Closed skyonedot closed 2 years ago
@tschubotz @johannesmoormann @lukasschor Hello, Can you check this, i even don't edit it. SAD
Thanks for the report. Most of these Safe have been found by another report already. Except:
0xecefde4b891733218692f6b3061f1b1a7fa1c0a2
0x43c3db51f7837add8bb6bf6f41191ac4ff2bf9fc
0xfd7dec19a3bc8b5ce18351aa16ba21493fb90b81
0xca5bec9eff81729e1fd1d44561dd36f895ce2b4f
0x01a0cbead3deff0eaf26e80dc5b7989a5ed1c622
0x02ebf2d04aaa3f28114929e3917b7381e4f41cc8
0x780f60d78de14cfce5f7747516415deb381f1501
0x03511d3e1e7969025c9d49a4f1f1aedb3841f75a
0x04d109c79a9533bdfc4a7e7aade9df9d95b4775e
However for these, I'm unable to follow how this is no legitimate use.
Related Safe Addresses
Reasoning
All of the multi-sign address, the behaviour is always same and stange .
100% of the every group multi-sign adddress addOwner and removeOwner transaction took place same time peried (usually within a day)
100% of the every group multi-sign adddress to add or remove address is same
100% of the every group owner is Empty (never send transactions)
100% of the every group multi-sign adddress addOwner and removeOwner transaction is sent by sameone
Please Check Table
Methodology
Addresses are reported by retrieving information from the chain, using bitquery's graphql, and detecting abnormal behavior, such as empty wallets, mutual transfers, etc.
When only some of the anomalous behaviors are present, we can consider the address reasonable, but when an address has all the anomalous behaviors, we have good reason to suspect that the address is false. Especially if the multi-signature address and the owner address have obvious exceptions both, then it is obvious that this is airdrop farmer.
Abnormal behaviors include
For Multi-Sign Address
For Owner Address
If the verification is passed and my strategy is great, I can provide my source code, but for now it is not conveninet
Safe Address
0xce495858e36c95f491b5a32ca2664405cf10ab76
Thanks