hop-protocol / hop-airdrop

Hop Airdrop distribution 🐰
177 stars 220 forks source link

Sybil Attacker Report #224

Open Nia854 opened 2 years ago

Nia854 commented 2 years ago

Related Addresses

0x0c9033CFF9303c5CCfa91E703fC2EC4B69412CaB phyye.eth 0xaBa6AfB7f0FAFF50118B5BFbDB94E858d5c5F093 xwewe.eth 0x42773e7712c5c6549be933e45f028fa7c6595387 liminm.eth 0xea108d9baa834e9bd64d921d43bd8db907c60d20 dycdq.eth
0x5a48c5934003041988c330c9c2a2a29bf631c20f
0x113406a66a9c41b9899f9bf08c39931cd7437ac3 0xc05425d552875ab18c0535429631d6030c3e578a 0xea7a2e298e218fd84d5b84345e6cae712f234ef2 0x2f87ea9fbff1d9eaefc5549a0cc4cfc150e7d0d4 0x2B5c59AcD5Dab53494e6a7E3EF67F7658F4738Eb 0xB4c87989460FBEECfb3500376d8bBd663157458a 0x2b5c59acd5dab53494e6a7e3ef67f7658f4738eb 0xBd78418676Eb4eBe14D8433EE5421eEbdA6248f6 wangyu.eth 0x5ecbeabbc05fb689ecd4eabdcbcd853301bfb11c 0xBd78418676Eb4eBe14D8433EE5421eEbdA6248f6 0x5ecbeabbc05fb689ecd4eabdcbcd853301bfb11c 0x543F270f25388E33C1CB31e32fBdAF203490F764 0x5852443c480540460cd7a4c54b63d7acfe49737a
0x72979fcb6b29b534c1213a267f14bb23e84fdc8d 0xa8B94eaDE4b2f03E2C236b62D2F90d290bb09B11 0xc8e5a63242fc8e3196947e566b4d31e62614ded2 0x449dC77935a0494d85ABBa884F1587bd1a2c2F4e puhongye.eth 0xB6d0dE397d0A4d42B33598F80F17d4cC28Aa30Cc

Reasoning

These 23 wallets belong to one individual have been sybill attacking the Hop Protocol, Arbitrum and Optimism layer2 protocols. First I discovered following wallets are performing identical tasks on the Ethereum mainnet:phyye.eth, xwewe.eth and liminm.eth. Also there are balances being transfered back and forth between those ENS registered wallets. And when we examined the activities on Arbiscan, it very clear all wallets have been used for sybill attcking the before mentioned protocols. For example, wallet xwewe.eth(0xaBa6AfB7f0FAFF50118B5BFbDB94E858d5c5F093) on April,4th, 2022 sent 0.003-0.004 ethereum to 16 different wallets. The previous day it sent 0.0004ethereum to 11 different wallets. All wallets minted the same NFT tokens on Arbitrum. Those wallets would also send very small amount of ethereum among themselves back and forth gambling for potential airdrop on Arbitrum and Optimism(Most of the wallets indeed qualify of recent announced Optimism airdrop). Wallets also sybill attacked Hop Protocol in anticipation of the potential airdrop.

Nia854 commented 2 years ago

rewarding address 0x6147B20E2542137055C87E6d86C8af5bF8Fb515a

shanefontaine commented 2 years ago

@Nia854

Thank you for the submission. Unfortunately, this submission does not meet one of the criteria for submissions:

Methodology that has a non-negligible chance of eliminating legitimate users will not be considered

There will need to be additional proof submitted in order to consider this a valid group that does not include any legitimate users. Please consider providing more information about the behavior of these addresses, such as identical types of transactions or similar timing of transactions. Please note that another user that submits an issue with a detailed, non-negligible chance of eliminating legitimate users, their submission will be considered before yours.