safe-global / safe-user-allocation-reports

The proposed list of SAFE user allocations has been published on the Safe forum.
Creative Commons Zero v1.0 Universal
34 stars 10 forks source link

Sybil Attacker Report #342

Closed Parkcora closed 2 years ago

Parkcora commented 2 years ago

Related Safe Addresses:

0x80fac6ea6f85d6228003a612431e218388bb52a4
0x2fe5e08c34178df3653ebbfa7ecf9e1ae9e2797d
0x9ef0e4e7a58c25d3201590efed2e1df42b294aef
0xe4afc90d8e08bd2a3a638cc2b1024bc49f55df21
0xb2285bc13bef95af73418bee8cea9629cce3e341
0x4b14f9cac4c868acabb6a30ae37a452694d20aab
0x0e2dbf98bdfa0dd2f2a6031c989d0bd0f7be4fd7
0x0ef98a437746bf1808523a0772fb3278af777279
0xb3df9e9c713433208d6c62bb578dd6759f6c7275
0x5db437f110ef8b05b7e37a85b64e2486b2d58b33
0xb255ad9ca333bd456fc9dd3fc79851d7fd6724a9
0x71557990b0d8913a6874642cddd4046d3c244ba4
0xfc2cfc73ef51c660c4da5fd510e9500a9e77512e
0x922fe6d42668f96484409ecada8699467195d439
0x84b4eade5f61397df7e4550a31f72fd545cf696b
0x377c364e09057dbe4169ebabb857b1663511ed23
0xb4c87e483546a35b7666c5fdab89920acf0cc463

