hop-protocol / hop-airdrop

Hop Airdrop distribution 🐰
176 stars 218 forks source link

Sybil Attacker Report #493

Closed hitflame closed 2 years ago

hitflame commented 2 years ago

Related Addresses

12 related addresses.

0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2
0xde9d23dd4ef797424e0ec8d310406c9348abf859
0xd67c3592ed81d1c7fc6f9ee06a1ae3ef7f7d8ffa
0xc0be42902e4c73f21dec71fb7dfc2223fd23d082
0x000c277d0048c99894a56619d47aec09256c7a72
0xeafc2ecfa9e67b779d922a0d59039ca3a887bd6e
0x5b39a7af4bc6d915bf48d3d7e0083f5b921c778a
0x206cb8e0d4c3b1593a3f7812244a3716a960d00a
0x3a60db96add6e41864b23afed27a050ff44cdf60
0x8e3322bcbf277d81e7d28f10612c8c2fcf259c95
0x34681d0c5934ee3a7132d4d70c5c64f57dda6d7a
0x4d4c08334a597bf47865ac09f1e8f27d501c6b10

Reasoning

1.An elligible for the airdrop Address 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 send 5 MATIC to these 11 addresses that elligible for the airdrop on 2021-10-28. These transactions can find here: https://polygonscan.com/address/0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2

  1. The 11 addresses used SuperFluid with UpgradeByETH in the same date.

Some transaction examples: 0xdd57ea4E1D618b9e09DBDb4A9E0b904B61b468C2 sent 5 MATIC to 0x8E3322BCBf277d81E7D28F10612C8c2fcf259C95, and then 0x8E3322BCBf277d81E7D28F10612C8c2fcf259C95 used SuperFluid with UpgradeByETH https://polygonscan.com/tx/0x0e0b45d41037fc16619d12a8d167327f537805b31fa6977bada7689f844eaead https://polygonscan.com/tx/0x9700543bfaa722308f1d7f02806effd1c233ebdcb4997504eef5be6c5797a8b0

0xdd57ea4E1D618b9e09DBDb4A9E0b904B61b468C2 sent 5 MATIC to 0x000c277d0048C99894A56619d47aeC09256c7A72, and then 0x000c277d0048C99894A56619d47aeC09256c7A72 used SuperFluid with UpgradeByETH
https://polygonscan.com/tx/0xe93e4a3e3b1e7262d9538107096a86fa0929c1e76c2b21e4c3d9c894f13ef5f6 https://polygonscan.com/tx/0x61bfe2d5e88a32cf312ad51086822cc696de81ccd4c105850d3ff8e269556d57

from_addr | to_addr | value | tx_id | block_height | date_at -- | -- | -- | -- | -- | -- 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x000c277d0048c99894a56619d47aec09256c7a72 | 5.0 | 0xe93e4a3e3b1e7262d9538107096a86fa0929c1e76c2b... | 20712784.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x206cb8e0d4c3b1593a3f7812244a3716a960d00a | 5.0 | 0x7aaa75c413390f60e91a5914d389953f9ca26964de59... | 20712775.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x34681d0c5934ee3a7132d4d70c5c64f57dda6d7a | 5.0 | 0x16b7f9e8934adffc06872f6ab27eb30c2d9ff214a33a... | 20712759.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x3a60db96add6e41864b23afed27a050ff44cdf60 | 5.0 | 0xbd37d3f1b282fc48adaf0aad3df4d294aed4bc264738... | 20712727.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x3a60db96add6e41864b23afed27a050ff44cdf60 | 5.0 | 0xe03c0a518a2b1bbd1d08b33a8b65871d5765adaa4cad... | 20712766.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x4d4c08334a597bf47865ac09f1e8f27d501c6b10 | 5.0 | 0xdf32394cae303d63f403f0adfbb6c812de65183ac642... | 20712752.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x5b39a7af4bc6d915bf48d3d7e0083f5b921c778a | 5.0 | 0xffa860ee7ab59485aa9dfde6c44bd134e55a28d2e8e8... | 20712740.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0x8e3322bcbf277d81e7d28f10612c8c2fcf259c95 | 5.0 | 0x0e0b45d41037fc16619d12a8d167327f537805b31fa6... | 20712788.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0xc0be42902e4c73f21dec71fb7dfc2223fd23d082 | 5.0 | 0xd442e737bcc75ad5ca5536ec309079aaaad9000a2b64... | 20712735.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0xd67c3592ed81d1c7fc6f9ee06a1ae3ef7f7d8ffa | 5.0 | 0xf0a0a0069c3251b96ce0c5045499c8b69418311d4a45... | 20712778.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0xde9d23dd4ef797424e0ec8d310406c9348abf859 | 5.0 | 0x45be739bd53ccee0826a4f990c34eca0085642e4c1da... | 20712747.0 | 2021-10-28 0xdd57ea4e1d618b9e09dbdb4a9e0b904b61b468c2 | 0xeafc2ecfa9e67b779d922a0d59039ca3a887bd6e | 5.0 | 0x8cbedb0b5f56fdc41beaabbb3319e46e72bc5ee55719... | 20712770.0 | 2021-10-28 image

Methodology

I checked polygon's matic transactions with polygonscan API and filtered transactions, where 10+ recipients addresses and sende are eligible for the airdrop. Then I checked when and how this wallets interact with HOP.

Rewards Address

0xdde6d1b5ec932cebf1c9aced1487f109f9ea34b2

shanefontaine commented 2 years ago

Thank you for your report.

Unfortunately, none of these addresses are eligible. All eligible addresses are here.

Please note that, per the rules, only the Hop Bridge User token allocations are taken into consideration for the Sybil attacker submissions and not Hop LPs. Additionally, the submitted addresses may have existed on the list in the past, but someone might have submitted these addresses as a Sybil attacker before you did.

hitflame commented 2 years ago

@shanefontaine Thank you. You mean i need to find sybil attacker addresses from eligibleAddresses.txt, not from finalDistribution.csv. Can you tell me the hop contract addresse or how i can find the hop contract addresses.

shanefontaine commented 2 years ago

@hitflame You can find all the mainnet contract addresses here.