safe-global / safe-user-allocation-reports

The proposed list of SAFE user allocations has been published on the Safe forum.
Creative Commons Zero v1.0 Universal
35 stars 10 forks source link

Sybil analysis: Addresses with exactly same activity pattern #214

Closed wjw12 closed 2 years ago

wjw12 commented 2 years ago

Related Safe Addresses

Provide a list of Safe addresses that would currently receive a SAFE user allocation.

0x0dA95CF71313986599468cc95dECebc3da28d924
0xf81ec65848D5728551847aE0Bc0a1a38D61Ce0DC
0xF7e10E94E383BAc8a616173EcFd3A54A8d9C7A1F
0xF737DB95DeCCa228100F2547711f447Dd86686b8
0xf6cB89a92F30233C8fdB67c09793fc0B9A765C0b
0xf4d063d27C4A3C90d2ECF3E366744C88eCE5C17b
0xf0acBA263B546A067371AF7b428F2D3F04774857
0xEa4cC58c8D081d8C94D1b8c400EaA984357C1Fba
0xDCF05cb2b2cE32361dB11DDDd732286eDB52c31E
0xdB5a5D45FCC27d1E193fE69384AD11C9851999c4
0xD5E0Ba4f3DEEFaffE7a1780a9E56B8931CDd6d83
0xd4390FeC8e5Ac2cFd79C0d78B2C4f9249EDed9C2
0xD0EdCE1B7595e1c4406fD4ee5727FB513b7B7081
0xcc4f2674c4bfcaccd8eddd812f23b5749b99b9c1
0xc770d0ce1325a877ce2b0af91f24f4b3d7167a9f
0xcdabaf7b0f82fafc6567b5910b55ab742fbfc362
0x02823bfa2d213538b016ebbbb5bc621e1ab7a2fa
0x0da95cf71313986599468cc95decebc3da28d924
0x166b9ad5da4f1fcd2e7b2c1411f0ac5bd875ba75
0x1a1ccd0b9cbc013a8bf9131dffb53fa914bcbb63
0x1b9cfc50b904987dd1675b664cb6919b9f447761
0x1d6308dfaeef77a7237697ff405dbd51c9da620d
0x20c01bd6701f1d81e45ade78f310667a9f4efb5f
0x231829e5f50f103ce5c772cb3e984a3ebf8d974a
0x292168a91bb6d0a44cc40a1fc45a0a06cdcdf8ff
0x2b20522eec11450feff2cef2f5dac23442090fa1
0x2ba1674d6c745f2f69a09c3b9936b042d3958b9f
0x2e1e509e4d8ad11bc71ca64e6b947ef2c5d0da73
0x3a7e659ff7d5ba5632772031e6a076dc98656968
0x3b4b77019ddbb8bd08a2058d77669374d598761f
0x406618cfdfb4a3e036207597d6d6e3c2da38bd6c
0x40903e62c146c36b694e5337c2729f4bf135bd3c
0x43b2e80d68e7ee56dc443a0dc9384f2e901b6231
0x47f84f2bd5da265dfbf92c7bd35ccf55037bd9cd
0x4fe7fc0a03681d4361bc48e8c9becab6e7f90bd4
0x52e7fb6572c2f174dba35872e21f63bee66fccc4
0x55d3e40b04b50b03c4e12ebebfe88c4f376e6788
0x594a22430e7f3bd888879050235af46cfc66dc57
0x5a71443f7f5083c8de6b0d3c2a61119ee3e5b688
0x6612b057f2147775c135fd0f05d77466a9aad4e4
0x6710022ae25cdebf4c16dd1ee8b5c9453dd0ad32
0x67339eb8dc6dad74cae01f18706a12ed74a0d0b6
0x675acd4dafc192ff390dcd567ba3905068312975
0x68ee8e9ca43a8a9bc8dfb13ea22cda53f04c1f0c
0x6b2650aa9a6f22623df74c25ab59632f0599a9e7
0x713390208da3adb2803a009317fc3d8e1402e62d
0x74d5008f2934d4ee85f93cbc951d7c05ca49aacc
0x88990e8e2d7cb918c7f2ffee9d0c2ee2137dc349
0x8959d5d574708c034d4cd6164afa2e45bb7577cd
0x8e53b4839718f2f19dfc66f1c4748208af90f8dc
0x8fb730e3fc869156c960895629560b2396936994
0x910de4de72201f43b66ad2c1a0dfe412ca81cde3
0x92cd97142e1868475f21a6ad716434d0cf7fa094
0x93d6f3b0cd1b83993e403657f843c62368d715b6
0x97d9ca631907d2f963af539afe4784441692a0b7
0x994e556ee4314c2e57dc1487fddb4765fa6cab75
0x9a9713d6836ae17a0e0941fde319c9197a70f288
0x9ae1519017245696a9a026fa8775be883e8b9fdc
0xa099b5e12021d6d05f92d096a19e9adfbc8604c3
0xa149c7d6afbd6f9f986930ec34fa9d06e959f44d
0xa32365da6ff369226f49a354f981115d389db2cc
0xac4cd010b9bc64007383d752d22702bcfb698e97
0xad84272533ca3e5cfaca351139ebc63a17fa2c78
0xb2610eade91f028e6b1f7b075c5ada5f48183934
0xb73e6b3cd55467d833d146d4feb667195942bf43
0xb93d8a67462286b62caf4534fca496a75e0578f6
0xc647ac01b01e0a7f5ed88151cf28591113b5f4c8

