Addresses are reported by retrieving information from the chain, using bitquery's graphql, and detecting abnormal behavior, such as empty wallets, mutual transfers, etc.
When only some of the anomalous behaviors are present, we can consider the address reasonable, but when an address has all the anomalous behaviors, we have good reason to suspect that the address is false. Especially if the multi-signature address and the owner address have obvious exceptions both, then it is obvious that this is airdrop farmer.
Abnormal behaviors include
For Multi-Sign Address
Few transactions were executed
There is a lot of overlap in the interactions, such as the destination address, and the time
The owner of multiple multi-signature addresses is exactly the same, and never changes from start to finish
Unusual transfer behavior
For Owner Address
Empty address
The first source of funds is the owner.
Mutual transfer
Behavior similarity
If the verification is passed, my strategy is star, and I can provide my source code.
Related Safe Addresses
Reasoning
The reason why these two group lists are taken out is that
There are three Groups here, and the abnormal behavior of these three Groups is same, as follows:
1.
Only about USDT execute transacion on the multi-sign account, no other token. And tranfer USDT has an big overlap of contract addresses
The owner of the above three multi-sign addresses are all
0x004db9806648244382b39befc183f39d575061ef
, owner send 0 transactions. Empty wallet0xea191ae1794ff92ee7fb02c71a6af4b912a2cff4
, owner send 0 transactions. Empty wallet0x946d66cdcc68cfe2d84c7fd9c8b790c48c189d30
, owner send 0 transactions. Empty wallet0xcf9ad8309182be3b83a461b9981a915d29542cb8
, owner send 0 transactions. Empty wallet, the fund came from main wallet https://etherscan.io/tx/0xf36e2dc55d71b204fe8d80a294e24938f99af70f12c456a09c64682c2564c6230x0e68cc646e2b9878d1472a218f0a505aa8f8555d
, owner send 39 transactions. main wallet, Use this wallet to provide the first money to other wallets.0x81c789d11b5221adf91fe52abaef04a464f666b9
, owner send 114 transactions. first assistant wallet, the fund came from main wallet https://etherscan.io/tx/0x121520d6780c57790870c50ec4235044cb41f380a7a824c00a62bfa4fc80c35b0xc9d4314c46dbb5417e752754331278f70dbbb064
, owner send 32 transactions. second assistant wallet, the fund came from main wallet https://etherscan.io/tx/0xc83d6df4add4a105b5b3c69003a7c60f78db92ca6693e8c1fc48b36db5072edc2.
Only about USDT execute transacion on the multi-sign account, no other token. And tranfer USDT has an big overlap of contract addresses
The Owner is the same group address, and it is obviously related.
0x31ac327c5d249398ab5b5c9b46d923d918da3ba6
,,owner send 0 transactions . Empty Wallet0x3ac544c3af5b0a127795330ecdf159a92a9414e5
,,owner send 0 transactions . Empty Wallet0x7809a48d219383827b91a88944c24b409afc585a
,,owner send 0 transactions . Empty Wallet0x8808d0da7a37a596a2ba24e97b23190f962cc893
,,owner send 0 transactions . Only received the transfer from wallet1 once, and there was no other operation.: https://etherscan.io/tx/0x7562ae06f2d4ef46c1b6df16c4a47d26b49f16d1895209d1e13f6555270b75d00x8707b488f0c6dc34b73866541e914b86d3671ca2
,,owner send 178 transactions. Wallet4, The first money came from Wallet1.: https://etherscan.io/tx/0xba4b2ea9970e1563ae61116b411c4adcda8d803b63092db9cf05b05cfe64c4210x93750d671c8f424e2a9d39ace60cedaaf69d03a8
,,owner send 86 transactions . Wallet1, Responsible for distributing funds0xb2e32e9ad0e004a0bd08899105a6fab8729cbc42
,,owner send 28 transactions . Wallet2, The first money came from Wallet1: https://etherscan.io/tx/0x16810dc371efc95e0d2b2cfa5108bb69af138a4f6b6d3e0cae48824e764c32723.
Only about USDT execute transacion on the multi-sign account, no other token. And tranfer USDT has an big overlap of contract addresses
They all have the same owner, and obviously, this owener is only one person, for the following reasons:
0xed57f48624f1044099c702432e95f533ac869bc9
, owner send 50 transactions. wallet1, Responsible for spreading funds to other wallets.0x719df48fadd1abd019c594a630064e0af0d6c329
, owner send 120 transactions. wallet2, First Fund From wallet1: https://etherscan.io/tx/0x6050219ab3667851c0facab97f2b12a9bafe64c370d98848ff0183be86e010300xaae8bf5da5122e3e4e0ebea763647574a034844e
, owner send 18 transactions. wallet3, First Fund From wallet1: https://etherscan.io/tx/0xb9e66b34c78c083f6aa30500ff29a3fdf8b7e65b5eaaa504fc986c3b63f97ad40x459628139100672d6f02bead1a94d11898fe2d76
, owner send 0 transactions. wallet4, Tx has never been executed, only money from wallet1. First Fund From wallet1: https://etherscan.io/tx/0xc892717ba3b486a893d06a6228c8ed5462576dc21ee374c4f4ff9d35b35b090b0xf9844a4cd6c9763f034297f382a0daf02aa7da24
, owner send 0 transactions. Empty wallet0x0a4ae50a824e0173beb1e8fb6aeea09cdf64c710
, owner send 0 transactions. Empty wallet0x3b782d82b8df7631536317b17b1384d78529681c
, owner send 0 transactions. empty wallet4.
Group3 Transfer USDT to Group2 txs (group2 never send token to group3) :
Methodology
Addresses are reported by retrieving information from the chain, using bitquery's graphql, and detecting abnormal behavior, such as empty wallets, mutual transfers, etc.
When only some of the anomalous behaviors are present, we can consider the address reasonable, but when an address has all the anomalous behaviors, we have good reason to suspect that the address is false. Especially if the multi-signature address and the owner address have obvious exceptions both, then it is obvious that this is airdrop farmer.
Abnormal behaviors include
For Multi-Sign Address
For Owner Address
If the verification is passed, my strategy is star, and I can provide my source code.
Safe Address
0xce495858e36c95f491b5a32ca2664405cf10ab76
Thanks