Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sybil Attacker Report #610

Open
Annu2047 opened this issue May 23, 2022 · 2 comments
Open

Sybil Attacker Report #610

Annu2047 opened this issue May 23, 2022 · 2 comments

Comments

@Annu2047
Copy link

Annu2047 commented May 23, 2022

Related Addresses

20 addresses:

0x0b1937f6ee406ca9e44dd99035da38840c242a9d
0xd5521ec73340df8522f47ecfed7324405d9312d5
0x71c4fa6a4fb81f67b670b06ddc44de24ed7f5326
0x7f405cf888cd86b6ddf239b6e800fe041c9bbc32
0x354044d39f1e31109ecab3407b99b2ad5ed6515d
0xa4caccef0dd28212b2aff92443bd560ba83ff428
0x1d19da85322c5f14201be546c326e0e6f521b6e6
0x992fb4f41663388cc611e8ef25e714a1541e456f
0x738c5dbca9f2d022174c7abf99da5bec001fc54d
0xcce0e1ab3ad9a9935a8b6814a337afe96b87b759
0x1b3dff537b7d46a0d30b1d20b101c483586747aa
0xad05b50b71d1c05e3309e9f99e633a21741b77d9
0x2b5ef7f8d42feb86ba3d4eec6e325ec314105f29
0x3f0c713b4e3fc2f56cfdbfcac0b45c927045a833
0x1fd8a6cf3ff837799d7416af511249df06fa3399
0x713996bb0e138f3b72f67baa9dc162dcccae132f
0x044504d5b1e4a2fe9822f290cfb836c82db1995a
0x082b9b776e5d0b1771594676d12619f479b0a69c
0x950a0be4d5e7c63017debfae67ada866b55e7335
0x659a88d1fc5065126a90ebf908379db1d5c94e37

Reasoning

All address received (0.01 - 0.14)ETH from 0x2fc617e933a52713247ce25730f6695920b3befe on arbitrum network

Tx details:

0x0b1937f6ee406ca9e44dd99035da38840c242a9d(https://arbiscan.io/tx/0x72ff8af64a4bab6afbb75da52fc8925bacc71420a5eb8f5b821b557bf508b277)
0xd5521ec73340df8522f47ecfed7324405d9312d5(https://arbiscan.io/tx/0x2fb94e1fc7f091534dc7ccabef348fe128b6779c880ea52fc59f3c596ba54a43)
0x71c4fa6a4fb81f67b670b06ddc44de24ed7f5326(https://arbiscan.io/tx/0xfa9bb83430e75dfdc3c54133a8a5c6b831ed4b54cde8d58f67769be6ffad07bc)
0x7f405cf888cd86b6ddf239b6e800fe041c9bbc32(https://arbiscan.io/tx/0xd4cf2efab465f3ed3d8228e6f417e3506cfcdcf41e50e511eb2a96b315c344b2)
0x354044d39f1e31109ecab3407b99b2ad5ed6515d(https://arbiscan.io/tx/0x9e346bad526e1319ae27831be301a12ca180629c8471eb2affb10a462fda9167)
0xa4caccef0dd28212b2aff92443bd560ba83ff428(https://arbiscan.io/tx/0x0bf2ea5c17a99b5b34cd0ca84c979d53284cd09c6b74fd197a75a01147d9636c)
0x1d19da85322c5f14201be546c326e0e6f521b6e6(https://arbiscan.io/tx/0x08bba579ab29f5124a7a2588cb117862ac69e5bedd4a40cb266a255bbe2e6fcf)
0x992fb4f41663388cc611e8ef25e714a1541e456f(https://arbiscan.io/tx/0x85b069d0c9436c0fd41447d3b019b388ac62b70ee6f2c4419074d105f8756e97)
0x738c5dbca9f2d022174c7abf99da5bec001fc54d(https://arbiscan.io/tx/0xc225a4c37f6a6b82a3a51f71ae87705f8fc32348811b9a659e9c244c3c2c7f7c)
0xcce0e1ab3ad9a9935a8b6814a337afe96b87b759(https://arbiscan.io/tx/0xf2c7c15c5fe44d339d89a8f29a539077d03dfef8ed0a015ac8b1198ba584e667)
0x1b3dff537b7d46a0d30b1d20b101c483586747aa(https://arbiscan.io/tx/0xe5def2c3e2595b350220df228e1ce1a3d3915e44a8a4394d7e6a0b795a33d019)
0xad05b50b71d1c05e3309e9f99e633a21741b77d9(https://arbiscan.io/tx/0xfe2553a056ebcc31cc5eddc81a7b2ae219a6f2d472e827568151425980c84570)
0x2b5ef7f8d42feb86ba3d4eec6e325ec314105f29(https://arbiscan.io/tx/0x3fa5b8c7f96f04cdd1e6d691f1bc3e570bbb5c3e63fa037175a2ec75e2877c7e)
0x3f0c713b4e3fc2f56cfdbfcac0b45c927045a833(https://arbiscan.io/tx/0x5d31d43b03b3e7846c6427bdfe402cf73d2b7a63e32310b1c6f2e6f70971821b)
0x1fd8a6cf3ff837799d7416af511249df06fa3399(https://arbiscan.io/tx/0x155d3d9a9eb2e390da3afcbb26f66a64baf40ccd09843930ac431895a60d3c19)
0x713996bb0e138f3b72f67baa9dc162dcccae132f(https://arbiscan.io/tx/0xd26b7c3ba5962d2d5b29f10f577185031084dc5d70745e5048d4104938fd17c7)
0x044504d5b1e4a2fe9822f290cfb836c82db1995a(https://arbiscan.io/tx/0x5dea1a67895be989634df43a68211f8bc5d02e1c6be00f5171f7a5df0f223f57)
0x082b9b776e5d0b1771594676d12619f479b0a69c(https://arbiscan.io/tx/0xc22996c8ac522a3e806d222ce4f2b17497e1b8d1a6ea95d5a7e5080a81e424c8)
0x950a0be4d5e7c63017debfae67ada866b55e7335(https://arbiscan.io/tx/0xe39b8d927e72405cd4d3822a3bdd83ad4a4f3ca8df24c66fdada470618a4a23a)
0x659a88d1fc5065126a90ebf908379db1d5c94e37(https://arbiscan.io/tx/0xa3704d2d1b9121f4727596485509a7264bb66430e31f2ca5320bc4ddb05a36f5)