Reasoning

  1. The creation time of these safes are continuous as shown in Table 1. All are created on 2022-07-09-2022-7-10.
  2. The previous transactions of all the safe creation transactions is the interactions with Metamask:Swap Router. All are done on 2022-07-03, as shown by visit the etherscan links in Table 2.
  3. After safe creation, all the creator addresses transfer to its safe address a very small amount ETH (0.00x ETH to 0.0x ETH, mostly 0.001, 0.0015, 0.002.) for 9 or 11 or 12 times, as shown by visit the etherscan links in Table 2. (also could be verified by visiting the gnosis-safe.io/app for these safe addresses.)
  4. The immediate transaction of each creator address after the tranferring to its safe was interacting with Uniswap Protocol: UNI token, as shown by visit the etherscan links in Table 2.
  5. There are many transactions between the creator addresses, as shown in Table 3 and Figure 1.
Table 1 CREATION_TIME CREATOR_ADDRESS SAFE_ADDRESS CREATION_TX_HASH
7/9/22 9:43 0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0x80fac6ea6f85d6228003a612431e218388bb52a4 0x0399e221c643328ac6ff6512d814ce2ae08cd6df71fdc217a0fce03906564eff
7/9/22 9:47 0xe6275888ba0a07ee4f1fed4cac43fafe2f897126 0x2fe5e08c34178df3653ebbfa7ecf9e1ae9e2797d 0x3718d4c859e78054112af303caf7bfc985b5871f018cf6f376e745346d4c79ce
7/9/22 10:22 0xc8534dfb197079a9a7f9c51906b7a80b9e0328b9 0x9ef0e4e7a58c25d3201590efed2e1df42b294aef 0x02e368cc8a61f64911dc26c56b223523722ccbb473d80d580358da75bed89364
7/9/22 10:26 0xc3b2600be71232695a223ae62c384104e9a9dfae 0xe4afc90d8e08bd2a3a638cc2b1024bc49f55df21 0x9f885dc7625cdae08f8ce669b821f8b2e4572166768e0b4053b3d587aa0a34f2
7/9/22 10:34 0xbc939fb00bea51812c3deb6fc1b04d037b4b0734 0xb2285bc13bef95af73418bee8cea9629cce3e341 0xab622a95b76b799367bf97d58933404473c33c4c90ebac53d9ceccf4e7d218d8
7/9/22 10:40 0x97c15532cf71815c9d89a0eb542078befe1ee622 0x4b14f9cac4c868acabb6a30ae37a452694d20aab 0x9e8ea36c3e9ba7c884589f366a5136970dba49fbba9313d467a9c9a672ea73ff
7/9/22 10:43 0xe4da6192a89dff5c02d754e5e7b319155109f43c 0x0e2dbf98bdfa0dd2f2a6031c989d0bd0f7be4fd7 0xac67c3ea60ef9d382b3dffd92705209bd4974b38f480b77260562e751d2179bf
7/9/22 10:47 0x0e61ff4845d4e365fc8e44a410102a5b0bb2a5ee 0x0ef98a437746bf1808523a0772fb3278af777279 0xd4249a8f49d93f49d4959cec43961177d7afa815b9b24034f2d9531d276cd3f6
7/9/22 18:46 0x772cb5a031623cd7ac3fa8fa4125596672b6c4ac 0xb3df9e9c713433208d6c62bb578dd6759f6c7275 0x8e11bc35aa0a6ee95e56167e6b415b92958a87e45a88d2e5bd06c2459c704f1c
7/10/22 2:48 0x6d4a56f6d55dbc0531d380752ba17d2c13f3ad9d 0x5db437f110ef8b05b7e37a85b64e2486b2d58b33 0xd382c1f8d5bcc9913a58280da816969fddf75fdb2ffe358df6b82619f8a84ba1
7/10/22 5:37 0x9e25d80b3838e816b07a868f598f4c115e9d7eca 0xb255ad9ca333bd456fc9dd3fc79851d7fd6724a9 0xf5efb899168b5e8476c2e54d6bcb52750853be1aa8caf2382beff42620d06dee
7/10/22 5:41 0x2aff3c5f51c0ae4a111edaec1daa305395361896 0x71557990b0d8913a6874642cddd4046d3c244ba4 0x268b3e0c3d3be8266ec6459358113d416001206ee447ca74e4ae6dd84363b121
7/10/22 5:43 0x7a3cac5012e7fbe9b0557757598da7e9c4e6a87e 0xfc2cfc73ef51c660c4da5fd510e9500a9e77512e 0x7039f214d3e8f4ae3f06fd7d4bf10e15fbfef3c35e5a85290c29e5c61cfe3143
7/10/22 5:46 0x54a9aadbfb39ea9906b823353978193da0032684 0x922fe6d42668f96484409ecada8699467195d439 0xadcf1ba672a9c43285f68587d50b90426a40f5132411d4f9822d3150b626ed71
7/10/22 5:49 0x0196ded59afe1df493cd2ae4c205c549f6e6d6fc 0x84b4eade5f61397df7e4550a31f72fd545cf696b 0x3fd9b93b0a85754a07f58f0f7f04c25d6244626a01c42737781199828c34d359
7/10/22 5:52 0xf0687e090fe3b11160596bcca10ddd2415012881 0x377c364e09057dbe4169ebabb857b1663511ed23 0xfa63b492970fc0f60934db188444f84ca7c5a77f48c92301472dbd35e450c803
7/10/22 5:56 0xb9178768f6d8d61f00bcf9767885befe7e54b48a 0xb4c87e483546a35b7666c5fdab89920acf0cc463 0xa5e896f5e6c6cc4747f41a333dd543272ae0685504ac5016105204574d7f27a3
Table 2 CREATOR_ADDRESS SAFE_ADDRESS Tx pattern link
