safe-global / safe-user-allocation-reports

The proposed list of SAFE user allocations has been published on the Safe forum.
Creative Commons Zero v1.0 Universal
34 stars 10 forks source link

Sybil Attacker Report #491

Closed GitHub-BlockWu closed 2 years ago

GitHub-BlockWu commented 2 years ago

0x52B87a21A4aaa1e1fb2A1d6709fF8192137b0dfA 0x99F3bbc0766d93ee8D28cE4A11C98f49e05af74c 0x6E91D2D3052C4BBD33fEa7Ebd487CA79C6e99d6C 0xcB1c3b015f5F2A9256ef5773abbD4eA47fC019E9 0x718D79d02D9Dd30f52D9b659a5541811417a2824 0x926F4b6637Db95837Af8ebff4e3fD7FBd926B39C 0xa1Cb0A8e8b3EFC315d99D8447Ab085e1acDd2473 0x821D5E2e8f439FE2Ec5b53B15eD760e2C11E993e 0x126BBAc5148Ef8F786114860564DEBEe5183A357 0x5135ef87A0c6b3acf36e3c4784c7Ce16434910A0 0x4283BFF1E9CaA42629b39D2d452978F1C688aaE4 0xCe00e6b17C99Cbb05Ae94329c582214eF0CBCa4D 0xaae7cBDDf5eFfAd91Aeb081fcC51827B047d95C0 0xb1075FBc0f16d844cE80ad0bE985315638cD91a7 0x11F761d77B6fcD2dc00fFF36702FbBF7A15dbb9f 0x9c849ed28D4731920f8eF77Dc34555750df3Fa90 0x02744FA4bcf876445759B8EeDD039501a4737f2f 0xcb0B052f01eEc8E213D0E5420777e061BBfC2647 0x014B668aCB9135A97E91dF88608E0b79b4974604 0x5a39a1c90474Ecc36E7cBD92FA304842F2247cd0 0x094F7299A76a0E7ABE4fF571478A72109BbA6e9b 0x6A0573f6Af5D56Fb19067B58071049a6e812fb8d 0x586e65219cf521BC728796989893fCe2aA199235 0x3a7B73EA4B7b194901E85dCe6c15bF53e57aB6d1 0x71e3437858c38a9333035B8436AcEce9002a6178 0x0e2d9Dd59885426ae2A315D3Bfaae406e88a2398 0x100bf4A992794dd42260f0D51A83225efAC0bcA0 0x7678edDcc8fC526EEa09231Da834bBDE39F370A5 0xa1Cb0A8e8b3EFC315d99D8447Ab085e1acDd2473 0x3B4241314caBd3Dfb078479815600d138fb18E5E 0x231bbfc8EAd6be522FB897CF9dADD177d85178a9 0x5Bc4ae0AD47d4a4b079D77a696E98038a91f7ACe 0x9A6068ad247742d56c1D98a4eaa4366f34516C13 0xc41d30E2d779aCD9607599Db87Df3a3B48Ee376C 0x35097B29D5E7be7D60fE178577db9Cf4d9289324 0x4B4B2746020E24084Dc6873FEfC3DAcC560F19E2 0x26f33b252E6a04fD5a5969ed28f4f495F34Cb38e 0x25060564af193abfc0FB6E16C7f9C7Ce1E73e86C 0xc2ff4908E70DfC06dD4667fa25Ff5893df72759D 0x92142c25477c57975D5E73Fa2ae8b8D582D8059c 0x10535244116CEf6EBb7DD8a49a64b8178F424256 0xfd91bF7Ea862f7114f68c5C96ABCc42D4B031f8D 0x5586E1ED1490a778245B252588039c65d37e88fD 0x3B4241314caBd3Dfb078479815600d138fb18E5E 0x4Dce224149445cA5d5157d7F8C0D1Be4c4E8C018 0xB06EE1624a4aC3a5A093364B238Abf11A71c0c4C 0xd94C57942a8c3ec924aEA676c4bCe2bBAb3eeC24 0xABf8335e5CAcf1E66B61D474ab4d51a86eb6b9AA 0x0e2d9Dd59885426ae2A315D3Bfaae406e88a2398 0xdF317bAAe693C53638fDB8621d1042448F29DB58 0x46A0f79917f89615D506D3DfA1e1a6518c98db65 0xCE6F9902b8079ceD04C0C225a2B175CD7386886A 0x7f30560fA87581793319ed33F0A5b41d59360c5b 0x2Cb0741C2b9632856aDc95d5A60300e873AffCD7 0xf8726eCA186d21810f0399Ec69673D676B01e446 0xb08425e41BaDc8639a434aAa2e1E44b2A0d9eCe4 0x16a043f70Ac74E72D0A9C8A099cC7a08927CD138 0xbbac24665dFa5BeEF505081046f03ec2974AFB30 0x1C0699CD5C8434d7375a7A36103DFBB5C127Df1d 0x5597CA0b1bA28eb581c995e407Fe97d34c79807A 0x11F761d77B6fcD2dc00fFF36702FbBF7A15dbb9f 0xb9cfD6FcB26CCEDBBA56d0E6cBf0C100BC3De409 0x462944a23AbF19485b6e957CC47a10B2D5b4fAD4 0x6D878422c26710b7524330AEB749c41177ba0F02 0x07118752f314D241421307DaF60fAE4a39Db032b 0xc2ff4908E70DfC06dD4667fa25Ff5893df72759D 0x3B4241314caBd3Dfb078479815600d138fb18E5E 0x19CF71D5B788734038845fd0aa009183ff76d7a4

