CryptoReal
CASE FILE — Jul 3, 2025

A Leaked RPC Endpoint Exposed Rowan Energy's Hidden 400 Million Token Mint

Rowan Energy marketed itself as a bridge between rooftop solar and blockchain rewards: carbon-neutral mining, "SmartMiner" hardware, and a private ledger that would pay homeowners for clean energy output. Behind that pitch sat a scheme that, by outside accounts, had been running under different guises for roughly five years, built around a token contract with an undisclosed mint function and close to 400 million tokens that were never supposed to exist. An independent researcher found the flaw by picking apart Rowan's supposedly private blockchain through RPC endpoints it had left open to the public, then minted a billion tokens as a demonstration before burning them and publishing the whole trail. Thousands of investors lost their holdings while the man behind the project, David Duckworth, spent roughly 69 days issuing denials and delays before going quiet and disappearing with an estimated tens of millions of dollars.

01The pitch: tokenized solar and a ledger nobody could audit

Rowan Energy's sales language leaned on "tokenized Renewable Energy Certificates and tokenized peer-to-peer energy trading," framed as a rework of how home solar gets monetized. The plan centered on a private blockchain that would log real energy production from SmartMiner units installed in houses around the UK, with device owners reportedly collecting £450 a year for their contribution to the network. The project's whitepaper described "services in the home renewable energy markets not previously available... providing a better ROI for those active participants in renewable energy."

The RWN token picked up listings on MEXC and ProBit, and Duckworth appeared in promotional videos walking through solar installations to explain the technology. Cracks showed up early, though: solar installers around the UK began publicly declining to work with Rowan, the on-chain "energy generation proofs" the project had promised never actually appeared, and the token's underlying logic looked to outside observers like a standard ERC-20 contract dressed up as proprietary infrastructure and kept behind closed doors "for security."

02An exposed RPC endpoint unravels the private blockchain

The discovery started with complaints about Rowan's own wallet software. Users reported that the official app was sending seed phrases over HTTPS rather than signing transactions locally on-device, and AnkerPay, a secondary wallet option, was found to be leaking RPC endpoints to anyone monitoring network traffic. An anonymous researcher followed that thread, running network analysis tools against the mobile app and finding that traffic was reaching a publicly accessible RPC address, 3.19.248.157:8504 — not the encrypted, locally-signed setup a "private" chain would imply.

From there, standard Ethereum RPC calls worked against the network without modification. A totalSupply() query against the token contract returned 945,000,010 tokens in circulation — far above the 545 million ceiling Duckworth had stated on Telegram: "The maximum total supply of RWN token is now 545 million with approx 139 million in circulation." Pulling the full bytecode from contract address 0x3D3F6CeDe89a048CfC3F6eCEbAccA97684202317 and running it through a decompiler surfaced an undisclosed function sitting among the ordinary ERC-20 methods: mintToken(address,uint256).

The verification method itself was simple — plain curl requests against the exposed RPC address. The raw totalSupply() response came back as 0x83252505cfe7e800, which resolves to 945,000,010 tokens once adjusted for the contract's 10 decimal places. In practical terms, the mint function meant new tokens could be created on demand, contradicting any claim of a fixed supply.

03Minting a billion tokens to prove the point

To confirm the function actually worked rather than simply existing in the bytecode, the researcher called it directly. One transaction created 1,000,000,000 new RWN tokens out of nothing, pushing total supply from 945 million to 1.945 billion within seconds — disproving Duckworth's fixed-supply claims outright. The freshly minted tokens were then sent to a burn address almost immediately, with the burn transaction recorded on-chain at hash 0xf55d021088c9bfa078248be8fad2fae2a0837263288c34cf49c565f0ba8d8392. No funds were taken and nothing was stolen — the point was strictly to demonstrate that the supply cap was fiction.

Notably, the mint transaction never appeared on Rowan's own block explorer, even though the subsequent burn transaction did show up there. According to the researcher's account, the billion tokens sat in the wallet for four minutes and four seconds — long enough to capture a balance screenshot, short enough to avoid any ambiguity about intent — before being routed to the burn address.