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0x80fac6ea6f85d6228003a612431e218388bb52a4 https://etherscan.io/address/0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a?agerange=2022-07-03~2022-07-10
0xe6275888ba0a07ee4f1fed4cac43fafe2f897126 0x2fe5e08c34178df3653ebbfa7ecf9e1ae9e2797d https://etherscan.io/address/0xe6275888ba0a07ee4f1fed4cac43fafe2f897126?agerange=2022-07-03~2022-07-10
0xc8534dfb197079a9a7f9c51906b7a80b9e0328b9 0x9ef0e4e7a58c25d3201590efed2e1df42b294aef https://etherscan.io/address/0xc8534dfb197079a9a7f9c51906b7a80b9e0328b9?agerange=2022-07-03~2022-07-10
0xc3b2600be71232695a223ae62c384104e9a9dfae 0xe4afc90d8e08bd2a3a638cc2b1024bc49f55df21 https://etherscan.io/address/0xc3b2600be71232695a223ae62c384104e9a9dfae?agerange=2022-07-03~2022-07-10
0xbc939fb00bea51812c3deb6fc1b04d037b4b0734 0xb2285bc13bef95af73418bee8cea9629cce3e341 https://etherscan.io/address/0xbc939fb00bea51812c3deb6fc1b04d037b4b0734?agerange=2022-07-03~2022-07-10
0x97c15532cf71815c9d89a0eb542078befe1ee622 0x4b14f9cac4c868acabb6a30ae37a452694d20aab https://etherscan.io/address/0x97c15532cf71815c9d89a0eb542078befe1ee622?agerange=2022-07-03~2022-07-10
0xe4da6192a89dff5c02d754e5e7b319155109f43c 0x0e2dbf98bdfa0dd2f2a6031c989d0bd0f7be4fd7 https://etherscan.io/address/0xe4da6192a89dff5c02d754e5e7b319155109f43c?agerange=2022-07-03~2022-07-10
0x0e61ff4845d4e365fc8e44a410102a5b0bb2a5ee 0x0ef98a437746bf1808523a0772fb3278af777279 https://etherscan.io/address/0x0e61ff4845d4e365fc8e44a410102a5b0bb2a5ee?agerange=2022-07-03~2022-07-10
0x772cb5a031623cd7ac3fa8fa4125596672b6c4ac 0xb3df9e9c713433208d6c62bb578dd6759f6c7275 https://etherscan.io/address/0x772cb5a031623cd7ac3fa8fa4125596672b6c4ac?agerange=2022-07-03~2022-07-10
0x6d4a56f6d55dbc0531d380752ba17d2c13f3ad9d 0x5db437f110ef8b05b7e37a85b64e2486b2d58b33 https://etherscan.io/address/0x6d4a56f6d55dbc0531d380752ba17d2c13f3ad9d?agerange=2022-07-03~2022-07-10
0x9e25d80b3838e816b07a868f598f4c115e9d7eca 0xb255ad9ca333bd456fc9dd3fc79851d7fd6724a9 https://etherscan.io/address/0x9e25d80b3838e816b07a868f598f4c115e9d7eca?agerange=2022-07-03~2022-07-10
0x2aff3c5f51c0ae4a111edaec1daa305395361896 0x71557990b0d8913a6874642cddd4046d3c244ba4 https://etherscan.io/address/0x2aff3c5f51c0ae4a111edaec1daa305395361896?agerange=2022-07-03~2022-07-10
0x7a3cac5012e7fbe9b0557757598da7e9c4e6a87e 0xfc2cfc73ef51c660c4da5fd510e9500a9e77512e https://etherscan.io/address/0x7a3cac5012e7fbe9b0557757598da7e9c4e6a87e?agerange=2022-07-03~2022-07-10
0x54a9aadbfb39ea9906b823353978193da0032684 0x922fe6d42668f96484409ecada8699467195d439 https://etherscan.io/address/0x54a9aadbfb39ea9906b823353978193da0032684?agerange=2022-07-03~2022-07-10
0x0196ded59afe1df493cd2ae4c205c549f6e6d6fc 0x84b4eade5f61397df7e4550a31f72fd545cf696b https://etherscan.io/address/0x0196ded59afe1df493cd2ae4c205c549f6e6d6fc?agerange=2022-07-03~2022-07-10
0xf0687e090fe3b11160596bcca10ddd2415012881 0x377c364e09057dbe4169ebabb857b1663511ed23 https://etherscan.io/address/0xf0687e090fe3b11160596bcca10ddd2415012881?agerange=2022-07-03~2022-07-10
0xb9178768f6d8d61f00bcf9767885befe7e54b48a 0xb4c87e483546a35b7666c5fdab89920acf0cc463 https://etherscan.io/address/0xb9178768f6d8d61f00bcf9767885befe7e54b48a?agerange=2022-07-03~2022-07-10
Table 3 FROM_ADDRESS TO_ADDRESS TX_HASH TIMESTAMP
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0xc3b2600be71232695a223ae62c384104e9a9dfae 0x3f7aaebdba66be4ce0179242f7995a6be829baf7a7ae0e30d1a8751385074633 3/4/2022 7:50
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0xe6275888ba0a07ee4f1fed4cac43fafe2f897126 0x42a13f08c948ae983a3eaebb399b3801f218bd3678ca4d52972d8de3c78c2458 3/4/2022 7:51
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0xc8534dfb197079a9a7f9c51906b7a80b9e0328b9 0xc2fb50a40782848d2be2170a5e1731338c6062ef1632be49f8954a50dc827266 3/4/2022 7:51
0xe4da6192a89dff5c02d754e5e7b319155109f43c 0x503612b9914f1c74618d30ea167d58a55d132335 0xa8dcdafc4952ad25a381078fd4b138ef6520c9eb4a3cbfed1ab7284f36a72015 3/4/2022 7:53