# Reasoning

The addresses listed above were created by 0x52B87a21A4aaa1e1fb2A1d6709fF8192137b0dfA for a long-term airdrop campaign, each safe has multiple internal txns, all safe transfers, internal launches and ERC-20 token transfers interact with (0x52B87a21A4aans1e1fb2A1d6709fF8192137b0dfA) All safes have transfer records (transfers between safes and safes, transfers between safes and owner address), I checked all SAFE transactions and came to this conclusion. After the announcement of Safe user allocations, the owner account collects the remaining Eth in all safes

Example:Batch collection of Eth balances to the owner's account

0x718D79d02D9Dd30f52D9b659a5541811417a2824 "September 7, 2022 Internal launch 0.0015Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x926F4b6637Db95837Af8ebff4e3fD7FBd926B39C "September 7, 2022 Internal launch 0.006Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0xa1Cb0A8e8b3EFC315d99D8447Ab085e1acDd2473 "September 7, 2022 Internal launch 0.002Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x821D5E2e8f439FE2Ec5b53B15eD760e2C11E993e "September 7, 2022 Internal launch 0.0018Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x126BBAc5148Ef8F786114860564DEBEe5183A357 "September 7, 2022 Internal launch 0.007eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x5135ef87A0c6b3acf36e3c4784c7Ce16434910A0 "September 7, 2022 Internal launch 0.009Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x4283BFF1E9CaA42629b39D2d452978F1C688aaE4 "September 7, 2022 Internal launch 0.0089Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0xCe00e6b17C99Cbb05Ae94329c582214eF0CBCa4D "September 7, 2022 Internal launch 0.0013Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0xaae7cBDDf5eFfAd91Aeb081fcC51827B047d95C0 "September 7, 2022 Internal launch 0.01Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x99F3bbc0766d93ee8D28cE4A11C98f49e05af74c "September 8, 2022 Internal launch 0.039Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0x6E91D2D3052C4BBD33fEa7Ebd487CA79C6e99d6C "September 8, 2022 Internal launch 0.0027Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account" 0xcB1c3b015f5F2A9256ef5773abbD4eA47fC019E9 "September 8, 2022 Internal launch 0.017Eth transferred to 0x56b803B91aBa4d7861Bb9Cda5FC2B5143fE2fC98 owner account"

The other 53 addresses all sent the safe remaining Eth to the owner account 0x52B87a21A4aaa1e1fb2A1d6709fF8192137b0dfA from September 7 to September 10, 2022 Check it out: https://etherscan.io/address/0x52b87a21a4aaa1e1fb2a1d6709ff8192137b0dfa#internaltx

-->

Methodology

tschubotz commented 2 years ago

There is not sufficient info on how this wouldn't eliminate legitimate usage other than the creation/execution account: 0x52B87a21A4aaa1e1fb2A1d6709fF8192137b0dfA. And that is actually a relayer.

Also "Methodology" is missing.

GitHub-BlockWu commented 2 years ago

Maybe I still need some time to provide the methodology, but he is indeed an airdrop hunter, and he doesn't want to see the airdrop hunter get Safe