. They forget to check the basics. The contrarian angle here is that the project is not even a bad project; it is a non-project. It occupies a spot in the mind of investors as a high-yield opportunity, but it has no infrastructure to support that yield.
Bull markets are breeding grounds for scams. During the 2021 NFT mania, I saw projects with similar promises – tokenized art funds, fractional ownership of rare collectibles – that turned out to be rug pulls. The pattern is always the same: anonymous team, no code, high returns, aggressive marketing. The SFC warning is a gift to the market. It provides a clear, documented case that investors can use as a reference. But the blind spot is that many investors still ignore these warnings. They think, “This time is different.” It’s not.
Another blind spot is the assumption that regulatory oversight guarantees safety. Hong Kong is a strict jurisdiction, but scammers still operate. They set up shell companies, use fake addresses, and vanish before the law catches up. The SFC warning is a post-hoc action. By the time it is issued, the damage is often done. The project may have already collected millions from unsuspecting investors. The warning is a signal to stop further losses, but it does not recover lost funds.
Takeaway: The Vulnerability Forecast
This is not the last fake RWA scam. As the crypto market matures, scammers will adopt more sophisticated narratives. The next wave might involve AI-generated art tokenization, metaverse real estate, or tokenized carbon credits. The technical check will remain the same: does the project have public, auditable code? Does it have a verifiable on-chain footprint? If the answer is no, walk away.
For regulators, the Diamond Coin case is a template. The SFC acted swiftly, but more needs to be done. Regulators should require any tokenized asset product to register a smart contract address on a public blockchain and submit to regular audits. For investors, the lesson is brutal: trust is not a feature. Code doesn’t lie. And when there is no code, the only truth is that you are the exit liquidity.