Closed Neverlander0 closed 2 years ago
Thanks for the report. Some of these wallets have been reported before, but we found the following to be related to airdrop farming:
0xfb5637d9aa502c0ac6779e87428ad735750d1f3d
0xf591b6678858044fc55681d0a86227ee13d33a59
0xf57cdeb0e7ecbc5be25731721f4400c0bf380443
0xf444d4daee0c2149ae859062e9ae03186bb7c6a3
0xf1864b5b6ad0219ff578e25eba1a56c603163c34
0xefbcf693798bc9c4c0bc74a1410ff805f95e8332
0xebd8a9c65a5f798670cd488ab957d81e71dbe73d
0xe973ed36c5d98302d456e7fd48813b2c6996a2ea
0xe73de476f9d393ca589049dbe64ee3df8413fe4e
0xe717ba1093913b47f476f75b0333cfccfbf32ada
0xde1e56dfd2a24ddb0089f4fbb8cf0603d55574ff
0xde1abd0b45b8845090cee575586d80ae9ed40faa
0xd477304e18c0df37030ee09709b42adb7143eec3
0xce608793cf8db09bb2e764fbb22779b253870fba
0xc62d82ac423e46302ca1bbc530dfafb75d14c3ac
0xc2af99b95872603e2d50045901e7692d2d85b95e
0xba0078dfacc4a06d335b04804e83f4caea095a12
0xb847984bec8ffe7851af125042f8a56b682e960c
0xa73cf67a9970d1e42d66ef1c547e92c03a261537
0x9f894f5e4f2d8e5b953fb6c01691f25ecd9e1ec0
0x9ca0c1d5740eab234e8040f181000b1cee065f4a
0x98e8a6c1670ce16072f59d9e96de82d7f92ee9e4
0x8c5b80337379d08011023f7ebcf242929989be99
0x779ced4f86e4ba2de7b303931efee17b0f23430c
0x6ea511a441f60f6838e5bf6c15db6dbe701f2a47
0x6cfaecf069bcaea72daa8ad9965335d9d6c823b4
0x6c51954dc6c652ba46f833f1cc66ec4d1ad2d3a2
0x5b05e0317fe05d16d9fb819c712ceb23d3894bba
0x5ac3b6d06495d48d8d8db55a85aeff39c8d974c7
0x589214586880a3099517a3fbdfe932939caa65c4
0x55b7c326ca5fd26f96b485df37da9eb911294652
0x5598e905a263bb1dd86c3e6eb9c4ad9824c63b24
0x53cc9dd3ded8cf62dbc7946d25b901b7adcdcf78
0x5052336f3627883234e3e2bf60308ce83880fde8
0x49e106e16affd7b3d691246301c4a26cdd7b4b3e
0x48a118f444bb4c4bae91b81dd64ae3cce276412a
0x418f18b6ec449296322cba386fe0e94ffca10d32
0x36a10c0e8278d549603cba4ebbf9ab290df93415
0x36721f87093fd9fc051e0b25e55ea29d26a8fbde
0x336e0bb4b4f8f1e9d38dcf650cb0f096ee3aa09c
0x32e7aa624c247ab1495d99b1f7d87490f85294ca
0x262623d6e46894fbebf1f53d832788a53d2e490f
0x23670b9ff6f1f4294f222a079fc47f2330e6c88b
0x21f467019584d4226cc1b1958499653b6e4a6c3e
0x21c3675c075cb516c52fb2da9c78d0fe0b4b72f8
0x1e8b92c75161e6ad8a9fe3ae0259444203b4d528
0x1e6b34fcc3d064e709a998625abf5474370a87e0
0x1ca6cf7c52cb0747817ce0aca1060b5c47be4180
0x17b2717ecc7fbc1538cd268cca7b395541f4a2c7
Related Safe Addresses
0xfb5637d9aa502c0ac6779e87428ad735750d1f3d 0xf591b6678858044fc55681d0a86227ee13d33a59 0xf57cdeb0e7ecbc5be25731721f4400c0bf380443 0xf444d4daee0c2149ae859062e9ae03186bb7c6a3 0xf1864b5b6ad0219ff578e25eba1a56c603163c34 0xefbcf693798bc9c4c0bc74a1410ff805f95e8332 0xebd8a9c65a5f798670cd488ab957d81e71dbe73d 0xe973ed36c5d98302d456e7fd48813b2c6996a2ea 0xe73de476f9d393ca589049dbe64ee3df8413fe4e 0xe717ba1093913b47f476f75b0333cfccfbf32ada 0xde1e56dfd2a24ddb0089f4fbb8cf0603d55574ff 0xde1abd0b45b8845090cee575586d80ae9ed40faa 0xd477304e18c0df37030ee09709b42adb7143eec3 0xce608793cf8db09bb2e764fbb22779b253870fba 0xc62d82ac423e46302ca1bbc530dfafb75d14c3ac 0xc2af99b95872603e2d50045901e7692d2d85b95e 0xba0078dfacc4a06d335b04804e83f4caea095a12 0xb847984bec8ffe7851af125042f8a56b682e960c 0xa73cf67a9970d1e42d66ef1c547e92c03a261537 0x9f894f5e4f2d8e5b953fb6c01691f25ecd9e1ec0 0x9ca0c1d5740eab234e8040f181000b1cee065f4a 0x98e8a6c1670ce16072f59d9e96de82d7f92ee9e4 0x8c5b80337379d08011023f7ebcf242929989be99 0x779ced4f86e4ba2de7b303931efee17b0f23430c 0x6ea511a441f60f6838e5bf6c15db6dbe701f2a47 0x6cfaecf069bcaea72daa8ad9965335d9d6c823b4 0x6c51954dc6c652ba46f833f1cc66ec4d1ad2d3a2 0x5b05e0317fe05d16d9fb819c712ceb23d3894bba 0x5ac3b6d06495d48d8d8db55a85aeff39c8d974c7 0x589214586880a3099517a3fbdfe932939caa65c4 