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0xbc939fb00bea51812c3deb6fc1b04d037b4b0734 0x80f58c6a589feb1d59d272a3eac9c55bf18c49d5c8c54cdb5fa770f556eeaf29 3/4/2022 8:27
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0x97c15532cf71815c9d89a0eb542078befe1ee622 0x503d8205978d71873b47ce06becc05c78b89e5a8f73322d3975fab9a69c0127b 3/4/2022 8:27
0x503612b9914f1c74618d30ea167d58a55d132335 0x772cb5a031623cd7ac3fa8fa4125596672b6c4ac 0xe590d6d13aacbd294854500ca3ad633a590f1199105fdacebc17011e60c8a8fe 3/6/2022 15:14
0x503612b9914f1c74618d30ea167d58a55d132335 0x9e25d80b3838e816b07a868f598f4c115e9d7eca 0x7e8c14f6e7de72d94cfff24de31d541eff0e28832f08f8d98cd31dd3da73954f 3/6/2022 15:14
0x503612b9914f1c74618d30ea167d58a55d132335 0x6d4a56f6d55dbc0531d380752ba17d2c13f3ad9d 0xb209618b0f79ab7ab6fcd27180efaf479fcdf48d96431d35ae2c7145280e36d6 3/6/2022 15:14
0x503612b9914f1c74618d30ea167d58a55d132335 0x2aff3c5f51c0ae4a111edaec1daa305395361896 0xa88acd2a25402288cbb5910ec161c1c2651dea7932a6544deac6f2552881008a 3/7/2022 11:58
0xd2e0960736d7a9dfcf890fd4d79551cb68bf112a 0x503612b9914f1c74618d30ea167d58a55d132335 0x8cb4a5b3977ac5eac8d9f17ff949bfd762c89d777275404d3f3b79c5e2c12056 3/8/2022 8:21
0xe6275888ba0a07ee4f1fed4cac43fafe2f897126 0x772cb5a031623cd7ac3fa8fa4125596672b6c4ac 0xb6f48250fc7a4c654f9e2b9cc3954d66a2b96c8bea45affd64adb9c0e36639e1 3/8/2022 8:22
0xc8534dfb197079a9a7f9c51906b7a80b9e0328b9 0x6d4a56f6d55dbc0531d380752ba17d2c13f3ad9d 0x61386b68f7fb9c8fe6cc2b12fa2485db7370259574903358ee8a9fedbab2de03 3/8/2022 8:22
0xc3b2600be71232695a223ae62c384104e9a9dfae 0x9e25d80b3838e816b07a868f598f4c115e9d7eca 0xe72330a00e63a819cb9b41186762545f3b4f457df386a3eb587b0cdb392b0b90 3/8/2022 8:24
0xe4da6192a89dff5c02d754e5e7b319155109f43c 0x0e61ff4845d4e365fc8e44a410102a5b0bb2a5ee 0x53a1cd45e8008cb96cbc2a88894791100310385050dd19537412efb0f79ffa37 3/19/2022 10:08
0x503612b9914f1c74618d30ea167d58a55d132335 0x7a3cac5012e7fbe9b0557757598da7e9c4e6a87e 0x459906d528f753b0093da771bb069ad8fb3dfba51a3d8dd36cbe38ceac182170 3/23/2022 8:44
0x503612b9914f1c74618d30ea167d58a55d132335 0x54a9aadbfb39ea9906b823353978193da0032684 0x6e4d48f139781c7d97a4343ab9323ce10577f2691224e60b0b5b3be88c6e95e0 3/23/2022 8:44
0x503612b9914f1c74618d30ea167d58a55d132335 0x0196ded59afe1df493cd2ae4c205c549f6e6d6fc 0xca7730b1937d3b99c9447cb8eee42abf12d50ad5e80167df7260caf9fe7c047b 3/23/2022 8:46
0x503612b9914f1c74618d30ea167d58a55d132335 0xb9178768f6d8d61f00bcf9767885befe7e54b48a 0xc3f1239accdd9d346657296c0e220621984f930ae581eebb0e0dbd02d9f3edeb 3/23/2022 8:46
0x503612b9914f1c74618d30ea167d58a55d132335 0xf0687e090fe3b11160596bcca10ddd2415012881 0x23395fa1c24ccd5289d8410d706cf590d7feb1268955797bebc4d0029e73d895 3/23/2022 8:46
0x503612b9914f1c74618d30ea167d58a55d132335 0x503612b9914f1c74618d30ea167d58a55d132335 0x6ba0662f4e9d96150f44e0be1bfbf203f104cafb537ef80628532af5ea4dbe70 5/1/2022 6:48
0x2aff3c5f51c0ae4a111edaec1daa305395361896 0x2aff3c5f51c0ae4a111edaec1daa305395361896 0xa2a4862373f3749773198e7bdd4c4b6cad5681cf406ce9f5824f68c3882a5a74 6/21/2022 21:41
0x503612b9914f1c74618d30ea167d58a55d132335 0xc3b2600be71232695a223ae62c384104e9a9dfae 0x3e8cac52a4561cc5d8bb58af79458567563f0e359a220c8440ea55843ad42cfb 7/25/2022 16:11
0x503612b9914f1c74618d30ea167d58a55d132335 0x503612b9914f1c74618d30ea167d58a55d132335 0x1b894353ce5f7ec92f63e190587510c3da443d0edc6de6f0d8b5db77e17399dc 9/2/2022 10:13

Figure 1

342

Methodology

It can be identified by visualization and further analysis of the details of the above transaction listed using etherscan.io

Safe Address

0xD50fF80Ce8EFc38D024272f4019978Dc017eA200

Parkcora commented 2 years ago

Why this is marked as invalid? These addresses were first proposed in this issue. There is no one else using the method provided in this issue. Could you help? @johannesmoormann Thank you very much.