Reasoning

These addresses have exactly 11 transactions between Jul-02-2022 6 AM and Jul-02-2022 10 AM UTC. The first incoming transaction are all of 0.0000011 ETH. Next, these safes transferred out 0.0000001 ETH to some other addresses. They repeated the transfer for 10 times, and left with a dust of 0.0000001 ETH.

Such behaviors are obviously non-organic.

You can just search these addresses on etherscan:

https://etherscan.io/address/0x0da95cf71313986599468cc95decebc3da28d924

https://etherscan.io/address/0xf81ec65848d5728551847ae0bc0a1a38d61ce0dc

https://etherscan.io/address/0xf7e10e94e383bac8a616173ecfd3a54a8d9c7a1f

The ENS names that initiated these transactions follow the same pattern. For example: Wilderness.eth, SouthernPine.eth, Caramel.eth

If you see the tx history of these ENSs that created the safes, they follow the same pattern, too. First, they received some ETH from another ENS (and the name follow the same pattern for example Fuchsia.eth which starts with capital letter), then they registered ENS, then they created a safe and did 11 transactions, then they received some ETH from FTX, then they staked AAVE and finally they deposited into zkSync. It's very likely that these are controlled by the same airdrop farmer.

Methodology

I sorted the excel sheet by the amount of eligible SAFE tokens. I identified that there are some addresses eligible of exactly the same amount of tokens (207.557 SAFE). After manually checking etherscan tx history, I found these addresses with exact same activity pattern.

Since the airdrop amount is determined partially by the balance of SAFE, it very unlikely that different SAFEs have exactly the same amount of airdrop. This is a useful clue.

Safe Address

wjw12 commented 2 years ago

Please see https://github.com/safe-global/safe-user-allocation-reports/issues/215 for more addresses with the same pattern

wjw12 commented 2 years ago

My Safe Address

eth:0x984129b1C8D6048DF516D81f730475AF7D0E4223

tschubotz commented 2 years ago

Thanks for the report. These Safes have been already removed by an earlier report though, hence closing this one.

wjw12 commented 2 years ago

Hey @tschubotz Some of my addresses are actually earlier than #221 Can you please check the timeline described at https://github.com/safe-global/safe-user-allocation-reports/issues/221#issuecomment-1250113842

@memebeat the author of #221 also helped to confirm the correct time sequence.

tschubotz commented 2 years ago

Reevaluating this based on https://github.com/safe-global/safe-user-allocation-reports/issues/221#issuecomment-1250022810 and #519

The following Safes are removed based on this report:

0xf7e10e94e383bac8a616173ecfd3a54a8d9c7a1f
0xf737db95decca228100f2547711f447dd86686b8
0xf4d063d27c4a3c90d2ecf3e366744c88ece5c17b
0x02823bfa2d213538b016ebbbb5bc621e1ab7a2fa
0x2b20522eec11450feff2cef2f5dac23442090fa1
0x2e1e509e4d8ad11bc71ca64e6b947ef2c5d0da73
0x3b4b77019ddbb8bd08a2058d77669374d598761f
0x43b2e80d68e7ee56dc443a0dc9384f2e901b6231
0x52e7fb6572c2f174dba35872e21f63bee66fccc4
0x67339eb8dc6dad74cae01f18706a12ed74a0d0b6
0x675acd4dafc192ff390dcd567ba3905068312975
0x6b2650aa9a6f22623df74c25ab59632f0599a9e7
0x93d6f3b0cd1b83993e403657f843c62368d715b6
0x97d9ca631907d2f963af539afe4784441692a0b7
0x994e556ee4314c2e57dc1487fddb4765fa6cab75
0xac4cd010b9bc64007383d752d22702bcfb698e97
0xc647ac01b01e0a7f5ed88151cf28591113b5f4c8