0x55b7c326ca5fd26f96b485df37da9eb911294652 0x5598e905a263bb1dd86c3e6eb9c4ad9824c63b24 0x53cc9dd3ded8cf62dbc7946d25b901b7adcdcf78 0x5052336f3627883234e3e2bf60308ce83880fde8 0x49e106e16affd7b3d691246301c4a26cdd7b4b3e 0x48a118f444bb4c4bae91b81dd64ae3cce276412a 0x418f18b6ec449296322cba386fe0e94ffca10d32 0x36a10c0e8278d549603cba4ebbf9ab290df93415 0x36721f87093fd9fc051e0b25e55ea29d26a8fbde 0x336e0bb4b4f8f1e9d38dcf650cb0f096ee3aa09c 0x32e7aa624c247ab1495d99b1f7d87490f85294ca 0x262623d6e46894fbebf1f53d832788a53d2e490f 0x23670b9ff6f1f4294f222a079fc47f2330e6c88b 0x21f467019584d4226cc1b1958499653b6e4a6c3e 0x21c3675c075cb516c52fb2da9c78d0fe0b4b72f8 0x1e8b92c75161e6ad8a9fe3ae0259444203b4d528 0x1e6b34fcc3d064e709a998625abf5474370a87e0 0x1ca6cf7c52cb0747817ce0aca1060b5c47be4180 0x17b2717ecc7fbc1538cd268cca7b395541f4a2c7 0x0ac7d3f641ff2d6fb5445c2d268ec16be3e1851a 0x0a4f9b36dec170275c1d33d13607b156b11bddad 0x04e35228541d895cdd6383e9ce3bd2f5dc2b028d 0x03882a98090de9f6337a149f62d1627eb8321bd8 0x00e10186bf1e23e65d58ccd4393e517279068de1 0x005699ff2f1853b7ff9bbba51298e55b583b5ac0
Reasoning
These Safe address not only are all created by 0xb211d379aac002e7b575a95496dd390719a60352 ,but they have the same Erc721 behavior like this. https://etherscan.io/address/0xebd8a9c65a5f798670cd488ab957d81e71dbe73d#tokentxnsErc721 https://etherscan.io/address/0xf591b6678858044fc55681d0a86227ee13d33a59#tokentxnsErc721 https://etherscan.io/address/0xf57cdeb0e7ecbc5be25731721f4400c0bf380443#tokentxnsErc721
1、Most important! An Erc721 token was transferred by 0x95e453D37AD4f2Dc877aBed99C3EEf382333Cb62 into Safe wallets on 2022-8-7 and then this Erc721 toekn was transferred out to 0xfc4913214444aF5c715cc9F7b52655e788A569ed on 2022-8-16. All these Erc721 token ID are continuous!
2、These Safe address are all created by 0xb211d379aac002e7b575a95496dd390719a60352 on 2022-8-6.
3、Let us analyse the owners of All Safe address!
There are only two owners. owner 1: 0xb211d379aac002e7b575a95496dd390719a60352 Safe address creator All 66 Safe address were created by this wallet.
owner 2: 0x95e453D37AD4f2Dc877aBed99C3EEf382333Cb62
executor:0xc38a623d8b0fe07607b8ee6921d9ef604367bdad All 66 Safe address were executed transactions by owner 1 or this address.
All 66 Safe address are controlled by owner 1 and owner 2 , can we find some connections between them? The answer is Yes.
https://etherscan.io/address/0x95e453d37ad4f2dc877abed99c3eef382333cb62#internaltx Eth in owner 2 is transferred from this Safe wallet https://etherscan.io/address/0x16ef625ed2a56074a80d15e2f516dafe7e24fdd0 and we found owner 1 is the creator and only owner of this Safe wallet.
Not only owner 2 but also executor 's eth is also from this Safe wallet. https://etherscan.io/tx/0xd7aec5f101d33421602dc69eaeda1dd93b54fd92ced845626b6a92c801419880
Obviously we can conclude that owner 1、owner 2 and executor wallet are controlled by one person. All 66 Safe address are controlled by the same creator、owners and executor.
From all analysis above, we can conclude that all owner and Safe address are actually controlled by one person, i means, airdrop farmer.
orginal report of #163: https://github.com/safe-global/safe-user-allocation-reports/issues/163
Methodology
Download all the transactions of Safe wallet factory and find the address created many Safe wallets. Analyse all the transacitons and behavior of the Safe wallets and finally find the suspicious airdrop farmer address. After finding suspicious airdrop farmer address , find the evidence how they do sybil-attack.
Safe Address
My Safe Address 0x75c5d4B456b697C9CCa3DAAf4c4a2392b3E1Ddbb