hop-protocol / hop-airdrop

Hop Airdrop distribution 🐰
174 stars 218 forks source link

Sybil Attacker Report #603

Closed gitNickV closed 2 years ago

gitNickV commented 2 years ago

Related Addresses

0xc4319a2356c0b0a8077c8a7ef858271062c74e21 0x736ba6cd4c8b7fe90e0464875126c1ca71e9d57f 0xc688d3ea03ac6c2d3a20cb8a4a1465153ae7815a 0xef6b1e3e5672d4a86b681bb903a10c5f7abe5518 0x478efb7a9e7649d23231ca1ba6d18d6521a21511 0xe6363df9ef56ddb88a24384442e751df9125e79f 0x006517986cada5ea371cea58af62ff9237e49c45 0x1735a0eb8602bb44e9c5bd7f4f75e3703b60f52d 0x3f36697a0fb5d4a8a214ca99767c8f34f5b21124 0x417fc8d69cf124f8a12ca39d61881dd2fbbe2222

Reasoning

Those wallets have almost exact same history of transactions on BSC. They all was initially funded by 0x5407857c0ca249590531293db9ce28b31a937499 for the same value of 0.05 in 2 batches:

Wallet BSC Funded at Funded value
0xc4319a2356c0b0a8077c8a7ef858271062c74e21 10.03.2022 15:47 0,05
0x736ba6cd4c8b7fe90e0464875126c1ca71e9d57f 10.03.2022 16:30 0,05
0xc688d3ea03ac6c2d3a20cb8a4a1465153ae7815a 10.03.2022 16:30 0,05
0xef6b1e3e5672d4a86b681bb903a10c5f7abe5518 10.03.2022 16:30 0,05
0x478efb7a9e7649d23231ca1ba6d18d6521a21511 10.03.2022 16:32 0,05
0xe6363df9ef56ddb88a24384442e751df9125e79f 29.04.2022 17:32 0,05
0x006517986cada5ea371cea58af62ff9237e49c45 29.04.2022 17:33 0,05
0x1735a0eb8602bb44e9c5bd7f4f75e3703b60f52d 29.04.2022 17:33 0,05
0x3f36697a0fb5d4a8a214ca99767c8f34f5b21124 29.04.2022 17:34 0,05
0x417fc8d69cf124f8a12ca39d61881dd2fbbe2222 29.04.2022 17:34 0,05

Their history of transactions contains same transactions with same timings. Those who was funded on 2nd batch (from 29.04.2022) have the same history like the first batch of wallets after this date.

Methodology

I analysed initial fundings those wallets recieved on different blockchains. Then I checked their BSC history manually and saw this transactions mirroring on all accounts.

Rewards Address

0x72153F1040BDfe6961bB73448f1AF265B2bFDf0b

shanefontaine commented 2 years ago

Thank you for the submission @gitNickV .

Those wallets have almost exact same history of transactions on BSC.

I am not seeing similar behaviors. Can you please elaborate on this point? For example, there is not many similarities that I can find between 0xa545fba9444b2ff8f05c2f9c8a235be65c784abd, 0xc2765344776123ef1162f0076414f136fe4e01ad, and 0xfcc4106f974d942f4a1e62e083c1830a7eadc303 on BSC.

gitNickV commented 2 years ago

Thank you for the submission @gitNickV .

Those wallets have almost exact same history of transactions on BSC.

I am not seeing similar behaviors. Can you please elaborate on this point? For example, there is not many similarities that I can find between 0xa545fba9444b2ff8f05c2f9c8a235be65c784abd, 0xc2765344776123ef1162f0076414f136fe4e01ad, and 0xfcc4106f974d942f4a1e62e083c1830a7eadc303 on BSC.

Why do you menitoned those addresses? They wasn't in this report. Looks like it is some missread from a different report you made.

I checked again accounts I reported in this report. And when you check their activty on BSC (including initiall funding method from same accounts with same amount) it is pretty clean they are the same guy.

shanefontaine commented 2 years ago

Thank you for your report @gitNickV. We have verified that the addresses in this report are Sybil attackers.

The report included 10 eligible addresses as Sybil attackers which means you are eligible for 1698.027658607117101204 HOP! When Hop DAO is live, we will make a proposal for this reward — subject to a 1 year lockup, as mentioned in the original Mirror post.

My statement above about those addresses was incorrect. Thank you for pointing that out.

The qualified addresses are as follows:

0xc4319a2356c0b0a8077c8a7ef858271062c74e21
0x736ba6cd4c8b7fe90e0464875126c1ca71e9d57f
0xc688d3ea03ac6c2d3a20cb8a4a1465153ae7815a
0xef6b1e3e5672d4a86b681bb903a10c5f7abe5518
0x478efb7a9e7649d23231ca1ba6d18d6521a21511
0xe6363df9ef56ddb88a24384442e751df9125e79f
0x006517986cada5ea371cea58af62ff9237e49c45
0x1735a0eb8602bb44e9c5bd7f4f75e3703b60f52d
0x3f36697a0fb5d4a8a214ca99767c8f34f5b21124
0x417fc8d69cf124f8a12ca39d61881dd2fbbe2222