04The undisclosed supply added up on its own

Beyond the demonstration mint, the researcher's follow-up analysis found that even with visibility into just 2.84% of all transactions via the limited explorer data available, known wallet balances alone already totaled 589 million tokens. MEXC's wallet held 266 million tokens by itself — nearly half of the supply Duckworth had publicly claimed existed in total. The broader breakdown of known holdings showed MEXC at 266 million tokens, ProBit at 34 million, a buyback wallet at 7 million, and 302,199 tokens sent to burn addresses.

By the researcher's estimate, the roughly 400 million tokens that were never disclosed would have been worth around $132 million at 2024's price peak for the RWN token. Rowan's block explorer, meanwhile, continued to display only a partial picture of on-chain activity, omitting the transactions that undercut the project's official numbers. All of the supporting material — transaction hashes, decompiled bytecode, RPC call outputs, and wallet balance screenshots — was published publicly. Duckworth did not respond to the findings.

05A name that had surfaced before

Reports suggest this was not Duckworth's first vanishing act. On the PropertyTribes forum in August 2011, a thread titled "David Duckworth gone missing?" documented users trying to reach him after he stopped responding, in the context of property investment dealings. One user, John Corey, wrote: "Anyone have David's number? Mobile would be best?" Alleged unpaid fees and abandoned partners from that earlier episode, according to those accounts, followed a similar pattern: solicit money on the promise of strong returns, go silent under scrutiny, then disappear. If the property-sector allegations are accurate, Rowan Energy would represent the same approach applied fourteen years later to a larger pool of victims, with blockchain terminology substituted for real-estate jargon.

06Sixty-nine days of denials before the project folded

Once the mint function became public, Duckworth's public statements followed a drawn-out pattern of denial, contradiction, and stalling, according to posts attributed to him:

  • April 16: "Claims are entirely false and misleading."
  • April 21: "Circulating supply has NOT increased."
  • April 21 (same day, different explanation): "Security lockdown initiated after discovering exploited unauthorized access point."
  • April 22: "Investigation ongoing, blockchain fully operational."

In the weeks that followed, vague assurances that updates were coming "next week" or were "almost ready" recurred repeatedly without any of the promised deadlines being met. By June 6, after roughly seven weeks without a substantive update, the message was still just "Update coming early next week," with no acknowledgment of the mint function, no audit, and no additional transparency offered. On June 21, the project's Telegram group was switched to announcement-only mode, cutting off investor questions. On June 24, Rowan Energy announced it was shutting down, citing "technical and reputational challenges" — language that named neither the mint function nor any fraud allegation directly.

07A parallel hardware business with its own complaints

Separate from the token, Rowan Energy also sold physical SmartMiner devices to homeowners across the UK, marketed as a complementary income stream alongside the RWN token. The offer was a £1,500 unit installed alongside existing solar panels, projected to generate £450 a year in carbon-credit income with a roughly three-year payback period. A number of customers bought in, and the hardware was physically installed in homes by outside contractors.

TrustPilot reviews for the company reflect widespread dissatisfaction, with one-star ratings including comments such as: "Zero stars if I could. Repeated promises, zero payments," "Device installed, money gone, support vanished," and "Three months past due, no payments, no contact." ESE Group carried out many of the installations; that company has its own prior conviction for deceiving customers in the UK solar sector. It remains unclear whether the hardware arm was a coordinated second scheme or simply became collateral damage once the token side collapsed.

08What was left behind

After the shutdown, Duckworth's online presence was largely erased: promotional YouTube videos, Twitter posts, and Telegram history disappeared, and his LinkedIn profile was scrubbed. RWN was delisted from its exchanges, and Rowan's blockchain infrastructure went offline. The SmartMiner units already installed in UK homes remained in place, now non-functional hardware that customers had paid roughly £1,500 apiece for.

Affected users have continued organizing outside official channels, including in an unofficial Telegram group formed to compile evidence, with some reportedly pursuing legal counsel. Unlike the deleted social media accounts, the on-chain record — the mint and burn transactions, the contract bytecode, the wallet balances — remains publicly verifiable and was not something Duckworth could remove.

Credit: Anonymous Researcher 1, Anonymous Researcher 2, PropertyTribes, TrustPilot, Conor Quinn, victim Telegram group, Newbury Today, Decrypt

Clean EnergyRowan EnergyRug Pull
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.