All addresses farmed Galaxy OAT (OAT) around 2022-04 for GAL airdrop.

Tx details:
0x0b1937f6ee406ca9e44dd99035da38840c242a9d(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x0b1937f6ee406ca9e44dd99035da38840c242a9d)
0xd5521ec73340df8522f47ecfed7324405d9312d5(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0xd5521ec73340df8522f47ecfed7324405d9312d5)
0x71c4fa6a4fb81f67b670b06ddc44de24ed7f5326(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x71c4fa6a4fb81f67b670b06ddc44de24ed7f5326)
0x7f405cf888cd86b6ddf239b6e800fe041c9bbc32(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x7f405cf888cd86b6ddf239b6e800fe041c9bbc32)
0x354044d39f1e31109ecab3407b99b2ad5ed6515d(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x354044d39f1e31109ecab3407b99b2ad5ed6515d)
0xa4caccef0dd28212b2aff92443bd560ba83ff428(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0xa4caccef0dd28212b2aff92443bd560ba83ff428)
0x1d19da85322c5f14201be546c326e0e6f521b6e6(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x1d19da85322c5f14201be546c326e0e6f521b6e6)
0x992fb4f41663388cc611e8ef25e714a1541e456f(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x992fb4f41663388cc611e8ef25e714a1541e456f)
0x738c5dbca9f2d022174c7abf99da5bec001fc54d(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x738c5dbca9f2d022174c7abf99da5bec001fc54d)
0xcce0e1ab3ad9a9935a8b6814a337afe96b87b759(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0xcce0e1ab3ad9a9935a8b6814a337afe96b87b759)
0x1b3dff537b7d46a0d30b1d20b101c483586747aa(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x1b3dff537b7d46a0d30b1d20b101c483586747aa)
0xad05b50b71d1c05e3309e9f99e633a21741b77d9(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0xad05b50b71d1c05e3309e9f99e633a21741b77d9)
0x2b5ef7f8d42feb86ba3d4eec6e325ec314105f29(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x2b5ef7f8d42feb86ba3d4eec6e325ec314105f29)
0x3f0c713b4e3fc2f56cfdbfcac0b45c927045a833(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x3f0c713b4e3fc2f56cfdbfcac0b45c927045a833)
0x1fd8a6cf3ff837799d7416af511249df06fa3399(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x1fd8a6cf3ff837799d7416af511249df06fa3399)
0x713996bb0e138f3b72f67baa9dc162dcccae132f(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x713996bb0e138f3b72f67baa9dc162dcccae132f)
0x044504d5b1e4a2fe9822f290cfb836c82db1995a(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x044504d5b1e4a2fe9822f290cfb836c82db1995a)
0x082b9b776e5d0b1771594676d12619f479b0a69c(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x082b9b776e5d0b1771594676d12619f479b0a69c)
0x950a0be4d5e7c63017debfae67ada866b55e7335(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x950a0be4d5e7c63017debfae67ada866b55e7335)
0x659a88d1fc5065126a90ebf908379db1d5c94e37(https://polygonscan.com/token/0x1871464f087db27823cff66aa88599aa4815ae95?a=0x659a88d1fc5065126a90ebf908379db1d5c94e37)

Methodology

Same as #602 (comment)

Rewards Address

0x6a1AF72bBcfD0BA492E502F83334d3910Fa025dB

@coin8848
Copy link

It's interesting that I don't have a GAL airdrop, I haven't even participated in any large GAL missions, and the 0x2fc617e933a52713247ce25730f6695920b3befe address, I have no idea what this is, maybe a faucet or an exchange address? I'm pretty sure it's definitely not my address because I only have one

@shanefontaine
Copy link
Member

@Annu2047 We have observed cases of apps sending funds through Disperse to help their users pay for gas on L2s. We have also seen altruistic people and faucets do the same. Because of this, we will need additional evidence. Some potential compelling evidence may be:

  • Identical transactions on the exact same day/time by most or all of the addresses
  • A trace of the ERC20 token between addresses (as opposed to native tokens)
  • A similar time/date that all the addresses started transacting on a chain

Minting an NFT within the same day is interesting, but does not provide conclusive evidence of a Sybil attack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants