<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>X-explore</title>
        <link>https://paragraph.com/@x-explore</link>
        <description>undefined</description>
        <lastBuildDate>Thu, 23 Jul 2026 07:18:56 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>X-explore</title>
            <url>https://storage.googleapis.com/papyrus_images/b6696ed73c3a67d513f527cea28497377b5d6ff503f0b3083984075dda9c7950.png</url>
            <link>https://paragraph.com/@x-explore</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[Comprehensive Analysis of Phishing Attacks on Blockchain]]></title>
            <link>https://paragraph.com/@x-explore/comprehensive-analysis-of-phishing-attacks-on-blockchain</link>
            <guid>TP92uaT7ijGWi4a78l7b</guid>
            <pubDate>Wed, 29 May 2024 03:04:54 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.IntroductionAccording to the article from Chainalysis in 2024, $24.2B worth of money has been received by illicit addresses which takes 0.34% of total on-chain transaction volume. With the increased interest in the blockchain industry, more users and assets started to flow in the Web 3 market, yet there have been increased reported incidents from users of cyber attacks. Among various attacks, phishing remains one of the major asp...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h1 id="h-introduction" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Introduction</strong></h1><p>According to the article from Chainalysis in 2024, $24.2B worth of money has been received by illicit addresses which takes 0.34% of total on-chain transaction volume. With the increased interest in the blockchain industry, more users and assets started to flow in the Web 3 market, yet there have been increased reported incidents from users of cyber attacks.</p><p>Among various attacks, phishing remains one of the major aspects of cyber attacks. Attacker targets various tokens such as stablecoins, ETH, or even altcoins. They lure users to sign malicious transactions or input private keys to hold control of the user’s account. The article will further investigate existing methods of phishing scams and explore methods to prevent or identify malicious accounts in the future.</p><h1 id="h-background-and-related-work" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Background &amp; Related Work</strong></h1><h1 id="h-existing-phishing-attack-methods-framework-off-chain" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Existing phishing attack methods Framework (off-chain)</strong></h1><p>Phishing attacks focus on alluring users to input private information in the online world. There are various ways to allure users but most phishing is done on platform such as email, Social media channels, or cloned websites that looks legitimate. Such email or website allures users to input private information or sign transactions that give control to the scammer. <strong>The article will investigate 3 major frameworks scammers utilize on off-chain first.</strong></p><h1 id="h-spear-phishing" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Spear Phishing</strong></h1><p>Spear Phishing attacks target specific individuals or organizations. By gathering customized information beforehand, the attacker crafts a personalized email to specific groups making the email legitimate. Moreover, with the rise of generative AI, one scammer now has the power to gather personalized information and craft personalized emails targeting wider user groups than before.</p><h1 id="h-pharming-attack" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Pharming attack</strong></h1><p>Pharming attack crafts URL that redirects to fake websites. For instance, on Slack, website, “<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://www.apple.com/">www.apple.com</a>&quot; can look identical to “<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://www.appie.com/">www.appie.com</a>&quot; when “i” is replaced with capital “I”. Through such a method, the scammer crafts malicious URLs and distributes them via email or SNS channels such as Telegram or Slack.</p><h1 id="h-fake-browser-extensions" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Fake browser extensions</strong></h1><p>The scammer programs malicious extensions programs and crafts download links which are then distributed through email or SNS channels. Upon clicking, such an extension will be downloaded in the user’s environment, which will look for private information such as mnemonic phrases and private keys.</p><p>Note that once a user clicks the <strong>download link, inputs private information, or signs transactions</strong>, the scammer is in total control of the account and the user has no method to roll back. Hence, it is crucial that a user does not click on sources he or she does not trust.</p><h1 id="h-extraction-of-funds-on-blockchain-on-chain" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Extraction of funds on Blockchain (on-chain)</strong></h1><p>Given the off-chain framework, the article will look at how scammer gains full control on on-chain wallets. In the field of blockchain, attackers can gain control of a user’s account in various ways. Especially with ERC-20 token contracts such as stablecoins and altcoins, scammers do not necessarily need a user’s private key but instead need a user’s signature sign-in on-chain or off-chain. The article will look at various ways attackers utilize to drain funds.</p><h1 id="h-private-key" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Private key</strong></h1><p>Extraction of private keys is not a common method nowadays. Attacker crafts websites or emails that require users to input a seedphrase or private key. Once the attacker gains the user’s private key or seed phrase, the attacker has total control of the wallet and address.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1e96fe23e35120034f64bb68cbc9eb61b2c2ee0ff8b8751427afd23e75acdd6d.png" alt="Image of sample pharming attack based on private key. (Source: X)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Image of sample pharming attack based on private key. (Source: X)</figcaption></figure><p>Even though it is a simple method, users in the past easily fell into the trap due to lack of knowledge in the field of blockchain.</p><h1 id="h-approve-and-transferfrom" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Approve &amp; TransferFrom</strong></h1><p>Upon the standard of ERC-20, ERC-20 tokens support push and pull transactions for the application of the De-Fi protocol. Push transaction is initiated by the payer who decides how much money to be sent to the payee. However, in pull transactions, payees instruct payers how much money to be sent. Hence, the third part can control the transactions. Pull transaction instructions are managed in Web 3 in the procedure below.</p><ol><li><p>Users call and sign Approve(). <code>approve( owner, spender, amount)</code> sets how much the token payee&apos;s address can take from user&apos;s address. Note that there are <code>increaseAllowance( spender, amount)</code> which can be exploited. The difference between approve and increaseAllowance is approve sets new allowance while increaseAllowance adds to existing allowance [sets a hard limit].</p></li><li><p>Once the boundary is set, payee can call <code>transferFrom(to, from, amount)</code> which will move user&apos;s token to payee&apos;s address.</p></li></ol><p>In real-world applications, it is usually a smart contract who is the payee. The user will transfer the ERC-20 token to the smart contract and the smart contract will manage funds accordingly. However, it is important to note that once the smart contract gets hacked, a user’s fund will be drained according to how much allowance has been set. In some scenarios, to simplify the user’s UI, smart contracts might ask for a high amount (Infinite amount) of allowance, so that the user do not have to sign every time to set allowances to save gas fees. Since the amount is set to an infinite amount, the user must make sure that the third party is a reliable source.</p><p>Setting allowance and utilizing the transferFrom method has been a vulnerable point for quite a long time. However, due to it’s practical application in Decentralized Finance (De-Fi) and dApps, Approve &amp; TransferFrom is frequently utilized nowadays with improvements made.</p><p>For instance, due to the max capacity of EVM set to 1024, complex procedures such as set allowance → transferFrom usually led to “1024 stack depth problem” as stacks exceeded the limitation of given spaces leading to revertation of the transaction.</p><p>Hence, if each method is called and proceeds to the next method, calling it would introduce a huge vulnerability point. Major exploitation can be re-entrancy attacks. Vitalik was aware of certain scenarios and made improvements back in 2017 and introduced the ERC-223 standard.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/592f54508a5ce1fc3fea11fbe4041b68bd1bcbcb66bdc356bdbd856499b51df9.png" alt="Screenshot of Vitalk’s comment on 1024 stack depth. (source: Github)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Screenshot of Vitalk’s comment on 1024 stack depth. (source: Github)</figcaption></figure><p>There have been other improved protocols introduced, such as permit or permit2, yet the security of the wallet depends on the user signing transaction. Hence, it is important to check 3 major aspects to prevent potential scams.</p><ol><li><p><strong>Approval amount</strong>: scammers often create an approval request with unusually high allowances in order to acquire total control of the dedicated ERC-20 token. When signing a contract, make sure to check the allowance amount.</p></li><li><p><strong>Verified Smart Contract</strong>: Make sure you are signing allowance signature to verified smart contracts provided by known dApps. Checking tags and memo from Etherscan or any other blockchain explorer can help identify if a contract has been flagged as malicious or not.</p></li><li><p><strong>Check security alerts</strong>: wallet providers such as Meta Mask or Wallet Connect generate prompts if you are interacting with potential scamming contracts. Make sure to check such alerts.</p></li></ol><h2 id="h-example-cases" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Example Cases</strong></h2><p>Let’s visualize how an actual attack is conducted and recorded in Blockchain Explorer.</p><p>Blockchain: BSC Chain</p><p>Date: 2023–05–11</p><p>Attacker: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x49dc14dd851b6eae8d685715e12a06cc1bfc5d8d">0x49Dc14Dd851B6EaE8d685715e12a06cc1BFC5d8d</a></p><p>Victim: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x5f464c94e93cebd56ae2f1220912ba0ab0a27a38">0x5F464c94e93CEbd56aE2F1220912BA0ab0a27a38</a></p><p><strong>Step1</strong>: User signs Approval contract</p><p>Upon receiving false information on the Web 2 environment through a telegram channel, Instagram, or phishing website, the user receives an Approve signature request.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d159260548158122e04b68a468b7a0d3d73c29e33ebed5d5c28263bcfb519af7.png" alt="Victim approved Scammer for Shiba Inu token" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Victim approved Scammer for Shiba Inu token</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b7983ef7da31af73e1a12d764b022cb57725c2e51448cef685f100a89ea767c8.png" alt="Approval and transfer Request. Victim approved total of 426923054270173310680061630 SHIB to be controlled by scammer" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Approval and transfer Request. Victim approved total of 426923054270173310680061630 SHIB to be controlled by scammer</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d0ac5f1c516eaa624cc327399f7e22c83a6b37c884971c867eb2dfe87729d472.png" alt="Screenshot of the fund flow from Dex or Cex → Victim → Scammer" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Screenshot of the fund flow from Dex or Cex → Victim → Scammer</figcaption></figure><p><strong>Step 2</strong>: Drain funds</p><p>Now, as the scammer has control over <code>426923054270173310680061630</code> or less amount of ERC-20 token funds in the victim&apos;s address, the scammer starts to transfer the victim&apos;s token to his or her account. As shown below, the total of <code>256153832.56</code> SHIB has been drained from the victim&apos;s account.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b7983ef7da31af73e1a12d764b022cb57725c2e51448cef685f100a89ea767c8.png" alt="the transaction was done by the attacker draining 256153832.56 SHIB" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">the transaction was done by the attacker draining 256153832.56 SHIB</figcaption></figure><h1 id="h-permit" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Permit</strong></h1><p>Permit was introduced in ERC-2612 as an improved measurement of the approve &amp; transferFrom workflow. Unlike approve and transferFrom, an off-chain signature is created meaning that users do not have to sign for approval on the on-chain before. The workflow of Permit and transferFrom follows below:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/659710fc03095db4c4a7ffccfb7dea7d173d8e4223460db9d8cfa68d8e930419.png" alt="Technological Flow of Permit protocol (source: Medium)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Technological Flow of Permit protocol (source: Medium)</figcaption></figure><ol><li><p>The user needs to create a signature through <code>permit (owner, spender, value, nounce, deadline)</code>. The return values for r, s, v which are 3 splits of signature that has been created.</p></li><li><p>Once the user creates the Permit signature with r,s, and v, a third party will call the <code>permit(owner,spender, value, deadline, v, r, s)</code> with the following values. Once transacted for stage change, it will set the allowance accordingly.</p></li><li><p>Within one transaction, once allowance is set, the third party will execute transfer.</p></li></ol><p>Through the creation of offline signature utilizing permit(), gas fees were able to be saved as there was no need to sign allowance on-chain. Moreover, security has been massively improved through creation of r, s, v, the user never exposes his or her private key to create a signature.</p><p>Note that not all ERC-20 standard token support methods permit(). Moreover, the core mechanism of permit() is in the workflow of approve &amp; transferFrom. Vulnerability points lie on the user creating or signing Permit().</p><h2 id="h-example-cases" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Example Cases</strong></h2><p>Let’s visualize how an actual attack is conducted and recorded in Blockchain Explorer.</p><p>Blockchain: ETH</p><p>Date: 2024–05–24</p><p>Attacker:<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/token/0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48?a=0x77865b925f96fc49837cfe27ec04cd5a691e61ef">0x77865b925f96fc49837cfe27ec04cd5a691e61ef</a></p><p>Victim: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x7cdd2a99fc014194218119a7100c259e31a10bf2">0x7cdd2a99fc014194218119a7100c259e31a10bf2</a></p><p><strong>Step1</strong>: User generates an Off-chain signature</p><p>Such a process cannot be tracked on Blockchain Explorer as it is done off-chain. The scammer will allure the victim to generate an off-chain signature with a simple click. Even though the victim has not signed a transaction online, signing an off-chain signature through the wallet already allows the scammer to perform TransferFrom later.</p><p><strong>Step2</strong>: Scammer signs the Permit contract from Off-chain signature</p><p>The scammer submits the signed message to the ERC-20 Token contract via an on-chain transaction. Upon validation against the victim’s address and nonce, an approval request will be made. Notice that through permit there has been only one on-chain transaction. Compared to traditional Approve&amp; TransferFrom, there is one less transaction saving gas fee.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0440e97e92b97b829ba1644be85f330c1a696d9a6b4ce41d3b21e5a3c7e7d36a.png" alt="Permit and transferFrom has been called within one execution" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Permit and transferFrom has been called within one execution</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4b96429ad5159cb06e48470198e6e735dc4faaeca0c08c9b51e2d1ac1ef89063.png" alt="Notice the unusually large amount in approval" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Notice the unusually large amount in approval</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/267429109508f27cd0f81373908ecb6789124592433a16d42c2431b0394f02c8.png" alt="A total of 173455570204 USDC has been drained" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">A total of 173455570204 USDC has been drained</figcaption></figure><h1 id="h-erc-4337-account-abstraction-or-smart-contract-wallet" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>ERC-4337 ( Account Abstraction or Smart Contract Wallet)</strong></h1><p>Introduced by Vitalk in 2021, the novel AA scheme has been created based on the current existing consensus layer protocol. Unlike the former introductions of AA schemes such as <strong>EIP-86</strong> ( Bare multi-sig AA), <strong>EIP-3074</strong> (Auth and Authcall), and <strong>EIP-2938</strong> (Account Abstraction), it was the first scheme that introduces AA within the current consensus layer protocol allowing easier integration in the current market.</p><h2 id="h-account-abstraction-aa" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Account Abstraction (AA)</strong></h2><p>In blockchain there exist two major types of accounts: Externally Owned Account and Smart Contract. The traits of the two accounts differ as shown in the table below.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/be8458e06ec268ec51c620ee13db4c6692168444c039a1218a37c7d1c512598c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The goal of AA is to create a unified account that holds the benefit of EOA and SC: full programmability with the ability to initiate transactions. The benefits of AA are:</p><ul><li><p>Ability to respond to contract calls directly</p></li><li><p>Ease of transfer ownership of account ( was not able to be done of EOA)</p></li><li><p>Introduce novel validation rules ( Pass key can be checked within SC levels)</p></li><li><p>Removes gas fee cost from EOA to smart contract</p></li><li><p>Manage one address instead of EOA and SC</p></li><li><p>Introduction of new payment of gas fee ( does not have to be native token)</p></li></ul><h2 id="h-workflow-of-erc-4337" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Workflow of ERC-4337</strong></h2><p>AA is a new standard that can create a unified account that massively improves UI for users. The technical flow of ERC-4337 follows as below:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b0d0b08560bee300e74e8e34a6cda3f644508a7958cab40a3ae1c27e283cc449.png" alt="Flow diagram of ERC-4337 (source: Eden Network)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Flow diagram of ERC-4337 (source: Eden Network)</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/2214b072091bc5fa1826162d9db43f294b788b67528d6d9660ea3f68b6b6d9ef.png" alt="Technical Flow diagram of ERC-4337 (source: Offical ERC-4337 Documentation)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Technical Flow diagram of ERC-4337 (source: Offical ERC-4337 Documentation)</figcaption></figure><p>ERC-4337 can be divided into four major processes.</p><p><strong>Step 1:</strong> Creation of User Operations</p><p>Through dApps and wallets, users can interact with AA scheme operations to create User Operations. Users have a better UI as the application can support various features in one, such as multi-signature, social recovery, etc. Once User Operations are created, it will create a signature offline which will be validated by the account later before execution.</p><p><strong>Step 2</strong>: Bundler Processing</p><p>Once a user submits the User Operations, it will be stored in the User Operation Mempool where the bundler will gather and aggregate into a bundle. The bundler will check the validity of the transactions and once passed, the bundled transactions will be sent to on-chain for processing.</p><p><strong>Step 3</strong>: Entrypoint Contract</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8e6122042528347c7f1c18db7e765c743ae5851f7555f24b1cbc94d93534fc79.png" alt="Regulation regarding EntryPoint Contract. (source: Offical ERC-4337 Document)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Regulation regarding EntryPoint Contract. (source: Offical ERC-4337 Document)</figcaption></figure><p>There is a unified Entrypoint Contract in the chain as mentioned in the above regulation. Upon receiving the bundle transactions it will perform gas calculations to ensure how much gas fee the smart contract account has to pay. Through the Entrypoint contract, users do not have to pay for the gas fee as the smart contract account pays or paymaster. Moreover, the most imperative advantage of the scheme is that gas fees do not have to be paid in Native tokens. Fee can be regulated upon dApps and paid with ERC-20 token via PayMaster. Such an arrangement improves the user’s experience with transactions.</p><p><strong>Step 4</strong>: Validation and Execution</p><p>Upon receiving methods from the Entrypoint Contract, validation of original User Operations will be done. Once validated, it will execute the transaction accordingly. Note that it is an EntryPoint contract that will add the transactions to the ETH network mempool.</p><h2 id="h-vulnerability-points" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Vulnerability Points</strong></h2><p>From a security perspective, there remain a lot of vulnerability points. Since the AA scheme allows the execution of user operations from off-chain managed bundler to an on-chain, it provides a lot of gaps for scammers to manipulate users to perform user operations. The article will provide potential vulnerability points throughout the operation execution process.</p><p><strong>Fake Entrypoint Contracts</strong></p><p>Note that there should be only one EntryPoint contract per chain. However, a scammer can craft his or her version of EntryPoint contracts on a chain to perform user operations. Since most of security protocols and monitoring will be heavily focused on singleton EntryPoint contract, the scammer might want to create his or her version to avoid it. Yet, such contract can be easily detected and managed accordingly with current blockchain monitoring systems.</p><p><strong>Malicious Bundler</strong></p><p>The scammer can craft his or her version of Bundler service with user operation mem pool. Bundler service consists of four major aspects: configuration, RPC server, Alternative mempool, and bundling UserOperations.</p><p>Configuration sets the address for EntryPoint and beneficiary accounts.</p><p>RPC Server handles operations given EntryPoint addresses.</p><pre data-type="codeBlock" text="async handleMethod (method: string, params: any[]): Promise&lt;any&gt; {
    let result: any
    switch (method) {
      case &apos;eth_supportedEntryPoints&apos;:
        result = await this.methodHandler.getSupportedEntryPoints()
        break
      case &apos;eth_sendUserOperation&apos;:
        result = await this.methodHandler.sendUserOperation(params[0], params[1])
        break
      case &apos;eth_estimateUserOperationGas&apos;:
        result = await this.methodHandler.estimateUserOperationGas(params[0], params[1])
        break
      case &apos;eth_getUserOperationReceipt&apos;:
        result = await this.methodHandler.getUserOperationReceipt(params[0])
        break
      case &apos;eth_getUserOperationByHash&apos;:
        result = await this.methodHandler.getUserOperationByHash(params[0])
        break
      // ...
      default:
        throw new RpcError(`Method ${method} is not supported`, -32601)
    }
    return result
  }
"><code><span class="hljs-function"><span class="hljs-keyword">async</span> <span class="hljs-title">handleMethod</span> (<span class="hljs-params">method: <span class="hljs-built_in">string</span>, <span class="hljs-keyword">params</span>: any[]</span>): Promise&#x3C;any></span> {
    <span class="hljs-keyword">let</span> result: <span class="hljs-function">any
    <span class="hljs-title">switch</span> (<span class="hljs-params">method</span>)</span> {
      <span class="hljs-keyword">case</span> <span class="hljs-string">'eth_supportedEntryPoints'</span>:
        result = <span class="hljs-keyword">await</span> <span class="hljs-keyword">this</span>.methodHandler.getSupportedEntryPoints()
        <span class="hljs-keyword">break</span>
      <span class="hljs-keyword">case</span> <span class="hljs-string">'eth_sendUserOperation'</span>:
        result = <span class="hljs-keyword">await</span> <span class="hljs-keyword">this</span>.methodHandler.sendUserOperation(<span class="hljs-keyword">params</span>[<span class="hljs-number">0</span>], <span class="hljs-keyword">params</span>[<span class="hljs-number">1</span>])
        <span class="hljs-keyword">break</span>
      <span class="hljs-keyword">case</span> <span class="hljs-string">'eth_estimateUserOperationGas'</span>:
        result = <span class="hljs-keyword">await</span> <span class="hljs-keyword">this</span>.methodHandler.estimateUserOperationGas(<span class="hljs-keyword">params</span>[<span class="hljs-number">0</span>], <span class="hljs-keyword">params</span>[<span class="hljs-number">1</span>])
        <span class="hljs-keyword">break</span>
      <span class="hljs-keyword">case</span> <span class="hljs-string">'eth_getUserOperationReceipt'</span>:
        result = <span class="hljs-keyword">await</span> <span class="hljs-keyword">this</span>.methodHandler.getUserOperationReceipt(<span class="hljs-keyword">params</span>[<span class="hljs-number">0</span>])
        <span class="hljs-keyword">break</span>
      <span class="hljs-keyword">case</span> <span class="hljs-string">'eth_getUserOperationByHash'</span>:
        result = <span class="hljs-keyword">await</span> <span class="hljs-keyword">this</span>.methodHandler.getUserOperationByHash(<span class="hljs-keyword">params</span>[<span class="hljs-number">0</span>])
        <span class="hljs-keyword">break</span>
      <span class="hljs-comment">// ...</span>
      <span class="hljs-literal">default</span>:
        <span class="hljs-keyword">throw</span> <span class="hljs-keyword">new</span> RpcError(`Method ${method} <span class="hljs-keyword">is</span> <span class="hljs-keyword">not</span> supported`, <span class="hljs-number">-32601</span>)
    }
    <span class="hljs-keyword">return</span> result
  }
</code></pre><p>Alternative memory stores the operations in array format before sending it to a chain. From a bundler’s perspective, prevention of DoS attacks should be managed here.</p><pre data-type="codeBlock" text="// add userOp into the mempool, after initial validation.
  // replace existing, if any (and if new gas is higher)
  // revets if unable to add UserOp to mempool (too many UserOps with this sender)
  addUserOp (userOp: UserOperation, userOpHash: string, prefund: BigNumberish, senderInfo: StakeInfo, referencedContracts: ReferencedCodeHashes, aggregator?: string): void {
    const entry: MempoolEntry = {
      userOp,
      userOpHash,
      prefund,
      referencedContracts,
      aggregator
    }
    const index = this._findBySenderNonce(userOp.sender, userOp.nonce)
    if (index !== -1) {
      const oldEntry = this.mempool[index]
      this.checkReplaceUserOp(oldEntry, entry)
      debug(&apos;replace userOp&apos;, userOp.sender, userOp.nonce)
      this.mempool[index] = entry
    } else {
      debug(&apos;add userOp&apos;, userOp.sender, userOp.nonce)
      this.entryCount[userOp.sender] = (this.entryCount[userOp.sender] ?? 0) + 1
      this.checkSenderCountInMempool(userOp, senderInfo)
      this.mempool.push(entry)
    }
    this.updateSeenStatus(aggregator, userOp)
  }
"><code><span class="hljs-comment">// add userOp into the mempool, after initial validation.</span>
  <span class="hljs-comment">// replace existing, if any (and if new gas is higher)</span>
  <span class="hljs-comment">// revets if unable to add UserOp to mempool (too many UserOps with this sender)</span>
  addUserOp (userOp: UserOperation, userOpHash: <span class="hljs-keyword">string</span>, prefund: BigNumberish, senderInfo: StakeInfo, referencedContracts: ReferencedCodeHashes, aggregator?: <span class="hljs-keyword">string</span>): void {
    const entry: MempoolEntry <span class="hljs-operator">=</span> {
      userOp,
      userOpHash,
      prefund,
      referencedContracts,
      aggregator
    }
    const index <span class="hljs-operator">=</span> <span class="hljs-built_in">this</span>._findBySenderNonce(userOp.sender, userOp.nonce)
    <span class="hljs-keyword">if</span> (index <span class="hljs-operator">!</span><span class="hljs-operator">=</span><span class="hljs-operator">=</span> <span class="hljs-number">-1</span>) {
      const oldEntry <span class="hljs-operator">=</span> <span class="hljs-built_in">this</span>.mempool[index]
      <span class="hljs-built_in">this</span>.checkReplaceUserOp(oldEntry, entry)
      debug(<span class="hljs-string">'replace userOp'</span>, userOp.sender, userOp.nonce)
      <span class="hljs-built_in">this</span>.mempool[index] <span class="hljs-operator">=</span> entry
    } <span class="hljs-keyword">else</span> {
      debug(<span class="hljs-string">'add userOp'</span>, userOp.sender, userOp.nonce)
      <span class="hljs-built_in">this</span>.entryCount[userOp.sender] <span class="hljs-operator">=</span> (<span class="hljs-built_in">this</span>.entryCount[userOp.sender] ?? <span class="hljs-number">0</span>) <span class="hljs-operator">+</span> <span class="hljs-number">1</span>
      <span class="hljs-built_in">this</span>.checkSenderCountInMempool(userOp, senderInfo)
      <span class="hljs-built_in">this</span>.mempool.<span class="hljs-built_in">push</span>(entry)
    }
    <span class="hljs-built_in">this</span>.updateSeenStatus(aggregator, userOp)
  }
</code></pre><p>Lastly, for Bundling userOperations, it creates the bundle that will be sent to the EntryPoint Contract. Bundlers must make sure they verify an operation’s ability to pay its fee before forwarding it in order to prevent DoS attacks. If not, then scammers can craft operations that seem like they pay a fee but will revert, causing congestion in the mempool of the chain.</p><p>Moreover, the verification steps should not violate state changes meaning it will verify according to data related to the sender. Verification and creation of Bundle is in the below code</p><pre data-type="codeBlock" text="async createBundle (): Promise&lt;[UserOperation[], StorageMap]&gt; {
    const entries = this.mempoolManager.getSortedForInclusion()
    const bundle: UserOperation[] = []
"><code>async createBundle (): Promise<span class="hljs-operator">&#x3C;</span>[UserOperation[], StorageMap]<span class="hljs-operator">></span> {
    const entries <span class="hljs-operator">=</span> <span class="hljs-built_in">this</span>.mempoolManager.getSortedForInclusion()
    const bundle: UserOperation[] <span class="hljs-operator">=</span> []
</code></pre><pre data-type="codeBlock" text="    // paymaster deposit should be enough for all UserOps in the bundle.
    const paymasterDeposit: { [paymaster: string]: BigNumber } = {}
    // throttled paymasters and deployers are allowed only small UserOps per bundle.
    const stakedEntityCount: { [addr: string]: number } = {}
    // each sender is allowed only once per bundle
    const senders = new Set&lt;string&gt;()    // all entities that are known to be valid senders in the mempool
    const knownSenders = entries.map(it =&gt; {
      return it.userOp.sender.toLowerCase()
    })    const storageMap: StorageMap = {}
    let totalGas = BigNumber.from(0)
    debug(&apos;got mempool of &apos;, entries.length)
    // eslint-disable-next-line no-labels
    mainLoop:
    for (const entry of entries) {
      // check reputation system
      // check duplicate UserOps per sender
      // check stake
      // check storage access
      // check UserOp call gas limit
      // check Paymaster deposit if present
      // If sender&apos;s account already exist: replace with its storage root hash
      senders.add(entry.userOp.sender)
      bundle.push(entry.userOp)
      totalGas = newTotalGas
    }
    return [bundle, storageMap]
  }
"><code>    <span class="hljs-comment">// paymaster deposit should be enough for all UserOps in the bundle.</span>
    const paymasterDeposit: { [paymaster: <span class="hljs-keyword">string</span>]: BigNumber } <span class="hljs-operator">=</span> {}
    <span class="hljs-comment">// throttled paymasters and deployers are allowed only small UserOps per bundle.</span>
    const stakedEntityCount: { [addr: <span class="hljs-keyword">string</span>]: number } <span class="hljs-operator">=</span> {}
    <span class="hljs-comment">// each sender is allowed only once per bundle</span>
    const senders <span class="hljs-operator">=</span> <span class="hljs-keyword">new</span> Set<span class="hljs-operator">&#x3C;</span><span class="hljs-keyword">string</span><span class="hljs-operator">></span>()    <span class="hljs-comment">// all entities that are known to be valid senders in the mempool</span>
    const knownSenders <span class="hljs-operator">=</span> entries.map(it <span class="hljs-operator">=</span><span class="hljs-operator">></span> {
      <span class="hljs-keyword">return</span> it.userOp.sender.toLowerCase()
    })    const storageMap: StorageMap <span class="hljs-operator">=</span> {}
    let totalGas <span class="hljs-operator">=</span> BigNumber.from(<span class="hljs-number">0</span>)
    debug(<span class="hljs-string">'got mempool of '</span>, entries.<span class="hljs-built_in">length</span>)
    <span class="hljs-comment">// eslint-disable-next-line no-labels</span>
    mainLoop:
    <span class="hljs-keyword">for</span> (const entry of entries) {
      <span class="hljs-comment">// check reputation system</span>
      <span class="hljs-comment">// check duplicate UserOps per sender</span>
      <span class="hljs-comment">// check stake</span>
      <span class="hljs-comment">// check storage access</span>
      <span class="hljs-comment">// check UserOp call gas limit</span>
      <span class="hljs-comment">// check Paymaster deposit if present</span>
      <span class="hljs-comment">// If sender's account already exist: replace with its storage root hash</span>
      senders.add(entry.userOp.sender)
      bundle.<span class="hljs-built_in">push</span>(entry.userOp)
      totalGas <span class="hljs-operator">=</span> newTotalGas
    }
    <span class="hljs-keyword">return</span> [bundle, storageMap]
  }
</code></pre><p><strong>Exploitation of PayMaster</strong></p><p>As PayMaster is a customized contract to handle transactions, scammers can divert the gas fee through the exploitation of vulnerabilities in code. Further research will be conducted in the future. Currently, there aren’t a lot of confirmed example cases of paymaster exploitation.</p><h2 id="h-example-cases" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Example Cases</strong></h2><p>Let’s visualize how an actual attack is conducted and recorded in Blockchain Explorer. Notice that AA is a scheme that processes the transactions in a bundle operation manner. Scammers typically utilize AA scheme to process transactions such as Perimt or Approve. The below example will look at the Approve &amp; TransferFrom request.</p><p>Blockchain: BSC Chain</p><p>Date: 2024–03–23</p><p>Attacker: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x454b8b645a981e6c197087ea154df94b5187d682">0x454b8b645a981e6c197087ea154df94b5187d682</a> , <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x170f7be1baf9234af5966d194a0a6bd6073eed99">0x170f7be1baf9234af5966d194a0a6bd6073eed99</a></p><p>Victim:<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x3f3ce11b7809ecf6f571943800c28f585e8b187d">0x3f3ce11b7809ecf6f571943800c28f585e8b187d</a></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://app.blocksec.com/explorer/tx/bsc/0x812bc694a8c6732b899e81727f128d06c2b7b6717a2dd67936079928b41621b3">https://app.blocksec.com/explorer/tx/bsc/0x812bc694a8c6732b899e81727f128d06c2b7b6717a2dd67936079928b41621b3</a></p><p><strong>Step1</strong>: User signs off-chain permit request</p><p>Like a typical permit request, the scammer will allure the user to sign a permit message. It will be disguised as a necessary step to approve a transaction or access service. The victim, believing the request is legitimate, will sign messages off-chain using their private key.</p><p><strong>Step2</strong>: Interact with Bundler</p><p>The scammer will now interact with a bundler who will handle the permit transaction as an operation. The scammer sends the transaction to the bundler and the bundler will now store the transaction under user operation mempool. After being stored in the user operation mempool, it will go through a validation process and handle over to the EntryPoint contract.</p><p><strong>Step3</strong>: EntryPoint Contract</p><p>Receiving the operation processes from the bundler, the EntryPoint contract will validate user operation in the bundle before execution. As shown in the screenshot below. Once it checks the availability of gas fee and the correctness of state changes, it will handle inner operations.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9faa2e90ae6b815300c313987253af225397488f802399b2cca5540868ef2865.png" alt="Screenshot of Operations before handling InnerOperations" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Screenshot of Operations before handling InnerOperations</figcaption></figure><p><strong>Step 4</strong>: Process State Changes</p><p>As highlighted below, the inner operation for this example contains two transferFrom operations. Notice the amount of value difference in transfer amount in two addresses: <code>212856150000000008192</code> , <code>37562849999999991808</code>. The ratio is roughly 0.85:0.15, which indicates a possible Drainer service where they provide scam as a service and share the drained amount with the Drainer and customer in a certain ratio. Details about Drainer&apos;s service will be discussed later in the article</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e02d1f7b6f237dd8eec6ecc1004e7c5791aa06316dcd223a8c2dd53380889d17.png" alt="Two operations of TransferFrom for BSC-USD Token where Approval and Transfer are inside" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Two operations of TransferFrom for BSC-USD Token where Approval and Transfer are inside</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6d9a9a12022f45c8ba299bf190bf7a31aa316c80a07864317aad6c3d9f9515b7.png" alt="Notice in unusually high value in Approval" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Notice in unusually high value in Approval</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d217df2f3ff9d7f4f0d13742c28ded49ce40d51f9927ee23fade4f64b92dcc5f.png" alt="Fund Flow and Operation flow" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Fund Flow and Operation flow</figcaption></figure><h1 id="h-attack-methods-from-scammers" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Attack Methods from Scammers</strong></h1><h1 id="h-crypto-drainers-scam-as-service-prodivers" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Crypto Drainers (Scam as Service Prodivers)</strong></h1><p>There have been increasing reports of Scam as Service Providers in the recent crypto Market. The providers work multi-chain, provide services to drain ERC-20 tokens, and earn stolen tokens as a reward. The article will look at an example case scenario from crypto drainers.</p><h1 id="h-inferno-drainer" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Inferno Drainer</strong></h1><p>According to Scam Sniffer, Inferno Drainers has stolen $80 million dollars or more within 1 year (11.2022–11.2023) of their active period time. Inferno Drainer sets up phishing websites with social engineering and shares the platform with the customer.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/aa7a47d33a62a98372856f74dcf2b5b184125f98db545740deb47754420585a1.png" alt="Article based on Scam Sniffer from Group-IB" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Article based on Scam Sniffer from Group-IB</figcaption></figure><p>The customer then sends socially engineered website links on Telegram, Facebook, Instagram, or other social networks to allure normal users. Victims who usually do not hold knowledge in the field of cryptocurrency and blockchain will grant access to the customer of Inferno Drainer without knowing.</p><p>The general flow of attack from Inferno Drainer is as below:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b4ea306f4fd083cac5d1e6e4bfa5d595411ba7e2b6a780f0c790a99f006de905.png" alt="Operation Flow of Inferno Drainer (source: Group-IB)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Operation Flow of Inferno Drainer (source: Group-IB)</figcaption></figure><p>As shown in the flowchart, Inferno Drainer mainly focuses on constructing phishing social engineered websites to drain victim’s funds and customers are in charge of spreading phishing websites to the victims. Once victims open the site and sign the transactions, customers will take 80% of the stolen token and Inferno Drainer will take 20%.</p><p>With a very simple setup with simple Approve&amp;TransferFrom method or Permit method, Inferno Drainer stoled over 80+ million dollars of assets on-chain.</p><h2 id="h-draining-method" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Draining Method</strong></h2><p>Inferno Drainer mainly used the classical Approve &amp; TransferFrom method or permit method. Let’s look at one of Approve&amp;TransferFrom during their active time</p><p><strong>Victim</strong>: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xe142c1858b8447238f3953e685e62ed6005dcaaa">0xe142C1858b8447238F3953e685e62ED6005DcAaA</a></p><p><strong>Attacker</strong>: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xFB4d3EB37bDe8FA4B52c60AAbE55B3Cd9908EC73">0xFC4EAA4ac84D00f1C5854113581F881b42b4A745</a></p><p>Token: PEPE</p><p>Lost amount: 26,372,295.3 ($220)</p><p><strong>Step1</strong> : Victim signs approve()</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/87be9ff7caa2bd8f58cddf4d2b98cadda680475454f60350e50cbf3e988d21ec.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d013915dcb6afa94ca5482f767a71fed46b1098333a231e5a3d3e033e16f182a.png" alt="Notice the value of the approved amount" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Notice the value of the approved amount</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/2844a20d865e96479a29ba5f001521b4fea7d1535cc64a637a10fbf0f342b0cc.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Step 2</strong>: Attacker performs TransferFrom()</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dcd2a504e40c43dc6174d4ec956e18345725aef0dfcc777c86c6fae519553399.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-angel-drainer-and-improvement-in-attacking-method" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Angel Drainer and Improvement in Attacking Method</strong></h1><p>After Inferno Drainer ended its service, a new form of more advanced drainer service came out. One of the notable drainer was Angel Drainer. Unlike Inferno drainer, Angel drainer leveraged advanced techniques to manipulate smart contract logic and user behaviour. Certain methods focused on bypassing security alerts that are triggered by behavioral analysis and rate limiting. The article will look at two main novel attack methods Angel Drainer utilized to drain funds.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/805bb3c3ff7b7398996959e8f131e00b2d52618a733bcaf28a145b1da3b0467f.png" alt="Screenshot of services Angel Drainer provides. (source: CheckPoint)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Screenshot of services Angel Drainer provides. (source: CheckPoint)</figcaption></figure><ol><li><p><strong>Nested Smart Contract Deployment Mechanism</strong></p></li></ol><p>As various phishing schemes that utilize Approve&amp;TransferFrom or Permit, blockchain security groups such as ChainAlysis, BlockAid, and Check Point also developed sophisticated monitoring algorithms that can identify potential scammers on the chain. In particular, transactions such as Permit and Approve&amp;TransferFrom on the scammer’s address were very simple to identify. Hence, Angel Drainer adopted a sophisticated method that bypasses security alerts through the creation of new smart contracts that perform Multicall function.</p><p><strong>Example</strong></p><p>To understand how Angel Drainer managed to bypass security alerts, we will look at a real example attack with an investigation of the smart contracts that have been utilized. Let’s explore the transactions behind :</p><p><code>0xb60c32fb28aa6160df6f472f494f162b997aa49fb06776dce250aff80602a8a3</code></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d9c29382c6b2eb987dcf11003eeb668929a8e562ef2402682c7d5456a4dc46c8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Step 1</strong>: Create a Nested Smart Contract</p><p>Angel Drainer first creates a smart contract with the following functions.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fdf6c332b24ac22f21701d5ce4b94c3be4d555fc7a9cce28f62dfdbcceb47cf4.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As shown in the screenshot below, for this specific transaction, Angel Drainer utilized <code>0x095838d2()</code> first and next calls <code>0xf2fde38b()</code> transferOwnership(address).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c7ec2eddc3e0b9eaf04b5dfd19baace5a42ade276b73c3fed91b27f90d646975.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For simplicity, we will call this contract the main contract. Within the main contract, we need to focus on a function <code>0x095838d2()</code>. The logic of the function is as followed:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5367f9b58349a29931324ece321748ed1592ffe4ebe648437dba00f4c3e74718.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ol><li><p>Requires three parameters <code>(secondContractAddress, tokenContractAddress, arrayOf3Elements)</code></p></li><li><p>Check if secondContractAddress is an existing contract. It checks the code size of the given address. If it is greater than zero it means the contract exists, if not vice versa.</p></li><li><p>If it is, execute the Multicall function which includes (Permit &amp; TransferFrom). If not, deploy a new contract with that address and then execute Muticall function.</p></li></ol><p>For this transaction case, secondContractAddress was Null leading it to create a new smart contract first.</p><p><strong>Step 2</strong>: Mutilcall Function</p><p>Once the main contract identifies or creates the second contract, the function Multicall() in second contract will be executed. Such a function exists to orchestrate the contract interaction. Let’s look on multicall() function’s main ability.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f13a548d44771cffc2f173b73b4ef928170b6fe4efe578f4c7c19fbbd880981b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As highlighted above, multicall accepts transaction operations as parameters and processes each parameter by making an external contract at the address specified in v1[v3]. Details of multicall can be seen in the process of execution below.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/659c5b16835c93f132115db3a6143a9ad84628bcfcafd6bff322717d0441d3f1.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As shown above, muticall processed a total of 3 transactions which are Permit and two transferFrom. Permit and transferFrom is made on token contract <code>Lido: stETH</code>.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6f5abaa78958d55767139b24a2d4deee1da475e0a806988911210377664f5584.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Notice the value difference in transferFrom. The ratio is 0.85:0.15. This notes the distribution of profit with Customer and Angel Drainer.</p><p><strong>Step3</strong>: Transfer of Ownership</p><p>In order for the scammer to have full control of the second contract. The last step of <code>0x095838d2()</code> includes executing TransferofOwnership from the second contract to the scammer&apos;s address.</p><p>We had a look over a manipulation method utilized by Angel Drainer to bypass security alerts by creating new contracts and processing operations within the multicall of new contracts. As the new contract do not holds any transaction records, obscures transactions through multicall, and is not directly deployed by the scammer’s address, it was able to bypass security alerts. However, thanks to the identification from Check Point Research, the Nested smart contract attack method can now be identified and will not bypass security alerts anymore.</p><p>2. EigenLayer Restake Farming attack</p><p>EigenLayer is a decentralized protocol designed to enhance the security and efficiency of blockchain networks through the process of “restaking” where it allows users to lock their tokens into a smart contract. Users can initially stake tokens for a certain period of time and earn rewards and also restake more tokens instead of un-staking and re-staking. Through such a process, it allows users to interact with multiple services and stake more tokens, which ultimately enhances the security and utility of the chain at the same time.</p><p><strong>Attack vector Point</strong></p><p>However, there was a vulnerability point in restaking mechanism. Mainly with <code>queueWithdrawal</code> mechanism of the EigenLayer protocol. To understand how the attack works, we need to understand how the staking and restaking process works.</p><p>EigenLayer protocol utilizes a special method for handling staking withdrawals.</p><p>After a user stakes a certain amount of token and later decides to withdraw the staked token, the transaction is not processed immediately. Instead, it is stored in a queue. Users have to wait a 7-day escrow period to unstake and on Etherreums partial withdrawals of stake funds are possible once every 4–5 days after a validator sweep. Since such an approval method was new, most security providers or internal security tooling did not validate such an approval type and mark it as a benign transaction. Therefore, it left a vulnerability point for Angel Drainer to exploit.</p><p><strong>Example</strong></p><p>Chain: ETH</p><p>Date: From 2024–01–15 To 2024–01–29</p><p>Attacker: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x8031A648B169a9fa6f63954C0F0B106E57027696">0x8031A648B169a9fa6f63954C0F0B106E57027696</a></p><p><strong>Step1</strong>: CREATE2 contract</p><p>This is the part where they were able to bypass security alerts and obscure the process. Angel Drainer prepares a contract using CREATE2 with parameters <code>(salt, bytecode)</code>. Then CREATE2 will generate a specific new address. The new address will be used to collect rewards and unstake tokens successfully bypassing the security alerts.</p><p><strong>Step2</strong>: initiate <code>queueWithdrawal</code></p><p>The attacker starts by initiating an unstake from the Eigen layer triggering the 7-day escrow period.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/75855a4bc6d7bca45bd2eaeccc394e70a2cfdd765c231d5220c2841ab06b5808.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Step3</strong>: Draining</p><p>After a certain period of time, the token will be drained to the CREATE2 address resulting in a successful attack as shown below.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/75855a4bc6d7bca45bd2eaeccc394e70a2cfdd765c231d5220c2841ab06b5808.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Thanks to Blockaid, such attacks have been identified and also been notified to EigenLayer Protocol. Currently, higher security measures have been set to detect such attacks unlike before.</p><h1 id="h-money-laundry-in-crypto" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Money Laundry in Crypto</strong></h1><h1 id="h-lazarus-group-and-ronin-bridge-attack" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Lazarus Group &amp; Ronin Bridge attack</strong></h1><p>The attack began with Lazarus gaining 5 keys out of nine private key holders for the execution on the cross-chain bridge. Such is possible due to the Shamir Secret Key arranged Multisignature account. After they gain access to the chain, they begin the laundering process.</p><p>Steps include:</p><ol><li><p>Stolen Ether distributed to intermediary wallets</p></li><li><p>Utilize Tornado Cash → random mix batch protocol</p></li><li><p>ETH to BTC</p></li><li><p>Mix and batch BTC</p></li><li><p>CEX to cashout</p></li></ol><p>Representation in the graph looks like below:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d93e430d5cf8717991a097af83f8b41e2d5b08a016d63f78684934f08e932ccd.png" alt="Fund flow diagram of Lazarus group (source: ChainAlysis)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Fund flow diagram of Lazarus group (source: ChainAlysis)</figcaption></figure><p>Detection of such activities was extremely difficult due to Tornado cash. However, after the U.S. gained control over Tornado Cash after its accusation of money laundering, the Lazarus group took a different method: Utilizing De-fi protocol.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/aed2b9214e8ef727853e600a4a4d3fe9b1efc3fe626ab638f3aec53ac60f525c.png" alt="Notice the funds travel through multiple bridges making it harder to be traced (source: ChainAlysis)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Notice the funds travel through multiple bridges making it harder to be traced (source: ChainAlysis)</figcaption></figure><p>The key idea is that on-chain transactions are visible to everybody and upon further investigation, transactions can be detected. However, through mix and batch methods, transactions diverge and then consolidate into a single wallet. This will be and has been the trend from sophisticated scammers.</p><p>Methods for laundering and phishing will evolve and matching detection methods are required to secure the funds of users.</p><h1 id="h-detection-of-malicious-account" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Detection of Malicious Account</strong></h1><h1 id="h-machine-learning" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Machine Learning</strong></h1><p>All the detection methods are based on the fundamentals explained above. However, such forensic processes by humans are very time-consuming and inaccurate; hence major companies such as ChainAlysis utilize machine learning to do so. Exact feature engineering and method has not been enclosed by ChainAlysis or any other security platforms. However, based on various research and documentation, the article suggests the following methods to be further investigated for development purposes in the future.</p><h1 id="h-graph-neural-network-machine-learning" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Graph Neural Network Machine Learning</strong></h1><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://ieeexplore.ieee.org/document/10191217">https://ieeexplore.ieee.org/document/10191217</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9824179/#:~:text=Many%20studies%20have%20been%20conducted%20to%20detect%20blockchain%20cybercriminal%20accounts,as%20typical%20financial%20transaction%20graphs.">https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9824179/#:~:text=Many studies have been conducted to detect blockchain cybercriminal accounts,as typical financial transaction graphs.</a></p></li></ul><h1 id="h-subgraph-elliptic2-machine-learning" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Subgraph Elliptic2 Machine Learning</strong></h1><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/our-new-research-enhancing-blockchain-analytics-through-ai">https://www.elliptic.co/blog/our-new-research-enhancing-blockchain-analytics-through-ai</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/pdf/2404.19109">https://arxiv.org/pdf/2404.19109</a></p></li></ul><h1 id="h-deep-neural-network-feature-engineering" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Deep Neural Network (Feature Engineering)</strong></h1><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sciencedirect.com/science/article/abs/pii/S095741742201555X">https://www.sciencedirect.com/science/article/abs/pii/S095741742201555X</a></p></li></ul><h1 id="h-conclusion" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Conclusion</strong></h1><p>Phishing attacks on blockchain have evolved with the industry&apos;s growth, targeting users through sophisticated methods to bypass security alerts. Users must be vigilant, ensuring to verify smart contracts, check approval amounts, and heed security alerts. Staying informed and adopting best practices are essential to safeguarding assets in the decentralized financial ecosystem.</p><p>User needs to remember two golden rules to prevent themselves from any form of attack now and in future.</p><p>We have explored how phishing attacks are conducted on blockchain and how scammers formulate both on and off-chain infrastructure to compromise users’ accounts and assets. However, with two golden rules you can prevent yourself from any form of attack.</p><ol><li><p>Protect your seed phrase</p></li><li><p>Understand what you sign on-chain</p></li></ol><p>Make sure to <strong>never expose your private key and seed phrase</strong> in Web 2 and Web3 environments and make sure you have a <strong>full understanding of what transaction you are signing.</strong></p><h1 id="h-references" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>References</strong></h1><div data-type="embedly" src="https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2024/" data="{&quot;provider_url&quot;:&quot;https://www.chainalysis.com&quot;,&quot;description&quot;:&quot;Read to learn about 2023 crypto hacking trends, including DeFi attack vectors and activity of North Korea-affiliated cyber criminals.&quot;,&quot;title&quot;:&quot;Stolen Crypto Falls in 2023, but Hacking Remains a Threat&quot;,&quot;mean_alpha&quot;:232.380568356,&quot;author_name&quot;:&quot;Chainalysis Team&quot;,&quot;url&quot;:&quot;https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2024/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/9efbec3ac0b59fc04923c89efe03452524231011dad47291b59c2c3a6a541771.png&quot;,&quot;thumbnail_width&quot;:1500,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Chainalysis&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:651,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1500,&quot;height&quot;:651,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/9efbec3ac0b59fc04923c89efe03452524231011dad47291b59c2c3a6a541771.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/9efbec3ac0b59fc04923c89efe03452524231011dad47291b59c2c3a6a541771.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2024/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Stolen Crypto Falls in 2023, but Hacking Remains a Threat</h2><p>Read to learn about 2023 crypto hacking trends, including DeFi attack vectors and activity of North Korea-affiliated cyber criminals.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.chainalysis.com</span></div><img src="https://storage.googleapis.com/papyrus_images/9efbec3ac0b59fc04923c89efe03452524231011dad47291b59c2c3a6a541771.png"/></div></a></div></div><div data-type="embedly" src="https://go.chainalysis.com/rs/503-FAP-074/images/The%202024%20Crypto%20Crime%20Report.pdf?version=0" data="{&quot;provider_url&quot;:&quot;https://www.chainalysis.com&quot;,&quot;description&quot;:&quot;Chainalysis helps government agencies, cryptocurrency businesses, and financial institutions engage confidently with cryptocurrency.&quot;,&quot;title&quot;:&quot;The Blockchain Data Platform - Chainalysis&quot;,&quot;thumbnail_width&quot;:1200,&quot;url&quot;:&quot;https://www.chainalysis.com/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/153a204f51ac41c1e2215c68d6db78ebef28c1bbd619bb6e8f7862ae18418b52.jpg&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Chainalysis&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:630,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1200,&quot;height&quot;:630,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/153a204f51ac41c1e2215c68d6db78ebef28c1bbd619bb6e8f7862ae18418b52.jpg&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/153a204f51ac41c1e2215c68d6db78ebef28c1bbd619bb6e8f7862ae18418b52.jpg"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://go.chainalysis.com/rs/503-FAP-074/images/The%202024%20Crypto%20Crime%20Report.pdf?version=0" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>The Blockchain Data Platform - Chainalysis</h2><p>Chainalysis helps government agencies, cryptocurrency businesses, and financial institutions engage confidently with cryptocurrency.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.chainalysis.com</span></div><img src="https://storage.googleapis.com/papyrus_images/153a204f51ac41c1e2215c68d6db78ebef28c1bbd619bb6e8f7862ae18418b52.jpg"/></div></a></div></div><div data-type="embedly" src="https://coinpaper.com/360/what-is-chainalysis-and-how-do-you-avoid-being-traced-by-them" data="{&quot;provider_url&quot;:&quot;https://coinpaper.com&quot;,&quot;description&quot;:&quot;Your wallet address isn&apos;t actually as anonymous as you wish it was, but there are ways to preserve your privacy on the blockchain.&quot;,&quot;title&quot;:&quot;What is Chainalysis and how does it work?&quot;,&quot;thumbnail_width&quot;:2125,&quot;url&quot;:&quot;https://coinpaper.com/360/what-is-chainalysis-and-how-do-you-avoid-being-traced-by-them&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/cb2781bef2a52130832008ed6e8185030a29e7338a02a2df5a0c61f2a06d87a6.png&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Coinpaper&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:1416,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:2125,&quot;height&quot;:1416,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/cb2781bef2a52130832008ed6e8185030a29e7338a02a2df5a0c61f2a06d87a6.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/cb2781bef2a52130832008ed6e8185030a29e7338a02a2df5a0c61f2a06d87a6.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://coinpaper.com/360/what-is-chainalysis-and-how-do-you-avoid-being-traced-by-them" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>What is Chainalysis and how does it work?</h2><p>Your wallet address isn&#x27;t actually as anonymous as you wish it was, but there are ways to preserve your privacy on the blockchain.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://coinpaper.com</span></div><img src="https://storage.googleapis.com/papyrus_images/cb2781bef2a52130832008ed6e8185030a29e7338a02a2df5a0c61f2a06d87a6.png"/></div></a></div></div><div data-type="embedly" src="https://www.chainalysis.com/blog/tornado-cash-sanctions-challenges/" data="{&quot;provider_url&quot;:&quot;https://www.chainalysis.com&quot;,&quot;description&quot;:&quot;The crypto mixer Tornado Cash is a decentralized, non-custodial smart contract. This complicates sanctions compliance-and here&apos;s why.&quot;,&quot;title&quot;:&quot;Understanding Tornado Cash, Its Sanctions Implications, and Key Compliance Questions - Chainalysis&quot;,&quot;author_name&quot;:&quot;Chainalysis Team&quot;,&quot;url&quot;:&quot;https://www.chainalysis.com/blog/tornado-cash-sanctions-challenges/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/9ca284b22df2607b926737ae970a2a975b12cc7006a53f33994f1e1212b7eb78.jpg&quot;,&quot;thumbnail_width&quot;:2560,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Chainalysis&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:1707,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:2560,&quot;height&quot;:1707,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/9ca284b22df2607b926737ae970a2a975b12cc7006a53f33994f1e1212b7eb78.jpg&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/9ca284b22df2607b926737ae970a2a975b12cc7006a53f33994f1e1212b7eb78.jpg"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.chainalysis.com/blog/tornado-cash-sanctions-challenges/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Understanding Tornado Cash, Its Sanctions Implications, and Key Compliance Questions - Chainalysis</h2><p>The crypto mixer Tornado Cash is a decentralized, non-custodial smart contract. This complicates sanctions compliance-and here&#x27;s why.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.chainalysis.com</span></div><img src="https://storage.googleapis.com/papyrus_images/9ca284b22df2607b926737ae970a2a975b12cc7006a53f33994f1e1212b7eb78.jpg"/></div></a></div></div><div data-type="embedly" src="https://www.erc4337.io/docs/bundlers/introduction" data="{&quot;provider_url&quot;:&quot;https://docs.erc4337.io&quot;,&quot;description&quot;:&quot;Complete guide to ERC-4337 Account Abstraction - smart accounts, bundlers, paymasters, and more&quot;,&quot;title&quot;:&quot;⭐️ Introduction&quot;,&quot;mean_alpha&quot;:86.25,&quot;thumbnail_width&quot;:1200,&quot;url&quot;:&quot;https://docs.erc4337.io/index.html&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/476d7f23b69b5ee423bf71b147190eb30c56de1362bb0fc9fcf156043b9a14d3.png&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Erc4337&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:630,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1200,&quot;height&quot;:630,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/476d7f23b69b5ee423bf71b147190eb30c56de1362bb0fc9fcf156043b9a14d3.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/476d7f23b69b5ee423bf71b147190eb30c56de1362bb0fc9fcf156043b9a14d3.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.erc4337.io/docs/bundlers/introduction" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>⭐️ Introduction</h2><p>Complete guide to ERC-4337 Account Abstraction - smart accounts, bundlers, paymasters, and more</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://docs.erc4337.io</span></div><img src="https://storage.googleapis.com/papyrus_images/476d7f23b69b5ee423bf71b147190eb30c56de1362bb0fc9fcf156043b9a14d3.png"/></div></a></div></div><div data-type="embedly" src="https://ethereum.stackexchange.com/questions/142102/solidity-1024-call-stack-depth" data="{&quot;provider_url&quot;:&quot;https://ethereum.stackexchange.com&quot;,&quot;description&quot;:&quot;In solidity there are two stacks: a nornal stack and a call stack. stack depth greater than 1024 will report an error. Question: (1) Whether call calls its own internal contract function will occup...&quot;,&quot;title&quot;:&quot;solidity 1024 call stack depth&quot;,&quot;mean_alpha&quot;:0,&quot;author_name&quot;:&quot;LEVI_104&quot;,&quot;url&quot;:&quot;https://ethereum.stackexchange.com/questions/142102/solidity-1024-call-stack-depth&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/dc7b2a51adecb9025c3c259ca1207f5f2fc8ebc314cfd83fd79e6d0cba01a644.png&quot;,&quot;thumbnail_width&quot;:316,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Ethereum Stack Exchange&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:316,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:316,&quot;height&quot;:316,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/dc7b2a51adecb9025c3c259ca1207f5f2fc8ebc314cfd83fd79e6d0cba01a644.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/dc7b2a51adecb9025c3c259ca1207f5f2fc8ebc314cfd83fd79e6d0cba01a644.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://ethereum.stackexchange.com/questions/142102/solidity-1024-call-stack-depth" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>solidity 1024 call stack depth</h2><p>In solidity there are two stacks: a nornal stack and a call stack. stack depth greater than 1024 will report an error. Question: (1) Whether call calls its own internal contract function will occup...</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://ethereum.stackexchange.com</span></div><img src="https://storage.googleapis.com/papyrus_images/dc7b2a51adecb9025c3c259ca1207f5f2fc8ebc314cfd83fd79e6d0cba01a644.png"/></div></a></div></div><div data-type="embedly" src="https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/" data="{&quot;provider_url&quot;:&quot;https://www.chainalysis.com&quot;,&quot;description&quot;:&quot;More than $30M worth of the crypto stolen by North Korean-linked hackers has been seized. Here&apos;s how Chainalysis tracked down the funds.&quot;,&quot;title&quot;:&quot;Crypto Community Makes Profiting Hard for North Korean Hackers&quot;,&quot;author_name&quot;:&quot;Erin Plante&quot;,&quot;url&quot;:&quot;https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/186eeeb26b0a115c8d16cb5abf3dc3f57e6e2b685133fd67221987827ba20d49.jpg&quot;,&quot;thumbnail_width&quot;:1800,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Chainalysis&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:700,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1800,&quot;height&quot;:700,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/186eeeb26b0a115c8d16cb5abf3dc3f57e6e2b685133fd67221987827ba20d49.jpg&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/186eeeb26b0a115c8d16cb5abf3dc3f57e6e2b685133fd67221987827ba20d49.jpg"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Crypto Community Makes Profiting Hard for North Korean Hackers</h2><p>More than $30M worth of the crypto stolen by North Korean-linked hackers has been seized. Here&#x27;s how Chainalysis tracked down the funds.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.chainalysis.com</span></div><img src="https://storage.googleapis.com/papyrus_images/186eeeb26b0a115c8d16cb5abf3dc3f57e6e2b685133fd67221987827ba20d49.jpg"/></div></a></div></div><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dexaran820.medium.com/erc-20-approve-transferfrom-asset-transfer-method-poses-a-threat-to-users-funds-safety-ff7195127018#:~:text=ERC%2D20%20defines%20two%20methods">https://dexaran820.medium.com/erc-20-approve-transferfrom-asset-transfer-method-poses-a-threat-to-users-funds-safety-ff7195127018#:~:text=ERC%2D20%20defines%20two%20methods</a></p><div data-type="embedly" src="https://medium.com/edennetwork/erc-4337-exploring-the-technical-components-of-account-abstraction-part-2-fec300a7f052" data="{&quot;provider_url&quot;:&quot;https://medium.com&quot;,&quot;description&quot;:&quot;ERC-4337: Exploring the Technical Components of Account Abstraction - Part 2 On March 1st 2023, ERC-4337 rolled out to Ethereum mainnet adding the ability for smart contracts to transact on behalf ...&quot;,&quot;title&quot;:&quot;ERC-4337: Exploring the Technical Components of Account Abstraction - Part 2&quot;,&quot;mean_alpha&quot;:83.277037037,&quot;author_name&quot;:&quot;Eden Network&quot;,&quot;url&quot;:&quot;https://medium.com/edennetwork/erc-4337-exploring-the-technical-components-of-account-abstraction-part-2-fec300a7f052&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/74b130d56efa75cd73f2293e7daab6e85ef297994890cf1e7d9e638014b70ca0.png&quot;,&quot;thumbnail_width&quot;:1200,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Medium&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:675,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1200,&quot;height&quot;:675,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/74b130d56efa75cd73f2293e7daab6e85ef297994890cf1e7d9e638014b70ca0.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/74b130d56efa75cd73f2293e7daab6e85ef297994890cf1e7d9e638014b70ca0.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://medium.com/edennetwork/erc-4337-exploring-the-technical-components-of-account-abstraction-part-2-fec300a7f052" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>ERC-4337: Exploring the Technical Components of Account Abstraction - Part 2</h2><p>ERC-4337: Exploring the Technical Components of Account Abstraction - Part 2 On March 1st 2023, ERC-4337 rolled out to Ethereum mainnet adding the ability for smart contracts to transact on behalf ...</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://medium.com</span></div><img src="https://storage.googleapis.com/papyrus_images/74b130d56efa75cd73f2293e7daab6e85ef297994890cf1e7d9e638014b70ca0.png"/></div></a></div></div><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://medium.com/neptune-mutual/understanding-erc-20-permit-and-associated-risks-41c29c969862#:~:text=EIP%2D2612%20introduces%20a%20feature">https://medium.com/neptune-mutual/understanding-erc-20-permit-and-associated-risks-41c29c969862#:~:text=EIP%2D2612%20introduces%20a%20feature</a></p><div data-type="embedly" src="https://medium.com/oak-security/a-deep-dive-into-the-main-components-of-erc-4337-account-abstraction-using-alt-mempool-part-1-3a1ed1bd3a9b" data="{&quot;provider_url&quot;:&quot;https://medium.com&quot;,&quot;description&quot;:&quot;A deep dive into the main components of ERC-4337: Account Abstraction Using Alt Mempool - Part 1 Account abstraction has been a highly desired feature within the Ethereum developer community for ...&quot;,&quot;title&quot;:&quot;A deep dive into the main components of ERC-4337: Account Abstraction Using Alt Mempool - Part 1&quot;,&quot;mean_alpha&quot;:255,&quot;author_name&quot;:&quot;Antonio Viggiano&quot;,&quot;url&quot;:&quot;https://medium.com/oak-security/a-deep-dive-into-the-main-components-of-erc-4337-account-abstraction-using-alt-mempool-part-1-3a1ed1bd3a9b&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/20281c1e919a6b1ac5e5ae4c3abbb3952d79f8725070cd3b76ae99cb72a25f8c.png&quot;,&quot;thumbnail_width&quot;:811,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Medium&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:701,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:811,&quot;height&quot;:701,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/20281c1e919a6b1ac5e5ae4c3abbb3952d79f8725070cd3b76ae99cb72a25f8c.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/20281c1e919a6b1ac5e5ae4c3abbb3952d79f8725070cd3b76ae99cb72a25f8c.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://medium.com/oak-security/a-deep-dive-into-the-main-components-of-erc-4337-account-abstraction-using-alt-mempool-part-1-3a1ed1bd3a9b" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>A deep dive into the main components of ERC-4337: Account Abstraction Using Alt Mempool - Part 1</h2><p>A deep dive into the main components of ERC-4337: Account Abstraction Using Alt Mempool - Part 1 Account abstraction has been a highly desired feature within the Ethereum developer community for ...</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://medium.com</span></div><img src="https://storage.googleapis.com/papyrus_images/20281c1e919a6b1ac5e5ae4c3abbb3952d79f8725070cd3b76ae99cb72a25f8c.png"/></div></a></div></div><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://eips.ethereum.org/EIPS/eip-4337#reputation-scoring-and-throttlingbanning-for-global-entities">https://eips.ethereum.org/EIPS/eip-4337#reputation-scoring-and-throttlingbanning-for-global-entities</a></p><div data-type="embedly" src="https://crypto.news/angel-drainer-targets-restaking-platforms-with-new-attack-vector-blokcaid-warns/" data="{&quot;provider_url&quot;:&quot;https://crypto.news&quot;,&quot;description&quot;:&quot;Phishing group Angel Drainer has started using a new attack vector, targeting restaking protocols, analysts at Blockaid alarm&quot;,&quot;title&quot;:&quot;Angel Drainer targets restaking platforms with new attack vector, Blokcaid warns&quot;,&quot;author_name&quot;:&quot;Denis Omelchenko&quot;,&quot;thumbnail_width&quot;:1380,&quot;url&quot;:&quot;https://crypto.news/angel-drainer-targets-restaking-platforms-with-new-attack-vector-blokcaid-warns/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/64c340b75defe4916df22a1e723195231d67954b452e23d8b5527205f0a0e6db.webp&quot;,&quot;author_url&quot;:&quot;https://crypto.news/author/denis-omelchenko/&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;crypto.news&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:824,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1380,&quot;height&quot;:824,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/64c340b75defe4916df22a1e723195231d67954b452e23d8b5527205f0a0e6db.webp&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/64c340b75defe4916df22a1e723195231d67954b452e23d8b5527205f0a0e6db.webp"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://crypto.news/angel-drainer-targets-restaking-platforms-with-new-attack-vector-blokcaid-warns/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Angel Drainer targets restaking platforms with new attack vector, Blokcaid warns</h2><p>Phishing group Angel Drainer has started using a new attack vector, targeting restaking protocols, analysts at Blockaid alarm</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://crypto.news</span></div><img src="https://storage.googleapis.com/papyrus_images/64c340b75defe4916df22a1e723195231d67954b452e23d8b5527205f0a0e6db.webp"/></div></a></div></div><div data-type="embedly" src="https://cryptodaily.co.uk/2024/02/angel-drainer-targets-users-with-malicious-smart-contract" data="{&quot;provider_url&quot;:&quot;https://cryptodaily.co.uk&quot;,&quot;description&quot;:&quot;Notorious phishing group Angel Drainer has managed to siphon over $400,000 from over 128 crypto wallets by deploying a malicious Safe vault contract.&quot;,&quot;title&quot;:&quot;Angel Drainer Targets Users With Malicious Smart Contract&quot;,&quot;thumbnail_width&quot;:1280,&quot;url&quot;:&quot;https://cryptodaily.co.uk/2024/02/angel-drainer-targets-users-with-malicious-smart-contract&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/77fe6946ec376bfc337fb5753332dae80d492a748a54b2b87044558e156c6725.jpg&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Cryptodaily&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:720,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1280,&quot;height&quot;:720,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/77fe6946ec376bfc337fb5753332dae80d492a748a54b2b87044558e156c6725.jpg&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/77fe6946ec376bfc337fb5753332dae80d492a748a54b2b87044558e156c6725.jpg"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://cryptodaily.co.uk/2024/02/angel-drainer-targets-users-with-malicious-smart-contract" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Angel Drainer Targets Users With Malicious Smart Contract</h2><p>Notorious phishing group Angel Drainer has managed to siphon over $400,000 from over 128 crypto wallets by deploying a malicious Safe vault contract.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://cryptodaily.co.uk</span></div><img src="https://storage.googleapis.com/papyrus_images/77fe6946ec376bfc337fb5753332dae80d492a748a54b2b87044558e156c6725.jpg"/></div></a></div></div><div data-type="embedly" src="https://malware.news/t/the-rising-threat-of-phishing-attacks-with-crypto-drainers/77000" data="{&quot;provider_url&quot;:&quot;https://malware.news&quot;,&quot;description&quot;:&quot;Unmasking Deceptive Tactics: A recent investigation by Check Point Research exposes a troubling trend in the cryptocurrency landscape. The cryptocurrency community has been witnessing an alarming increase in sophisticated phishing attacks. These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance Smart Chain to Polygon, Avalanche, and almost 20 other networks by using a crypto wallet-draining technique.&quot;,&quot;title&quot;:&quot;The Rising Threat of Phishing Attacks with Crypto Drainers&quot;,&quot;mean_alpha&quot;:0,&quot;author_name&quot;:&quot;MalBot&quot;,&quot;thumbnail_width&quot;:512,&quot;url&quot;:&quot;https://malware.news/t/the-rising-threat-of-phishing-attacks-with-crypto-drainers/77000&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/15d325b3dac0d0ac72de0415cbcf21663009d05bf09615cdfce4dd056da5e25f.png&quot;,&quot;author_url&quot;:&quot;https://malware.news/u/MalBot&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Malware Analysis, News and Indicators&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:512,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:512,&quot;height&quot;:512,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/15d325b3dac0d0ac72de0415cbcf21663009d05bf09615cdfce4dd056da5e25f.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/15d325b3dac0d0ac72de0415cbcf21663009d05bf09615cdfce4dd056da5e25f.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://malware.news/t/the-rising-threat-of-phishing-attacks-with-crypto-drainers/77000" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>The Rising Threat of Phishing Attacks with Crypto Drainers</h2><p>Unmasking Deceptive Tactics: A recent investigation by Check Point Research exposes a troubling trend in the cryptocurrency landscape. The cryptocurrency community has been witnessing an alarming increase in sophisticated phishing attacks. These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance Smart Chain to Polygon, Avalanche, and almost 20 other networks by using a crypto wallet-draining technique.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://malware.news</span></div><img src="https://storage.googleapis.com/papyrus_images/15d325b3dac0d0ac72de0415cbcf21663009d05bf09615cdfce4dd056da5e25f.png"/></div></a></div></div><div data-type="embedly" src="https://research.checkpoint.com/2023/the-rising-threat-of-phishing-attacks-with-crypto-drainers/" data="{&quot;provider_url&quot;:&quot;https://research.checkpoint.com&quot;,&quot;description&quot;:&quot;By Oded Vanunu, Dikla Barda, Roman Zaikin Unmasking Deceptive Tactics: A recent investigation by Check Point Research exposes a troubling trend in the cryptocurrency landscape. The cryptocurrency community has been witnessing an alarming increase in sophisticated phishing attacks. These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance [...]&quot;,&quot;title&quot;:&quot;The Rising Threat of Phishing Attacks with Crypto Drainers - Check Point Research&quot;,&quot;author_name&quot;:&quot;etal&quot;,&quot;url&quot;:&quot;https://research.checkpoint.com/2023/the-rising-threat-of-phishing-attacks-with-crypto-drainers/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/de293e8a13c09e0132f98662d79b39a1a69e8f59ab2e4775142cd2188dcca416.webp&quot;,&quot;thumbnail_width&quot;:1024,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Check Point Research&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:585,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:1024,&quot;height&quot;:585,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/de293e8a13c09e0132f98662d79b39a1a69e8f59ab2e4775142cd2188dcca416.webp&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/de293e8a13c09e0132f98662d79b39a1a69e8f59ab2e4775142cd2188dcca416.webp"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://research.checkpoint.com/2023/the-rising-threat-of-phishing-attacks-with-crypto-drainers/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>The Rising Threat of Phishing Attacks with Crypto Drainers - Check Point Research</h2><p>By Oded Vanunu, Dikla Barda, Roman Zaikin Unmasking Deceptive Tactics: A recent investigation by Check Point Research exposes a troubling trend in the cryptocurrency landscape. The cryptocurrency community has been witnessing an alarming increase in sophisticated phishing attacks. These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance [...]</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://research.checkpoint.com</span></div><img src="https://storage.googleapis.com/papyrus_images/de293e8a13c09e0132f98662d79b39a1a69e8f59ab2e4775142cd2188dcca416.webp"/></div></a></div></div><div data-type="embedly" src="https://www.blockaid.io/blog/emerging-attack-vector-restake-farming" data="{&quot;provider_url&quot;:&quot;https://www.blockaid.io&quot;,&quot;description&quot;:&quot;Angel Drainer group has introduced a new attack vector utilizing a protocol to execute a novel form of approval farming attack through the queue Withdrawal mechanism.&quot;,&quot;title&quot;:&quot;Emerging Attack Vector: Restake Farming | Blockaid Blog&quot;,&quot;thumbnail_width&quot;:800,&quot;url&quot;:&quot;https://www.blockaid.io/blog/emerging-attack-vector-restake-farming&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/c20ea522e56085a2266e921b942898dc0621edbc62ebb60d70e20e327ed4609d.png&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Blockaid&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:420,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:800,&quot;height&quot;:420,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/c20ea522e56085a2266e921b942898dc0621edbc62ebb60d70e20e327ed4609d.png&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/c20ea522e56085a2266e921b942898dc0621edbc62ebb60d70e20e327ed4609d.png"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.blockaid.io/blog/emerging-attack-vector-restake-farming" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>Emerging Attack Vector: Restake Farming | Blockaid Blog</h2><p>Angel Drainer group has introduced a new attack vector utilizing a protocol to execute a novel form of approval farming attack through the queue Withdrawal mechanism.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.blockaid.io</span></div><img src="https://storage.googleapis.com/papyrus_images/c20ea522e56085a2266e921b942898dc0621edbc62ebb60d70e20e327ed4609d.png"/></div></a></div></div><div data-type="embedly" src="https://www.chainalysis.com/blog/2024-crypto-money-laundering/" data="{&quot;provider_url&quot;:&quot;https://www.chainalysis.com&quot;,&quot;description&quot;:&quot;Learn about crypto money laundering in 2023, key trends, and how money laundering tactics are changing in our preview of the 2024 Crypto Crime Report.&quot;,&quot;title&quot;:&quot;2024 Crypto Money Laundering Report - Chainalysis&quot;,&quot;author_name&quot;:&quot;Chainalysis Team&quot;,&quot;url&quot;:&quot;https://www.chainalysis.com/blog/2024-crypto-money-laundering/&quot;,&quot;thumbnail_url&quot;:&quot;https://storage.googleapis.com/papyrus_images/5bd2e288f60b53fcd94e46b5e5d588963d15adf0360207a77a8f5b926d943cfc.jpg&quot;,&quot;thumbnail_width&quot;:2560,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Chainalysis&quot;,&quot;type&quot;:&quot;link&quot;,&quot;thumbnail_height&quot;:1111,&quot;image&quot;:{&quot;img&quot;:{&quot;width&quot;:2560,&quot;height&quot;:1111,&quot;src&quot;:&quot;https://storage.googleapis.com/papyrus_images/5bd2e288f60b53fcd94e46b5e5d588963d15adf0360207a77a8f5b926d943cfc.jpg&quot;}}}" format="small"><link rel="preload" as="image" href="https://storage.googleapis.com/papyrus_images/5bd2e288f60b53fcd94e46b5e5d588963d15adf0360207a77a8f5b926d943cfc.jpg"/><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://www.chainalysis.com/blog/2024-crypto-money-laundering/" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>2024 Crypto Money Laundering Report - Chainalysis</h2><p>Learn about crypto money laundering in 2023, key trends, and how money laundering tactics are changing in our preview of the 2024 Crypto Crime Report.</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://www.chainalysis.com</span></div><img src="https://storage.googleapis.com/papyrus_images/5bd2e288f60b53fcd94e46b5e5d588963d15adf0360207a77a8f5b926d943cfc.jpg"/></div></a></div></div>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/20007aba1b6e8108355e696e32872b85d965cebc6a8f223265bbdb9180836cd0.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[探索dYdX价格操控攻击]]></title>
            <link>https://paragraph.com/@x-explore/dydx</link>
            <guid>P3T32NyPdzfSRiWWsq0b</guid>
            <pubDate>Tue, 21 Nov 2023 14:49:44 GMT</pubDate>
            <description><![CDATA[这篇文章由X-explore和吴说区块链共同发布。 2023年11月18日，dYdX v3保险基金使用了900万美元用于填补$YFI清算导致的亏损。该公司的首席执行官表示，这明显是一起针对dYdX的市场价格操纵攻击。 因此，我们对$YFI在dYdX中的价格操纵进行探索。 通过本文，读者可以了解到：黑客如何通过$YFI价格操纵在dYdX中获取利润。黑客的总利润。黑客的链上追踪和去匿名化过程。1. 黑客在dYdX中的操作步骤在l2beat浏览器中可以看到地址0x779c313c968aA36fb696DAcca674Dc757c8BB4C2的交易细节。我们以该地址为例，该地址在被清算前赚取了750%的利润。dYdX ExplorerBalance changes of user 0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556https://explorer.dydx.exchange首先，在2023年11月7日23:35:23，向dYdX存入35,000 USDC。然后，在2023年11月9日00:...]]></description>
            <content:encoded><![CDATA[<p>这篇文章由X-explore和吴说区块链共同发布。</p><p>2023年11月18日，dYdX v3保险基金使用了900万美元用于填补$YFI清算导致的亏损。该公司的首席执行官表示，这明显是一起针对dYdX的市场价格操纵攻击。</p><p>因此，我们对$YFI在dYdX中的价格操纵进行探索。</p><p>通过本文，读者可以了解到：</p><ol><li><p>黑客如何通过$YFI价格操纵在dYdX中获取利润。</p></li><li><p>黑客的总利润。</p></li><li><p>黑客的链上追踪和去匿名化过程。</p></li></ol><h2 id="h-1-dydx" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. 黑客在dYdX中的操作步骤</h2><p>在l2beat浏览器中可以看到地址0x779c313c968aA36fb696DAcca674Dc757c8BB4C2的交易细节。我们以该地址为例，该地址在被清算前赚取了750%的利润。</p><div data-type="embedly" src="https://dydx.l2beat.com/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes" data="{&quot;provider_url&quot;:&quot;https://explorer.dydx.exchange&quot;,&quot;description&quot;:&quot;Balance changes of user 0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556&quot;,&quot;title&quot;:&quot;dYdX Explorer&quot;,&quot;url&quot;:&quot;https://explorer.dydx.exchange/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Dydx&quot;,&quot;type&quot;:&quot;link&quot;}" format="small"><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://dydx.l2beat.com/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>dYdX Explorer</h2><p>Balance changes of user 0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://explorer.dydx.exchange</span></div></div></a></div></div><ul><li><p>首先，在2023年11月7日23:35:23，向dYdX存入35,000 USDC。</p></li><li><p>然后，在2023年11月9日00:39:11，以$6,199的价格开仓了49.67 YFI-USDC合约，成本为$302,865，杠杆为8.6倍。</p></li><li><p>接下来，在2023年11月11日04:46:23至2023年11月17日14:32:35期间，随着YFI价格的上涨，黑客提取了6次unrealized profit，总计$271,602。总利润为$236,602。</p></li><li><p>最后，在2023年11月18日10:40:47，由于价格急剧下跌，该地址被清算。YFI和USDC的余额均归零。值得一提的是，在强制平仓时，$YFI在dYdX的场内价格约为$9,000，强制清算价格为$11,400。因此，dYdX的保险基金遭受了巨大损失。</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/64194e154088c7b4d4a823ca530079074502e27882885bb040fdad0e2dec9148.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4b22531c2b1762e17e319ffa5faf12101108df4a59b2c637e1c00f70b5ae40eb.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>我们还希望在DEX上找到价格操纵的证据，就像这个Twitter链接中所提到，黑客在2023年11月初，对Sushi的现货价格进行操纵：<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/lookonchain/status/1719403866146656447%E3%80%82">https://twitter.com/lookonchain/status/1719403866146656447。</a></p><p>然而，我们无法找到任何可疑的交易或地址。我们猜测$YFI的价格操纵可能仅发生在dYdX中，因为dYdX的未平仓合约与价格呈正相关关系。这只是一个猜测。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3f677e14d6f4b0b499c8500015a7a1de6b1ca0ee5cdea0b4073456af4f81bf4e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2.黑客收益</h2><p>黑客共有129个地址，我们可以根据这些地址与dYdX地址的流入和流出情况计算黑客的总收益。</p><p>下图是所有的黑客地址信息，黑客在dYdX中赚取了1275万美元，其中555万美元来自$YFI价格，其余来自$Sushi的价格操纵。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3b9386639c3d5a520e0430734420e4983b3ebbec9c8df6e39fe81e7de7ad7e9e.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. 黑客追踪</h2><p>黑客将第二部分提到的上述地址的资金存入到huobi交易所，我们进行了跨交易所的资金追踪并发现了一个与黑客相关的可疑地址，部分资金被转入该地址0x8Af700bA841f30e0a3Fcb0EE4C4A9D223E1eFA05。这个地址是一个经常被使用的地址，并与Binance和Bitget有着很强的关联。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a04705eeb62445ae3218a8e5469755fa2d47ca9ff2277235a817db1881fbb740.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>此外，从链上可以看到，这个可疑地址和黑客地址在购买sDAI并在去中心化交易所上操纵Sushi价格的时间几乎完全一致。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d83cf293c4887c2943584d9e0bdb8842c2711c0d963b202219a766b3ab5287ef.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c211242056ad9f18689be3601c33d14f6c7d050cc518d2fef48c7c98341a582d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>敬请关注我们。</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
        </item>
        <item>
            <title><![CDATA[Exploring dYdX Price Manipulation]]></title>
            <link>https://paragraph.com/@x-explore/exploring-dydx-price-manipulation</link>
            <guid>aSIoKvulm2904y4E7xge</guid>
            <pubDate>Mon, 20 Nov 2023 14:45:04 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. On 18 Nov 2023, about $9m from the dYdX v3 insurance fund were used to fill gaps on liquidations processed in the YFI market, and the CEO said this was pretty clearly a targeted market manipulation attack against dYdX. We do an exploring of dYdX price manipulation in $YFI. From this article, readers will know:Based on chain info, how the hacker gets the profit in dYdX about YFI price manipulation.The total profit of this hacker....]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p>On 18 Nov 2023, about $9m from the dYdX v3 insurance fund were used to fill gaps on liquidations processed in the YFI market, and the CEO said this was pretty clearly a targeted market manipulation attack against dYdX.</p><p>We do an exploring of dYdX price manipulation in $YFI.</p><p>From this article, readers will know:</p><ul><li><p>Based on chain info, how the hacker gets the profit in dYdX about YFI price manipulation.</p></li><li><p>The total profit of this hacker.</p></li><li><p>The on-chain trace and de-anonymize of the hacker.</p></li></ul><h2 id="h-1-the-process-of-hacker-in-dydx" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. The process of hacker in dYdX</h2><p>l2beat shows the detail of balance of the address in dYdX. We take 0x779c313c968aA36fb696DAcca674Dc757c8BB4C2 as an example. <strong>This address earns 750% profit before busted trade.</strong></p><div data-type="embedly" src="https://dydx.l2beat.com/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes" data="{&quot;provider_url&quot;:&quot;https://explorer.dydx.exchange&quot;,&quot;description&quot;:&quot;Balance changes of user 0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556&quot;,&quot;title&quot;:&quot;dYdX Explorer&quot;,&quot;url&quot;:&quot;https://explorer.dydx.exchange/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes&quot;,&quot;version&quot;:&quot;1.0&quot;,&quot;provider_name&quot;:&quot;Dydx&quot;,&quot;type&quot;:&quot;link&quot;}" format="small"><div class="react-component embed my-5" data-drag-handle="true" data-node-view-wrapper="" style="white-space:normal"><a class="link-embed-link" href="https://dydx.l2beat.com/users/0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556/balance-changes" target="_blank" rel="noreferrer"><div class="link-embed"><div class="flex-1"><div><h2>dYdX Explorer</h2><p>Balance changes of user 0x02d67dfaba1d195c0cbbda8ce051922d23ac7adbbb90a4cb3be667708a200556</p></div><span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-link h-3 w-3 my-auto inline mr-1"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg>https://explorer.dydx.exchange</span></div></div></a></div></div><ul><li><p>First, deposit 35,000 USDC to dYdX at 2023-11-07 23:35:23.</p></li><li><p>And then, open 49.67 YFI-USDC contract at the price of 6,199U. The cost is 302,865U and the leverage is 8.6X at 2023-11-09 00:39:11.</p></li><li><p>Then, between 2023-11-11 04:46:23 and 2023-11-17 14:32:35, with the increase of the YFI price, the hacker withdrew the unrealized profit 6 times and 271,602 USDC. The total profit is 236,602 USDC.</p></li><li><p>Finally, at 2023-11-18 10:40:47, the address is bust trade after the huge decrease in price. The balance of YFI and USDC is to the zero. It is worth mentioning that at the time of brute force, the on-site price of dYdX was approximately 9,000U, and the forced liquidation price was 11,400U. So the dYdX insurance fund lost a lot.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/64194e154088c7b4d4a823ca530079074502e27882885bb040fdad0e2dec9148.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4b22531c2b1762e17e319ffa5faf12101108df4a59b2c637e1c00f70b5ae40eb.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>We also want to find the evidence to show the price manipulation in the dex as this hacker did at the beginning of Nov, 2023 like this twitter <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/lookonchain/status/1719403866146656447">https://twitter.com/lookonchain/status/1719403866146656447</a>.</p><p>However, we cannot find any suspicious transaction or address. We guess that this price manipulation in YFI is only in the dYdX because the open interest of dYdX is positively related to the price. Just a guess.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ac832a9c30cf043df9efeb941375fe7b39c344665043e275e9d03ed3655ceaac.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2-hacker-profit" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. Hacker Profit</h2><p>The hacker has 129 addresses and we can calculate the profit according to sum the inflow and outflow between these addresses and dYdX fund address.</p><p>Here is an overall screenshot of the hacker addresses. The hacker earns 12.75M in the dYdX and the 5.55M is from YFI and the other is from Sushi.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4915e1ba57ed4f21e3f3d3bca66f5b86070550f67d9e7d448b38aa25e98e24dd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-3-hacker-anonymization" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. Hacker Anonymization</h2><p>The profit in the above addresses in part2 deposited to Huobi Exchange via two combined addresses. We do a cross exchange fund trace and find a suspicious address related to the hacker and part of the fund to this address 0x8Af700bA841f30e0a3Fcb0EE4C4A9D223E1eFA05. This address is a frequently used address and has connections with Binance and Bitget.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/73a36fde79c855c3710559ca6d73c2dff7017c46d457fc06d905da7a979bf51f.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In addition, we can also see on the chain that this suspicious address and the hacker address are basically exactly the same at the time when they purchased sDAI and manipulated the price of Sushi on DEX.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e41dcfb7ce16d6fae25c5fb3d9fd4beb0d72e525ee3b6a4306837a3717234d5a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c211242056ad9f18689be3601c33d14f6c7d050cc518d2fef48c7c98341a582d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For more, please follow x-explore.</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
        </item>
        <item>
            <title><![CDATA[Exploring the Sybil Group in the Celestia Airdrop After claiming]]></title>
            <link>https://paragraph.com/@x-explore/exploring-the-sybil-group-in-the-celestia-airdrop-after-claiming</link>
            <guid>9RgDFVJbKlcR6aimrkOb</guid>
            <pubDate>Thu, 02 Nov 2023 07:45:56 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.1. BackgroundThe crypto market&apos;s crazy in October came to an end with the launch of the Celestia. The Celestia airdrop attract the people interest for airdrop and sybil again. According to our statistics, as of November 1, 2023, 20:00 UTC+8, a total of 138,981 addresses have claimed the airdrop, accounting for 72% of the total airdrop addresses of 191,391. The claimed airdrop amount totals 44.4 million, representing 74% of t...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h2 id="h-1-background" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. Background</h2><p>The crypto market&apos;s crazy in October came to an end with the launch of the Celestia. The Celestia airdrop attract the people interest for airdrop and sybil again. According to our statistics, as of November 1, 2023, 20:00 UTC+8, a total of 138,981 addresses have claimed the airdrop, accounting for 72% of the total airdrop addresses of 191,391. The claimed airdrop amount totals 44.4 million, representing 74% of the total airdrop amount of 60 million. Based on Celestia node data, this article focuses on revealing three key results:</p><ol><li><p>The distribution of the celestia airdrop sybil groups.</p></li><li><p>The profitability of large-scale sybil group.</p></li><li><p>Technical analysis of certain sybil group.</p></li></ol><h2 id="h-2-the-overall-statistic-of-sybil-group" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. The overall statistic of sybil group</h2><p>Sybil groups often swiftly deposit airdrop tokens into various exchanges. These exchanges allocate only one deposit address per user and we do tracking of funds flowing to the airdrop addresses. When funds from multiple airdrop addresses converge into a single address, it is considered these addresses are controlled by a certain sybil group. Furthermore, based on intelligence, we have excluded exchange addresses and suspected exchange addresses, including hot wallet addresses from eight exchanges such as Binance, Bybit, Kucoin, OKX, MEXC, etc.</p><p>We gathered data from 209,989 valid TIA transfer transactions on Celestia blockchain from block 1 to block 6471. We traced the funds of the 138,981 addresses that claimed the airdrop one by one, considering the tracking complete when the funds remained in a specific address or went to the deposit addresses allocated by exchanges to their users. The graph below illustrates the distribution of sybil group sizes based on the number of addresses.</p><ol><li><p><strong>Large-scale sybil groups(group more than 20 addresses) have 27,090 airdrop addresses, accounting for 20.1% of the total.</strong> They have received a total of 5.22 million TIA.</p></li><li><p><strong>Sybil groups(group between 5 and 20 addresses) have 27,907 airdrop addresses, accounting for 20.7% of the total.</strong> They have received a total of 6.65 million TIA.</p></li><li><p>Additionally, <strong>there are 51,494 addresses that do not form part of a group, representing 38.2% of the total.</strong> They have received a total of 17.05 million TIA. In conclusion, the number of addresses receiving airdrops by sybil groups is nearly equivalent to that of regular users. This reflects the continued widespread participation in the airdrop market and sybil group, posing a significant challenge for project owner in their efforts to identify and filter out sybil addresses.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/17e2c573ec4e7997b5b2511fbcd5bfcac12f4248620e230acb3c345e3b5f025a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-3-case-analysis-of-sybil" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. Case Analysis of Sybil</h2><h3 id="h-31-super-large-scale-sybil-group" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.1 Super Large-scale Sybil Group</h3><p><strong>Below is our discovery of the most profitable sybil group, holding a total of 300 airdrop addresses and receiving a total of 77,391 TIA.</strong> This sybil group initially consolidated the funds from the airdrop addresses into the address: celestia135605ttacyg3q42c062dxg66g86y8wt5dl0y72, and then deposited from the consolidation address to user deposit address on OKX: celestia15tk34janlw2nqwa65zcw7kh6g6xysz665yggde.</p><p>Additionally, we noticed that all 300 addresses of this sybil group received exactly 258 TIA each, indicating that the Celestia Project owner did not successfully detect this batch of highly similar addresses while filtering out sybil addresses.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3a1b0f3763926a5c28d67f20ae594fb2d5452298050191294b4d5ae34342a298.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Apart from this super-large-scale sybil group, there are also:</p><ol><li><p>Sybil consolidation address (Address: celestia17kswujt05rzpprkdtyav42xla0rkf5lx2zsks4), with <strong>372</strong> addresses, and receiving <strong>64,443</strong> TIA.</p></li><li><p>Binance user deposit address (Address: celestia1fd3mclxp4e2fh0wpau3eg55x2fsm7yjxzg29j2, memo: 102235249), with <strong>404</strong> airdrop addresses, and receiving <strong>66,082</strong> TIA.</p></li><li><p>Binance user deposit address (Address: celestia1fd3mclxp4e2fh0wpau3eg55x2fsm7yjxzg29j2, memo: 100324643), with 312 airdrop addresses, and receiving <strong>50,909</strong> TIA.</p></li><li><p>Binance user deposit address (Address: celestia1fd3mclxp4e2fh0wpau3eg55x2fsm7yjxzg29j2, memo: 101213950), with <strong>340</strong> airdrop addresses, and receiving <strong>57,564</strong> TIA.</p></li><li><p>Sybil consolidation address (Address: celestia1zzk9p6lgapadnv4q5n4m2uqcrfchycne605jag), with <strong>373</strong> addresses, and receiving <strong>60,687</strong> TIA.</p></li><li><p>Kucoin user deposit address (Address: celestia1cylgjyd70mheg3j3e2n7t758r07rarwytagltr, memo: 1934750426), with <strong>297</strong> airdrop addresses, and receiving <strong>31,131</strong> TIA.</p></li><li><p>Sybil consolidation address (Address: celestia1l7c4nddq0t5ncllhst8d8mtwtcq5mg70ajgq5t), including <strong>278</strong> addresses, and receiving <strong>57,267</strong> TIA.</p></li><li><p>Binance user deposit address (Address: celestia1fd3mclxp4e2fh0wpau3eg55x2fsm7yjxzg29j2, memo: 100415822), with <strong>212</strong> airdrop addresses, and receiving <strong>37,389</strong> TIA.</p></li></ol><h3 id="h-32-sybil-group-technical-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.2 Sybil Group Technical Analysis</h3><p>It&apos;s worth noting that sybil groups were among the first users to engage in large-scale transactions on Celestia. The graph below illustrates the number of valid TIA transfer transactions in each block for the first 100 blocks. It is evident that a significant surge in transactions occurred as early as the 4th block, with a total of 149 transactions, of which 101 were attributed to a sybil user&apos;s fund consolidation activities. This occurred long before the surge in trading following the opening of deposits by exchanges such as Binance, approximately 95 blocks later.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/2e2161d5d0fdaf4ebe967ea7ffc672cf02d3ac332b19569a435bf7a13801547c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Taking a closer look at this group, in the 4th and 5th blocks, they consolidated all TIA tokens from 106 airdrop addresses into the address celestia1r7wln0ggc22y5hv6ny960j2lh9lg40gyl56s6c. It&apos;s worth noting that they used uncommon fixed gas values of 127,843 and 127,965, suggesting that they not only possess automated scripting capabilities but can also run multiple programs simultaneously. <strong>This further indicates that some sybil groups have advanced technical skills.</strong></p><p>For more, please follow x-explore.</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
        </item>
        <item>
            <title><![CDATA[In-Depth Analysis of Airdrop Hunters]]></title>
            <link>https://paragraph.com/@x-explore/in-depth-analysis-of-airdrop-hunters</link>
            <guid>gjlTpM1w07CAATtXBa2R</guid>
            <pubDate>Mon, 26 Jun 2023 08:06:47 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. Since Uniswap began using airdrop strategies to reward its early users in 2020, airdrops have sparked a huge craze in Web3. Influenced by this, numerous projects have seen a surge in people hunting for the next "free lunch" (looking for new airdrop projects). Now, nearly three years have passed since Uniswap&apos;s airdrop, and during this time many large projects have followed suit, using airdrops to reward users or attract att...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p>Since Uniswap began using airdrop strategies to reward its early users in 2020, airdrops have sparked a huge craze in Web3. Influenced by this, numerous projects have seen a surge in people hunting for the next &quot;free lunch&quot; (looking for new airdrop projects). Now, nearly three years have passed since Uniswap&apos;s airdrop, and during this time many large projects have followed suit, using airdrops to reward users or attract attention. According to estimates from X-explore, over 20% of the airdrops in Arbitrum&apos;s airdrop in March this year were claimed by so-called &quot;free riders&quot; who use Sybil attacks. Therefore, we hope to answer the following two questions through a deep analysis of users who have successfully claimed multiple airdrops:</p><ol><li><p><strong>Who are these airdrop &quot;experts&quot;?</strong></p></li><li><p><strong>What are their subsequent &quot;targets&quot;?</strong></p></li></ol><p>To answer the above questions, among the myriad of Ethereum and its layer 2 projects, we have carefully selected five projects with &quot;<strong>over 100,000 airdrop claim addresses</strong>&quot; and &quot;<strong>total airdrop value exceeding $140 million</strong>&quot;. These are Uniswap, ENS, Optimism, Blur, and Arbitrum. We will delve into the users of these five projects in the following articles, with particular attention to the &quot;expert&quot; users who have received multiple airdrops from these projects.</p><p><em>Note: The basis for calculating coin prices in this article is data from CoinMarketCap as of June 7, 2023. Most of the screenshots in the article are from June 14, 2023, so the prices may be slightly different, please forgive any confusion this may cause.</em></p><h2 id="h-who-are-the-airdrop-hunters" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Who are the Airdrop Hunters?</h2><p>We define addresses that have <strong>received</strong> <strong>at least three airdrops</strong> out of the five projects as <strong>Airdrop Hunters</strong>. Those that <strong>received</strong> <strong>three to four airdrops</strong> are classified as <strong>Standard Airdrop Hunters</strong>, while those that <strong>received</strong> <strong>all five airdrops</strong> are named <strong>Premium Airdrop Hunters</strong>. In this analysis, we found a total of 34,547 Standard Airdrop Hunter addresses, with an average airdrop income per address of $9,384 and a median airdrop income per address of $6,497. As for Premium Airdrop Hunters, we found a total of 932 addresses, with an average airdrop income per address of $18,935 and a median airdrop income per address of $14,288. Judging from the average and median income, the term &quot;premium&quot; is indeed fitting for the Premium Airdrop Hunters.</p><h3 id="h-1-x-explore-address-tag-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. X-explore Address Tag Analysis</h3><p>To better reveal the characteristics of Airdrop Hunter addresses, we combined X-explore&apos;s proprietary on-chain label system and conducted an in-depth analysis of the above addresses in terms of behavior, assets, activity level, and trading profitability. We found that, whether they are Standard Airdrop Hunters or Premium Airdrop Hunters, their trading volumes on Decentralized Exchanges (DEX) and Non-Fungible Tokens (NFT) far exceed those of ordinary (normal) users.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5cb36ee511c67afc65160c725e54b046f158b233b02ded54b52681407e4d3cc7.png" alt="Airdrop Hunters&apos; Tag on X-explore" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Tag on X-explore</figcaption></figure><ul><li><p><strong>Median Dex Trader:</strong> Users who rank in the top 10% in terms of trading volume on DEX</p></li><li><p><strong>Median NFT Trader:</strong> Users who rank in the top 10% in terms of NFT trading volume</p></li><li><p><strong>Heavy Dex Trader:</strong> Users who rank in the top 1% in terms of trading volume or number of transactions on DEX</p></li><li><p><strong>Heavy NFT Trader:</strong> Users who rank in the top 2.5% in terms of NFT trading volume or number of transactions</p></li></ul><p>These data show that Airdrop Hunters are more active in the cryptocurrency market than ordinary users, demonstrating higher enthusiasm in trading digital assets, especially in DEX and NFT transactions.</p><h3 id="h-2-initial-active-time-on-ethereum" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Initial Active Time on Ethereum</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3b63bbe83760c225b3535f2066be966cfa9c63ac1e68d12683cb20dc261ad28d.png" alt="Airdrop Hunters&apos; Initial Active Time on Ethereum (Cumulative)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Initial Active Time on Ethereum (Cumulative)</figcaption></figure><p>Combining the airdrop time of on-chain projects and the initial active time of Airdrop Hunters on Ethereum, we find that most <strong>Airdrop Hunters are actually early users of Ethereum</strong>. At the time of Uniswap&apos;s airdrop (September 2020), more than half of the Airdrop Hunters had started to be active on Ethereum. The initial activity time distribution of the Premium Airdrop Hunters is also significantly earlier than that of the Standard Airdrop Hunters.</p><h3 id="h-3-activity-level-on-ethereum" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Activity Level on Ethereum</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c6f3ac2234eaea4b45b0f99286354da88b2b647b4577549713601b0a3397d37c.png" alt="Airdrop Hunters&apos; Activity Status on the Ethereum Chain" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Activity Status on the Ethereum Chain</figcaption></figure><p>We randomly sampled user accounts created before June 2021, selecting over 30,000 addresses, and compared their activity levels with those of Airdrop Hunters. As shown in the figure, <strong>Airdrop Hunters are active users on Ethereum</strong>, where <strong>Premium Airdrop Hunters</strong> make an average of <strong>over 50 transactions per month</strong> on Ethereum, and <strong>Standard Airdrop Hunters</strong> also make <strong>over 21 transactions</strong> per month. In comparison, the <strong>addresses we randomly sampled</strong> only <strong>average 0.16 transactions</strong> per month on Ethereum. These results further emphasize the enthusiasm and activity of Airdrop Hunters in on-chain activities. They significantly outperform ordinary users in terms of the number of transactions.</p><h3 id="h-4-behavior-after-the-project-airdrop" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. Behavior After the Project Airdrop</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d940263a4d9bc19fe3458e215beae6e4d225fe6e2db80344732aebd23fb96596.png" alt="Airdrop Hunters&apos; Activity on Optimism  (OP)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Activity on Optimism (OP)</figcaption></figure><p>We have been tracking the activity of airdrop recipients (including ordinary users and airdrop hunters) after airdrops from five projects. We found that after the project&apos;s airdrop, the activity levels of all users tend to decline, especially among ordinary users. Airdrop hunters are consistently more active than ordinary users at any given time.</p><p>Optimism, however, is an exception: before the Optimism airdrop, the activity level of ordinary users on the OP chain actually surpassed premium airdrop hunters. Yet, after the Optimism airdrop, the activity level of ordinary users continued to decline. On the contrary, premium airdrop hunters saw an upward trend in their activity levels on the OP chain after receiving the airdrop, and even in the next month following the airdrop, their activity level surpassed that of ordinary users. Through our in-depth analysis, we found that this is mainly due to the <strong>OP airdrop rules considering the activity of the addresses on Ethereum</strong>. The results show that many previously inactive premium airdrop hunters <strong>started to take interest</strong> in OP after receiving the airdrop, and <strong>began actively interacting</strong> with different projects on the OP chain.</p><h3 id="h-5-summary" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. Summary</h3><p>After sampling and analyzing the detailed on-chain behavior of many Airdrop Hunter addresses, we found that the above analysis is further corroborated. The on-chain activity characteristics of Airdrop Hunters can be summarized as follows:</p><ol><li><p>Most Airdrop Hunters are keen on DEX or NFT transactions.</p></li><li><p>Airdrop Hunters are mainly composed of early users.</p></li><li><p>The activity level of Airdrop Hunters is significantly higher than that of ordinary users.</p></li><li><p>A well-designed airdrop rule can have a positive impact on airdrop hunters.</p></li></ol><h2 id="h-what-is-the-next-target-for-airdrop-hunters" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What is the &apos;Next Target&apos; for Airdrop Hunters?</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f18430cc4f3cc2257f42963e72445de50d8b71c16f9ec5f5fe4bb3828f4c2fd9.png" alt="Airdrop Hunters&apos; next target" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; next target</figcaption></figure><p>After gaining some understanding of the Airdrop Hunter, we were curious about their &quot;next target&quot;. What projects are they optimistic about? To answer this question, we studied the projects they participated in and their behavior patterns when interacting with the projects through on-chain data. While helping readers understand which on-chain projects are worth interacting with, it further reveals the methods Airdrop Hunters use to interact with these projects. It&apos;s worth mentioning that we have included these Airdrop Hunters in our monitoring system. In the future, X-explore will continue to follow the latest movement of these Airdrop Hunters to bring more valuable analysis to readers.</p><p>We have divided the projects preferred by Airdrop Hunters into several tracks, each sorted by the participation rate of Premium Airdrop Hunters and selected projects with a participation rate of 25% or more. If a project has multiple smart contracts, we choose the one with the highest participation rate. Below are the track and project categories:</p><ol><li><p>Decentralized Finance (DeFi): Uniswap, SushiSwap, 0x, <strong>Metamask Swap</strong>, Balancer, 1inch, Paraswap, Aave, Rarible, InstaDApp, dydx, Compound</p></li><li><p>Non-Fungible Tokens (NFTs): Opensea, Blur, LooksRare, X2Y2, <strong>Foundation</strong></p></li><li><p>Layer 2 Solutions and Cross-chain Protocols: Arbitrum, Polygon, <strong>ZkSync lite</strong>, Optimism, HOP, <strong>ZkSync Era,</strong> <strong>Starknet</strong></p></li><li><p>Decentralized Applications (DApps): <strong>DeBank</strong></p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b42b807873dcdf884013860d8190d64c255d6e9b79e5c6be25a0e1e3d20535e4.jpg" alt="Airdrop Hunters&apos; Preference" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Preference</figcaption></figure><p>The projects highlighted in bold and encircled in red indicate that the project has not yet conducted an airdrop and has not yet issued tokens. We will delve into the behaviors of Airdrop Hunters on these projects.</p><h3 id="h-1-defi-track-metamask-swap-router" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. DeFi Track: Metamask: Swap Router</h3><p>After our analysis, the <strong>total trading volume of Airdrop Hunters</strong> on Metamask is <strong>$191,438,051</strong>, with a <strong>median trading volume</strong> of <strong>$1,255</strong> per Airdrop Hunter. In addition, we removed Airdrop Hunters from all 1,811,782 Metamask Swap users and sampled the same number of other Metamask users from these 1,776,303 addresses. We found that their <strong>total trading volume</strong> on Metamask is <strong>$205,673,503</strong>, with a <strong>median trading volume of $474</strong>. Although the total trading volume difference is not substantial, the median indicates a more balanced trading volume among Airdrop Hunters, with most of them having a trading volume greater than $1,000. Below is the transaction pair information for both Airdrop Hunters and other users:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fefb4df710545de20f4fc4ec20c6cac8895c7e845a3d1501f900053e9c7982c3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/18e78500ac22733bffdbe369a5ef761c4b0d3fc418c9aeba8f9b926f0f85fdc2.png" alt="(Common Coin refers to the top 50 coins by market capitalization on CoinMarketCap, excluding stablecoins)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">(Common Coin refers to the top 50 coins by market capitalization on CoinMarketCap, excluding stablecoins)</figcaption></figure><p>We found that Airdrop Hunters have a very similar preference for trading pairs on Metamask Swap and Uniswap. Compared to ordinary users, Airdrop Hunters tend to trade stablecoins and more mainstream cryptocurrencies: USDC, USDT, WETH, DAI, WBTC, etc. These stablecoins and mainstream cryptocurrencies have higher liquidity and relatively stable prices, reducing the risk of trading. In addition, stablecoins and mainstream cryptocurrencies are also easier to transfer and trade across multiple platforms, enhancing the flexibility of funds. This indicates that <strong>while Airdrop Hunters are pursuing returns</strong>, they also <strong>pay attention to</strong> <strong>risk control and the flexible use of funds</strong>.</p><h3 id="h-2-nft-track-foundation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. NFT Track: Foundation</h3><p>We randomly sampled three Airdrop Hunters who have participated in Foundation and found that their interactions on Foundation are not frequent. Most of the interactions are placing bids for NFTs, although two of the Airdrop Hunters actually purchased NFTs.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b65961cba1368c3fdde495bbfb87dd4007de28ad9e72257bc23c718fa70994ce.png" alt="Airdrop Hunters&apos; behavior on Foundation" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; behavior on Foundation</figcaption></figure><p>The airdrop rules of Blur can give us some insights. Some people, although they haven&apos;t purchased NFTs, could get considerable airdrop income just by swapping coins and placing bids. So when interacting with projects, we can <strong>try different functions of the project</strong>, which might lead to unexpected benefits.</p><h3 id="h-3-layer-2-solution-track-zksync-lite-zksync-era-starknet" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Layer 2 Solution Track: zkSync lite, zkSync Era, Starknet</h3><p><strong>zkSync (lite):</strong> We randomly selected 4 airdrop hunters who had bridged to zkSync lite. Next, we will use screenshots with explanations to guide you through these airdrop hunters&apos; behavior patterns on zkSync. If you want to understand the complete behavior of airdrop hunters, please refer to the link we attached.</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0x1254df8581b92609f087a505f77b4a9dc89502c3">Airdrop Hunter 1</a>:</p><p>Hunter 1&apos;s first transaction occurred on 2021-11-01, where he transferred in an amount from another address. It&apos;s worth noting that the interval between his two subsequent Swap transactions was only 15 seconds. He first swapped ETH for USDT, then swapped USDT back to ETH. This rapid and continuous trading behavior looks like an attempt to increase his activity level on the zkSync.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4e28df5a960599d51f93bd8cdb286fba51e839e3c1ee2f1831127d9ef78925b7.png" alt="Airdrop Hunter 1 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (1)</figcaption></figure><p>I&apos;ve omitted several cross-chain and address transfer operations in the middle. Hunter 1 performed a similar trading operation again 8 months ago, on October 20, 2022. This time, the stablecoin switched from USDT to USDC, with an interval of about 30 seconds.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bfd3bbb3ccc648dcdf6b5601d329106adf4979a7203b01b138d66045892c8e80.png" alt="Airdrop Hunter 1 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (2)</figcaption></figure><p>Two months ago, this address performed a series of similar trading operations (a total of 39 transactions), with each transaction spaced approximately 20 seconds apart.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3cafa445125d97fe9fa0c8d34214da40237376d1a345ace83a34f902f3d3a18a.png" alt="Airdrop Hunter 1 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (3)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0x1a616dae57382a9084c026d3f475aed59c2668cb">Airdrop Hunter 2</a>:</p><p>Hunter 2&apos;s behavior is relatively simple. They bridged from the mainnet on 2021-11-10 and made their first transaction three months ago (exchanging ETH for USDC). Then, this address had another transaction that bridged from the mainnet and has had no other transactions since.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e665782073f0e95d6f89c5cd1937c4f92be1b2dc1d911edf55eb0f072d7dec60.png" alt="Airdrop Hunter 2" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 2</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0xb26d9424f0f435c8b10ed478af36da8ca7d5b095">Airdrop Hunter 3</a>:</p><p>Hunter 3&apos;s behavior on zkSync lite is very similar to that of Hunter 1. They both bridge from the mainnet to zkSync at the end of 2021, then used zkSync&apos;s Swap feature to convert ETH to stablecoins, and then exchanged the stablecoins back to ETH (ETH &lt;-&gt; USDT). Moreover, they both carried out multiple transactions with time intervals of about 20 seconds. This may indicate that they are trying to increase their activity by frequently trading.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6909176bf329dce44321e26ef931eaccb908d2a67f4d8371c91e49a170ef0443.png" alt="Airdrop Hunter 3 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (1)</figcaption></figure><p>Ignoring several scattered transactions in between, Hunter 3 performed a similar set of operations on 2022-05-25, with transaction time intervals of about 20 seconds.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/50cd25d39945281868cb92782ac4b52a98702c4ad93b969ae9428a9f98b4f8c2.png" alt="Airdrop Hunter 3 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (2)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0xb2801900fb83990284f394ae48182602c3c7fc51">Airdrop Hunter 4</a>:</p><p>After bridged to zkSync lite, Hunter 4 made a few transactions and then bridged again after a while. This behavior pattern may mean that they are trying to maintain a certain level of activity on the zkSync and carry out fund transfers and allocations when needed.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9a092d51de7baac4d99153da56ab6d5d61707b22f4ac3dfdc796e0730326e2af.png" alt="Airdrop Hunter 4" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 4</figcaption></figure><p><strong>zkSync Era:</strong> In addition to zkSync lite, many airdrop hunters also choose to interact on the mainnet of zkSync Era through cross-chain transactions. Notably, within the first two days of the zkSync Era mainnet going live, a substantial number of airdrop hunters began interacting here, demonstrating their high interest and active participation in the zkSync Era project.</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explorer.zksync.io/address/0x1254df8581b92609f087a505f77b4a9dc89502c3">Airdrop Hunter 1</a>:</p><p>Airdrop Hunter 1 exhibits almost the same behavioral pattern on both zkSync lite and zkSync Era. After the zkSync Era went live on March 24, 2023, Airdrop Hunter 1 immediately bridged to zkSync Era on the next day, showing a high level of interest and quick response to this new project. He then used the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://syncswap.gitbook.io/syncswap/">SyncSwap</a> contract to perform token swap operations.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/50afcebf29958f94a2711142a7e18c98c23b6aecd724f70a741c92cfbc2cf332.png" alt="Airdrop Hunter 1 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (1)</figcaption></figure><p>Airdrop Hunter 1 undertook similar transaction behavior again seven days after the initial interaction (April 2, 2023) to increase activity. This timing seems very clever, raising questions as to whether he is trying to enhance activity levels in different weeks.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e1e7c765bdff8a268526cdd19677ce76447722f3cf39c624510ac83a7411368d.png" alt="Airdrop Hunter 1 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (2)</figcaption></figure><p>Airdrop Hunter 1&apos;s last operation on zkSync Era took place a month ago (May 19, 2023), and this operation still involved using SyncSwap to complete the exchange operation between ETH and USDC.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b7cc53e4c167920c32f4a7010db95b401df9f421c87103717fbfc7de4a945dcf.png" alt="Airdrop Hunter 1 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (3)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explorer.zksync.io/address/0x1a616dae57382a9084c026d3f475aed59c2668cb">Airdrop Hunter 2</a>:</p><p>Airdrop Hunter 2 bridged to zkSync Era on the day the zkSync Era mainnet was launched, just like Airdrop Hunter 1, showing his high attention and activity to the project. His multiple transactions on zkSync Era were made through the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://wiki.mute.io/mute/mute.io-overview/master">Mute</a> project. Unlike Airdrop Hunter 1, who exchanged between currencies, Airdrop Hunter 2 made an ETH to ETH exchange through a contract. This method can both pay lower fees, avoid the risk of price fluctuations, and leave active traces on zkSync.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8b4af424821ebe99807f06b824159a6e6de880f90fdf1d7939355cfc1e8f3304.png" alt="Airdrop Hunter 2" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 2</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explorer.zksync.io/address/0xb26d9424f0f435c8b10ed478af36da8ca7d5b095">Airdrop Hunter 3</a>:</p><p>Airdrop Hunter 3 and Airdrop Hunter 1 bridged to zkSync Era on the same day (2023-03-25), and their operations on the chain are very similar to those of Airdrop Hunter 1. The only difference is that Airdrop Hunter 3 used the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.spacefi.io/">SpaceFi</a> project to exchange between ETH and USDC.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/40e02526649ce466790037496d7fda0640fd769d3090402abf7afa33954885b8.png" alt="Airdrop Hunter 3 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (1)</figcaption></figure><p>A week after the first interaction (2023-04-03), Airdrop Hunter 3 returned to zkSync Era again. This time, Airdrop Hunter 3 used SyncSwap instead of SpaceFi. While boosting his activity level, he also participated in multiple projects within the zkSync Era ecosystem.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/78b309b1dd572a24072d4d9808c4c57593d04052ce5967b17916309ee642cbc4.png" alt="Airdrop Hunter 3 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (2)</figcaption></figure><p>Airdrop Hunter 3 continued with transfers and other activities afterwards, and also participated in the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://developer.izumi.finance/">iZUMi</a> project, where he made transactions between ETH and ETH. Notably, there are multiple records of outbound transfers from this address on 2023-05-15.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/aafb97771afea4c20bf2b3571877ba8694019577bf7312c786fdf02e9d5e9ec6.png" alt="Airdrop Hunter 3 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (3)</figcaption></figure><p><strong>StarkNet</strong>: As there are fewer airdrop hunters bridged to Starknet, and the transaction behavior pattern of airdrop hunters is quite similar to zkSync, we choose a representative address for analysis and illustration. <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://starkscan.co/contract/0x017e05e3623509146f7ccbc6d0ca3be5d728a6ed3c2208dd812d6f57b5c20a78#transactions">Airdrop Hunter</a>:</p><ol><li><p>About two months ago (2023-04-12), the airdrop hunter crossed to Starknet, and on the same day used the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.myswap.xyz/#/">myswap</a> project on Starknet to make transactions between ETH and USDC.</p></li><li><p>On Starknet, he also minted some NFTs.</p></li><li><p>Twenty-five days ago (2023-06-01), he made transactions between ETH and USDT through myswap again.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d495ba6ca4388214e725936f2562439f2cd7af7001896066c307e9b0f69fa0f4.png" alt="Airdrop Hunter on Starknet" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter on Starknet</figcaption></figure><h3 id="h-4-dapp-track-debank" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. Dapp Track: DeBank</h3><p>DeBank is a decentralized finance (DeFi) data analysis and asset management platform that provides users with a comprehensive view of their investments and debts across different DeFi projects. It offers real-time project data, transaction records, and risk assessments to help users make informed investment decisions.</p><p>Recently, DeBank has been expanding its DeFi services, including swap functions. The community is eagerly anticipating DeBank&apos;s airdrop. However, unlike the community members who follow tutorials to utilize DeBank primarily for airdrops, most airdrop hunters have merely registered with DeBank. They did not utilize DeBank&apos;s Swap function as suggested in the airdrop tutorial. Below, we illustrate how airdrop hunters interact with DeBank:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ea68906b36f1d1d88afaa937eaa5b42b890a407206a3a4b79ceed7876804d388.png" alt="Airdrop Hunter&apos;s operation on Debank (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter&apos;s operation on Debank (1)</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c8ca25dc2b46b17ed0ffbeeac0bdc6af903f1c63864e848c1be6176222eb466a.png" alt="Airdrop Hunter&apos;s operation on Debank (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter&apos;s operation on Debank (2)</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/653c81fa9efb9911e313963ac162d5c8d9980f003eb7975eb20c45df9e7f6a46.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>From the behavior of these premium airdrop hunters, it seems more like they have registered with DeBank to enable its analytics feature, rather than use DeBank&apos;s Swap function to increase their chances of potential airdrop.</p><h3 id="h-5-summary" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. Summary</h3><p>Upon a deep analysis of the projects chosen by airdrop hunters on-chain, we&apos;ve identified key driving factors for their selection:</p><ol><li><p><strong>Industry Influence:</strong> Most hunters tend to select projects that have wide-ranging influence and reputation within their field. Apart from DeBank, these projects have all surpassed an astounding 700,000 contract interactions on Ethereum.</p></li><li><p><strong>Preference for Layer 2 Solutions:</strong> Airdrop hunters clearly prefer Layer 2 projects, such as Arbitrum, zkSync lite, and zkSync Era. Layer 2 solutions offer faster transaction confirmation times and lower transaction fees, which are obviously very important for hunters frequently participating in DeFi and NFT projects.</p></li></ol><p>Through the in-depth analysis of X-explore, we found that although <strong>airdrop hunters on Arbitrum and Optimism display quality behavioral patterns</strong>, on <strong>zkSync and Starknet, they seem to inflate the volume and activity levels artificially</strong>. This is closely related to the integrity of the ecosystem on the chain. Optimism and Arbitrum had some development and settling time before the airdrop announcement, while zkSync&apos;s airdrop call was continuous before the Era mainnet launch. These findings force us to rethink: What is the real significance of an airdrop? How can we identify truly valuable users when formulating airdrop rules, instead of those who only exploit airdrops and engage in meaningless interactions? These are questions that project teams need to delve into.</p><h2 id="h-insights-from-airdrop-hunters" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Insights from Airdrop Hunters</h2><ol><li><p><strong>Airdrop hunters are mainly real and high-quality users</strong>: They actively participate in various blockchain projects, engage in cross-chain transactions, and maintain consistent activity on multiple platforms. Despite the heated discussions about &quot;Sybil addresses&quot;, we did not find obvious &quot;free rider&quot; behavior among airdrop hunters. On the contrary, their behavior patterns reflect a deep involvement in projects and a passion for the blockchain world, rather than just aiming for short-term airdrop gains.</p></li><li><p><strong>Successful examples can be referred to when setting up airdrop rules</strong>: In analyzing the traces of airdrop hunters on Optimism, we found that there are many premium airdrop hunters who received a large amount of OP airdrops due to their activity on Ethereum and ultimately became loyal users of the OP chain. Therefore, when project teams set up airdrop rules, they can take the behavior of airdrop hunters into account to ensure that airdrops are more effectively distributed to such high-quality users. This also helps the project teams use airdrops as an incentive mechanism to enhance project participation and user loyalty.</p></li><li><p><strong>A good airdrop needs to satisfy two core conditions</strong>: rational airdrop rule design and a robust ecosystem. In the presence of well-designed airdrop rules and a robust ecosystem, we witnessed how high-quality users on Arbitrum/Optimism maintain continuous activity. However, if you are eager to release airdrop information before the ecosystem is well-established, it may lead to the appearance of superficial prosperity. Even high-quality airdrop hunters may engage in &quot;boosting activity intentionally&quot; on zkSync/Starknet. In the upcoming X-explore articles, we will delve into the low-quality users and &quot;Sybil attack&quot; behavior on ZkSync/Starknet, revealing the true situation beneath the appearance of prosperity.</p></li></ol>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/ffe8a54572dd8475955499bc0f9c7f17467f671b886fb1fa337f4fa04d3c0fb5.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[空投猎人深度分析]]></title>
            <link>https://paragraph.com/@x-explore/DRTFdA5F06KhwNxSHhrv</link>
            <guid>DRTFdA5F06KhwNxSHhrv</guid>
            <pubDate>Mon, 26 Jun 2023 08:06:13 GMT</pubDate>
            <description><![CDATA[本文由 X-explore 与吴说区块链联合发布。 自2020年Uniswap开始采用空投策略奖励其早期用户以来，空投已在Web3领域引发了巨大热潮。在此影响下，各大项目上涌现出大量寻找下一份"免费午餐"（寻找新的空投项目）的羊毛党。现在，距离Uniswap的首次空投已接近三年，期间有许多大型项目纷纷仿效其策略，利用空投来回馈用户或吸引眼球。根据X-explore的预估，今年三月Arbitrum的空投中，有超过20%的空投被使用女巫攻击的羊毛党所获得。因此，我们希望通过对成功领取多次空投的用户进行深度分析，回答下面两个问题：这些空投「高手」都是什么人？他们后续的「目标」是什么？为了回答上述问题，在繁多的以太坊及其二层网络项目中，我们精细筛选出了5个「领取空投地址数超过10万」且「空投总价值超过1.4亿美元」的项目，它们是Uniswap、ENS、Optimism、Blur和Arbitrum。我们将在接下来的文章中深入分析这五个项目的用户，并特别关注那些多次获得这些项目空投的「高手」用户。 注：此篇文章计算币价的依据为 2023-06-07 CoinMarketCap 的数据，文章截...]]></description>
            <content:encoded><![CDATA[<p>本文由 X-explore 与吴说区块链联合发布。</p><p>自2020年Uniswap开始采用空投策略奖励其早期用户以来，空投已在Web3领域引发了巨大热潮。在此影响下，各大项目上涌现出大量寻找下一份&quot;免费午餐&quot;（寻找新的空投项目）的羊毛党。现在，距离Uniswap的首次空投已接近三年，期间有许多大型项目纷纷仿效其策略，利用空投来回馈用户或吸引眼球。根据X-explore的预估，今年三月Arbitrum的空投中，有超过20%的空投被使用女巫攻击的羊毛党所获得。因此，我们希望通过对成功领取多次空投的用户进行深度分析，回答下面两个问题：</p><ol><li><p><strong>这些空投「高手」都是什么人？</strong></p></li><li><p><strong>他们后续的「目标」是什么？</strong></p></li></ol><p>为了回答上述问题，在繁多的以太坊及其二层网络项目中，我们精细筛选出了5个「<strong>领取空投地址数超过10万</strong>」且「<strong>空投总价值超过1.4亿美元</strong>」的项目，它们是Uniswap、ENS、Optimism、Blur和Arbitrum。我们将在接下来的文章中深入分析这五个项目的用户，并特别关注那些多次获得这些项目空投的「高手」用户。</p><p><em>注：此篇文章计算币价的依据为 2023-06-07 CoinMarketCap 的数据，文章截图大多数为 2023-06-14，因此价格可能略有不同，造成混淆敬请见谅。</em></p><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">空投猎人是谁？</h2><p>我们将在五个项目中至少拿到三次空投的地址，称之为<strong>空投猎人(Airdrop Hunter)</strong>；其中拿到<strong>三到四次空投</strong>的地址，称之为<strong>普通空投猎人(Standard Airdrop Hunter)</strong>；而获得<strong>全部五次空投</strong>的地址，命名为<strong>精品空投猎人 (Premium Airdrop Hunter)</strong>。在这次分析中，我们总共找到了 34,547 个普通空投猎人地址，其中单地址的平均空投收益为 9,384 USD, 单地址空投收益中位数为 6,497 USD。至于精品空投猎人地址，我们总共找到了 932 个，其中单地址的平均空投收益为 18,935 USD，单地址空投收益中位数为 14,288 USD。从平均收益和中位数收益上看，精品空投猎人无愧「精品」二字。</p><h3 id="h-1-x-explore" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. X-explore标签分析</h3><p>为了更好地揭示空投猎人地址的特性，我们结合X-explore自研的链上标签系统，从行为、资产、活跃程度、交易盈利情况等维度深入分析了上述地址。我们发现，无论是普通空投猎人还是精品空投猎人，他们在去中心化交易所（DEX）和非同质化代币（NFT）上的交易量都远超过一般用户。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5cb36ee511c67afc65160c725e54b046f158b233b02ded54b52681407e4d3cc7.png" alt="Airdrop Hunters&apos; Tag on X-explore" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Tag on X-explore</figcaption></figure><ul><li><p><strong>Median Dex Trader</strong>：在DEX上交易量位于前10%的用户</p></li><li><p><strong>Median NFT Trader</strong>：在NFT交易量位于前10%的用户</p></li><li><p><strong>Heavy Dex Trader</strong>：在DEX上交易量或交易次数位于前1%的用户</p></li><li><p><strong>Heavy NFT Trader</strong>：在NFT交易量或交易次数位于前2.5%的用户</p></li></ul><p>这些数据显示，空投猎人在加密货币市场中的活跃度高于普通用户，他们在交易数字资产，特别是在DEX和NFT交易上表现出更高的积极性。</p><h3 id="h-2" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. 以太坊首次活跃时间</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3b63bbe83760c225b3535f2066be966cfa9c63ac1e68d12683cb20dc261ad28d.png" alt="空投猎人首次在以太坊活跃时间（累计）" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">空投猎人首次在以太坊活跃时间（累计）</figcaption></figure><p>结合链上项目的空投时间和空投猎人们在以太坊首次活跃时间，我们发现<strong>大多数的空投猎人实际上是以太坊的早期用户</strong>。在Uniswap进行空投的时候（2020-09），已经有超过一半的空投猎人开始在以太坊活跃。而精品空投猎人的首次活跃时间分布，也明显早于普通空投猎人。</p><h3 id="h-3" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. 以太坊活跃度</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c6f3ac2234eaea4b45b0f99286354da88b2b647b4577549713601b0a3397d37c.png" alt="空投猎人以太链上活跃情况" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">空投猎人以太链上活跃情况</figcaption></figure><p>我们对2021年6月之前创建的用户账号进行了随机抽样，选取了超过30,000个地址，并将这些地址与空投猎人的活跃度进行了比较。如图所示，<strong>空投猎人是以太坊上的活跃用户</strong>，其中<strong>精品空投猎人</strong>每个月在以太坊上平均进行<strong>超过50笔</strong> transaction，而<strong>普通空投猎人</strong>每个月在以太坊上也有着<strong>超过21笔</strong>的transaction。与此相比，我们<strong>随机抽样的地址</strong>在以太坊上的月均transaction仅为<strong>0.16笔</strong>。这一结果再次强调了空投猎人在链上活动中的积极性与活跃度，他们在交易数量上明显超过了普通用户。</p><h3 id="h-4" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. 项目空投后的表现</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d940263a4d9bc19fe3458e215beae6e4d225fe6e2db80344732aebd23fb96596.png" alt="空投猎人 OP 活跃情况" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">空投猎人 OP 活跃情况</figcaption></figure><p>我们针对空投领取用户（包含普通用户以及空投猎人）在五个项目空投后的表现进行追踪，其中发现在项目空投后，所有用户的活跃度都呈现下跌趋势，尤其是普通用户尤其明显。空投猎人在任何时间段的活跃程度明显高于普通用户。</p><p>其中 Optimism 是个例外：Optimism 空投前，普通用户在 OP 链上的活跃度实际上超过了精品空投猎人。然而，Optimism 空投后，普通用户的活跃度依然呈现下降趋势。相反的，精品空投猎人在收到空投后，他们在 OP 链上的活跃度却有增加的趋势，甚至在空投后的下一个月，他们的活跃度已经超越了普通用户。通过我们的深入分析，我们发现这主要是因为 <strong>OP 空投规则考虑了地址在以太坊上的活跃度</strong>。结果显示，许多<strong>原先在 OP 链上不活跃的精品空投猎人</strong>，<strong>在收到空投后开始对 OP 提起了兴趣，并积极在 OP 链上与不同项目进行互动</strong>。</p><h3 id="h-5" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. 小结</h3><p>在抽样分析了许多空投猎人地址的详细链上行为后，我们发现上述分析得到了进一步印证。空投猎人在链上的活动特性，可以简单归纳为以下几点：</p><ol><li><p>空投猎人大多数热衷于 DEX 或者 NFT 的交易</p></li><li><p>空投猎人主要由早期用户组成</p></li><li><p>空投猎人的活跃度明显高于一般用户</p></li><li><p>良好的空投规则设计对空投猎人能起到积极的作用</p></li></ol><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">空投猎人的「下一个目标」是什么？</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f18430cc4f3cc2257f42963e72445de50d8b71c16f9ec5f5fe4bb3828f4c2fd9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>在对空投猎人群体有了一定了解之后，我们很好奇他们的「下一个目标」是什么？他们还看好哪些项目？为了回答这个问题，我们通过链上数据研究了他们参与的项目，以及他们与项目交互时的行为模式。在帮助读者了解链上还有哪些值得交互的项目的同时，进一步揭露空投猎人与这些项目交互的方法。值得一提的是，我们将这些空投猎人纳入了监控，未来 X-explore 将持续关注这些空投猎人的最新动态，为大家带来更多有价值的分析。</p><p>我们将空投猎人偏好的项目分为几个赛道，每个赛道按照<strong>精品空投猎人</strong>参与的比例排序，挑选出参与率大于或等于25%的项目。如果一个项目有多个合约，我们则选择参与比例最高的那个合约。以下是赛道和项目的分类：</p><ol><li><p>去中心化金融(DeFi)：Uniswap、SushiSwap、0x、 <strong>Metamask Swap</strong>、Balancer、1inch、Paraswap、Aave、Rarible、InstaDApp、dydx、Compound</p></li><li><p>非同质化代币(NFTs)：Opensea、Blur、LooksRare，X2Y2，<strong>Foundation</strong></p></li><li><p>Layer 2 解决方案和跨链协议：Arbitrum、Polygon、<strong>ZkSync lite</strong>、Optimism、HOP、<strong>ZkSync Era</strong>、<strong>Starknet</strong></p></li><li><p>去中心化应用（DApps）：<strong>DeBank</strong></p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b42b807873dcdf884013860d8190d64c255d6e9b79e5c6be25a0e1e3d20535e4.jpg" alt="Airdrop Hunters&apos; Preference" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; Preference</figcaption></figure><p>其中，粗体以及红色方框圈出的项目表示该项目尚未空投且尚未发币。我们将深入分析空投猎人在这些项目上的行为。</p><h3 id="h-1-defi-metamask-swap-router" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. DeFi 赛道：Metamask: Swap Router</h3><p>经过我们的分析空投猎人在 Metamask 的总交易量为 <strong>191,438,051</strong> USD，空投猎人交易量的中位数为 <strong>1,255</strong> USD。另外我们从 Metamask Swap 全体 1,811,782 个用户中剔除空投猎人，再从这 1,776,303 个地址中抽了和空投猎人相同数量的其他 Metamask 的用户，发现它们在 Metamask 的交易量为 <strong>205,673,503</strong> USD，交易量的中位数为 <strong>474</strong> USD，虽然总交易量差异不大，但中位数表明空投猎人的交易量更为平均，大多数的空投猎人都会有大于 1,000 USD 的交易量。</p><p>以下为空投猎人以及其他用户的交易币对以及相关信息：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fefb4df710545de20f4fc4ec20c6cac8895c7e845a3d1501f900053e9c7982c3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/18e78500ac22733bffdbe369a5ef761c4b0d3fc418c9aeba8f9b926f0f85fdc2.png" alt="（Common Coin 为 CoinMarketCap 前50大市值的币种扣除稳定币）" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">（Common Coin 为 CoinMarketCap 前50大市值的币种扣除稳定币）</figcaption></figure><p>我们发现空投猎人在 Metamask Swap 和在 Uniswap 有着非常相似的币对偏好，相较于一般用户而言，空投猎人倾向交易稳定币以及较主流的币种: USDC, USDT, WETH, DAI, WBTC, 等。因为这些稳定币和主流币种的流动性较高，价格相对稳定，降低了交易的风险。此外，稳定币和主流币种也更容易在多个交易平台间进行转移和交易，提高了资金的灵活性。这说明了<strong>空投猎人在追求收益的同时，也注重风险的控制和资金的灵活运用</strong>。</p><h3 id="h-3-nft-foundation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. NFT 赛道：Foundation</h3><p>我们随机抽样了三位有参与 Foundation 的空投猎人，发现空投猎人在 Foundation 上的交互并不频繁，大部分交互行为是对 NFT 进行出价（Place Bid），不过其中有两位空投猎人也实际购买了 NFT。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b65961cba1368c3fdde495bbfb87dd4007de28ad9e72257bc23c718fa70994ce.png" alt="Airdrop Hunters&apos; behavior on Foundation" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunters&apos; behavior on Foundation</figcaption></figure><p>从 Blur 空投规则可以给我们启示，有些人虽然没有购买 NFT，但只是进行换币以及出价就能获得可观的空投收益，所以在与项目方交互时我们可以<strong>多尝试该项目不同的功能</strong>，积极参与且试用项目的同时说不定能有意外之喜。</p><h3 id="h-3-layer-2-zksync-lite-zksync-era-starknet-zksync-lite" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Layer 2 解决方案赛道：zkSync lite, zkSync Era, Starknet zkSync (lite):</h3><p>我们随机选取了4个有跨链到 zkSync lite 的空投猎人。接下来，我们将利用截图配合说明的方式，带大家了解这些空投猎人在 zkSync 上的行为模式，如果想要了解空投猎人的完整行为，请参考我们附上的链接。</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0x1254df8581b92609f087a505f77b4a9dc89502c3">空投猎人1</a>:</p><p>猎人1的首次 transaction 发生在 2021-11-01，他从另一个地址转入了一笔款项。值得注意的是，他后来的两笔 Swap 交易间隔仅15秒。他首先将 ETH 交换为 USDT，然后又将 USDT 交换回 ETH。这种快速连续的交易行为，看起来像是在刷提高活跃度。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4e28df5a960599d51f93bd8cdb286fba51e839e3c1ee2f1831127d9ef78925b7.png" alt="Airdrop Hunter 1 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (1)</figcaption></figure><p>中间有几次跨链以及地址转账的操作被我省略了，猎人1在8个月前，即 2022-10-20，又进行了一次类似的交易操作 (主角从 USDT 变成 USDC)，时间间隔大约30秒。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bfd3bbb3ccc648dcdf6b5601d329106adf4979a7203b01b138d66045892c8e80.png" alt="Airdrop Hunter 1 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (2)</figcaption></figure><p>在两个月前，该地址又进行了一系列类似的交易操作（共39笔），每笔交易时间间隔大约20秒：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3cafa445125d97fe9fa0c8d34214da40237376d1a345ace83a34f902f3d3a18a.png" alt="Airdrop Hunter 1 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (3)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0x1a616dae57382a9084c026d3f475aed59c2668cb">空投猎人2</a>:</p><p>猎人2的行为相对简单，它在 2021-11-10 从主网跨链过来，并在三个月前首次进行交易（将ETH兑换为USDC）。然后该地址又有一笔交易从主网跨链过来，至今并无其他交易。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e665782073f0e95d6f89c5cd1937c4f92be1b2dc1d911edf55eb0f072d7dec60.png" alt="Airdrop Hunter 2" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 2</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0xb26d9424f0f435c8b10ed478af36da8ca7d5b095">空投猎人3</a>:</p><p>猎人3和猎人1在 zkSync lite 上的行为非常相似，他们都是在 2021 年末从主网跨链到 zkSync，然后使用了 zkSync 的交易功能，将 ETH 转换为稳定币，再将稳定币兑换回 ETH (ETH &lt;-&gt; USDT)，而且他们都进行了多笔时间间隔在 20 秒左右的交易。这可能表明他们在尝试通过频繁的交易行为来增加活跃度：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6909176bf329dce44321e26ef931eaccb908d2a67f4d8371c91e49a170ef0443.png" alt="Airdrop Hunter 3 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (1)</figcaption></figure><p>中间多笔零星的交易暂且略过，猎人3在 2022-05-25 的时候又进行了一波类似的操作，交易时间间隔也都约为 20 秒</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/50cd25d39945281868cb92782ac4b52a98702c4ad93b969ae9428a9f98b4f8c2.png" alt="Airdrop Hunter 3 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (2)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0xb2801900fb83990284f394ae48182602c3c7fc51">空投猎人4</a>:</p><p>猎人4在进行跨链操作后进行了几次交易，然后在一段时间后又进行了跨链操作。这种行为模式可能意味着他们在尝试在 zkSync 链上保持一定的活跃度，并在需要时进行资金的转移和调配。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9a092d51de7baac4d99153da56ab6d5d61707b22f4ac3dfdc796e0730326e2af.png" alt="Airdrop Hunter 4" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 4</figcaption></figure><p><strong>zkSync Era:</strong> 除了 zkSync lite，许多空投猎人也选择跨链到 zkSync Era 的主网进行交互。值得关注的是，在 zkSync Era 主网上线的首两天，就有相当数量的空投猎人开始在这里进行交互，这体现出空投猎人对 zkSync Era 项目的高度关注和积极参与。</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explorer.zksync.io/address/0x1254df8581b92609f087a505f77b4a9dc89502c3">空投猎人 1</a><strong>:</strong></p><p>空投猎人1在 zkSync lite 和 zkSync Era 上几乎展现了相同的行为模式。zkSync Era在 2023-03-24 上线后，空投猎人1在第二天就立刻进行了跨链操作，对这个新项目展现出了极高的关注度和快速的响应。然后使用 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://syncswap.gitbook.io/syncswap/smart-contracts/smart-contracts">SyncSwap</a> 的合约来进行换币的操作。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/50afcebf29958f94a2711142a7e18c98c23b6aecd724f70a741c92cfbc2cf332.png" alt="Airdrop Hunter 1 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (1)</figcaption></figure><p>空投猎人1在首次交互后的七天之后（2023-04-02）再次采取了类似的交易行为来提高活跃度。这个时间点显得非常巧妙，引人怀疑他是否在尝试提高不同周的活跃度。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e1e7c765bdff8a268526cdd19677ce76447722f3cf39c624510ac83a7411368d.png" alt="Airdrop Hunter 1 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (2)</figcaption></figure><p>空投猎人1在zkSync Era上的最后一次操作发生在一个月前（2023-05-19），这次操作依然是使用 SyncSwap 来完成ETH与USDC之间的换币操作。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b7cc53e4c167920c32f4a7010db95b401df9f421c87103717fbfc7de4a945dcf.png" alt="Airdrop Hunter 1 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 1 (3)</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explorer.zksync.io/address/0x1a616dae57382a9084c026d3f475aed59c2668cb">空投猎人 2</a>:</p><p>空投猎人2在zkSync Era主网上线的当天就跨链到zkSync Era，和空投猎人1一样，展示了其对项目的高度关注和活跃度。他在zkSync Era上的多次交易都是通过<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://wiki.mute.io/mute/mute.io-overview/master">Mute</a>项目进行的，不同于空投猎人1进行币种之间的交换，空投猎人2是通过合约进行了ETH到ETH的兑换，这种方式既能付出较低的手续费，又能规避币价波动的风险，并在zkSync上留下了活跃痕迹。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8b4af424821ebe99807f06b824159a6e6de880f90fdf1d7939355cfc1e8f3304.png" alt="Airdrop Hunter 2" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 2</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zkscan.io/explorer/accounts/0xb26d9424f0f435c8b10ed478af36da8ca7d5b095">空投猎人3</a>:</p><p>空投猎人3和空投猎人1在同一天（2023-03-25）跨链至zkSync Era，且在链上的操作与空投猎人1也非常相似。唯一的不同在于，空投猎人4使用的是 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.spacefi.io/contracts">SpaceFi</a> 项目来进行 ETH 与 USDC 之间的交换。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/40e02526649ce466790037496d7fda0640fd769d3090402abf7afa33954885b8.png" alt="Airdrop Hunter 3 (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (1)</figcaption></figure><p>空投猎人3在首次交互的一周后（2023-04-03）再次回到zkSync Era。这一次，空投猎人3使用的是SyncSwap，而不是SpaceFi，他在刷活跃度的同时也参与了zkSync Era生态上的多个项目。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/78b309b1dd572a24072d4d9808c4c57593d04052ce5967b17916309ee642cbc4.png" alt="Airdrop Hunter 3 (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (2)</figcaption></figure><p>空投猎人3在后续也持续了转账和其他活动，其中还参与了<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://izumi.finance/home">iZUMi</a>这个项目，并进行了ETH和ETH之间的交易。值得注意的是，这个地址在2023-05-15有多笔转出的记录。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/aafb97771afea4c20bf2b3571877ba8694019577bf7312c786fdf02e9d5e9ec6.png" alt="Airdrop Hunter 3 (3)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter 3 (3)</figcaption></figure><p><strong>StarkNet:</strong> 由于跨链到 Starknet 的空投猎人数量较少，并且空投猎人的交易行为模式和 zkSync 相当类似，我们就选择一个代表性的地址来进行分析和举例说明。 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://starkscan.co/contract/0x017e05e3623509146f7ccbc6d0ca3be5d728a6ed3c2208dd812d6f57b5c20a78#transactions">空投猎人:</a></p><ol><li><p>大约两个月前（2023-04-12），空投猎人跨链到Starknet，并在同一天使用了Starknet上的 myswap 项目进行ETH和USDC之间的交易。</p></li><li><p>在Starknet上，他还铸造了一些NFT。</p></li><li><p>在15天前（2023-06-01），他又通过 myswap 进行了ETH和USDT之间的交易。</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d495ba6ca4388214e725936f2562439f2cd7af7001896066c307e9b0f69fa0f4.png" alt="Airdrop Hunter on Starknet" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter on Starknet</figcaption></figure><h3 id="h-4-dapp-debank" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. Dapp 赛道：DeBank</h3><p>DeBank 是一个去中心化金融（DeFi）的数据分析和资产管理平台，提供用户对自己在不同 DeFi 项目中的投资和债务的全景视图。它还提供实时的项目数据、交易记录和风险评估，帮助用户做出知情的投资决策。 DeBank 近期也在拓展自己的 DeFi 业务，包含 swap 等功能，社区对 DeBank 的空投也是翘首以待。但精品空投猎人和社区撸 Debank 的教程不同，精品空投猎人大多只注册了 DeBank，并没有和撸空投教程一样使用 DeBank 的Swap 功能 ，下面展示一下精品空投猎人是怎么与 Debank 交互的：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ea68906b36f1d1d88afaa937eaa5b42b890a407206a3a4b79ceed7876804d388.png" alt="Airdrop Hunter&apos;s operation on Debank (1)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter&apos;s operation on Debank (1)</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c8ca25dc2b46b17ed0ffbeeac0bdc6af903f1c63864e848c1be6176222eb466a.png" alt="Airdrop Hunter&apos;s operation on Debank (2)" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Airdrop Hunter&apos;s operation on Debank (2)</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/653c81fa9efb9911e313963ac162d5c8d9980f003eb7975eb20c45df9e7f6a46.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>从精品空投猎人的行为来看，更像是为了链上的分析而注册了 DeBank 开启分析的功能，不像是其他薅羊毛意图明显的用户，使用 DeBank 的 Swap 功能来增加自己潜在获得空投的机会。</p><h3 id="h-5" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. 小结</h3><p>在深入分析空投猎人在链上的项目选择后，我们发现了空投猎人选择项目的关键驱动因素：</p><ol><li><p><strong>行业影响力</strong>：大多数猎人倾向于选择在其领域内具有广泛影响力和知名度的项目。除 DeBank 外，这些项目在以太坊上的合约交互次数都超过了惊人的70万次。</p></li><li><p><strong>Layer 2 解决方案的优先选择</strong>：空投猎人明显偏向于选择 Layer 2 的项目，如 Arbitrum、zkSync lite 和 zkSync Era。Layer 2 解决方案提供了更快的交易确认速度和更低的交易费用，这对于频繁参与 DeFi 和 NFT 项目的猎人而言，显然非常重要。</p><p>通过 X-explore 的深入分析得出：尽管 Arbitrum 和 Optimism 上的空投猎人表现出优质的行为模式，但在 zkSync 和 Starknet 上，他们却呈现出刷量刷活跃度的现象。这和链上生态的完整度息息相关，Optimism 和 Arbitrum 在空投公布前已经有一段时间的发展及沉淀，而 zkSync 则在 Era 主网上线前空投呼声就不曾间断。这一发现使我们不得不重新思考：空投的真正意义是什么？我们如何才能在制定空投的规则中找到真正有价值的用户，而不是那些只为了利用空投而进行大量无意义交互的羊毛党？这些都是项目方需要深入探讨的问题。</p></li></ol><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">空投猎人带给我们的启示</h2><ol><li><p><strong>空投猎人主要是真实且高质量的用户</strong>：他们积极参与各种区块链项目，进行跨链交易，并在多个平台上保持稳定的活跃性。尽管「女巫地址」的讨论颇为热烈，但我们并未在空投猎人中发现明显的「羊毛党」行为。相反，他们的行为模式反映出对项目的深度参与和对区块链世界的热爱，而不仅仅是为了获取短期的空投收益。</p></li><li><p><strong>在制定空投规则时，可以借鉴成功的例子</strong>：在分析空投猎人在 Optimism 的踪迹时，我们发现了不少精品空投猎人因其在以太坊上的活跃性而获得大量的 OP 空投，最后成为 OP 链上的忠实用户。因此，项目方在制定空投规则时，可以将空投猎人的行为考虑进去，确保空投能更有效地分配给这类的高质量用户。这也有助于项目方利用空投作为一种激励机制，提升项目的参与度和用户忠诚度。</p></li><li><p><strong>良好的空投需要满足两个核心条件</strong>：合理的空投规则设计以及完备的生态链。在空投规则得当且生态链健全的情况下，我们见证了在 Arbitrum/Optimism 上的高质量用户如何保持持续的活跃度。然而，若在生态链尚未完备的前提下便急于发布空投信息，可能导致表面繁荣的出现，即使是优质的空投猎人在 zkSync/Starknet 上也可能会有刷活跃度的行为。在接下来的 X-explore 文章中，我们将深入探索 ZkSync/Starknet 上的低质量用户以及「女巫攻击」的行为，揭示表面繁荣下的真实情况。</p></li></ol>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/2354003c202fbaea90c5272ffd543552d6a8b0a7eb32f936b14a481764ce96f2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[New Tactics and Trends about Transfer Phising Attacks, $8 Million has been stolen]]></title>
            <link>https://paragraph.com/@x-explore/new-tactics-and-trends-about-transfer-phising-attacks-8-million-has-been-stolen</link>
            <guid>Uk3l9LUVIizZZ3OwsZFO</guid>
            <pubDate>Mon, 10 Apr 2023 08:20:30 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.Ⅰ. IntroductionThe zero-value transfer phishing attack, which has been ongoing for nearly half a year, has recently undergone a technological upgrade. On-chain monitoring has revealed that it has now evolved into small-value transfer phishing and fake token transfer phishing. The new attack methods have already generated profits of up to $8 million, and combined with our previous report on zero-value transfer phishing (Address Po...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h2 id="h-introduction" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Ⅰ. Introduction</h2><p>The zero-value transfer phishing attack, which has been ongoing for nearly half a year, has recently undergone a technological upgrade. On-chain monitoring has revealed that it has now evolved into <strong>small-value transfer phishing</strong> and <strong>fake token transfer phishing</strong>. The new attack methods have already generated profits of up to $8 million, and combined with our previous report on zero-value transfer phishing (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth/cL3d_CyNujXq8XY7ueP4omNXx_IY1EG5Dz0FD0vJ90M">Address Poisoning Attack, A continuing Threat</a>), the total loss on the chain has reached $32 million.</p><p>We urge users to triple-check the correctness of the address when making transactions. Wallet APP and blockchain browser teams should promptly improve product security features.</p><p>In addition, X-explore can provide real-time address labels for this attack.</p><h2 id="h-old-overview-of-zero-value-transfer-fishing-attacks" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Ⅱ. (Old) Overview of Zero-Value Transfer Fishing Attacks</h2><p>Since November 2022, a new phishing method has emerged on the chain. Attackers construct addresses that are similar to the intended recipients of normal transactions, and then send large amounts of false token transfer data with a value of zero to on-chain users. This allows them to profit from mistaken transactions.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/120ce841bd841a09913f9d1652255a2b7c6aeb521fdb58a4041adb4e59dda97f.png" alt="Zero Value Token Transfer Phishing with same characters as victim&apos;s" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Zero Value Token Transfer Phishing with same characters as victim&apos;s</figcaption></figure><p>This type of attack has the following characteristics:</p><ul><li><p>The attack is covert and pervasive. Attackers construct addresses that have only one character difference or no difference at all from legitimate addresses. Blockchain browsers automatically omit the middle characters of an address. Therefore, attackers only need to focus on creating addresses that appear identical to the original ones. Additionally, as mainstream token logic does not verify zero-value transfers, anyone can initiate such transfers, which means any transactions can be inserted into anyone&apos;s transaction list.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0f00d23687d3f96d5a18f5d4b68c264f08279a47814a056afc97823e19493af7.png" alt="Phishing address" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Phishing address</figcaption></figure><ul><li><p>The cost is low, and the return is high. The gas cost of Zero Value Phishing on the ETH chain alone is around 2,000 ETH (about $4M), and the accumulated funds obtained through this scam amount up to $21M.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c7d41cc0499aad7bf941e9f2a148447e7c47ecce6d8123a3c8f43139e0298eb1.png" alt="Costs and Stolen Funds of Zero Value Phishing Attacks on the Ethereum Blockchain" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Costs and Stolen Funds of Zero Value Phishing Attacks on the Ethereum Blockchain</figcaption></figure><h2 id="h-latest-small-amount-transfer-fishing-attacks" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Ⅲ. (Latest) Small-Amount Transfer Fishing Attacks</h2><h3 id="h-1-introduction-to-the-principle" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Introduction to the Principle</h3><p>After monitoring normal token transfers, the attacker narrows the original token amount by tens or hundreds of thousands of times, and then forwards it to the victim through the phishing wallet in order to skip the monitoring of traditional zero value token phishing, including bypassing Etherscan&apos;s zero-value transfer phishing attack warning. By increasing the credibility of the address through actual transfers, more victims are deceived.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1902319a830d89dfd23fd2ad44ac32d72154ce57d60f591a862d4b85cf956f5e.png" alt="Small value token phishing attack" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Small value token phishing attack</figcaption></figure><h3 id="h-2-attack-situation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Attack Situation</h3><p>The small-value transfer phishing attack first occurred on February 19, 2023 and lasted until March 26, with a total of 250,000 phishing attacks inserted into users&apos; transaction lists. Currently, there is only one small-value transfer phishing attacker on the Ethereum network.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/86e513cd17bcb716c163f54dc0f42b86ab1173b25aaa50843506264a4b7b1a02.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The attacker launched 30,000 contract calls for the attacks, with a total gas fee cost of 404 ETH (about $727k), and the cost for the small-value tokens was approximately $40k. Among them, the cost of phishing tokens for USDT accounted for 71% of all phishing tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bc730df039ba4319271101143164121ea8f1d71199c21bc72f4b26cfc17975f1.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>There were a total of 73,000 victims of the poisoning attacks, and a total of 23 unfortunate users transferred to the wrong address, totaling $1.2 million. Among the stolen funds, USDC and USDT accounted for 51% and 49%, respectively.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bf07e91ad06fcfa102b7348578dfe434106024f068138d7dda74dc5ae84466a5.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b5afa451b7e113b4d8d65cb4a7c661cf540c246e896a19be9cd63b31cab87c2c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3-attack-tracing" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Attack Tracing</h3><p>The attacker&apos;s direct source of funds comes from other phishing addresses. Tracing back to the earliest address, the source of funds is FixedFloat. The attacker&apos;s real address is <strong><em>User1</em></strong>:<em>0xe153605BA5bDAa492246603982AbfCcb297c72e9</em>, and two other commonly used addresses are also associated with this address: <strong><em>User2</em></strong>:<em>0x0a153cd1b0f36447e4d541e08fabd45f7a302817</em> and <strong><em>User3</em></strong>:<em>0x5b8544e1e7958715ededa0e843561ebbf0c728a8</em>. The attacker&apos;s address is also associated with deposit addresses from Binance, Coinbase, Kucoin, and Kraken exchanges, which can be further investigated through the exchange&apos;s KYC information.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/af3657681dab44eb45fcafcfca96cbcb2ec98c34caf0405c9e6e3232f49ed455.png" alt="fund flow tool: MetaSleuth.io" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">fund flow tool: MetaSleuth.io</figcaption></figure><p>The attacker&apos;s fund flow mainly consists of three parts:</p><p>Ⅰ. Transferring funds is the cost of other attacks, such as gas fees for zero-value transfer phishing.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0fa33223207b93d7319f70640a15eef84920bb25de154a5584177cbbfeb4b3bd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Ⅱ. Keeping the funds in the current address, or participating in staking to earn profits.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ee1b1afa6d811070c1a3088217681f5027bb3aad58a38c941e6e4dc041e341f8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Ⅲ. Laundering the funds. For example, the attacker transferred 130 ETH to Avalanche, then through multiple hops, transferred them back to ETH, and finally converted them into USDT, which was laundered into MEXC for withdrawal. The MEXC user deposit address is <em>0xDa818c1174105a49C8B3Fe43a96039024244df6B</em>.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/253745bdcf6c7b8ea03f395894d17adb79d9d254f5dc1278b602d39743847bb7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-latest-fake-token-transfer-fishing-attacks" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Ⅳ. (Latest) Fake Token Transfer Fishing Attacks</h2><h3 id="h-1-introduction-to-the-principle" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Introduction to the Principle</h3><p>After monitoring token transfers, the attacker creates fake tokens with the same name and constructs transfer records of the same quantity to the user. The phishing wallet and the original address have exactly the same number of digits in the visualization on the browser, with only one or two letters&apos; case differences in the checksum result.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d8cb64d654073e86cf4d4d0f5c016ecccd8d07b7e48dc2bb41000fbcc602002d.png" alt="Fake token phishing attack" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Fake token phishing attack</figcaption></figure><h3 id="h-2-attack-situation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Attack Situation</h3><p>The fake token transfer attack has been ongoing since March 18, 2023, and is expected to continue as a long-term phishing attack, similar to zero-value token transfer phishing.</p><p>Since March 18th, within 19 days, the gas cost for the fake token poisoning phishing attack has spent 158 ETH, completing 423,000 address poisonings and accumulating 102,000 addresses that have been subjected to fake token poisoning phishing attacks.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/12457257c9b0b9d34ab64c28c747cc1f8be4e8dbe2a945504d3da85fec399454.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In the past 19 days, a total of 27 victims suffered losses, with a stolen amount of $6.75 million, of which 60% was USDT and 40% was USDC.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a307cd002b57add60b258c329607d2a78c85d1d80bbc82991312f929fc61ac76.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The worst victim mistakenly transferred a total of $4 million worth of USDC in two consecutive transactions (<em>0x02f35f520e12c9383f8e014fbe03ad73524be95d</em>).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b61d6ab3286e85b4bec4cfd23f3bc03d76a7d597c22737b51346921b6389e68e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3-attack-tracing" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Attack Tracing</h3><p>The source and flow of funds for the attacker are both related to Tornado.cash. Just from the address <em>0x6AA7BA04DD9F3a09a02941901af10d12C8D1C245</em>, there has been an inflow of 1500 ETH into Tornado.cash.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/67220075fcf9bb0ab6a9ee2115df8fcdd25edb5f1c2e5289009e27af7b7d1157.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-v-conclusion" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">V. Conclusion</h2><ul><li><p>This article provides data visualization and continuous tracking of the two upgraded methods of Transfer Phising Attacks, revealing the latest trends and techniques of on-chain phishing attacks by hackers.</p></li><li><p>Due to these malicious attacks, the user experience on Etherscan browser has dramatically decreased. It takes several seconds to distinguish whether a transaction is real or fake, and a large amount of fake data occupies the space on the blockchain, making it difficult to distinguish between real and fake.</p></li><li><p>We propose all on-chain users stop copying addresses from the blockchain for transactions and not trust the identification and prevention methods of blockchain browsers and wallets. Hackers always stay ahead of any defense techniques, and the addresses they construct are always hard to defend against. We recommend that all on-chain users obtain addresses offline and confirm them again before conducting transactions and building their own address books.</p></li></ul><p>Dune Dashboard: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dune.com/opang/zero-value-token-transfer-phishing-scam">https://dune.com/opang/zero-value-token-transfer-phishing-scam</a></p><p>The x-explore platform is capable of providing real-time monitoring of phishing attacks on the blockchain. We welcome all blockchain browsers and wallet teams to consult with us.</p><p>For more, please follow x-explore.</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/8065a41104152ff8b970bf476983ce8aa93561618dbdae4be775cd406015b754.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Advanced Analysis For Arbitrum Airdrop]]></title>
            <link>https://paragraph.com/@x-explore/advanced-analysis-for-arbitrum-airdrop</link>
            <guid>LkyJPs8v4QkRWxZAx2gc</guid>
            <pubDate>Wed, 22 Mar 2023 07:24:58 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.OverviewThe long-awaited Arbitrum has finally released its airdrop news. Along with the airdrop news, they also released their rules for checking Sybil addresses.https://github.com/ArbitrumFoundation/sybil-detectionAccording to the rule described, we can infer that the project team:Excluded cross-chain bridges, centralized exchanges, and smart contracts while detecting SybilA relatively tolerant detection was adopted for small-sc...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h2 id="h-overview" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Overview</h2><p>The long-awaited Arbitrum has finally released its airdrop news. Along with the airdrop news, they also released their rules for checking Sybil addresses.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/88901415f4516c5de072a9f26e5c3c2069d368809214d534b5ace305b23386a7.png" alt="https://github.com/ArbitrumFoundation/sybil-detection" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">https://github.com/ArbitrumFoundation/sybil-detection</figcaption></figure><p>According to the rule described, we can infer that the project team:</p><ol><li><p>Excluded cross-chain bridges, centralized exchanges, and smart contracts while detecting Sybil</p></li><li><p>A relatively tolerant detection was adopted for small-scale and same-person addresses</p></li><li><p>Only data before the snapshot (Feb 6, 2023) was used for Sybil detection</p></li><li><p>Only data from Arbitrum and Ethereum was used for Sybil detection, while ignoring data from other Ethereum layer 2 chains such as Optimism and Polygon.</p></li></ol><p>We found that the above Sybil detection rules will cause significant loopholes. After many confrontations between Sybils and the project party, Sybils often use exchanges on a large scale for depositing their funds. This will result that these Sybils are not excluded from the Aribtrum&apos;s airdrop.</p><p>Through our internal same-person/Sybil address recognition model, <strong>we successfully identified more than 279,328 same-person addresses and 148,595 Sybil addresses that received the airdrop.</strong></p><h2 id="h-same-person-addresses" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Same-person addresses</h2><p>The same-person addresses refer to addresses that are controlled by the same entity. We run the Louvain Community Detection Algorithm on the sub-graph consisting of <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dune.com/blockworks_research/arb-airdrop">all the 624,136 airdropped EOA addresses (By the way, there are also 1007 contract addresses that received the airdrop and we will disclose it later on)</a>. The results show that there are <strong>a total of 279,328 addresses</strong> form more than <strong>60,000 communities</strong>. Since personal addresses in the same community have frequent fund transfers, they are considered same-person addresses. <strong>They account for approximately 557 million tokens or 47.96% of the total Arbitrum airdropped token.</strong></p><p>Below is the distribution of the same-person address group size and its corresponding address count. From the following figure, we can see that a large number of small-scale same-person communities have received tokens in this Arbitrum airdrop event.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ce225149deedbee6191052401c82162129974863e94c813bdf7bf321296a6b26.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Below is the distribution of the same-person address group size and its corresponding claimable token (Unit: token)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/93714aea882e835142720c25b834ef4b807eea4ec0b5326b3cae05b082949ebd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-sybil-addresses" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Sybil addresses</h2><p>We further examined these same-person addresses and established the strictest screening criteria to identify Sybil among them. There are a total of <strong>148,595</strong> Sybil addresses that received the airdrop. They account for approximately <strong>253 million</strong> Arbitrum or 21.8% of total airdropped tokens. The composition of Sybil addresses comes from two parts:</p><ol><li><p>Communities with a large number of same-person addresses</p></li><li><p>High-confidence Sybil addresses identified by X-explore on Ethereum and multiple Ethereum layer 2 chains (Arbitrum, Optimistism, etc)</p></li></ol><p>To combat Sybil detection, Sybil uses cross-chain bridges, centralized exchanges, and smart contracts to prevent direct connections between large numbers of addresses and make each address as independent as possible to evade Sybil detection. In Arbitrum Sybil hunting, the project party also removed entity addresses such as bridges, exchanges, and smart contracts. According to our analysis, some Sybil successfully countered the detection rules and a large number of addresses received this airdrop.</p><h3 id="h-case-1-cex-sybil" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Case 1: CEX Sybil</h3><p>Examples of CEX Sybil with more than 250 addresses.</p><ol><li><p>Between August 24 and August 28, 2022, a total of 2997 addresses that received the airdrop withdrew funds from Binance Exchange (0xb38e8c17e38363af6ebdcb3dae12e0243582891d). The withdrawal amounts were very consistent, between 0.00114 and 0.00116 ETH (about 2 USD). These addresses received a total of 1.83 million airdrop tokens.</p></li><li><p>Between June 3 and June 4, 2022, a total of 1001 addresses that received the airdrop withdrew funds from FTX Exchange (0xa60113f7d43130919802b0863abdcdb956664fd5). The withdrawal amounts were very consistent, between 0.0022 and 0.0023 ETH (about 4 USD). These addresses received a total of 1.04 million airdrop tokens.</p></li><li><p>Between November 27 and November 30, 2022, a total of 645 addresses that received the airdrop withdrew funds from Binance Exchange (0xb38e8c17e38363af6ebdcb3dae12e0243582891d). The withdrawal amount was very consistent at 0.05 ETH (about 9 USD). These addresses received a total of 700,000 airdrop tokens.</p></li><li><p>Between October 29 and November 01, 2022, a total of 1035 addresses that received the airdrop withdrew funds from Binance Exchange (0xb38e8c17e38363af6ebdcb3dae12e0243582891d). The withdrawal amount was very consistent at 0.003ETH (about 5 USD). These addresses received a total of 980,000 airdrop tokens.</p></li><li><p>On February 6, 2023, 294 addresses that received the airdrop withdrew funds from Binance Exchange (0xb38e8c17e38363af6ebdcb3dae12e0243582891d). The withdrawal amount was very consistent at 0.0008 ETH (about 1.5 USD). These addresses received a total of 291,000 airdrop tokens.</p></li><li><p>On December 12, 2022, 273 addresses that received the airdrop withdrew funds from Binance Exchange (0xb38e8c17e38363af6ebdcb3dae12e0243582891d). The withdrawal amount was very consistent at 0.0095 ETH (about 17 USD). These addresses received a total of 242,000 airdrop tokens.</p></li><li><p>On August 19, 2022, 261 addresses that received airdrops withdrew funds from the FTX exchange (0xa60113f7d43130919802b0863abdcdb956664fd5). And the amount of funds withdrawn is very consistent, at 0.003 ETH (about 5 USD). These addresses received a total of 189,000 tokens.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d268020fa435522e8373313cac8149dde8c63e6c873f170afb4696abd1884b3a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>We further took out these Sybil addresses that withdrew from exchanges (FTX). In addition to the consistent amount of funds, they also have very consistent smart contract calls.</p><p>Note: The nodes in the figure represent addresses, while the edges represent interactions between addresses.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f782b1bc6e2d6cf43b689d9c9a15f3106a5809e5d0372e74f706589bd8ab1b10.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-case-2-bridge-sybil" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Case 2: Bridge Sybil</h3><p>Examples of Bridge Sybil</p><ol><li><p>Between November 02 and November 07, 2022, a total of 1114 addresses that received the airdrop crossed over to Arbitrum via HOP Bridge(0x33ceb27b39d2bb7d2e61f7564d3df29344020417). The deposit amounts were very consistent, between 0.0025 and 0.0025 ETH (about 4 USD). These addresses received a total of 1.08 million tokens.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/97ad7661e9e725b02d231f6a59608623d1e7ff1a4bbac1592e16258a638d5611.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-case-3-smart-contract-sybil" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Case 3: Smart contract Sybil</h3><p>Examples of Smart contract Sybil</p><ol><li><p>Address 0x922008a118feff7fb017ee67eb3b02371e559999 deposited funds into 1,274 airdrop addresses via the Disperse contract (0x692b5a7ecccad243a07535e8c24b0e7433238c6a). The deposit amount was very consistent at 0.0005 ETH (about 8 USD). These addresses received a total of 1.059 million Tokens.</p></li></ol><p>Similarly, the number of Sybil addresses that prevent their direct connection via the Disperse contract (defined as a single address depositing funds into 50 different airdrop addresses) was 9,483. These addresses received a total of 10.98 million tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8f40147a5b7a008473f30e84bb5bb7537f46b1f978f0d67897a3143010a555db.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-case-4-sybil-collects-funds-after-snapshot" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Case 4: Sybil collects funds after snapshot</h3><p>We have chosen a representative example from this type of Sybil. The example Sybil has a total of 198 addresses and earned 174,375 Tokens. Although these addresses have obvious collection behavior, they were not excluded from the airdrop addresses because the collection behavior occurred after the snapshot. Therefore, we call on the Arbitrum team to conduct a final Sybil screening before the airdrop. (Sybil addresses in this figure have been sampled)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3dd4076a18a49ea0ee19ce88e17476b9d085ab8e9349877697e99ca2246ca6ac.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-case-5-sybil-on-another-chain-optimism" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Case 5: Sybil on another chain (Optimism)</h3><p>We have selected an example that is representative of this kind of Sybil. The example Sybil contains a total of 202 addresses and earned 204,250 tokens. These addresses also have very similar transaction records on the Arbitrum chain, but the transaction amounts and times are slightly different, so they were not identified as Sybil. However, they also have identical transaction records on the OP (Optimism) chain. It is worth mentioning that X-explore can not only identify Sybil addresses on Arbitrum, but also supports Ethereum, Optimism, and other Ethereum layer 2 chains.</p><p>Further looking at these Sybil results, we will find that some projects (Synapse, Balancer, etc.) are being attacked by these Sybils. If the project party does not filter out Sybils when airdropping tokens in the future, these Sybils will once again become big winners.</p><p>(Sybil addresses in this figure have been sampled)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ec4abb5062c5d271b961547d1f3a5f0843f3e87dde1db74696a013eb72086d35.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>We can infer that the rules established by the Arbitrum were not effective in preventing the following four types of Sybils:</strong></p><ol><li><p>Sybils with fewer than 20 addresses</p></li><li><p>Sybils that deposit and withdraw through exchanges, cross-chain bridges, smart contracts</p></li><li><p>Sybils with obvious collection behavior of NFTs or funds after the snapshot</p></li><li><p>Sybils with obvious batch operation behavior on other chains such as Optimism, Ethereum</p></li></ol><h2 id="h-smart-contracts-receive-airdrop" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Smart Contracts receive airdrop:</h2><p>When we were investigating Sybil, we also found some interesting examples. The winners of this Arbitrum airdrop were not only EOA, but some contract addresses also received airdrops. A total of 1,007 contract addresses received airdrops, and the total number of Arbi tokens received was about 1 million.</p><p>Examples:</p><ol start="2"><li><p>0x8c44c0ab9a15bacad7a4b663a89593c406c6b4ea</p></li><li><p>0x44e4c3668552033419520be229cd9df0c35c4417</p></li><li><p>0x6e87672e547d40285c8fdce1139de4bc7cbf2127</p></li><li><p>0x8585a10f59fd4dd6e7d5e19254d5a791dc25f3f4</p></li></ol><h2 id="h-summary" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Summary:</h2><p>Sybil hunting has always been a hot potato for project parties. Project parties need Sybil to support the popularity of the project, but on the other hand, they have to bear the risk of Sybil&apos;s profits and the risk of market dumping after Sybil cashed out. According to X-explore&apos;s estimates, there are around 150k Sybil addresses and at least 4000 Sybil communities included in the airdrop and the total profit of Sybil addresses accounts for more than 253 million tokens. <strong>After multiple rounds of verification, we have obtained a very reliable list of Sybil addresses. Arbitrum is welcome to contact us for it.</strong></p><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/155a9e8f092404cae5613e8971e85f7ff3b662268ef2a4db955437e4cc823db4.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Is There Any Wash Trading in Centralized Exchanges?]]></title>
            <link>https://paragraph.com/@x-explore/is-there-any-wash-trading-in-centralized-exchanges</link>
            <guid>wGYBvenFk2j7r80GAy8j</guid>
            <pubDate>Thu, 23 Feb 2023 10:44:43 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. According to a recent article by WuBlockchain, the trading volume of cryptocurrency exchanges has increased significantly since the opening of 2023. Derivatives trading on the main exchanges rose 47.6% this January compared to the previous month. These such rocketing trading volumes are probably mingled with fake trades on the CEXs as the article indicates. Wash trading on cryptocurrency exchanges is not a new topic. Due to the ...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p>According to a recent article by WuBlockchain, the trading volume of cryptocurrency exchanges has increased significantly since the opening of 2023. Derivatives trading on the main exchanges rose 47.6% this January compared to the previous month. These such rocketing trading volumes are probably mingled with fake trades on the CEXs as the article indicates.</p><p>Wash trading on cryptocurrency exchanges is not a new topic. Due to the lack of regulation on centralized exchanges, some CEXs tend to wash their trades to cover up the true trading volumes in order to improve their rankings in trading volume. So as with the following contents, we construct methods of trading volume analysis to identify and elaborate the fake trading volume.</p><p>We obtained historical K-line data, real-time depth data, and real-time transaction data of several mainstream exchanges through open APIs. These exchanges include Binance, Bybit, OKX, Bitget, Phemex, Kucoin, and Dydx.</p><h2 id="h-1-a-quick-overview-of-trading-volume-across-exchanges" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. A Quick Overview of Trading Volume Across Exchanges</h2><h3 id="h-volume-across-exchanges" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Volume across exchanges</h3><p>We chose BTC future contracts as our first detection analysis. By deep diving into the volume of BTC futures of each exchange after 1st September, 2022, some similar patterns could be observed across most exchanges.</p><p>Some similarities/differences in the volume across exchanges:</p><ul><li><p>The general shape and trend of the volumes were somewhat uniform. With similar spikes in volumes at the same period of time except for Phemex</p></li><li><p>The periods of the peak and valley volume coincided with each exchange except for Phemex.</p></li></ul><p>Referring to the chart below, the shape of Phemex&apos;s trading volume was abnormal compared with other CEXs.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/2068f61a30098fdd4a4b644d2b669da99aaded4c824e994e094b9bfa91a93f84.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The picture below showed the price and trading volume chart of Phemex&apos;s uBTCUSD trading pair. It can be clearly seen that the trading volume increased rapidly from 19 Aug 2022, and staged a call back for this such insane trading volume starting from 16 Sep 2022 until 19 Nov 2022. After that, without any sign, the volume fell sharply and turned the level down to the trading volume before 19 Aug 2022. From Jan 2023, the volume seemed to rebound again and continue to keep at a high level.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7d03a534017d246dced1b044f950a40b6a5553546d9e3835724cd19108eaa0ec.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2-the-relationship-between-volume-and-price" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. The Relationship between Volume and Price</h2><p>Common sense is that price fluctuating volatility on the market would result in spikes in trading volume as investors will close off their trades, or open new ones. From our experience, periodic huge volume tends to follow huge dips/rises in prices, even more in the futures/derivatives markets.</p><p>By considering that cryptocurrency has the characteristic of leverage trading, any vigorous movement in the market could be amplified and cause a take-profit or a stop-out. This would be a big reason for a soar in volume. So we targeted Phemex trading volume change when prices moved sharply as one of our investigations.</p><h3 id="h-a-snapshot-of-the-price-volume-relationship" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Snapshot of the Price-volume Relationship</h3><p><strong>Before 10 Aug, 2022.</strong></p><p>We selected 5 mins K-line data for the following.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a9edab1c8863c52c1337689af9a0c752227686b910faf5577bc24c1f4d4d2775.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>There&apos;s some kind of positive correlation between <em>candle height</em> and <em>volume difference [lag 1]</em></p><p><strong>Point 1</strong></p><ul><li><p>While the candle height is high (indicating a large market movement), there&apos;s a fluctuation of trading volume.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/52aaeeccb1813ee07ed72bcde1a814db1fe83f48aadd71dc0b8f2258187d73b8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Looking into only 4th Dec, 2022 [<em>we separate the axis for a better view.</em>]</p></li><li><p>A huge market movement along with volume fluctuations</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dec432d6938e8c061d98d72a25a3d9a417ea1eef63a2f49c6ad8b5255d1e9f38.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Point 2</strong></p><ul><li><p>Between 5th - 6th Jan, 2022.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3a91eb4881ed3a6dd7a5b22762567b3bbcbfe2d99d3ee0ceafc2828e32c595f6.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Zooming into the fluctuation. [<em>we separate the axis for a better view.</em>]</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/78e779628b3377a1f6a0252ed3425488e23ab9ab7d061e2ee8a6847a6e85bfa3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>The movement has a large correlation.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3100ae9374ce0b3881d99718846882a0ff7ba9e0773fb7c822f7f3f5cf21a080.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>After 10 Aug, 2022.</strong></p><p>Here, we look into the 5 mins data same as before.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/721ab5d71d9702a9a63a087c6fa783496d7ad1f4b66be569c86c917fcaaa130b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>It can be observed that when there is a huge <em>volume difference [Lag 1]</em>, there doesn&apos;t seem to be much correlation with <em>candle length.</em></p></li></ul><p><strong>Point 5</strong></p><ul><li><p>There is a huge market movement around 19th Aug, 06:35.</p></li><li><p>❌ However, there isn&apos;t any volume difference.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/91143000f2be5eebbfde2f4d027f16d77550075d1d6a8745fb7ee4db30116128.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>At 19th Aug, 2022.</p></li><li><p>❌ Taking a closer look here, it seems that there&apos;s not much correlation.</p></li><li><p>💡 There was a sudden spike in market movement. However, there wasn&apos;t any volume difference.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/39bd546db4e34cabbfac4275abb14abbe76c28f02fc47460e17c8387fb8b6048.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Point 6</strong></p><ul><li><p>There seems to be a huge change in volume. [Lag 1]</p></li><li><p>❌ However, there doesn&apos;t seem to have been any many changes in the market prices.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6adc3ca3781281081bddd793fd4881b25bbbede8b549c909bda78bf66ea017a9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>At 26th Aug, 02:35, there was a sudden spike in Volume (as seen from the large lag 1 difference).</p></li><li><p>❌ However, there wasn&apos;t any price difference.</p></li><li><p>💡 With a large volume difference, there wasn&apos;t any large market movement.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/348a70ef2cc00988117e4646e47ddbac52caa9f38a9b24090a2fc3d22ef38da5.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Trading Volume spikes are somewhat along with huge market movement - [Before 10 Aug]</strong></p><p><strong>Prices and Volume seem to be independent, as spikes in volume and market movement have weak/no correlations. [After 10 Aug]</strong></p><p>In order to be more quantitative, the comparison with the volume price correlation between different exchanges, we calculated the correlation coefficient of each exchange.</p><h3 id="h-calculation-of-correlation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Calculation of correlation</h3><p>To quantify this, we calculate the (Pearson) correlation coefficient between the candle length and the volume.</p><ul><li><p>The per-day correlation was calculated and plotted on a graph against time.</p></li><li><p>Pearson&apos;s product-moment correlation coefficient was used here as it could represent the strength of the putative linear association between the variables.</p></li><li><p>A correlation coefficient of zero indicates that no linear relationship exists between two continuous variables, and a correlation coefficient of −1 or +1 indicates a perfect positive and negative linear relationship respectively. A good gauge of correlation can be found in the table below.</p></li><li><p>We mainly analyze BTC contracts, but also include an ETH trading pair.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bb54aa0c382d46ba91d2d8d9b36a2c5b9be25d7335e8f0c95a898fd8c44c7059.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-comparing-across-exchanges-and-symbols" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Comparing across exchanges and symbols.</h3><p>Taking the same K-Line data from various exchanges to compare the correlation between their candle height and their volume with these parameters:</p><ul><li><p>We&apos;ll look at the correlation from Sept 2021 onwards (where possible)</p></li><li><p>We&apos;ll look mainly at the 5 mins K-line intervals.</p></li><li><p>Taking Bybit and Binance as an example for now.</p></li></ul><p><strong>ByBit</strong></p><p>Looking at the correlation per day:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a6dc7a7da599f76b85e62a8a06711c8ab30a2d5bc8266f436c94a10f4f89355e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Correlation per-day ranges from a minimum of 0.6 to a maximum of 0.97.</p></li></ul><p>Taking a Simple Moving average with window of 10. (SMA10)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7bd431830b0f1b4880bb593211706e51ffb710acbdc09c7eb1062bfece7dc1bd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>SMA10 is increasing</p></li><li><p>BTCUSDT SMA10 holding above 0.8, with ETHUSDT holding above 0.7</p></li></ul><p><strong>Binance</strong></p><p>Looking at the correlation per day:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/075e83cd10ad8860b31b5c07cf3a33208b41249f9eef33486bdf88d187e6ee60.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Similar to Bybit. Correlation ranges from 0.63 to 0.97.</p></li></ul><p>Taking a Simple Moving average with window of 10. (SMA10)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/328d80ab7d3bcb5e708248226328fa2564a09328e0e6dd0b5db014eea6df6943.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>SMA10 is increasing</p></li><li><p>Both SMA are mostly above the 0.8 threshold.</p></li></ul><p>Adding other exchanges into the same graph, as well as ETHUSDT data.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9c829f140d7a34dd9b0cd75fe9b3e1ea0638c6d9161b78c646e263b72088ff15.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Of the exchanges:</p><ul><li><p>Dydx&apos;s correlation coefficients show periodicity before May 2022. In August 2021, Dydx started the trade-to-earn activity, with a round of epoch every 30 days, and the distribution of rewards is mainly based on the user&apos;s transaction fees. Therefore, when the user&apos;s fee expenditure is less than the rewarded, it brings wash trading. Further, before the end of each period, the trading volume rises sharply (20220215, 20220314, 20220412). With the rapid decline of the DYDX token price to less than $2 in May 2022, transaction mining is no longer profitable, and the correlation coefficients of Dydx are gradually recovering.</p></li><li><p>Binance, Bitget, OKX as well as Bybit have a similar SMA10 correlation coefficient, which holds constantly above 0.75, indicating strong linear relationship.</p></li><li><p>Kucoin&apos;s XBTUSDTM is linear contract, due to the limitation of the API, we can only get the data since December 2022. The SMA10 ranges from 0.56 to 0.71, indicating a weak linear relationship.</p></li><li><p><strong>Phemex&apos;s uBTCUSD SMA10 dropped significantly after May 2022, where it ranges from 0.11 to 0.43, indicating weak to no linear relationships. The correlation coefficient returned to normal levels starting on November 20, continued until January 5, and then decreased again. In line with the changing trend of transaction volume which is also consistent with the information in Wu blockchain&apos;s article. This is different from other exchanges.</strong></p></li><li><p>Combining the correlation analysis and the changing trend of trading volume, <strong>we can infer that Phemex has the behavior of fake volume, and fake volume will be traded when the market price is stable. Abnormally enlarged volumes often occur during this period.</strong></p></li></ul><h2 id="h-3-transaction-streams" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. Transaction Streams</h2><p>We also analyzed the recent trades/transactions of a few exchanges.</p><p>Large market movement tends to be large transaction volumes. This would generally be due to:</p><ul><li><p>A sudden increase and influx in the number of trades.</p></li><li><p>Trades that interact with higher volumes.</p></li></ul><h3 id="h-binance" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Binance</h3><p>We took a look from 4th Nov, 08:00 to 23:59：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5bc2af84e42a23e35b63e22481fe18689142f28486938b1a99bf7c530ef1c0ee.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>There was randomness in the number of traded orders on Binance, which is consistent with common sense.</p></li></ul><p>We specialized in individual trade sizes. Here, we plotted the individual trade sizes as well as the K-line candle length for the corresponding timings.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8199be422a5b3373828566f12a9473879a1546d86609d1ec7c314672d45104c7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>It is observed that where there the K-line lengths are high, there the trades are higher volume.</p></li></ul><h3 id="h-phemex" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Phemex.</h3><p>Raw Phemex&apos;s trades.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b93a21ba52b55950f11eb8348e8ec81a9b7d00c586e0095619c25464f2cce16f.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Noted that there seems to be a hard cap at both +-10K.</p></li></ul><p>Overlaying the K line volume, we were here to see if there are any patterns between a higher K line volume and a larger (single) trade</p><p><strong>Raw trade view</strong></p><p>Overlaying the reported K line volume over the individual trade data.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/97bc42c2f952b968f8007799d4fc71c3d100ce38425dbaf1009d0794848d2ca6.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Zoomed in view</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a27218a20b4299fe823a9b973d5a621de2c18bb88e93959705b9b31358b8522a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Hourly view.</strong></p><p>K line trade volume grouped over the hour.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b6608967c9d9bf4604c97b8a9574809da61646520ba34744fd081466fc29a47e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>No obvious relations between the raw trades and the K line volume. The size of the trading order did not show randomness.</p></li><li><p>Compared with Binance, the trade sizes were relatively stagnant. What changed was the density of trade and not the individual trade sizes.</p></li></ul><h2 id="h-4-orderbook-depth-vs-trading-volume" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">4. Orderbook Depth vs Trading Volume</h2><p>Depth is considered an important measure of exchange liquidity. Traders prefer markets with better depth because of lower transaction costs. We investigate the orderbook depth of the various exchanges to determine if there are any patterns or trends that might be observed.</p><p>The orderbook depth data was recorded every 10 seconds.</p><h3 id="h-spread" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Spread</h3><p>Taking the 1st layer&apos;s bid and ask, we derived the spread at a particular time. We plotted it against time to get a plot.</p><p><strong>Raw Spread of the exchanges.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fbc9f99635c13aedb4e2537c4cdb2d811cb30daef2638d2516977c8c8e8649f9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Phemex had the highest spread of all the exchanges.</p></li></ul><p><strong>Spread, averaged by minute.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b70ae1420f281fd49b14703c79114d712bd1f0757d1d174de7693b391ae6fa73.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Averaged by the minute, it is observed that phemex&apos;s spread would easily be 3-5x of any other exchanges.</p></li></ul><p>Questioning that there would be such high volume traded on Phemex, considering that their spread isn&apos;t the tightest.</p><h3 id="h-with-a-fixed-slippage-how-many-contracts-can-be-traded" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">With a Fixed Slippage, how many contracts can be traded？</h3><p>Here, we&apos;d like to see what QTY of coins we&apos;ll get if we set a specific amount of slippage. The more contracts traded, the better liquidity of the exchange.</p><p>Here, we set the slippage amount to be <strong>10 USD/T</strong>.</p><p>(We calculated the number of coins [BTC] that is in the book before a 10 USD/T Slippage from the mid point)</p><p><strong>BIDs</strong> Looking into the number of coins we&apos;ll get before a slip of 10 USD/T occurs.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e3d884a7ae55b026246379995d54f0dce6374af064c9de574d4a9b54798b19a8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>Binance seems to have a consistently high qty, indicating that their book depth is very healthy. Traders may open more than 100 BTC contracts by taking a slippage of 10USDT.</p></li></ul><p>Turning into Phemex&apos;s uBTCUSD volume</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b3e45a4966369392e551fb0fb184f64221b5efbb31217ecb1eea22750d3a5361.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>It is observed that:</p><ul><li><p>The book&apos;s depth was inconsistent. Ranging from 0.1 to 50 coins.</p></li><li><p>The same was observed for the asks.</p></li></ul><h3 id="h-fixed-usdt-amount" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Fixed USD/T amount.</h3><p>We also tried another way. We fixed the amount spent and determined the percentage slip that would result from that.</p><p>For this experiment, we first set the amount spent at <strong>100K/150K/200K USD/T.</strong> We calculated the amount of coins bought, and the average price of each coin. Here, we plotted the coin volume vs slip (From mid-price). We need to pay attention to the number on the x-axis. The change in the value of the y-axis was due to the fluctuation of the market price.</p><ul><li><p>We only took the book depth that is deep enough.</p></li></ul><p><strong>Asks 100K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d3fe5af3a91ee6c05e68bdbf1b9d76f64d937f10a84a3ec4105b2e9d12cf39bc.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Asks 150K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8b2884c878bc6a87b22a346318b6d321f387ad0b6ae7aa3ab9309c873f8bdd61.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Asks 200K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5ea179e50aeb0c14923fdf1dc0e49034888dd0e7f833f7f70e9fb97fb29d6988.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>For the asks, Phemex had the highest slippage.</p></li></ul><p><strong>Bids 100K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b54b0010be55e60938b76d4adb238f25f76b06cf3857e52d7c037a6c1f3f8373.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Bids 150K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/63598ada2eedb1a3985a72d5e486137171a368807b61fb4b117a0269230acd46.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Bids 200K</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/236dea7b8a6326b06710f1862d68407c9d81872966c643ad27e5eba43bfdc6eb.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>For the bids, Phemex also had the highest slippage.</p></li></ul><p>To conclude, <em>Binance</em> and D<em>ydx</em> seem to have really good book depth and prices. Kucoin and Okx follow behind, and Phemex has some of the largest slippages.</p><h2 id="h-5-estimating-fake-trading-volume" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">5. Estimating fake trading volume.</h2><p>After the comparative analysis of trading volume and price changes, and the comparison with the order depth, it can be reasonably speculated that Phemex is suspected of the fake trading volume.</p><p>In this part, we will introduce a method for estimating the real proportion of reported trading volume.</p><h3 id="h-ratio-model" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Ratio Model</h3><p>We built a model with the following</p><ul><li><p>Observing that there was a weak correlation between Phemex&apos;s price fluctuations and trading volume, we assumed that fake transactions on the exchange mainly occur during periods of small price fluctuations. That is to say, the trading volume during significant price fluctuations is real. This is a conservative assumption for estimating the proportion of false trading volume。</p></li><li><p>Divide the trading volume of exchanges with normal trading volume (Binance, OKX, etc) when the market fluctuates rapidly by the trading volume of the whole day to get the ratio R.</p></li><li><p>Divide the trading volume of abnormal exchange when the market fluctuates rapidly by the ratio R to estimate the real trading volume.</p></li></ul><p>Using the selected days, we calculated the percentage of each day&apos;s volume as compared to the corrosponding daily volume of that exchange.</p><ul><li><p>The plot of the ratio (of the spike volume vs the daily volume) against the dateime is shown below.</p></li></ul><p><strong>Full Plot</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/60cd1567a8e584df84febe8f558532a3459c937435da2d4324205911bdcca36c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>On the scatter plot, at each datetime (per 5 mins intervals), usually lower than 10% of the daily volume, with the exception of a few.</p></li><li><p>Most points on the scatter plot show that the percentages vary between 1% and 8%.</p></li></ul><p><strong>Zoomed in plot</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3f50b48464547d697302474da70534c03ea19ff01fef8fdbdfa2d5c561f8a118.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p><strong>Phemex&apos;s Spike volume ratio tends to be significantly lower, with a gap separating Phemex&apos;s plotted points from the other exchanges.</strong></p></li><li><p>Phemex&apos;s spike ratio for the datetimes seems to vary between 0.02% and 0.09%, with some occasional points above 0.5%.</p></li></ul><p>It is observed that OKX seems to have the highest percentage.</p><p>Phemex&apos;s plotted points seem to be below the 1% mark for most days.</p><p>Using the mean of the ratio per datetime and Phemex&apos;s spike k-lines&apos; trading volume, we look to estimate the real volume of Phemex.</p><p>Taking the estimated volume per day, we compared it against the reported volume data and showed the results in a line plot below.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a88586b255add7b40ad35f65468910aa1d569552f0c30cb5a9ea4e77a6d0d8ff.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p>There were some obvious disparities, and the estimated volume lies entirely below the reported volume.</p></li><li><p>The daily ratio of estimates vs report volume ranged from about 3% to 92.8%</p></li><li><p><strong>Taking a simple ratio over the sum of volumes on all dates, the min/max estimated volume ranged from 5% - 25% of the reported data.</strong></p></li><li><p>Using the same method to estimate the true volume ratio of Binance and Bybit, the result was very close to the reported volume.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e9c0c38d580eee5056f87f39b6a25cdd583ad3704ea237d3d1b436bf9f62ac97.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/aa4f7fd087dc31ad8122fcd22bc4fc23262941102f9b212f45a9de9f5f3f3ecf.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-summary" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Summary</h2><p>We have adopted various public data from the most popular centralized exchanges</p><ul><li><p>Phemex&apos;s trading volumes showed a different pattern than other exchanges. The sudden increase in volume on Phemex&apos;s platform seems interesting, which is abnormal.</p></li><li><p>The correlation of trading volume vs kline height data is seen to be significantly lower for Phemex, compared to any other exchanges. This indicates that Phemex&apos;s trading volume was not solely dependent on the market movement, and there might be other forces driving their volume.</p></li><li><p>Phemex seems to have the highest spread and slippages across most exchanges. This should have deterred some clients from trading.</p></li><li><p>Running a ratio analysis estimates of some spiked volumes, the estimated volume stood between min/max 5% - 25% of Phemex&apos;s reported volume.</p></li><li><p>By deep diving into individual trade data, Phemex&apos;s trade sizes did not change much even when there were market movements, or when the Kline volume data was reportedly high. In contrast with Binance, there were (single) large volume trades when there were market movements that caused huge kline volume.</p></li></ul><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
        </item>
        <item>
            <title><![CDATA[中心化交易所资产分析-Huobi.com]]></title>
            <link>https://paragraph.com/@x-explore/huobi-com</link>
            <guid>I9ZelSs2QI7zOyT1IDEV</guid>
            <pubDate>Thu, 19 Jan 2023 11:50:45 GMT</pubDate>
            <description><![CDATA[本文对 Huobi.com 资产清单进行了深度分析，首先回顾了 Huobi 资产清单公布前后的相关事件信息，并梳理了Twitter中对资产清单的FUD，包括BETH资金有效性以及挪用的质疑，ETH大额转出的质疑。接着，我们基于链上数据对社区FUD进行了逐一分析，这些FUD并不成立。最后，我们对Huobi资产清单进行CheckList评估，其中低流动性资产占比超过50%，有 17.44亿。2.15亿HECO链上资产存在超额计算，3亿TRX资产为孙哥个人资产。整体来说，低流动性资产占比过高为最为显著的风险，实际存在风险资产达18.4亿，占公布总额的53%。此外，我们也给出了我们对市场的判断，HT看跌，Huobi发行的BETH看涨。(不构成投资建议) ——本文由 X-explore 与吴说区块链联合发布。1. 背景：11月初，中心化交易所FTX发生超大规模的挤兑事件，有超过60亿资产在2-3天内被提取，造成流动性枯竭，并最终导致FTX破产。为了证明没有挪用用户资产，各家交易所纷纷公布自己的资产信息清单。将交易所保管用户资产的情况公之于众。根据Nansen Portfolio统计的信息，...]]></description>
            <content:encoded><![CDATA[<p>本文对 Huobi.com 资产清单进行了深度分析，首先回顾了 Huobi 资产清单公布前后的相关事件信息，并梳理了Twitter中对资产清单的FUD，包括BETH资金有效性以及挪用的质疑，ETH大额转出的质疑。接着，我们基于链上数据对社区FUD进行了逐一分析，这些FUD并不成立。最后，我们对Huobi资产清单进行CheckList评估，其中<strong>低流动性资产占比超过50%，有 17.44亿。2.15亿HECO链上资产存在超额计算，3亿TRX资产为孙哥个人资产</strong>。整体来说，低流动性资产占比过高为最为显著的风险，<strong>实际存在风险资产达18.4亿，占公布总额的53%</strong>。此外，我们也给出了我们对市场的判断，HT看跌，Huobi发行的BETH看涨。(不构成投资建议)</p><p>——本文由 X-explore 与吴说区块链联合发布。</p><h2 id="h-1" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. 背景：</h2><p>11月初，中心化交易所FTX发生超大规模的挤兑事件，有超过60亿资产在2-3天内被提取，造成流动性枯竭，并最终导致FTX破产。为了证明没有挪用用户资产，各家交易所纷纷公布自己的资产信息清单。将交易所保管用户资产的情况公之于众。根据Nansen Portfolio统计的信息，目前已有18家头部交易所公布了资产信息清单。我们在交易所官网、CoinMarketCap（<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://coinmarketcap.com/zh/exchanges/binance/#reserve">https://coinmarketcap.com/zh/exchanges/binance/#reserve</a>）以及Nansen（<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://portfolio.nansen.ai/entities">https://portfolio.nansen.ai/entities</a>）上都可以查到明细信息，包含地址以及金额。</p><p>伴随着资产信息清单的公开，持续性的挤兑逐渐平稳。然而社区依然存在质疑，近几日，由于 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/BlockBeatsAsia/status/1608762818802909186">huobi.com 裁员事件</a>、<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Sidd_0000123/status/1612293435779874816">发山寨Pi币事件</a>、<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/ArkQaq/status/1610988124393598976">“老鼠仓”事件</a>，导致的社区FUD愈演愈烈，其中也包含对Huobi资产信息清单的质疑。</p><p>因此，我们计划对各家交易所的资产信息清单进行客观的分析，希望可以消除社区的恐慌情绪。我们将从三方面进行CheckList分析。</p><ol><li><p>资产有效性：</p><ol><li><p>资产余额正确。</p></li><li><p>资产所有权清晰。</p></li><li><p>资产来源于平台用户。</p></li></ol></li><li><p>资产配置合理性：</p><ol><li><p>主流Token占比。</p></li><li><p>低流动性Token占比。</p></li></ol></li><li><p>资产使用情况：</p><ol><li><p>资产未用于投资。</p></li><li><p>资产未关联风险机构。</p></li></ol></li></ol><h2 id="h-2-huobi" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. Huobi 链上资产</h2><h3 id="h-21-huobi" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.1 Huobi 资产概况</h3><p>2022年10月上旬，百域资本完成对Huobi大股东的股份收购，孙宇晨是这一并购基金的核心出资人，收购价格在10亿美元往上（来源：<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mp.weixin.qq.com/s/oZY7MPfj3bTV55iZwNws-g">吴说独家新闻</a>，<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/justinsuntron/status/1591323854785622017">H.E. Justion Sun(@justinsuntron)</a>），在交接过程中已完成100%保证金储备验证。</p><p>Huobi在11月13日公开了冷热钱包地址以及资产储备——<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.huobi.com/support/zh-cn/detail/24922606430831">火币资产透明化工作报告（一）</a>，报告中公布了32K BTC、274K ETH、820M USDT、9.7B TRX，<strong>共折合3.5B USD</strong>。</p><p>与此同时，为进一步提升使用者信心，加速资产透明度建设工作进程，Huobi在<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.huobi.com/support/zh-cn/detail/24922606430831">火币资产透明化工作报告（一）</a>中宣布将在近一个月内与第三方合作完成100%保证金默克尔树储备证明并对外公示（两个月过去了，Huobi并没有兑现承诺……）</p><h3 id="h-22-fud" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.2 社区FUD</h3><p>社区不断有针对资产清单的质疑，我们整理了Twitter上的相关信息，目前主要的质疑点可以分为3类。</p><p><strong>2.2.1 针对 BETH 资金有效性的质疑？</strong></p><p>官方公开的 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xa929022c9107643515f5c777ce9a910f0d1e490c">0xa929022c9107643515f5c777ce9a910f0d1e490c</a> 的地址有96,671个BETH，这个地址是火币发行的HECO链的跨链桥。然而 Etherscan 中未发现该地址有 BETH 资产(From: Moc<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Btman_Jeff/status/1591630990153502720">@Btman_Jeff</a>)。 此外，该地址只有22278 个ETH，不足以与公布的96,671 BETH数量产生 1:1 质押关系。（From: DeFi小矿工<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/DeFi8362/status/1592837574791290880">@DeFi8362</a>）。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/530674baf15823c01884fc65a231a2b30c4ab7228e8799ae1760d6055ab9dff6.png" alt="Moc(@Btman_Jeff)曾质疑在披露地址没有找到对应数量的BETH资产" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Moc(@Btman_Jeff)曾质疑在披露地址没有找到对应数量的BETH资产</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/950d2656df4ea27a2f988930996cc1b59426f74d913aba06bffdb117fd5d3f8d.png" alt="DeFi小矿工(@DeFi8362)也发推称披露地址BETH与ETH 1:1的质押数量对不上" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">DeFi小矿工(@DeFi8362)也发推称披露地址BETH与ETH 1:1的质押数量对不上</figcaption></figure><p><strong>2.2.2 挪用用户资金参与质押的质疑？</strong></p><p>从链上数据来看，Binance 持有60.6亿ETH和1.08亿Beth，质押比为0.017；Huobi 持有1.51亿ETH，却持有1.28亿HBeth，质押比为0.85。也就是说Huobi用户一大半的ETH都拿去质押了，同样是知名中心化交易所的用户，行为上却出现了近50倍的差异，所以 huobi 可能私自挪用客户资金去做质押赚取收益并且没有经过用户授权（FROM：BitRun<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/BitRunX/status/1612874061520179200">@BitRunX</a>）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/55bf85e5ac47ae090c622f2124d5ea0fac48d760e8ceb60286c5aa0982f8be7a.png" alt="BitRun(@BitRunX)也质疑BETH的锚定ETH资产已被挪用" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">BitRun(@BitRunX)也质疑BETH的锚定ETH资产已被挪用</figcaption></figure><p><strong>2.2.3 针对 ETH 资产所有权清晰的质疑？</strong></p><p>Huobi 快照前（10月11日）入金17.5万 ETH， Huobi 快照后（11月13日）立刻从出金地址 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc......3Fc(huobi 34)</a> 出金10000 ETH分别流入Binance 和 OKX。可能是为了快照金额足够从其他地方临时挪过来填补空缺，快照后就还回去了（From：Moc<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Btman_Jeff/status/1591630990153502720">@Btman_Jeff</a>）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/65bb5eab70e4b57104ad1dd28deb5d25abcf10c765e570946765055c164cf9e5.png" alt="Moc(@Btman_Jeff)质疑huobi为了资产证明临时调度外部资金" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Moc(@Btman_Jeff)质疑huobi为了资产证明临时调度外部资金</figcaption></figure><h2 id="h-3-x-explore" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. X-explore 分析</h2><h3 id="h-31-checklist" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.1 CheckList分析</h3><p>对照CheckList，我们对Huobi的资产清单进行了分析：<strong>其中低流动性资产占比超过50%。2.15亿HECO链上资产存在超额计算，3亿TRX资产为孙哥个人资产。</strong></p><ol><li><p>资产有效性：</p><ol><li><p>资产余额正确：</p><ol><li><p>存在价值2.15亿HECO链质押资产超额计算（见3.3.3）</p></li></ol></li><li><p>资产所有权清晰。✅</p></li><li><p>资产来源平台用户：</p><ol><li><p>存在价值3亿TRX链资产与huobi用户无关（见3.3.2）</p></li></ol></li></ol></li><li><p>资产配置合理性：</p><ol><li><p>主流Token占比。价值 16.75亿（5.5亿 BTC，2.26亿 ETH，8.16亿 USDT，6004万 USDC，2032万 XRP）</p></li><li><p>低流动性Token占比。价值 17.44亿（10亿 HT，0.98亿 XCN，5.3亿 TRX，1.16亿 BETH）（见3.3.1）</p></li></ol></li><li><p>资产使用情况：</p><ol><li><p>资产未被挪用。✅</p></li><li><p>资产未关联风险机构。✅</p></li></ol></li></ol><h3 id="h-32-fud" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.2 社区FUD分析</h3><p><strong>3.2.1 BETH 资产有效性 &amp; 挪用用户资金</strong></p><p>BETH 的资金储备<strong>真实有效</strong>，锚定资产在信标链约1.16亿。在huobi公布的资产清单中显示，地址 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xa929022c9107643515f5c777ce9a910f0d1e490c">0xa92……490c</a>（HECO链的跨链桥） 在ETH链上拥有资产 96671 个BETH，从官网信息得知其锚定ETH已质押到以太坊2.0信标链。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f500644f015c7ae2f4625cbc8341e6599a4e75022840e59fb1863814048b5a16.png" alt="  huobi官网BETH质押信息" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">  huobi官网BETH质押信息</figcaption></figure><p>从链上数据查找到两个与huobi紧密关联的地址大量参与了信标链质押，质押总金额达 91552 ETH，非常接近公布的BETH资产数。</p><ol><li><p>资金来源为huobi的地址 0xB73f4d4E99F65Ec4B16B684e44f81Aeca5ba2B7C 从2020年12月起逐渐累积在信标链质押 51776 ETH</p></li><li><p>资金来源为huobi的地址 0x194BD70B59491ce1310ea0BCeAbdb6c23aC9D5b2 从2020年12月起逐渐累积在信标链质押 39776 ETH</p></li></ol><p>在上海升级后，以太坊2.0信标链质押ETH开放提现后，这部分质押ETH将可提出。故BETH 的资金储备真实有效。对应twitter用户质疑BETH无质押物和质疑huobi挪用BETH质押资金的答案已清晰。</p><p><strong>3.2.2 ETH 资产所有权清晰</strong></p><p>地址 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc......3Fc(huobi 34)</a> 快照前在10月11日的大量入金是 huobi 从多签钱包转入16.9万ETH，资金源头是火币出金钱包，结合孙宇晨收购huobi的时间节点可以得知，应该是被收购而进行的资产整理（<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0xce60b7d010e85ca4c689b848ed23b0d20cfe1918819eb7770c5be8d916b6f0bb">交易信息</a>）</p><p>地址 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc......3Fc(huobi 34)</a> 快照后的10000 ETH出金<strong>不是为了快照而调度的外部资金</strong>，官方称此行为是大户的个人行为，平台不做限制。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/28eb30142d5b8ce5f1b21b5332067b0640e9e3afef98954d6353412c76f54410.png" alt="Huobi 回复10000 ETH流出" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Huobi 回复10000 ETH流出</figcaption></figure><p>事件发生时正处FTX暴雷，huobi 每日都有近20k ETH的转出。如果官方答复属实，从金额上看也是合理的。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9fd391c9bfcb8fbaf4f59ca18bc5b66c4bcf838df62db4ad8cf89c61df54b82b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-33" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.3 风险分析</h3><p><strong>3.3.1 低流动性Token占比过高（50.4%）</strong></p><p>低流动性 Token 总价值 17.44亿（10亿 HT，0.98亿 XCN，5.3亿 TRX，1.16亿 BETH）</p><ul><li><p>HT 为Huobi发行的平台币，当前代币总数量为2.04亿 HT，根据Huobi公布的数据市场流通量 1.62亿 HT。目前huobi公布的资产清单上的地址持有量为1.91亿 HT，远超市场流通量，达到了代币总量的94%。流动性非常不足。</p></li><li><p>XCN 为小市值Token，火币目前持有该币种占总流通的份额超过9%（火币持有19.4亿，总流通214亿），流动性较低。</p></li><li><p>TRX 为TRON链的原生Token，火币目前持有该币种占总流通的份额同样超过10%（火币持有97亿，总流通918亿）, 流动性较低。</p></li><li><p>BETH 为质押锁定的Token，必须在以太坊上海升级后，用户才能够提取出Token，因而目前该Token不具备流通性。</p></li></ul><p>下面对比了一下其他交易所在主流资产以及这几个低流动性资产上的持有占比：</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bc37eaaba944efa7246fd430514955b48c185ea1c92b0a69d9709010f5c52ac3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>由上表可知，huobi持有这几个低流通性币种的比例大大高于同行。参考FTX事件中FTT价格的巨幅下跌，当交易所发生大规模挤兑时，市场不具备足够的深度来接收低流动性币种的抛压，因而会导致这些币价大幅跳水，从而引发平台资金的大幅缩水。</p><p><strong>3.3.2 TRX链资产中3亿与huobi用户无关</strong></p><p>在huobi公布的资产清单中，一共列出了TRX链上的13个地址，合计97亿枚TRX，其中有6个地址累积54亿TRX（约3亿 USD）与Huobi用户无关，<strong>为TRX链上线时空投的TRX，疑似Justin Sun个人资产。</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b601e8c0324c1546586ef39330ea95e87ea914c0200e834319d6c5feb8175fe6.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>如上图所示，我们进行了链上追踪。其中有6个资产清单中的地址在2022年5月26日、5月30日至6月4日、6月15日接收到来自币安热钱包累积54亿TRX的转账。</p><p>与此同时，在2022年5月24号、5月29号以及5月30日某个币安用户的入金地址上累积接收123亿TRX的转账。这些资金均直接来自于TRX链在2018年6月上线时，疑似Justin Sun个人地址上被空投的TRX。</p><p>币安在2022年5月份的前20天，平均每日出入金约5亿TRX。然而，入金方面，在5月24日入金27亿，在5月30日入金更是达到84亿。出金方面，在5月26日出金16亿、5月30日出金达到了40亿，6月1日出金为31亿，6月2日出金为20亿。因此，我们可以将币安在5月下旬的大额入金与出金直接关联，从而推测，huobi公布的资产清单中的54亿TRX疑似Justin Sun个人资产。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4bc438ea030a142cf8a2137918857f6ef6b7fd8b8a6eca41e6b150adda712a89.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>地址清单：</p><blockquote><pre data-type="codeBlock" text="Huobi asset reserves announced addresses：
TF2fmSbg5HAD34KPUH7WtWCxxvgXHohzYM
TYh6mgoMNZTCsgpYHBz7gttEfrQmDMABub
TKgD8Qnx9Zw3DNvG6o83PkufnMbtEXis4T
THZovMcKoZaV9zzFTWteQYd2f3NEvnzxAM
TZ1SsapyhKNWaVLca6P2qgVzkHTdk6nkXa
TRSXRWudzfzY4jH7AaMowdMNUXDkHisbcd

Binance Hot Wallet
TV6MuMXfmLbBqPZvBHdwFsDnQeVfnmiuSi

Binance Deposit Address
TJkgTCg91dEfsT9to74VDXi7uUxRDqF2ft

Suspicious Justin Sun Own Addresses
TSnjgPDQfuxx72iaPy82v3T8HrsN4GVJzW
TGqxgpMFfvUcpC2R4JccY1t6oFe8WfTQGT
TTNaP9JFf2MvCs1jJUVH8Eh5tiD8Cg8aC2
"><code>Huobi asset reserves announced addresses：
TF2fmSbg5HAD34KPUH7WtWCxxvgXHohzYM
TYh6mgoMNZTCsgpYHBz7gttEfrQmDMABub
TKgD8Qnx9Zw3DNvG6o83PkufnMbtEXis4T
THZovMcKoZaV9zzFTWteQYd2f3NEvnzxAM
TZ1SsapyhKNWaVLca6P2qgVzkHTdk6nkXa
TRSXRWudzfzY4jH7AaMowdMNUXDkHisbcd

Binance Hot Wallet
TV6MuMXfmLbBqPZvBHdwFsDnQeVfnmiuSi

Binance Deposit <span class="hljs-selector-tag">Address</span>
TJkgTCg91dEfsT9to74VDXi7uUxRDqF2ft

Suspicious Justin Sun Own Addresses
TSnjgPDQfuxx72iaPy82v3T8HrsN4GVJzW
TGqxgpMFfvUcpC2R4JccY1t6oFe8WfTQGT
TTNaP9JFf2MvCs1jJUVH8Eh5tiD8Cg8aC2
</code></pre></blockquote><p><strong>3.3.3 HECO链质押资产超额计算2.15亿</strong></p><p>在huobi公布的资产清单中，包含了地址 0xa929022c9107643515f5c777ce9a910f0d1e490c 在ETH链上共2.36亿资产。该地址是 HECO 链锚定 ETH 链上的资产（包括USDT、ETH、BETH）的质押地址。该地址上的资产会在HECO链上进行1:1的铸造与流通。因此这部分资产中，<strong>只有在HECO链上huobi实际拥有的部分，才可以认为是huobi的资产，剩余部分均为用户资产</strong>。存在非平台用户的资产，但他自己说是冷热钱包中的部分主要资产储备。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a726c57d929656d2b5fbc1ad8af1f83876d31a6309ad7cce19581f5dae552763.png" alt="Huobi 在 HECO 链上资产情况" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Huobi 在 HECO 链上资产情况</figcaption></figure><p>我们对HECO链上，这3类资产的头部持仓地址进行分析，发现其中有8个地址可以关联为huobi地址，剩余均被我们认为是用户资产。其中：</p><ul><li><p>huobi关联地址的 BETH 占总发行量的 4.71%；</p></li><li><p>huobi关联地址的 USDT 占总发行量的 8.39%；</p></li><li><p>huobi关联地址的 ETH 占总发行量的 14.82%。</p></li></ul><p>因此，去除huobi关联地址后的超额计算资产共计 2.15 亿。 附录：</p><pre data-type="codeBlock" text="HECO链上的huobi交易所关联地址：
0xcee6de4290a4002de8712d16f8cfba03cb9afcf4 beth 4.71%
0x1d8c642891a10188290c58753d75828214967354 usdt 5.61%
0x74bcd3333c44120acf47a68bb8532f1be0eded2b usdt 1.59%
0x67221451121647e46dc691d7f2188f4c10e868dd usdt 1.18%
0xc9121e476155ebf0b794b7b351808af3787e727d hbtc 4.86%
0xee367ce9b18b1bd445909edac8eb0a6c33c10a51 hbtc 4.23%
0x69f8dc5c4d8f7da1ab241c19b8fbc202bd9a1f09 shib 0.29%
0xcee6de4290a4002de8712d16f8cfba03cb9afcf4 usdc 64.63% 
0x3dd223968c2acb1071dfb327cc0065a5fa4d4b15 eth  14.82%
"><code>HECO链上的huobi交易所关联地址：
<span class="hljs-number">0xcee6de4290a4002de8712d16f8cfba03cb9afcf4</span> beth <span class="hljs-number">4.71</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x1d8c642891a10188290c58753d75828214967354</span> usdt <span class="hljs-number">5.61</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x74bcd3333c44120acf47a68bb8532f1be0eded2b</span> usdt <span class="hljs-number">1.59</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x67221451121647e46dc691d7f2188f4c10e868dd</span> usdt <span class="hljs-number">1.18</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xc9121e476155ebf0b794b7b351808af3787e727d</span> hbtc <span class="hljs-number">4.86</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xee367ce9b18b1bd445909edac8eb0a6c33c10a51</span> hbtc <span class="hljs-number">4.23</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x69f8dc5c4d8f7da1ab241c19b8fbc202bd9a1f09</span> shib <span class="hljs-number">0</span><span class="hljs-number">.29</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xcee6de4290a4002de8712d16f8cfba03cb9afcf4</span> usdc <span class="hljs-number">64.63</span><span class="hljs-operator">%</span> 
<span class="hljs-number">0x3dd223968c2acb1071dfb327cc0065a5fa4d4b15</span> eth  <span class="hljs-number">14.82</span><span class="hljs-operator">%</span>
</code></pre><h3 id="h-34" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.4 风险提示</h3><p><strong>3.4.1 HT 看跌</strong></p><p>目前，HT Token已经完全开放流通，总流通量为203,980,445，其中超过93%的资产在Huobi的资产清单列表中。与此同时，当前Huobi市场上的全部买盘为1千万，占总流通量的5%，并且HT并没有在任何一家主流交易所上架，包括Binance、OKX、Bybit、Coinbase、Crypto.com。因此，一旦Huobi发生大规模挤兑或者其他威胁事件，市场不具备足够的深度来接收HT的抛压，因而会导致币价大幅跳水。这样的事情历史上也多次发生，例如FTX大规模挤兑时，FTT瞬间暴跌下跌90%，DCG大规模抛售资产时，FIL暴跌30%。</p><p><strong>3.4.2 BETH 看涨</strong></p><p>当前huobi发行的BETH已经与ETH的价格脱钩10%，实际上，huobi质押了足额的ETH在信标链上（详情3.2.1），因此在上海升级后，用户可以直接在平台上将BETH与ETH进行1:1的兑换。因此，脱钩现象很快会结束。Huobi ETH2质押活动的官网上对赎回代币也有说明。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c7802dfb7675d6c2ca8c1188c2163d84d4ec5c60a2770e3a20e0e93109ad82f2.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>敬请关注我们。</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/6130042b7d7c085bebffa3c39779a9423b0ce30a3c256b0dbe89d2582b64b383.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Deep Analysis of CEX Reserves-Huobi.com]]></title>
            <link>https://paragraph.com/@x-explore/deep-analysis-of-cex-reserves-huobi-com</link>
            <guid>CxBkw9UELpCQKf5uBkmx</guid>
            <pubDate>Thu, 19 Jan 2023 11:49:36 GMT</pubDate>
            <description><![CDATA[This article is a deep analysis of Huobi.com asset list. First, we reviewed the information about the events before and after the announcement of Huobi&apos;s asset list, and combed through the FUDs on Twitter about the asset list, including the questioning of the validity of BETH funds and the misappropriation, and questioning of a large number of ETH transfers. Then, we analyzed these FUDs based on the on-chain data, and these FUDs did not hold up. Finally, we evaluated the Huobi&apos;s ass...]]></description>
            <content:encoded><![CDATA[<p>This article is a deep analysis of Huobi.com asset list. First, we reviewed the information about the events before and after the announcement of Huobi&apos;s asset list, and combed through the FUDs on Twitter about the asset list, including the questioning of the validity of BETH funds and the misappropriation, and questioning of a large number of ETH transfers. Then, we analyzed these FUDs based on the on-chain data, and these FUDs did not hold up. Finally, we evaluated the Huobi&apos;s assets based on our Checklist and found that <strong>more than 50% assets(around $1.744 billion) with low liquidity, $215 million assets on the HECO chain is over-calculation, and $300 million TRX assets are Sun&apos;s personal assets.</strong> In general, a high proportion of illiquid assets is a significant risk. <strong>The actual assets at risk amounted to $1.84 billion, around 53% of the total published assets</strong>. In addition, we also gave our judgment on the market, with HT Token bearish and Huobi-issued BETH bullish.(Does not constitute investment advice)</p><p>——This article is jointly published by X-explore and WuBlockchain</p><h2 id="h-1-background" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. Background</h2><p>In early November, a mega bank run on the centralized exchange FTX occurred, with over $6 billion in assets withdrawn within 2 to 3 days, causing liquidity collapse and ultimately leading to FTX&apos;s bankruptcy. In order to prove that there was no misappropriation of user assets, exchanges have published lists of their own asset information and exposed the exchange&apos;s custody of the assets to the public. According to information from Nansen Portfolio statistics, 18 head exchanges have now published asset information. The list is available on the exchanges&apos; websites, CoinMarketCap (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://coinmarketcap.com/zh/exchanges/binance/#reserve">https://coinmarketcap.com/zh/exchanges/binance/#reserve</a>) and Nansen (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://portfolio.nansen.ai/entities">https://portfolio.nansen.ai/entities</a>). We can find detailed information, including addresses and asset amounts.</p><p>As the asset lists were disclosed to the public, the continuing bank run was stabilized. But there still remain doubts in the community. Due to <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/BlockBeatsAsia/status/1608762818802909186">Huobi&apos;s layoff, </a><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Sidd_0000123/status/1612293435779874816">the event of Altcoin Pi</a>, and the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/ArkQaq/status/1610988124393598976">event of rat trading</a>, the vibe of FUD has been intensified, including doubts about Huobi&apos;s asset list.</p><p>Therefore, we planned to conduct an objective analysis of each exchange&apos;s asset information list in order to rebuild confidence in the community. We made a CheckList analysis from three perspectives.</p><ol><li><p>Validity of Assets</p><ol><li><p>Assets with the correct balance</p></li><li><p>Assets with clear ownership</p></li><li><p>Assets originated from platform users</p></li></ol></li><li><p>Rationality of Assets</p><ol><li><p>Proportion of mainstream tokens</p></li><li><p>Proportion of illiquid tokens</p></li></ol></li><li><p>Utilization of Assets</p><ol><li><p>Not used for investments</p></li><li><p>Not linked to risky institutions</p></li></ol></li></ol><h2 id="h-huobi-on-chain-asset" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Huobi On Chain Asset</h2><h3 id="h-21-overview-of-huobis-asset" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.1 Overview of Huobi&apos;s Asset</h3><p>In early October 2022, About Capital Management acquired shares from Huobi&apos;s big shareholders. Justin Sun is the core contributor to this Merge and Acquisition fund, at a purchase price of $ 1 billion upwards (source: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mp.weixin.qq.com/s/oZY7MPfj3bTV55iZwNws-g">Wushuo Exclusive News</a>, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/justinsuntron/status/1591323854785622017">H.E. Justin Sun (@justinsuntron))</a>, with 100% margin reserve verification completed during the handover process.</p><p>on November 13, Huobi disclosed the hot and cold wallet addresses and asset reserves - <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.huobi.com/support/en-us/detail/24922606430831">Huobi&apos;s Work Report on Asset Transparency (I),</a> in which 32K BTC, 274K ETH, 820M USDT, and 9.7B TRX were announced, equivalent to 3.5B USD in total.</p><p>At the same time, in order to further rebuild users&apos; confidence and accelerate the process of asset transparency construction work, Huobi announced in Huobi&apos;s Work Report on Asset Transparency (I) that Huobi would cooperate with a third party to complete the 100% margin Merkle tree reserve proof and publicize it to the public within a month (two months already passed and Huobi has not fulfilled its promise until now...)</p><h3 id="h-22-community-fud" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.2 Community FUD</h3><p>Since the community continues to have doubts about the assets list, we collected the related information from Twitter and the information thus can be classified into three types.</p><p><strong>2.2.1 Question on the Validity of the BETH</strong></p><p>The public address <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xa929022c9107643515f5c777ce9a910f0d1e490c">0xa929022c9107643515f5c777ce9a910f0d1e490c</a> has 96,671 BETH. This address is the cross-chain bridge for the HECO chain issued by Huobi. However, no BETH assets are found in Etherscan (From Moc<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Btman_Jeff/status/1591630990153502720">@Btman_Jeff</a>). In addition, the address has only 22,278 ETH, which is not enough to create a 1:1 staking relationship with the announced amount of 96,671 BETH. (From DeFi小矿工<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/DeFi8362/status/1592837574791290880">@DeFi8362</a>).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1ac6cd7e156c60bccf225cda01c660e540e312dd1bcadebf9b98b300450ebd33.png" alt="Moc (@Btman_Jeff) had questioned that the corresponding number of BETH assets were not found at the disclosed address" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Moc (@Btman_Jeff) had questioned that the corresponding number of BETH assets were not found at the disclosed address</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ee7bdcf351944ddaca6efab20242237d046a6d543fa502736ae56678c8c38156.png" alt="DeFi小矿工(@DeFi8362)tweeted that disclosed address BETH and ETH 1:1 staking numbers is not corresponding" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">DeFi小矿工(@DeFi8362)tweeted that disclosed address BETH and ETH 1:1 staking numbers is not corresponding</figcaption></figure><p><strong>2.2.2 Question on the Misappropriation of Funds</strong></p><p>From the data on the chain, Binance holds $6.06 billion ETH and $108 million Beth, with a staking ratio of 0.017; Huobi holds $151 million ETH but $128 million HBeth, with a staking ratio of 0.85. That means a large part of Huobi users&apos; ETH is staked. The difference in behavior is nearly 50 times, so Huobi may have privately misappropriated customer funds to make pledges to earn revenue without user authorization (FROM BitRun<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/BitRunX/status/1612874061520179200">@BitRunX</a>).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/343eefffb48305410f4dbed9ef9783f114e2679b0b0a6f93bdc0fd7a36f2a664.png" alt="BitRun(@BitRunX)doubted that BETH&apos;s collateralized ETH assets have been misappropriated" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">BitRun(@BitRunX)doubted that BETH&apos;s collateralized ETH assets have been misappropriated</figcaption></figure><p><strong>2.2.3 Question on Clear Ownership?</strong></p><p>Before the Huobi snapshot (October 11), 175,000 ETH was deposited, and immediately after the Huobi snapshot (November 13), 10,000 ETH was withdrawn from the withdrawal address <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc..... .3Fc(Huobi 34)</a> and withdrew 10,000 ETH to Binance and OKX respectively. Probably the amount was temporarily moved from other places to fill the gap for the snapshot and returned after the snapshot (FROM Moc@Btman_Jeff).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/689a6f5636c2360cffa08ad1dfa92816de3266fd03e20c2da3e9bcb973527dbe.png" alt="Moc(@Btman_Jeff) questioned whether Huobi temporarily dispatches external funding for asset certification" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Moc(@Btman_Jeff) questioned whether Huobi temporarily dispatches external funding for asset certification</figcaption></figure><h2 id="h-3-x-explore-analysis" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. X-explore Analysis</h2><h3 id="h-31-checklist-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.1 CheckList Analysis</h3><p>Based on the CheckList, we analyzed Huobi&apos;s asset list: more than 50% of them are low-liquidity assets. $215 million HECO on-chain assets are over-calculated, and $300 million TRX assets are Sun&apos;s personal assets.</p><ol><li><p>Validity of Assets</p><ol><li><p>Assets with the correct balance</p><ol><li><p>Existence of pledged assets worth $215 million HECO chain over-calculated (refer to 3.3.3)</p></li></ol></li><li><p>Assets with clear ownership ✅</p></li><li><p>Assets originated from platform users</p><ol><li><p>Existence of $300 million worth of TRX chain assets is not relevant to Huobi users (refer to 3.3.2)</p></li></ol></li></ol></li><li><p>Rationality of Assets</p><ol><li><p>Proportion of mainstream tokens, valued at $1.675 Billion ($550 million BTC, $226 million ETH, $816 million USDT, $60.04 million USDC, $20.32 million XRP）</p></li><li><p>Proportion of illiquid tokens, valued at $1.744 Billion ($1 billion HT, $0.98 billion XCN, $530 million TRX, $116 million BETH)</p></li></ol></li><li><p>Utilization of Assets</p><ol><li><p>No use for investments✅</p></li><li><p>No link to risky institutions✅</p></li></ol></li></ol><h3 id="h-32-community-fud-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.2 Community FUD Analysis</h3><p><strong>3.2.1 BETH Validity of Assets &amp; Misappropriate Funds</strong></p><p>BETH&apos;s capital reserve is real and valid, and the anchor assets are about $116 million in the beacon chain. In the asset list published by Huobi, the address <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xa929022c9107643515f5c777ce9a910f0d1e490c">0xa92......490c</a> (cross-chain bridge of HECO chain) has assets of 96,671 BETH on ETH chain, and the information from the official website shows that its collateralized ETH has been pledged to the Ether 2.0 beacon chain.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5f2b1c92a84fe7be68006d6fe6c764a437ebd237cb4700b27c356cb657407266.png" alt="Huobi website BETH staking info" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Huobi website BETH staking info</figcaption></figure><p>From the on-chain data, we found that two addresses closely associated with Huobi were heavily involved in beacon chain pledges, with a total pledge amount of 91,552 ETH, very close to the published BETH asset count.</p><ol><li><p>The source of funds is Huobi&apos;s address 0xB73f4d4E99F65Ec4B16B684e44f81Aeca5ba2B7C the gradual accumulation of pledges in the beacon chain from December 2020 51776 ETH</p></li><li><p>The source of funds is Huobi&apos;s address 0x194BD70B59491ce1310ea0BCeAbdb6c23aC9D5b2 Gradual accumulation of pledges in the beacon chain from December 2020 39776 ETH</p></li></ol><p>After the upgrade in Shanghai, this pledged ETH will be available for withdrawal when the Ether 2.0 beacon chain pledged ETH is open for withdrawal. Therefore, the fund reserve of BETH is real and valid. The answer to Twitter users&apos; questions about BETH without a pledge and questions about Huobi&apos;s misappropriation of BETH pledge funds is clear.</p><p><strong>3.2.2 ETH Assets Clear Ownership</strong></p><p>Address <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc......3Fc(Huobi 34)</a> Before Oct 11, the large amount of deposit is Huobi transferring 169,000 ETH from a multi-signature wallet, the source of funds is Huobi out of the money bag, combined with the time node of Sun&apos;s acquisition of Huobi can be learned, should be acquired and the asset finishing（<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0xce60b7d010e85ca4c689b848ed23b0d20cfe1918819eb7770c5be8d916b6f0bb">transaction info</a>).</p><p>Address <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0xcac725bef4f114f728cbcfd744a731c2a463c3fc">0xCAc......3Fc(Huobi 34)</a> the 10,000 ETH withdrawal after the snapshot is not external funds dispatched for the snapshot. Officials say this behavior is the personal behavior of large investors. The platform does not have restrictions.</p><p>The 10,000 ETH withdrawal after the snapshot is not external funds dispatched for the snapshot. Officials say this behavior is the personal behavior of large investors. The platform does not have restrictions.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/28eb30142d5b8ce5f1b21b5332067b0640e9e3afef98954d6353412c76f54410.png" alt="Huobi&apos;s 10000 ETH OUT" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Huobi&apos;s 10000 ETH OUT</figcaption></figure><p>The incident occurred at the time of the FTX crash, and Huobi was seeing nearly 20k ETH transfers daily. If the official response is true, it is reasonable in terms of the amount.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9fd391c9bfcb8fbaf4f59ca18bc5b66c4bcf838df62db4ad8cf89c61df54b82b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-33-risk-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.3 Risk Analysis</h3><p><strong>3.3.1 Too Much Share of Low Liquidity Tokens（50.4%)</strong></p><p>Low liquidity token valued at $1.744 billion ($1 billion HT, $0.98 billion XCN, $530 million TRX, $116 million BETH)</p><ul><li><p>HT is the platform coin issued by Huobi. The total number of tokens is currently 204 million HT, and according to Huobi&apos;s published data, the market circulation is 162 million HT. The current address holdings on Huobi&apos;s published asset list are 191 million HT, far exceeding the market circulation and reaching 94% of the total number of tokens. Liquidity is insufficient.</p></li><li><p>XCN is a small-cap Token, and Huobi currently holds more than 9% of the total circulation of this coin (1.94 billion held by Huobi, 21.4 billion in total circulation), with low liquidity.</p></li><li><p>TRX is the native Token of TRON chain, Huobi currently holds more than 10% of the total circulation of this coin (9.7 billion held by Huobi, 91.8 billion in total circulation), with low liquidity.</p></li><li><p>BETH is a staked-locked Token, which must be upgraded in Shanghai by Ethernet before users can withdraw the Token, and thus the Token is not currently circulating.</p></li></ul><p>The following is a comparison of other exchanges&apos; holdings in mainstream assets as well as in these few less liquid assets.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6a92ac49eb76e0d04e5fbc36881897c4ab8def87d9ff09534ef74830a5d8dd01.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As can be seen from the table above, Huobi holds a much higher percentage of these low-liquidity coins than its peers. Referring to the huge drop in FTT prices in the FTX event, when a bank run occurs on the exchange, the market does not have enough depth to receive the sell-off of low liquidity coins, thus leading to a significant drop in the price of these coins and thus triggering a significant drawdown of platform funds.</p><p><strong>3.3.2 $300 million TRX chain assets are not related to Huobi users</strong></p><p>In the list of assets published by Huobi, a total of 13 addresses on the TRX chain are listed, totaling 9.7 billion TRX, of which 6 addresses accumulating 5.4 billion TRX (about $300 million USD) are not related to Huobi users, and are TRX airdropped when the TRX chain was launched, suspected to be Justin Sun&apos;s personal assets.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b601e8c0324c1546586ef39330ea95e87ea914c0200e834319d6c5feb8175fe6.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As shown above, we performed an on-chain trace. Six of the addresses in the asset list received transfers from the Coin Hot Wallet accumulating $5.4 billion TRX on May 26, May 30 to June 4, and June 15, 2022.</p><p>Meanwhile, on May 24, May 29, and May 30, 2022, a certain Coin user&apos;s deposit address received cumulative transfers of 12.3 billion TRX. These funds all came directly from TRX, which was suspected to have been airdropped on Justin Sun&apos;s personal address when the TRX chain went live in June 2018.</p><p>In the first 20 days of May 2022, Binance&apos;s average daily deposits and withdrawals were about $500 million TRX. However, deposits were 2.7 billion on May 24 and 8.4 billion on May 30. In terms of withdrawals, 1.6 billion were made on May 26, 4 billion on May 30, 3.1 billion on June 1, and 2 billion on June 2. Therefore, we can directly correlate the large deposits and withdrawals in late May, and thus speculate that the 5.4 billion TRX in the asset list published by Huobi is suspected to be Justin Sun&apos;s personal assets.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9099c87abdd7214533bed24adab3fddebc43a50fc14fa1ded8cde1e912168be7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>地址清单：</p><pre data-type="codeBlock" text="Huobi asset reserves announced addresses：
TF2fmSbg5HAD34KPUH7WtWCxxvgXHohzYM
TYh6mgoMNZTCsgpYHBz7gttEfrQmDMABub
TKgD8Qnx9Zw3DNvG6o83PkufnMbtEXis4T
THZovMcKoZaV9zzFTWteQYd2f3NEvnzxAM
TZ1SsapyhKNWaVLca6P2qgVzkHTdk6nkXa
TRSXRWudzfzY4jH7AaMowdMNUXDkHisbcd

Binance Hot Wallet
TV6MuMXfmLbBqPZvBHdwFsDnQeVfnmiuSi

Binance Deposit Address
TJkgTCg91dEfsT9to74VDXi7uUxRDqF2ft

Suspicious Justin Sun Own Addresses
TSnjgPDQfuxx72iaPy82v3T8HrsN4GVJzW
TGqxgpMFfvUcpC2R4JccY1t6oFe8WfTQGT
TTNaP9JFf2MvCs1jJUVH8Eh5tiD8Cg8aC2
"><code>Huobi asset reserves announced addresses：
TF2fmSbg5HAD34KPUH7WtWCxxvgXHohzYM
TYh6mgoMNZTCsgpYHBz7gttEfrQmDMABub
TKgD8Qnx9Zw3DNvG6o83PkufnMbtEXis4T
THZovMcKoZaV9zzFTWteQYd2f3NEvnzxAM
TZ1SsapyhKNWaVLca6P2qgVzkHTdk6nkXa
TRSXRWudzfzY4jH7AaMowdMNUXDkHisbcd

Binance Hot Wallet
TV6MuMXfmLbBqPZvBHdwFsDnQeVfnmiuSi

Binance Deposit <span class="hljs-selector-tag">Address</span>
TJkgTCg91dEfsT9to74VDXi7uUxRDqF2ft

Suspicious Justin Sun Own Addresses
TSnjgPDQfuxx72iaPy82v3T8HrsN4GVJzW
TGqxgpMFfvUcpC2R4JccY1t6oFe8WfTQGT
TTNaP9JFf2MvCs1jJUVH8Eh5tiD8Cg8aC2
</code></pre><p><strong>3.3.3 HECO chain staked assets over-calculated by $215 million</strong></p><p>Included in the list of assets published by Huobi is the address 0xa929022c9107643515f5c777ce9a910f0d1e490c A total of $236 million assets on the ETH chain. This address is the staked address for assets (including USDT, ETH, BETH) on the HECO chain collateralized ETH chain. The assets on this address are minted and circulated 1:1 on the HECO chain. Therefore, only the portion of this asset that is actually owned by Huobi on the HECO chain can be considered Huobi&apos;s asset, and the remainder is all user assets. Assets of non-platform users exist, but he himself says that they are part of the main asset reserve in the hot and cold wallets.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8033992e56dc4ce0ba6abbffe95cb5cb613cc12e45ffaa22c88c73d01fb06fc2.png" alt="Huobi&apos;s assets info on HECO chain" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Huobi&apos;s assets info on HECO chain</figcaption></figure><p>We analyzed the top holding addresses of these 3 types of assets on the HECO chain and found that 8 of them can be associated as Huobi addresses and the rest are all considered by us as user assets. Including:</p><ul><li><p>BETH for Huobi-associated addresses accounted for 4.71% of the total issuance</p></li><li><p>USDT for Huobi-associated addresses accounted for 8.39% of the total issue volume.</p></li><li><p>The ETH of Huobi-associated addresses accounts for 14.82% of the total issue volume.</p></li></ul><p>Therefore, the total over-calculated assets after removing Huobi-affiliated addresses are $215 million. Appendix：</p><pre data-type="codeBlock" text="linked to Huobi addresses on HECO chain：
0xcee6de4290a4002de8712d16f8cfba03cb9afcf4 beth 4.71%
0x1d8c642891a10188290c58753d75828214967354 usdt 5.61%
0x74bcd3333c44120acf47a68bb8532f1be0eded2b usdt 1.59%
0x67221451121647e46dc691d7f2188f4c10e868dd usdt 1.18%
0xc9121e476155ebf0b794b7b351808af3787e727d hbtc 4.86%
0xee367ce9b18b1bd445909edac8eb0a6c33c10a51 hbtc 4.23%
0x69f8dc5c4d8f7da1ab241c19b8fbc202bd9a1f09 shib 0.29%
0xcee6de4290a4002de8712d16f8cfba03cb9afcf4 usdc 64.63% 
0x3dd223968c2acb1071dfb327cc0065a5fa4d4b15 eth  14.82%
"><code>linked to Huobi addresses on HECO chain：
<span class="hljs-number">0xcee6de4290a4002de8712d16f8cfba03cb9afcf4</span> beth <span class="hljs-number">4.71</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x1d8c642891a10188290c58753d75828214967354</span> usdt <span class="hljs-number">5.61</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x74bcd3333c44120acf47a68bb8532f1be0eded2b</span> usdt <span class="hljs-number">1.59</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x67221451121647e46dc691d7f2188f4c10e868dd</span> usdt <span class="hljs-number">1.18</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xc9121e476155ebf0b794b7b351808af3787e727d</span> hbtc <span class="hljs-number">4.86</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xee367ce9b18b1bd445909edac8eb0a6c33c10a51</span> hbtc <span class="hljs-number">4.23</span><span class="hljs-operator">%</span>
<span class="hljs-number">0x69f8dc5c4d8f7da1ab241c19b8fbc202bd9a1f09</span> shib <span class="hljs-number">0</span><span class="hljs-number">.29</span><span class="hljs-operator">%</span>
<span class="hljs-number">0xcee6de4290a4002de8712d16f8cfba03cb9afcf4</span> usdc <span class="hljs-number">64.63</span><span class="hljs-operator">%</span> 
<span class="hljs-number">0x3dd223968c2acb1071dfb327cc0065a5fa4d4b15</span> eth  <span class="hljs-number">14.82</span><span class="hljs-operator">%</span>
</code></pre><h3 id="h-34-risk-reminder" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.4 Risk Reminder</h3><p><strong>3.4.1 HT Bearish</strong></p><p>Currently, HT Token is fully open for circulation with a total liquidity of 203,980,445, of which over 93% of the assets are in Huobi&apos;s asset list. At the same time, the current full buy order on the Huobi market is $10 million, or 5% of total liquidity, and HT is not listed on any of the major exchanges, including Binance, OKX, Bybit, Coinbase, Crypto.com. Therefore, in the event of a bank run or other threatening event on Huobi, the market does not have sufficient depth to receive the HT sell-off, thus causing the coin price to dive significantly. This has happened many times in history. For example, FTT plunged 90% in a bank run on FTX, and FIL plunged 30% in a massive sell-off of assets by DCG.</p><p><strong>3.4.2 BETH Bullish</strong></p><p>The current BETH issued by Huobi has been decoupled from the price of ETH by 10%. In fact, Huobi staked a full amount of ETH on the beacon chain (details 3.2.1), so after the Shanghai Upgrade, users can exchange BETH to ETH 1:1 directly on the platform. Therefore, the decoupling phenomenon will end soon. The <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.huobi.com/en-us/staking/eth2/">official website of Huobi ETH2</a> staked campaign also has instructions for redeeming tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c7802dfb7675d6c2ca8c1188c2163d84d4ec5c60a2770e3a20e0e93109ad82f2.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For more, please follow x-explore:</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/6130042b7d7c085bebffa3c39779a9423b0ce30a3c256b0dbe89d2582b64b383.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[假币盛行：月入百万不是梦]]></title>
            <link>https://paragraph.com/@x-explore/O0KsgR1JxCjfAMpQ4gtH</link>
            <guid>O0KsgR1JxCjfAMpQ4gtH</guid>
            <pubDate>Fri, 13 Jan 2023 11:06:15 GMT</pubDate>
            <description><![CDATA[——本文由 X-explore 与吴说区块链联合发布。 摘要： 链上每天有少则几百，多则上千的ERC20 Token被创建，这其中混杂着超过15%的假币合约（我们将短时间之内快速创建、吸引正常用户购买并结束整个生命周期的代币称为假币）。基于链上数据分析，发行假币的每日盈利可达 22.4 ETH。 本文对假币产业深入挖掘，揭示黑产团伙的假币盈利流程，分析2022年假币态势，最后案例分析黑产团伙手法升级的演变过程。作为黑产行业揭秘的一部分，希望Web3用户更加提高警惕。什么是链上假币链上每天都有几百个新的erc20 token被创建，其中包括：项目方发行的价值Token：这些Token经过较为严格的审计后，会被收录在CoinMarketCap以及CoinGecko中。后期，还会在中心化交易所上架交易。测试Token：有很多合约的创建者都是正在学习写合约，或者正在测试合约部署。广告Token：一些平台，比如赌博平台会将URL作为Token名称，分发给链上用户。起到广告宣传的效果。假币Token：我们将短时间之内快速创建、吸引正常用户购买并结束整个生命周期的代币称为假币。链上假币Toke...]]></description>
            <content:encoded><![CDATA[<p>——本文由 X-explore 与吴说区块链联合发布。</p><p><strong>摘要：</strong></p><p>链上每天有少则几百，多则上千的ERC20 Token被创建，这其中混杂着超过15%的假币合约（我们将短时间之内快速创建、吸引正常用户购买并结束整个生命周期的代币称为假币）。基于链上数据分析，发行假币的每日盈利可达 22.4 ETH。</p><p>本文对假币产业深入挖掘，揭示黑产团伙的假币盈利流程，分析2022年假币态势，最后案例分析黑产团伙手法升级的演变过程。作为黑产行业揭秘的一部分，希望Web3用户更加提高警惕。</p><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">什么是链上假币</h2><p>链上每天都有几百个新的erc20 token被创建，其中包括：</p><ol><li><p><strong>项目方发行的价值Token</strong>：这些Token经过较为严格的审计后，会被收录在CoinMarketCap以及CoinGecko中。后期，还会在中心化交易所上架交易。</p></li><li><p><strong>测试Token</strong>：有很多合约的创建者都是正在学习写合约，或者正在测试合约部署。</p></li><li><p><strong>广告Token</strong>：一些平台，比如赌博平台会将URL作为Token名称，分发给链上用户。起到广告宣传的效果。</p></li><li><p><strong>假币Token</strong>：我们将短时间之内快速创建、吸引正常用户购买并结束整个生命周期的代币称为假币。</p></li></ol><p>链上假币Token被赋予的使命只有一个，收割链上用户，这种假币往往寿命很短，存活几天到几十分钟的都有，它会伪装成一个真币，厉害点的会碰瓷某个项目，之后由创建者隐藏在背后画线，创造出币价持续走高的k线图，吸引链上用户资金流入，最终币价会在所有人都等着继续升值的时候瞬间归零。 由于链上存在很多喜欢买高潜力新币的用户以及跟单巨鲸的用户，造假团伙就会朝着这方面去努力营造假象。比如用多个小号反复和池子交易以拉升价格；或者碰瓷某个项目方，误导不知情用户；亦或者合约内定义虚假事件，营造出各大交易所、V神、孙宇晨等巨鲸地址都在购买假币的假象。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b39ce10da07b2fb969fd47c19a4f0ac6f375691d38194261050596c2ffcaa2d1.png" alt="假币完整生命周期" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">假币完整生命周期</figcaption></figure><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">假币盈利流程</h2><p>我们对假币完整生命周期进行了分析，在吸引用户资金的手段、收割方式、资金流转方式方面进行了总结和分类。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f4396134a93019a732ec575755f6d64765d4d6b820b3f33e7d1d03074ce0c688.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>（*EOA: Externally Owned Accounts 外部账户；*CA: Contact Account 合约账户）</p><p>各流程详细说明如下：</p><ol><li><p>假币团伙将部分资金转入一个新的EOA账户，作为之后的gas费和创建流动性的资产</p></li><li><p>使用EOA账户完成假币CA的创建，同时给部分指定用户 mint 假币，合约中可能还隐藏着假币常有的功能，如貔貅、假空投等</p></li><li><p>假币团伙使用EOA将假币和另一个有价值的币（通常是WETH）在uniswap创建流动性池，以使假币产生价值</p></li><li><p>假币团伙使用一些手段达到吸引用户资金的目的（下文介绍）</p></li><li><p>假币团伙使用收割资金的方式完成获利（下文介绍）</p></li><li><p>假币团伙将收割到的资金洗白提到混币器或交易所，或者资金流转进入下一轮假币循环（下文介绍）</p></li></ol><p>其中，④吸引用户资金的手段、⑤收割方式、⑥资金流转方式的详细分类如下：</p><h3 id="h-1" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. 吸引用户资金的手段分类：</h3><p><strong>1.1 哄抬币价</strong></p><p>假币团伙会通过刷量方式将假币的价格营造出币价持续走高的大好趋势，以此吸引不知情用户。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7f6780f64b4e4c81f66a4351bdd46e517df579cda60738fdf1da28fa6185ef05.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>以上图中的Layer代币为例，分析所有购买代币的用户交易次数与金额，可以看出大部分的交易贡献都来自用户<code>0xaecf2954a6c49e99e570dfaaa857c53e17a88027</code> ，该用户购买代币38次（占总交易次数的60%），金额达到41 ETH（占总交易额的90.1%）。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bc20be1f6c91f50706bd87fd5fdc6587f23c8efafff2bd334d03223510894464.png" alt="  图中为该币种所有购买代币的交易数量与金额分析" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">  图中为该币种所有购买代币的交易数量与金额分析</figcaption></figure><p>从资金来源看，假币创建者的资金来源是token刷量的用户0xae……27；从资金去向来看刷量用户刷量41 ETH后剩下的9 ETH直接Transfer给了假币创建者。可以肯定该地址与假币创建者属于同人身份，币价上升的趋势为该团伙主动操盘。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3326153a7f07c876aaf3a7b1a7ee92c26f85df5325363a3365eff45c54436dbc.png" alt="  假币创建者资金来源为token刷量的用户地址" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">  假币创建者资金来源为token刷量的用户地址</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e19c94f0dfb534d085b61c521c3acc9c04a5d5b8b1db18404c1d87f6f3e37699.png" alt="  刷量用户将剩下资金直接转账给假币创建者" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">  刷量用户将剩下资金直接转账给假币创建者</figcaption></figure><p><strong>1.2 热点话题</strong></p><p>假币团伙会根据最近网上的热点话题，发行对应的假的项目代币，以此增加假币的可信度或直接项目碰瓷，甚至于夸张点说只需要看看每天发行的假币名字就能了解到时下流行的新闻。根据我们的统计，近几个月仅仅是关于 FIFA 的假币就有不下于66个。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d2adb740b653c004c9b8a808000f772ab9af9d7f89417970fe87ea9d646af202.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>1.3 虚假转账</strong></p><p>假币团伙会通过虚假事件给大量巨鲸地址转账，<strong>这种转账不会真正的转移token给用户，只是会在区块链浏览器中记录下转账的Logs，实际上并没有完成token转移的操作</strong>。以此来欺骗一些跟单巨鲸的用户，以及试图让该假币可信度再次提升。</p><p>比如<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0x518a1c329d6077b7c70182e39755988a4068cb56f9f6e04f0f9854ad97030fca">这笔交易</a>，就是很典型的假空投，欺骗浏览器而制造假的erc20转账记录。假币团伙伪造了与项目方LayerZero名字相同的代币，并在交易日志伪造了Stargate Finance合约部署者给500个链上巨鲸空投的假象，被空投的巨鲸包括了Binance、Kucoin、FTX等交易所地址，会让链上用户误以为这些交易所即将上架这些代币。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/17af5515d63ca86a03a56210a37968305a6a59f37660b6534f3645cae1970a85.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ab8cbfb689a92bce25d05d6386aaae3a20ad3993129d6c2341b623010ce2976d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>从这笔交易提交的参数可以看出，发送方和接收方都是该团伙随意指定的交易双方，随时可以构造假的交易事件来误导链上用户和链上监控者的交易决策。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dc070fea5711bc0472100ef3ae53a01a65d4e6e76deafe473b25aee5a636e590.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>在token合约airdrop()函数里得知，该函数仅仅是循环并记录了500个转账事件，并没有实际的token转移。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e8d07a9d860233af7e4aec8d48a794c631fc16ab8376d40517ec026a362b992d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>然而正常的转账逻辑应该是是 <strong>减少发送者的 balance -&gt; 增加接收者的 balance -&gt; Transfer 记录事件。</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b8b6848a04170340624e49f3e52285c5c3eca0342af5696c98ff5c641bde8332.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. 收割方式分类：</h3><p>当假币团伙吸引到了用户资金进入池子后，会通过各种方式阻挠用户资金离场，包括快速收割使用户来不及卖掉、或者在合约中定义了“用户买完就不让再次交易”的逻辑、或者百分之一百的代币手续费、或者买完就被拉入代币黑名单、还有更离谱的是代币创建者监控买币用户，然后主动调用合约将用户手里的代币燃烧掉……。之后就是收割池子里的资金了。</p><p><strong>2.1 删除流动性</strong></p><p>假币创建者可以随时在 Uniswap 上为假币添加流动性（创建交易对，向池子支付两种代币）、删除流动性，而不需要经过任何审计或许可，这就直接导致了创建者可以为任何代币添加流动性，包括假币。而创建者也有权撤销池子流动性以拿回所有的两种代币，所以很多假币会在交易对中代币价值价值最高的时候以 owner 身份删除流动性从而拿到池子里的所有代币，完成对用户资金的收割。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/437e9055c517a618ff5f53425dd4817803050b80d3da817f4ea52c2c3a55d23c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a6570eda073978a5e1b788ccf24e5b1df8133e993bad673f30642a2c3143b150.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3d77604dd9a84df22f5544034a466f18bf86036cd59cd788508b5a959c271be7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>2.2 砸盘</strong></p><p>假币创建者掌握着假币的最高权限，可以随时 mint 大量假币，也可以用创建合约时发行给的大量假币将假币池子里的所有的另一种有价值的代币瞬间抽空，而与删除流动性不同的是，此时池子里会有大量的假币和极少的另一种 token，而创建者手里的权限可以保证他在未来能够反复收割。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3e968ae45f4c871b774265c1223204bb2881fa3215e9442e12955defa833938c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9c97424b7baa75206936cfce2b2213c53cc7712b7409b871ea554848f7c4e560.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. 资金流转方式分类：</h3><p>资金流转技术逐渐提升并加以混用，会使得其他人的溯源与追踪工作难以进行，能够很大程度的避免其他人注意，使自己闷声发大财。</p><p><strong>3.1 直接转账</strong></p><p>直接进行eth的转账是最粗糙的方式，是该团伙最初的资金流转方式，代表该团伙一开始最简陋但最方便的技术手段。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8df79da844ab9cb0f0892a47c618a36076690032954a9126cb683c672a2336af.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>3.2 通过 1inch 转账</strong></p><p>在这个阶段，该团伙使用 1inch 的 swap 功能将造假币赢得的 WETH 置换为 ETH，并直接发送给另一个新地址。将资金的流转隐藏到与1inche的 swap 交互中，这种交易较为不易追踪。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8c7fb939c6db6f9802870d45e4f21961b85b7bdcfed78ac69b32779e525474aa.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>3.3 通过 uniswap 转账</strong></p><p>该团伙将资金流转融入到正常的swap中（该团伙使用持有大量假币的地址，到交易对池子中砸盘，将获利的 WETH 直接出到新地址，为下一次发假币做准备），从而在 etherscan 交易列表里隐藏了大额的 WETH 的交易。在上游地址的交易列表只能看到大额假币流入 uniswap，这种方式较难追踪。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dca79fcbeb35a1865848a64eac6b4b0a741f49599e925afef923376905f9545b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">假币发行以及盈利的态势分析</h2><h3 id="h-1" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. 假币发行情况</h3><p>我们基于链上行为筛选出了最置信的假币名单，发现每日发行假币的占比在15%左右。</p><p>从近几个月ETH链上新币中假币的占比可以看出，近半年来每日创建的新币数量和假币数量均呈上升趋势，在2022年10月24日左右达到巅峰水平，单日新增 token 757个，其中130个是假币；11月之后每日新币与假币数量逐渐趋于稳定，单日新增 token 在300个左右，假币在31个左右。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6765033e925ff9573434c061d7a2f062ae70115d2945d8c734b3dcd2315763b3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. 盈利情况</h3><p>我们计算了买币的用户损失情况（同等于假币团伙每天的盈利），如图用户损失资金全部为假币团伙盈利，近8个月平均每天链上假币团伙收益为22.4 ETH。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/82cea4c09bbb5728c7185eac7788f41538ab7a08f034de8f470da5c6bd8cad9a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. 黑产分析</h3><p>从各地址发假币数量的占比可以看出大部分的假币创建行为都是用新地址完成的，盈利之后资金流转到下个地址，开始下一轮发假币的收割行为。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/62bcb3f01e301ddc35d27a82a4171a9468dfdb685c198752689489270a44253b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ce6b1f6612a1f9381b32b54c47cb2ee1e1cb4399bba015a5b9a5390599ec1070.png" alt="发假币数量最多的地址名单top10" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">发假币数量最多的地址名单top10</figcaption></figure><p><strong>平均每个假币池子的成本是3.4 ETH，平均每天有31个假币诞生，平均每个假币盈利0.72 ETH，大部分假币都是当天完成对用户的收割。</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8389b078e7cdf50e5aeaf8219aaaa9e348927260971664821e05e5e2631b9089.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-4" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. 购买者分析</h3><p>假币购买者当中MEV与普通用户的交易占比是1:9，平均每个假币交易对池子MEV bot发起0.79个交易，正常用户发起6.8个交易。（MEV bot是指通过更改区块中的交易顺序，以此在正常链上交易中套利的机器人）</p><p>在盈利方面MEV盈利概率远大于普通用户，购买假币的MEV几乎百分百能盈利，而正常用户用户大部分都会亏钱（75%）。少量能挣钱的正常用户是因为买卖操作非常迅速，在假币团伙还没来得及收割前就已经卖出了假币。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5876c056fba8efc88940c534dc44a39229f1b6736367eb13195ce0580c4ca20c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>从正常用户购买假币的次数可以看出，大部分用户只购买过几次假币就停止了，购买假币次数为1-2次的用户占69.9%，购买假币次数为3-5次的用户占13.4%，应该是被收割之后变得小心了，其余的用户是冲新币用户，曾经或现在以冲土狗获得收益为乐。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8aedb8e319e7dd0286e559071c28aa95f394ffb851856a5f3de80a62254ef1d3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>最后，以一个<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x80021a58606cb6722b789a558f5d2d1ff623fe50">冲土狗用户的交易历史</a>来分析该用户的心路历程，他在假币上至少损失了11 ETH。可以发现该用户在2022年5月前冲土狗比较频繁，回报盈利也相当不错（多数盈利在10倍左右，例如该用户曾从 JPG 池子里获得了2 ETH的利润）。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/272264c3ee5a844827ee8d3b60253150fb04a39290b8f43221894b738508c345.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4e2c63a86b4b9e3e9243a6b292b7d171413dc496d4ba10049d386b043e309b5a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>直到市场转熊之后，假币也多了起来，冲了5个token其中4个都是假币，但赚到一笔依旧回本（盈利：1.1 ETH，亏损：0.13 ETH）。但几个月后该用户又一次没禁得住诱惑，自认为找到一个优质token之后，像其他上当用户一样投入了大量ETH，仅一分钟后就被假币团伙收割资金。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a0d9c9b24beee6a7c2cf829763c3b7c59132ede75347d466dad1b16364569386.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c93c6dca1a11a45bb3c3590919b54d27f12265fd5d3a7384d81c58b9a3a4abdb.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">假币发行技术升级</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3bdff9d66fab18554aff4f533376a8ddc2583113f1cecb57716dd32ae21e8fb8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-1" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. 常规流程</h3><p>最普遍的假币创建方式，在uniswap v2 执行add_Liquidity()函数创建假币与WETH的交易对并添加流动性，之后通过执行remove_Liquidity()函数删除流动性来完成用户资金收割。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9cdd39ff226a7f3aae288824d6bc2dac520991a63b52dd9d630d0ddf729d7058.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>以创建者 0xF6F2E5E9EFa7582deD9a4ebb2ffc333a59C30d4D 的操作记录为例，首先创建token合约，然后用刚创建的token和20 ETH 创建了一个uniswap v2的交易对。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/998b79c0cd5f683747ee4f28a530c931f4c62fce57a5d6bfb8356c07d76a6367.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>之后就用小号去swap把控价格吸引用户入场，以下是该团伙其中一个小号的交易记录，可以看到这些交易全都是用ETH买假币的刷量交易。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/71044adb203e5f4ada953bc636a373887c15779ce76d98855f67b94af013770d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>创建者会监控买币的真正用户，然后调用代币内的submit()函数burn掉用户的token余额，防止用户套利离场。最后创建者就删除流动性，转移从池子获得的所有资金（这部分资金包括：创建池子的本金+小号wash trading投入+真实买币用户亏损）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1d5b4c68ab8fb7a4173584edbb058a6c25c035411550589fdfdf5af85c03f537.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3db95529a97c27c18252a50248f3d843a2981f4216883d386f824c4d432752bf.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. 套现升级</h3><p>收割时使用更加隐蔽的砸盘，通过小号用大量的假币把用户资金WETH从池子里置换出来。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7ce1263d02185349097c8ec141f9bc2265e208303567b39e298d00118976eb49.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>例如交易对<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x17d786f0f689e1b121ad38c2fbd6e27d4bdcb407#tokentxns">uniswap v2: OASYS 2</a>，假币团伙通过小号用大量假币去砸盘，置换出60 ETH。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/42d3c679e9262d4aa97ea53e12fba41a9edb39e2c829cfaf9fe559fbabaaadce.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. 创建交易对升级</h3><p>在创建交易对时不直接调用add_Liquidity()函数，而将这一步操作编码在假币合约构造函数中，在假币被创建的时候，交易对便自动创建了。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c76cd11226ac3f5c0cc55a2e7feb45cc514a7272c3119de431c88b8febfa0e79.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>比如 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x3dd64863a9381715a66dfb76b7059698b841ff5e#code">BIYC</a> 这个token就是在创建时就调用了uniswap v2的工厂合约进行了交易对创建。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f22fb4def058bdedf0da2a2159906111efc1db4b11f9632b6be7680f40cb6f44.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-4" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. 币对升级</h3><p>交易对不再局限于假币与WETH之间，而使有价值的币都可以替换WETH实现套利。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b28729b70aada002b61b33a50d13a120c293121aa1496fecf391d79666fc6431.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>以下<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0x6a520175b09b2bbd5bc5470d229bbf93c5eef6abbe1e534eef8f0843a4dec748">这笔交易</a>就是假币与USDC一起形成的交易对</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9faf9670d64ea565944e7dc46a6268a07815e59c1b05365868157a978b0ce9f7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-5-router" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. router 升级</h3><p>虽然 uniswap v2 更普及，但假币也能拓展到uniswap v3以及其他无需审核的dex，当前假币都是通过v2的工厂合约创建。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d714dc431c905a65efaa3c403926d9a5b7a5302a6a3fbe7d1fd960219d33a6dc.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>敬请关注我们。</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/f0c01521479418a7e015f27f63c2994b896cb0242b106214df5b6290b1cd54bd.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Fake Token Trendy: The Next Millionaire is You]]></title>
            <link>https://paragraph.com/@x-explore/fake-token-trendy-the-next-millionaire-is-you</link>
            <guid>MwWclZyIIHb6iooRtyhf</guid>
            <pubDate>Fri, 13 Jan 2023 11:04:46 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. Abstract: Hundreds of ERC20 tokens are created daily, but more than 15% are fake tokens (we define fake tokens that are created quickly in a short period of time, attract ordinary users to buy them and end their entire life cycle). Based on our on-chain analysis, the daily profit from the fake tokens can reach 22.4 ETH. This article will be digging into the fake token industry, revealing the process of how the black groups are m...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p><strong>Abstract:</strong></p><p>Hundreds of ERC20 tokens are created daily, but more than 15% are fake tokens (we define fake tokens that are created quickly in a short period of time, attract ordinary users to buy them and end their entire life cycle). Based on our on-chain analysis, the daily profit from the fake tokens can reach 22.4 ETH.</p><p>This article will be digging into the fake token industry, revealing the process of how the black groups are making a profit, and analyzing the 2022 fake token trend. In the end, our teams study the evolution of the escalation of the black groups as a revelation and warning of the black industry and raise vigilance with Web3 users.</p><h2 id="h-what-is-a-fake-token" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What is a Fake Token?</h2><p>Hundreds of ERC20 tokens are created per day, including:</p><ol><li><p><strong>Valuable Token</strong>: These Tokens are included in CoinMarketCap and CoinGecko after a more rigorous audit. Later, they will also be listed on centralized exchanges.</p></li><li><p><strong>Test Token</strong>: There are many contract creators who are learning to write contracts or are testing contract deployments.</p></li><li><p><strong>Advertising Token</strong>: Some platforms, such as gambling platforms, will distribute URLs as Token names to users on the chain. It serves as an advertising effect.</p></li><li><p><strong>Fake Token:</strong> we define fake tokens that are created quickly in a short period of time, attract ordinary users to buy them and end their entire life cycle.</p></li></ol><p>Because there are so many users who love to purchase new tokens and follow the whales, the fake token groups will work towards this to create the illusion. For instance, using multiple alternate accounts to repeatedly trade with the pool to drive up the price; or getting some kind of relation with a certain project to mislead uninformed users; or defining fake events within the contract to create the illusion that major exchanges, Vitalik, Sun Yuchen and other whale addresses are buying fake tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b39ce10da07b2fb969fd47c19a4f0ac6f375691d38194261050596c2ffcaa2d1.png" alt="The Life Cycle of Fake Token" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">The Life Cycle of Fake Token</figcaption></figure><h2 id="h-the-profit-process-of-fake-token" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">The Profit Process of Fake Token</h2><p>We have analyzed the complete life cycle of a fake token, summarizing and classifying it in terms of the methods of attracting user funds, the exploited methods, and the flow of funds.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ef59dc3ef4aeb62b926b6731b748c3c863b84de3b95e818db5cd88772b9ce934.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>（*EOA: Externally Owned Accounts；*CA: Contact Account）</p><p>The detailed process is shown below：</p><ol><li><p>Fake token group transfers some of the funds to a new EOA account for the subsequent gas fee and the creation of liquid assets</p></li><li><p>Apply the EOA account to complete the process of creating of fake CA, while giving some of the designated users mint fake tokens, the contract may also be hidden in the fake token and often has features, such as honeypot token, fake airdrop</p></li><li><p>Fake token group uses EOA to create a liquidity pool of fake tokens and other valuable tokens (usually WETH) in Uniswap to make the fake tokens valuable</p></li><li><p>Fake token group uses a number of techniques to attract user funds (describe the following)</p></li><li><p>Fake token group uses the harvesting of funds to complete the profit (describe the following)</p></li><li><p>The fake token group launders the illicit funds to a mixer or exchange, or the funds flow into the next round of the new fake tokens (describe the following)</p></li></ol><p>Point 4 (methods of attracting user funds), point 5 (exploited methods) and point 6 (flow of funds) are highlighted and described as the following:</p><h3 id="h-1-methods-of-attracting-user-funds" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Methods of Attracting User Funds</h3><p><strong>1.1 Inflating the Coin Pirce</strong></p><p>The fake token group will create a great trend of continuously high coin prices by brushing up the volume, thus attracting uninformed users.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7f6780f64b4e4c81f66a4351bdd46e517df579cda60738fdf1da28fa6185ef05.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Taking the Layer token in the above chart as an example, by analyzing the number of transactions and amount of all users who purchased tokens, we can see that most of the transaction contributions came from user 0xaecf2954a6c49e99e570dfaaa857c53e17a88027 , who purchased tokens 38 times (60% of the total number of transactions) and the amount reached 41 ETH (90.1% of the total transaction amount).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bc20be1f6c91f50706bd87fd5fdc6587f23c8efafff2bd334d03223510894464.png" alt="Analysis of the number and amount of transactions of all bought tokens of this cryptocurrency" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Analysis of the number and amount of transactions of all bought tokens of this cryptocurrency</figcaption></figure><p>From the source of funds, the fake token creator&apos;s source of funds is token with wash-trading users 0xaecf2954a6c49e99e570dfaaa857c53e17a88027; From the destination of funds, the wash trading users laundered 41 ETH and the remaining 9 ETH directly transferred to the fake token creator. There is no doubt that the address and the fake token creator belong to the same identity, and the rising token price is the group&apos;s manipulation.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3326153a7f07c876aaf3a7b1a7ee92c26f85df5325363a3365eff45c54436dbc.png" alt="The fake coin creator is funded by the wash trading users address" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">The fake coin creator is funded by the wash trading users address</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e19c94f0dfb534d085b61c521c3acc9c04a5d5b8b1db18404c1d87f6f3e37699.png" alt="Wash trading users transfer the remaining funds directly to the fake token creator" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Wash trading users transfer the remaining funds directly to the fake token creator</figcaption></figure><p><strong>1.2 Following the Hot Topics</strong></p><p>The fake token groups will issue the associated fake project tokens based on the recent online hot topics so as to increase the credibility of the fake token or accident faking a project, even to the point of exaggeration that you only need to look at the name of the fake token issued every day to understand the current popular news. According to our statistics, there have been no less than 66 fake tokens related to FIFA in recent months.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d2adb740b653c004c9b8a808000f772ab9af9d7f89417970fe87ea9d646af202.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>1.3 Fake Transfer</strong></p><p>The fake token groups will transfer money to a large number of giant whale addresses through fake events. <strong>Such transfers will not really transfer tokens to users, but will just record the Logs of the transfer in the blockchain browser, without actually completing the operation of the token transfer.</strong> In this way, to deceive some users who follow the giant whale, as well as try to make the fake token credible again.</p><p>For example, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0x518a1c329d6077b7c70182e39755988a4068cb56f9f6e04f0f9854ad97030fca">this transaction</a> is typical of a fake airdrop. The fake token groups faked tokens with the same name as the project owner LayerZero and faked the illusion of Stargate Finance contract deployers giving airdrops to 500 on-chain giant whales in the transaction logs. The airdropped giant whales included the addresses of exchanges such as Binance, Kucoin, FTX, etc., which would make on-chain users believe that these exchanges were about to shelve these tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dc7cfae64736705147a6377d5cb69d56e5ca9d0c93574f570280bc56f6caa803.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ab8cbfb689a92bce25d05d6386aaae3a20ad3993129d6c2341b623010ce2976d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>From the parameters submitted for this transaction, it can be seen that both the sender and the receiver are arbitrarily designated by the group as the two sides of the transaction, and can construct fake transaction events at any time to mislead the transaction decisions of the on-chain users and the on-chain monitor.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dc070fea5711bc0472100ef3ae53a01a65d4e6e76deafe473b25aee5a636e590.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In the token contract airdrop() function, we learn that the function just loops and records 500 transfer events, and there is no actual token transfer at all.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e8d07a9d860233af7e4aec8d48a794c631fc16ab8376d40517ec026a362b992d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>However, the normal transfer logic would be to <strong>reduce the sender&apos;s balance -&gt; increase the receiver&apos;s balance -&gt; Transfer logs the event.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b8b6848a04170340624e49f3e52285c5c3eca0342af5696c98ff5c641bde8332.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2-exploited-methods" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Exploited Methods</h3><p>When the fake token group has attracted user funds into the pool, they will obstruct the user funds from leaving the market in various ways, including quick exploits so that users cannot sell in time, or defining the logic of &quot;no re-trade after users purchase&quot; in the contract, or 100% token fee, or being blacklisted after purchase and so on. What&apos;s more outrageous is that the token creator monitors the user who bought the token, and then actively calls the contract to burn the token in the balance. After that, it is time to exploit the money in the pool.</p><p><strong>2.1 Removing Liquidity</strong></p><p>The creator of a fake token can add liquidity (create a transaction pair, pay two tokens to the pool) and remove liquidity on Uniswap at any time without any audit or permission, which directly leads to the creator being able to add liquidity to any token, including fake tokens. The creator also has the right to withdraw the pool liquidity to get back all the two tokens, so many fake coins will remove liquidity as owner when the value of the tokens in the transaction pair is highest, thus getting all the tokens in the pool and completing the exploit of the user&apos;s money.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/437e9055c517a618ff5f53425dd4817803050b80d3da817f4ea52c2c3a55d23c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a6570eda073978a5e1b788ccf24e5b1df8133e993bad673f30642a2c3143b150.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3d77604dd9a84df22f5544034a466f18bf86036cd59cd788508b5a959c271be7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>2.2 Crashing Pool</strong></p><p>The fake token creators hold the highest authority over the fake token and can mint a large number of fake tokens at any time, or use a large number of fake tokens issued when creating the contract to instantly empty the fake pool of all the other valuable tokens. Unlike the removal of liquidity, there will be a large number of fake tokens and very few other tokens in the pool at this time, and the authority of the creators will ensure that they can exploit normal users repeatedly in the future.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3e968ae45f4c871b774265c1223204bb2881fa3215e9442e12955defa833938c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9c97424b7baa75206936cfce2b2213c53cc7712b7409b871ea554848f7c4e560.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3-the-flow-of-funds" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. The Flow of Funds</h3><p>The mixing of money flow techniques will make it difficult for others to trace, and can largely prevent others from noticing and making a fortune for themselves.</p><p><strong>3.1 Direct Transfer</strong></p><p>Direct eth transfer is the crudest way, the initial way of the group&apos;s money flow, and represents the most rudimentary but most convenient technical method for the group to begin with.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8df79da844ab9cb0f0892a47c618a36076690032954a9126cb683c672a2336af.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>3.2 Transfer via 1inch</strong></p><p>At this stage, the group uses 1inch&apos;s swap function to replace the WETH earned from counterfeiting with ETH and send it directly to another new address. By hiding the flow of funds in a swap interaction with 1inch, this transaction is less traceable.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8c7fb939c6db6f9802870d45e4f21961b85b7bdcfed78ac69b32779e525474aa.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>3.3 Transfer via Uniswap</strong></p><p>The group integrates the money flow into the normal swap (the group uses addresses holding large amounts of fake coins, goes to the trading pair pool to smash them, and directs the profitable WETH out to the new address for the next fake coin dispatch), thus hiding the transactions of large amounts of WETH in the etherscan transaction list. The transaction list in the upstream address can only see the large number of fake coins flowing into Uniswap, which is harder to track this way.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/dca79fcbeb35a1865848a64eac6b4b0a741f49599e925afef923376905f9545b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-situation-analysis-of-fake-token-issuance-and-profitability" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Situation Analysis of Fake Token Issuance and Profitability</h2><h3 id="h-1-issuance-of-fake-token" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Issuance of Fake Token</h3><p>We came up with the list of the most credible fake coins based on on-chain behavior and found that the percentage of fake coins issued daily is around 15%.</p><p>From the proportion of fake coins among new coins on the ETH chain in recent months, we can see that the number of new coins and fake coins created daily has been on the rise in the past six months, reaching a peak level around October 24, 2022, with 757 new tokens added in a single day, 130 of which were fake coins; after November, the number of new coins and fake coins per day gradually stabilized, with around 300 new tokens added in a single day After November, the number of new tokens and counterfeit coins gradually stabilized, with around 300 new tokens and 31 counterfeit coins in a single day.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6765033e925ff9573434c061d7a2f062ae70115d2945d8c734b3dcd2315763b3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2-profitability" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Profitability</h3><p>We calculated the loss of users who bought coins (the same as the daily profit of the fake token group), as shown in the chart, users lost money all for the profit of the fake token group. The average daily gain of the fake token groups on the chain for the past 8 months is 22.4 ETH.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/82cea4c09bbb5728c7185eac7788f41538ab7a08f034de8f470da5c6bd8cad9a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3-black-groups-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Black Groups Analysis</h3><p>The percentage of the number of fake tokens issued at each address shows that most of the fake creation is done with the new addresses, and after making a profit, the funds flow to the next address to start the next round of exploited behavior of issuing fake tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/62bcb3f01e301ddc35d27a82a4171a9468dfdb685c198752689489270a44253b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b90e11a3e7f19ae5dd3af31a7e33818b7e3a38d59a49e967f98ccdc9ea04d0af.png" alt="List of top 10 addresses with the largest number of fake tokens" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">List of top 10 addresses with the largest number of fake tokens</figcaption></figure><p><strong>The average cost of each fake pool is 3.4 ETH, with an average of 31 fake tokens born per day, and an average profit of 0.72 ETH per fake token. Most fake tokens will exploit users on the same day.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8389b078e7cdf50e5aeaf8219aaaa9e348927260971664821e05e5e2631b9089.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-4-fake-token-buyer-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. Fake Token Buyer Analysis</h3><p>The ratio of MEV to normal user transactions among fake token buyers is 1:9, with an average of 0.79 transactions initiated per fake token transaction to the pool MEV bot and 6.8 transactions initiated by normal users. (MEV bots are bots that arbitrage normal on-chain transactions by changing the order of transactions in the block).</p><p>In terms of profitability MEV have a much higher probability of making a profit than normal users. MEVs who buy fake tokens are almost 100% able to make a profit, while most normal user users will lose money (75%). The small number of normal users who can make money is because the buying and selling operation is very fast, and the fake tokens are sold before the fake token gang has time to harvest them.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/13d3edd79508ee93b6f73c0ac3f07c609dc3cde14d36c6614e30508651e6af02.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>From the number of times normal users bought fake tokens, we can see that most of them only bought fake tokens a few times and then stopped. 69.9% of users bought fake tokens 1-2 times, and 13.4% of users bought fake tokens 3-5 times. The users should have become careful after being exploited, and the rest of them are rushing new token users who used to or are now taking pleasure in gaining revenue by Meme.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4ad1851dfd98567094eca6d89b4c1cece70d0b77bad4c1dfcc25f467e37fb48d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>An example from <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x80021a58606cb6722b789a558f5d2d1ff623fe50">a Meme&apos;s transaction</a> history, we can see that the user had a lot of Meme transactions before May 2022 and made a great profit (Most of the profits are around 10 times, for example, this user 2 ETH profits from JPG pool).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8ace8f8a1e5dd5835bec1d95b9a5522b48140dc48cafa6646f148dae0e0cbfeb.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0dde1a259ee4cd4bfe99f8beefaac70beeeb6ff3f6b6480d6834faa518e447ff.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>When the market turned to bear, the fake tokens started rising up. The user topped up 5 tokens and 4 of them are fake, but the user can still get the original funds back in one transaction (Profit: 1.1 ETH, Loss: 0.13 ETH). A few months later, the user once again did not resist the temptation, after thinking the user found a high-quality token, like other duped users invested a lot of ETH, only a minute after the fake token group exploited funds.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/eb58db36f19176856cfba194ced2693e8a4fd27cf499e9f80f65c0dbf569645e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a9078d50f48769f05a0ee5a593b48d3e0168dddd28a2a1e39276f6fda9eb749e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-upgrade-of-fake-token-release-technology" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Upgrade of Fake Token Release Technology</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1f6ce69d730f1d777753da240ee7fd78c01ba13d6d51d63f36d6bccd02435b73.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-1-regular-process" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Regular Process</h3><p>The most common way to create fake tokens is to execute add_Liquidity() in Uniswap v2 to create a pair of fake token with WETH and add liquidity, and then delete the liquidity by executing remove_Liquidity() to complete the user funds exploit.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/af1732bd1fe883e889eeff9ae7173a730b569c73b3a39feb1d0bcc951ecb82e9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Take the example of creator 0xF6F2E5E9EFa7582deD9a4ebb2ffc333a59C30d4D, first creating the token contract, then creating a Uniswap v2 transaction pair with the just created token and 20 ETH.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/998b79c0cd5f683747ee4f28a530c931f4c62fce57a5d6bfb8356c07d76a6367.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The following is the transaction record of one of the alt accounts in the fake token group. Faker used the alternate account to swap and control the price to attract users to enter. We could see that these transactions are all washing transactions with ETH to buy fake tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/71044adb203e5f4ada953bc636a373887c15779ce76d98855f67b94af013770d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The creator monitored the real users who buy tokens, then called the submit() function within the token burn off the user&apos;s token balance to prevent them from arbitrage away from the market. Finally, the creator removed the liquidity and transferred all the funds obtained from the pool (this part of the funds includes: the principal of the pool creation + the alt account wash trading input + the loss of real token buying users)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1d5b4c68ab8fb7a4173584edbb058a6c25c035411550589fdfdf5af85c03f537.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3db95529a97c27c18252a50248f3d843a2981f4216883d386f824c4d432752bf.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2-cash-out-upgrade" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Cash Out Upgrade</h3><p>A more concealed crashing pool happened when exploited. Fakers would swap WETH and fake token out of the pool via alt accounts.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b43d795d4db24067cc1846af0dbb736d8b22bd92ccadfdb36513f9db934434a5.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Such as trading pair <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x17d786f0f689e1b121ad38c2fbd6e27d4bdcb407#tokentxns">Unisawap V2: OASYS2</a>, fake token groups crash into the pool to gain 60 WTH via alt accounts with lots of fake tokens.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/42d3c679e9262d4aa97ea53e12fba41a9edb39e2c829cfaf9fe559fbabaaadce.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-3-created-pair-upgrade" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Created Pair Upgrade</h3><p>When creating a transaction pair, the add_Liquidity() function is not directly called, but this step is coded in the fake token contract constructor. When the fake token is created, the transaction pair is automatically created.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/cc04d7bcf4308ec8ec23960d6fa3aedce5234c17979a2540a037906804fd44a2.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For example, the token <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/address/0x3dd64863a9381715a66dfb76b7059698b841ff5e#code">BIYC</a> calls the factory contract of Uniswap v2 to create a trading pair when created.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f22fb4def058bdedf0da2a2159906111efc1db4b11f9632b6be7680f40cb6f44.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-4-token-pair-upgrade" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">4. Token Pair Upgrade</h3><p>Token pairs are no longer limited to fake coins and WETH, but valuable tokens can replace WETH to have arbitrage.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e271ab12be84d7140ad936eca0633fd206bfa2d09b345b57c7e83f8f53d0c579.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherscan.io/tx/0x6a520175b09b2bbd5bc5470d229bbf93c5eef6abbe1e534eef8f0843a4dec748">The following transaction</a> is a token pair formed by a fake token and USDC.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9faf9670d64ea565944e7dc46a6268a07815e59c1b05365868157a978b0ce9f7.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-5-router-upgrade" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">5. Router Upgrade</h3><p>While Uniswap v2 is more popular, fake tokens can also expand to Uniswap v3 and other Dexes that do not require vetting, and currently fake tokens are created through v2&apos;s factory contracts.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f364c75281a1c0277bb7a82f0597f352703a40754dba4ae1c18b8d2d8612703b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/f0c01521479418a7e015f27f63c2994b896cb0242b106214df5b6290b1cd54bd.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Sybil tools revealing - Good work requires sharp tools]]></title>
            <link>https://paragraph.com/@x-explore/sybil-tools-revealing-good-work-requires-sharp-tools</link>
            <guid>uycju0MpJUSUhxQknRfY</guid>
            <pubDate>Fri, 09 Dec 2022 10:04:31 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.BackgroundIn the world of Web2, the underground industry lasts for years. After years of research and analysis, attacking methods of the underground industry can be divided into multi-IP address, multi-device, and multi-account attacks. There are some commonly used tools such as modem pool, multi-device opening tools, and auto captcha solver. With the rise of Web3, due to its anonymity and transparency, the underground industry q...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h2 id="h-background" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Background</h2><p>In the world of Web2, the underground industry lasts for years. After years of research and analysis, attacking methods of the underground industry can be divided into multi-IP address, multi-device, and multi-account attacks. There are some commonly used tools such as modem pool, multi-device opening tools, and auto captcha solver.</p><p>With the rise of Web3, due to its anonymity and transparency, the underground industry quickly set its sights on Web3. According to research by HACK 3D, in the first half of 2022, nearly $2 billion was hacked on Web3. The X-explore team would like to reveal to you some tools frequently used by Sybil and describe the outline of Web3 underground industry for you.</p><h2 id="h-purpose-of-sybil-prevalent-smart-contract" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Purpose of Sybil prevalent smart contract</h2><ol><li><p><strong>Increasing efficiency:</strong> Some campaigns need users to interact with a smart contract or hold a variety of ERC 20 tokens. Sybil could write such smart contracts to automate those processes and increase efficiency in attending (attacking) those campaigns</p></li><li><p><strong>Reducing the cost:</strong> After Ethereum introduced the base fee in EIP-1599 protocol, each transaction fee included the base fee and the priority fee. The smart contract with batch transfer functionality could reduce the transaction fee significantly.</p></li><li><p><strong>Preventing Sybil detection:</strong> With Sybil&apos;s rampant, more and more project owners are aware of the fairness of airdrops. Sybil will create or use smart contracts to attend to those projects and avoid direct interaction with projects. In this case, the traditional Sybil identification rules might not detect those Sybil properly.</p></li></ol><h2 id="h-sybil-prevalent-smart-contracts-case-study" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Sybil prevalent smart contracts case study</h2><p>X-explore reviewed those Sybil prevalent smart contracts and picked three representative projects:</p><ol><li><p>Role obtaining trick: purchase token bundle</p></li><li><p>NFT scalper trick: NFT batch transfer</p></li><li><p>Low cost trick: ZkSync</p></li></ol><h3 id="h-1-role-obtaining-trick-purchase-token-bundle" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. Role obtaining trick: purchase token bundle</h3><p><strong>X-explore summary</strong></p><ol><li><p>The campaign designed for obtaining the Discord roles of Arbitrum guild by holding tokens is Sybil-prone</p></li><li><p>Sybil could obtain the Discord roles of Arbitrum guild easily (purchase token bundle by calling a smart contract)</p></li><li><p>The smart contract creators could not only be Sybil but also make a profit by providing their smart contracts to others. There are a varity of Tokens required to obtain Discord role of Arbitrum guild. If users buy those tokens one by one on Dex (decentralized exchange), they will actually have to pay a considerable transaction fee. Therefore, if the price of the smart contract call is reasonable, the contract is like a wholesaler, making it convenient and cheap for users to obtain Discord role of Arbitrum guild, but most contracts are priced well above their true cost.</p></li></ol><p><strong>Smart contract summary：</strong></p><p>X-explore found a few smart contracts with the same purpose. By calling those contracts, they will transfer the necessary token for gaining the Discord roles of <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://guild.xyz/arbitrum">Arbitrum guild</a>.</p><p><strong>Sybil purpose：</strong></p><p>Arbitrum is the leader of Ethereum Layer 2, and there are many Sybil who makes huge profits from OP (another Ethereum Layer 2) airdrop. Besides attending Arbitrum Odyssey, obtaining Discord roles of Arbitrum guild is also known as another way to increase the probability of Arbitrum potential airdrop.</p><p><strong>Sybil case study:</strong></p><ol><li><p>Sybil attended the arbitrum odyssey and minted the odyssey NFT</p></li><li><p>Sybil called the smart contract to purchase token bundle and obtain Discord roles of Arbitrum guild.</p></li></ol><p><strong>Sybil Address Examples：</strong></p><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arbiscan.io/address/0x8bed76d470b0113652ea04c403426817ad443976">https://arbiscan.io/address/0x8bed76d470b0113652ea04c403426817ad443976</a></p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ed353cc1ff0a629bd472b1713cf680195aabb6cc10a86deb579e7769a8ffe0da.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arbiscan.io/address/0x7e61bea56798d98c923a7aad4e2b0df58610eee8">https://arbiscan.io/address/0x7e61bea56798d98c923a7aad4e2b0df58610eee8</a></p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/33ba7e9a8a9cdca86b5d446224c5a4ee253f18aa37a76f62943e95d104862940.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Smart contract token bundle corresponds to the requirement of Discord roles of Arbitrum guild</strong></p><p>Besides two roles that you could not obtain by holding the token, the smart contract will transfer all the necessary tokens of other roles to the smart contract caller. (Left figure is transaction details, right figure is the requirement of Discord roles of Arbitrum guild)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/845e0035eab69772e15dc4247ed2f9b38639c0d5345134bc363999477c6ffa1b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Smart contract detailed analysis:</strong></p><p><strong>Profit winner smart contract:</strong> We found a smart contract (0x1879822678f5d295bc76dda858c781a113cdc058) in which the contract caller needs to pay 25 USD to buy the token for the Discord role of Arbitrum guild. The smart contract was called 5,991 times, total profit = (25 - 12.64) * 5991 ~= 74,049 USD</p><p><strong>Charity smart contract:</strong> We also found a smart contract (0x34c26d67d8b295e11897280f56b08726b112b1b1) which you don&apos;t need to pay any money and it will return you the necessary token. After we dug into the smart contract, we found out this smart contract was probably created by Sybil and after Sybil addresses got the role of Arbitrum guild, the token balance of the smart contract was only worth 5 USD.</p><p>The series of Arbitrum guild smart contracts which were called more than 100 times:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ce182d67edcde6c5524f82e58c20563f888688faa36b3b323510575e4e544c56.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2-nft-scalper-trick-nft-batch-transfer" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. NFT scalper trick: NFT batch transfer</h3><p><strong>X-explore summary:</strong></p><ol><li><p>Batch transfer ERC-721 could save more than 50% of the transaction fee compared to single ERC-721 transfer</p></li><li><p>In a situation of low return on investment(ROI), the saving of transaction fee could rise Sybil&apos;s profit significantly</p></li></ol><p><strong>Contract Address:</strong> 0x2e2234b3a848f895a60b2071f90303cd02f7491d</p><p><strong>Contract Summary:</strong> This is an ERC-721 batch transfer smart contract. The smart contract caller could transfer the ERC-721 in a batch way to save the transaction fee.</p><p><strong>Smart Contract case study：</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d5046003c359d6fd387d38625888663c51bb884a98a5d11e3182a1531776b2dd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Buy and Batch Transfer transactions:</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/08db94e9a0677aad8e2d1626617b5cb725ecfa5c93f815a2da4c6bb184ed3eac.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Buy NFT at 0.001 Ether/each (Disregard transaction fee for now)</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b880bb2260d3479886142e80ced7195bf871480667e3cddb17aaa0e6c745b473.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Batch Transfer 3 NFTs</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a9dfcf4c1a9bcb4023668d03197f80c990a78e637741df4ab8eeb46d9a428399.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Single NFT Transfer (0.00075 on average)</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3e20a5025de8534a885363cdf77e0cd8e428094d843d540c3d4ad593c7e8ea16.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/49964db94df5b928abe2f754743cce89c2e3241a103936c72b4b5855bf4190e9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Sell NFT at 0.005 ETH (0.01098/2)</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/af071bef304fe8b1a185c2bc7c9fb42e7cad8fc7073646023aaae75c0228fc24.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>If we only focused on the Buy and Sell price of the NFT, we could see the ROI is around 500% (0.001 Buy, 0.005 Sell). However, for those low ROI situations, the transaction fee is also a huge cost for the scalper. For example, we could calculate the reality ROI of the above NFT scalper.</p><p>ROI (Using <strong>single</strong> ERC-721 transfer smart contract):</p><ul><li><p>The cost of single NFT, including token price and transaction fee: (0.003 + 0.0027 + 0.00075*3)/3= 0.00265</p></li><li><p>The selling price of single NFT: 0.01098/2 = 0.00549</p></li><li><p>ROI: 207 %</p></li></ul><p>ROI (Using <strong>batch</strong> ERC-721 transfer smart contract):</p><ul><li><p>The cost of single NFT, including token price and transaction fee: (0.003 + 0.0027 + 0.0012)/3= 0.0023</p></li><li><p>The selling price of single NFT: 0.01098/2 = 0.00549</p></li><li><p>ROI: 239 %</p></li></ul><p><strong>In summary: The NET batch transfer could increase the ROI by 30%</strong></p><h3 id="h-3-low-cost-trick-zksync" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. Low cost trick: ZkSync</h3><p><strong>X-explore summary：</strong></p><ul><li><p>Compared with Ethereum, ZkSync has a lower transaction fee (around 43% in the Sybil case study)</p></li><li><p>Sybil could utilize ZkSync to prevent tracing from the basic Sybil identification rules (the transaction on ZkSync will only be recorded on ZkSync not Ethereum)</p></li></ul><p><strong>Smart contract addresses：</strong></p><ul><li><p>zkSync: 0xabea9132b05a70803a4e85094fd0e1800777fbef</p></li><li><p>Gitcoin: Bulk Checkout: 0x7d655c57f71464b6f83811c55d84009cd9f5221c</p></li></ul><p><strong>Smart contract summary：</strong></p><ul><li><p>zkSync: Implementing the low-cost transaction fee by crossing the transaction to Layer 2. Gitcoin users could use ZkSync as a way to checkout</p></li><li><p>Gitcoin: Bulk Checkout: Gitcoin users could donate multiple projects in one transaction</p></li></ul><p><strong>Sybil purpose:</strong></p><p>Gitcoin aims to decentralize funding access, empowering any community to run their own grants program. Some Sybil will donate to the project list on Gitcoin because the project is potentially airdropping to the donator. Due to the high transaction fee on Ethereum, the donator could grant a Gitcoin project on ZkSync. Furthermore, if you use ZkSync to donate to a project, the record will only exist in ZkSync Layer 2 chain, and it could create barriers for the Sybil analytics tool.</p><p><strong>Hand-on experiment from X-Explore team:</strong></p><ul><li><p>Donate through ZkSync: Donate 1 DAI for two projects costs 3.65 USD (Including: cross chain transaction fee + ZkSync swap ETH to DAI fee + Gitcoin checkout transaction fee)</p></li><li><p>Donate through Ethereum: Donate 1 DAI for two projects costs: 6.33 USD (Including: Ehereum Swap ETH to DAI on Uniswap transaction fee + Gitcoin checkout transaction fee)</p></li></ul><p><strong>ZkSync could save around 43% of the cost</strong></p><h2 id="h-x-explore-summary" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">X-explore summary</h2><ol><li><p>The project owner should design reasonable campaigns to avoid low cost attacks by Sybil</p></li><li><p>Sybil attacks escalate with confrontation, so traditional Sybil identification mechanisms are likely to be bypassed</p></li><li><p>Due to the transparency nature of Web 3, we can also grasp every move of the underground industry through on-chain monitoring and analysis. X-Explore will continue to monitor the underground industry in the future and unveil the veil of Sybil with you.</p></li></ol><h2 id="h-reference" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Reference</h2><p>Discord roles of Arbitrum guild: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Layer2_Master/status/1585506822764433408">https://twitter.com/Layer2_Master/status/1585506822764433408</a></p><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/727429ee8bf417806aec9f62bfd8dc0705f5e61c9923a41eddf80dd1d2052b45.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[女巫工具揭秘 - 工欲善其事，必先利其器]]></title>
            <link>https://paragraph.com/@x-explore/z9klNABHgTiWDonr0WTj</link>
            <guid>z9klNABHgTiWDonr0WTj</guid>
            <pubDate>Fri, 09 Dec 2022 10:03:25 GMT</pubDate>
            <description><![CDATA[本文由 X-explore 与吴说区块链联合发布。背景：在 Web2 的世界中，黑产行之有年，黑产的手法在经过多年的研究以及沉淀后，不外乎可分为：多IP地址、多设备以及多账号的攻击。常使用的工具如：猫池、多开工具以及打码平台。 随着 Web3 的兴起，由于其匿名化以及完全公开的特性，黑产很快的就盯上了这块大饼。据 HACK 3D的研究表明，在 2022 的上半年 Web3 项目就有将近 20 亿美元被黑客攻击。X-Explore 团队想在此为大家揭秘一些女巫团伙常用的工具，为大家刻画 Web3 黑产的轮廓。女巫使用合约目的：提高效率: 有些项目活动是需要与多个合约交互或是持有多种 Token，因此女巫可以透过写合约的方式来将这些操作自动化，提高自己参与项目活动的效率降低成本: 以太坊在 EIP-1559 协议中引入了交易基础费，每一笔交易都由基础费以及矿工小费所组成，因此链上使用合约批量的进行一些操作能够节省手续费避免链上追踪: 随着女巫以及科学家在各类活动的猖獗，越来越多项目方会在空投之前进行女巫的过滤，随着对坑的升级，女巫也会制造或使用各种合约来避免直接与项目合约交互，这种手...]]></description>
            <content:encoded><![CDATA[<p>本文由 X-explore 与吴说区块链联合发布。</p><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">背景：</h2><p>在 Web2 的世界中，黑产行之有年，黑产的手法在经过多年的研究以及沉淀后，不外乎可分为：多IP地址、多设备以及多账号的攻击。常使用的工具如：猫池、多开工具以及打码平台。 随着 Web3 的兴起，由于其匿名化以及完全公开的特性，黑产很快的就盯上了这块大饼。据 HACK 3D的研究表明，在 2022 的上半年 Web3 项目就有将近 20 亿美元被黑客攻击。X-Explore 团队想在此为大家揭秘一些女巫团伙常用的工具，为大家刻画 Web3 黑产的轮廓。</p><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">女巫使用合约目的：</h2><ol><li><p><strong>提高效率</strong>: 有些项目活动是需要与多个合约交互或是持有多种 Token，因此女巫可以透过写合约的方式来将这些操作自动化，提高自己参与项目活动的效率</p></li><li><p><strong>降低成本</strong>: 以太坊在 EIP-1559 协议中引入了交易基础费，每一笔交易都由基础费以及矿工小费所组成，因此链上使用合约批量的进行一些操作能够节省手续费</p></li><li><p><strong>避免链上追踪</strong>: 随着女巫以及科学家在各类活动的猖獗，越来越多项目方会在空投之前进行女巫的过滤，随着对坑的升级，女巫也会制造或使用各种合约来避免直接与项目合约交互，这种手法会使得一些传统基于规则的女巫识别策略被绕过。</p></li></ol><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">女巫合约案例分析：</h2><p>以下我们将对挖掘出来的其中三个女巫合约进行深度的分析：</p><ol><li><p>链上身份获取利器：Token 批量购买</p></li><li><p>NFT 羊毛利器: NFT 批量转移</p></li><li><p>低成本利器：ZkSync</p></li></ol><h3 id="h-1-token" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. 链上身份获取利器：Token 批量购买</h3><p><strong>X-explore 总结：</strong></p><ol><li><p>Arbitrum guild discord 准入的活动设计不科学（只要有 Token 就可以加入）</p></li><li><p>女巫极其便捷获得身份（购入符合活动门槛的 Token）</p></li><li><p>编写合约的人既可以自己当女巫，也可以开放合约给大家使用并从中获利。购买 Arbitrum guild 角色所需 Token 种类繁多，如果用户逐个在 Dex 上买的话，其实也要支付可观的的交易手续费，因此如果合约调用的价格合理，合约则像是批发商，让用户便捷且便宜的获得 Arbitrum guild 角色，但大多数合约的定价都远高于其真实成本。</p></li></ol><p><strong>合约概述</strong>: 这些批量买 Token 的合约都是一次性购买多个 Token 以符合获得多个 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://guild.xyz/arbitrum">arbitrum guild</a> 的身份，有一些博主也都在推荐使用这类的合约来获得 arbitrum guild 的身份。</p><p><strong>女巫意图</strong>: Arbitrum 是 ETH L2 的领跑者，很多人在同性质的 OP 链空投中赚的盆满钵满。在 Arbitrum 尚未宣布空投时，大家就在尝试各种方法来增加自己获得空投的概率。其中除了参与 Arbitrum 奥德赛之外，参与 Arbitrum guild 就被认为是另一种潜在获得空投的方式。</p><p>通过链上合约分析的能力，我们在 Arbitrum 链上共找到 189 个这种相同目的的合约，共有 21,771 个地址调用这些合约。其中我们又筛选大于一百个地址调用过的合约：符合条件的合约有 14 个，总计 21,436个地址调用了这些合约。</p><p><strong>合约使用案例</strong>: 女巫团伙批量薅奥德赛 NFT 以及调用合约批量买 Token 获得 Arbitrum guild 的角色 基本上交易拓扑跟时间都高度相似，都是跨链过来Mint了奥德赛的NFT然后再调用合约批量购买获取 Arbitrum guild 的所有角色</p><p><strong>女巫地址范例：</strong></p><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arbiscan.io/address/0x8bed76d470b0113652ea04c403426817ad443976">https://arbiscan.io/address/0x8bed76d470b0113652ea04c403426817ad443976</a></p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ed353cc1ff0a629bd472b1713cf680195aabb6cc10a86deb579e7769a8ffe0da.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arbiscan.io/address/0x7e61bea56798d98c923a7aad4e2b0df58610eee8">https://arbiscan.io/address/0x7e61bea56798d98c923a7aad4e2b0df58610eee8</a></p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/33ba7e9a8a9cdca86b5d446224c5a4ee253f18aa37a76f62943e95d104862940.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>合约具体内容对应具体 arbitrum guild 角色取得条件. 除了两个没有办法直接透过购买ERC20 Token取得的roles, 基本上这个合约把其他的 Token 都买齐了，也都符合最低的持有数量。（左图为合约购买细节，右图为获得arbitrum guild角色的条件）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/845e0035eab69772e15dc4247ed2f9b38639c0d5345134bc363999477c6ffa1b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>智能合约详细分析</strong>：</p><p><strong>有些合约的调用金额是远高于 Token 价格的</strong>： 0x1879822678f5d295bc76dda858c781a113cdc058，这个合约总共被调用 5,991次，调用金额约为 25.5 U。<strong>合约可获利（25 - 12.64) USD * 5,991 ~= 74,049 USD</strong>，也是这类合约中的获利王。</p><p><strong>有些合约是赔本生意</strong>: 0x34c26d67d8b295e11897280f56b08726b112b1b1，这个合约本身不用钱也可以调用，但根据其代币的库存来看，很大概率是女巫团伙自己创建的合约，创建合约批量取得 arbitrum guild 角色后，合约本身的代币也所剩无几。</p><p>大于100个地址调用的同类型合约明细：（数据统计时间为 2022/12/01）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/23b17a699aa8aba71f8560822fd7cf1395b12154a3b778f5d2607072c0b2e5d4.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-2-nft-nft" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. NFT 羊毛利器: NFT 批量转移</h3><p><strong>X-explore 总结：</strong></p><ol><li><p>批量转 ERC-721 的合约能比单个转 ERC-721 的合约省下约 50% 交易手续费</p></li><li><p>在获利较低廉的情况下，省下的手续费能让女巫获利可观的增加 (30%)</p></li></ol><p><strong>合约地址</strong>: 0x2e2234b3a848f895a60b2071f90303cd02f7491d</p><p><strong>合约概述</strong>: 这是一个批量 ERC-721 的合约，用户可以透过这个合约将 ERC-721 批量的进行转移，到其归集地址上进行 NFT 的批量贩售</p><p><strong>女巫意图</strong>: ETH 的每一笔交易都会有基础交易费，对一些批量薅 NFT 的女巫来说，如果 NFT 的价格不是特别高的话，ETH 手续费也是比较可观的成本，因此女巫会想利用批量转 NFT 的合约来节省手续费以最大化利润。</p><p><strong>合约使用范例：</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d5046003c359d6fd387d38625888663c51bb884a98a5d11e3182a1531776b2dd.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Buy and Batch Transfer transactions:</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/08db94e9a0677aad8e2d1626617b5cb725ecfa5c93f815a2da4c6bb184ed3eac.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Buy NFT at 0.001 Ether/each (Disregard transaction fee):</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b880bb2260d3479886142e80ced7195bf871480667e3cddb17aaa0e6c745b473.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Batch Transfer 3 NFTs:</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a9dfcf4c1a9bcb4023668d03197f80c990a78e637741df4ab8eeb46d9a428399.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Single NFT transfer：</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3e20a5025de8534a885363cdf77e0cd8e428094d843d540c3d4ad593c7e8ea16.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Sell NFT at 0.005 ETH (0.01098/2):</strong></p><p>只看买 NFT 价格和卖 NFT 价格会觉得根本是暴利，翻了5倍左右(0.001买、0.005卖)，但这种单价不高的NFT获利情况是和手续费息息相关的，且每笔交易也都要给NFT平台交易费，因此能够节省手续费是相当关键的。</p><p>如果不使用批量转账工具的话，该NFT平均单个转移的费用为0.00075</p><ul><li><p>每个NFT购买以及转移成本：(0.003 + 0.0027 + 0.00075*3 )/3 = 0.00265</p></li><li><p>每个NFT实际卖出：0.01098/2 = 0.00549</p></li><li><p>报酬率为：207%。</p></li></ul><p>如果使用批量转账工具的话：</p><ul><li><p>每个NFT购买以及转移成本：(0.003 + 0.0027 + 0.0012 )/3 = 0.0023</p></li><li><p>每个NFT实际卖出：0.01098/2 = 0.00549</p></li><li><p>报酬率为：238%。</p></li></ul><p><strong>可以看到女巫团伙成功的利用了批量转账的工具减少了约30%的成本。</strong></p><h3 id="h-3-zksync" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3.低成本利器: zkSync</h3><p><strong>X-explore 总结：</strong></p><ul><li><p>ZkSync 相比于以太坊，有着较低的交易手续费 (这个案例中女巫省下43%成本)</p></li><li><p>女巫批量使用 ZkSync 在 Gitcoin 付款，可以避免女巫策略直接的识别（因为捐赠记录只会在 L2 链上，而不在 ETH 上）</p></li></ul><p><strong>合约地址：</strong></p><ul><li><p>zkSync: 0xabea9132b05a70803a4e85094fd0e1800777fbef</p></li><li><p>Gitcoin: Bulk Checkout: 0x7d655c57f71464b6f83811c55d84009cd9f5221c</p></li></ul><p><strong>合约概述：</strong></p><ul><li><p>zkSync：可以帮助实现低手续费的 ETH Layer 2 链，用户在 Gitcoin checkout 时可以选择使用 zkSync 来付款</p></li><li><p>Gitcoin: Bulk Checkout：这是 gitcoin 上面的一个合约，让用户可以通过一次的合约调用来实现多个项目的捐赠</p></li></ul><p><strong>女巫意图：</strong></p><p>Gitcoin 是一个项目的捐赠平台，可以透过 Gitcoin 来对一些自己感兴趣的项目进行捐赠，其中除了促进 Web3 的发展之外，有些项目可能会在未来对捐赠方进行空投。因此女巫会创建批量的地址并使用 Gitcoin 进行捐赠。其中由于以太坊的手续费昂贵，用户可以透过 zkSync 来对 Gitcoin 进行捐赠以节省手续费，且在 Gitcoin 使用 ZkSync 当作付款方式的话，这个捐赠记录只会在 zkSync L2链上，避免女巫分析工具有效追踪。</p><p><strong>经过 X-explore 团队在 2022/12/04 实测：</strong></p><ul><li><p>使用 zkSync： 个别捐赠 1 DAI 给两个项目的成本约为 3.65 U （将ETH跨链到 zkSync 手续费+ zkSync 买 DAI 成本和手续费 + Gitcoin 使用 zkSync checkout 手续费）</p></li><li><p>使用以太坊：个别捐赠 1 DAI 给两个项目的总成本约为 6.33 U （ETH 在 Uniswap 买 DAI 成本和手续费 + Gitcoin 使用 ETH checkout 手续费）</p></li></ul><p><strong>使用 zkSync 约可以省下 43% 左右的成本</strong></p><h2 id="h-x-explore" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">X-explore总结</h2><ol><li><p>项目方应设计合理的活动门槛，避免被女巫低成本的批量攻击。</p></li><li><p>女巫的攻击随着对抗而升级，因此传统的女巫识别机制很有可能被绕过。</p></li><li><p>由于 Web 3 公开透明的特性，黑产的一举一动我们也可以透过链上的监控以及分析有所掌握，X-Explore 也会在未来持续的监控黑产，和大家一起揭开女巫的面纱。</p></li></ol><p>敬请关注我们。</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/727429ee8bf417806aec9f62bfd8dc0705f5e61c9923a41eddf80dd1d2052b45.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[链上地址投毒，让你防不胜防]]></title>
            <link>https://paragraph.com/@x-explore/jCuIfWjzCJNeA7CLvwFo</link>
            <guid>jCuIfWjzCJNeA7CLvwFo</guid>
            <pubDate>Fri, 02 Dec 2022 18:55:38 GMT</pubDate>
            <description><![CDATA[Abstract: 近一周，0U 转账的链上地址投毒攻击愈演愈烈，截至12月2日，已经有超过37W地址被投毒，总计92个受害地址，被盗取金额超过164W USD。 本篇文章，X-explore 对攻击态势进行了全面分析，对攻击者进行了链上溯源，同时也深入分析了攻击的实现方式。 我们呼吁钱包APP加强风险提示，普通用户在转账时谨防此类攻击。因为我们注意到UTC时间11月2日10点38分，有一位链上用户损失惨重，近100万美金因投毒而被转到黑客地址。本文由 X-explore 与吴说区块链联合发布。1. 背景近期，我们的链上风险监控发现ETH、BSC链上频繁出现 0u 转账现象，以下图bsc链的交易数据为例，受害者A发出一笔正常交易将452 BSC-USD发给B后，会收到C转来的0 BSC-USD，同时，在同一笔交易hash内用户A自己也会不受控制的给C转0 BSC-USD（实现了“一来一回”的0 BSC-USD转账操作）用户交易列表出现的现象在社区中，很多用户不知所以然，担心自己的钱包私钥已经泄漏，攻击者正在窃取资产。2. 攻击意图其实遇到这种情况的用户不用紧张，大家的资产是安全的...]]></description>
            <content:encoded><![CDATA[<p><strong>Abstract</strong>:</p><p>近一周，0U 转账的链上地址投毒攻击愈演愈烈，截至12月2日，已经有超过37W地址被投毒，总计92个受害地址，被盗取金额超过164W USD。</p><p>本篇文章，X-explore 对攻击态势进行了全面分析，对攻击者进行了链上溯源，同时也深入分析了攻击的实现方式。</p><p>我们呼吁钱包APP加强风险提示，普通用户在转账时谨防此类攻击。因为我们注意到UTC时间11月2日10点38分，有一位链上用户损失惨重，近100万美金因投毒而被转到黑客地址。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a06fcb0f1eb93bfed9f75064e198d034c0a08ddbcf7ad071ffe75457ae2d625d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>本文由 X-explore 与吴说区块链联合发布。</p><h2 id="h-1" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. 背景</h2><p>近期，我们的链上风险监控发现ETH、BSC链上频繁出现 0u 转账现象，以下图bsc链的交易数据为例，受害者A发出一笔正常交易将452 BSC-USD发给B后，会收到C转来的0 BSC-USD，同时，在同一笔交易hash内用户A自己也会不受控制的给C转0 BSC-USD（实现了“一来一回”的0 BSC-USD转账操作）</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0abd812db6c209f494766c7c437fde0babc72c6baafe643c8d79d0c9d94491e5.png" alt="用户交易列表出现的现象" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">用户交易列表出现的现象</figcaption></figure><p>在社区中，很多用户不知所以然，担心自己的钱包私钥已经泄漏，攻击者正在窃取资产。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f152179c35b62c33855ad10deb1c73466dfd39a4c13526785da225f08820f52c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. 攻击意图</h2><p>其实遇到这种情况的用户不用紧张，大家的资产是安全的，私钥并没有泄漏，只需要仔细确认地址小心别转错账就没事，黑客的手法很简单：</p><ol><li><p>在链上监控几个稳定币的转账信息，捕获受害者地址A正常发送给用户B的转账信息。</p></li><li><p>精心构造与用户地址B首尾一致的黑客地址C，使受害者A与黑客地址C互相转帐0U。（这里攻击者可以使用靓号生成工具 Profanity，在几秒内生成与用户地址前后7位相同的地址）</p></li><li><p>受害者A下次转账时粗心大意直接复制历史交易的地址时，很容易错误复制到黑客准备的地址C，从而将资金转错账</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c9e1af5c7f2a536a0d45fa285fa7a630d8b8d58f81d252e539daf1c2d56bcf15.png" alt="受害者给正常地址转账" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">受害者给正常地址转账</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6720578a290930e8b137226ad52bd757be54ae15a59d5205f217d97572a5c697.png" alt="黑客地址给受害者转0U" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">黑客地址给受害者转0U</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ef360614a77a2a8e885a0810feefe1322180e0d812d1b81b5b284a101aefa571.png" alt="受害者给黑客地址转账" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">受害者给黑客地址转账</figcaption></figure><p>我们认为这种攻击是链上地址投毒攻击：</p><ol><li><p>首先，黑客让自己的地址出现在用户交易历史中，诱导用户误认为是可信的交互地址。</p></li><li><p>此外，黑客构造出的地址与用户可信地址首尾相同，被用户当作下次交易的对象。 链上投毒很容易使用户产生资损，链上用户需共同警惕！</p></li></ol><h2 id="h-3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. 攻击态势</h2><p>截止12月2日，在BSC与ETH链上的攻击次数分别超过32万次和5万次，受攻击影响的独立地址数分别超过16万个以及4万个。</p><p>从趋势上看，BSC链自从11月22日开始爆发，ETH链则从11月27日开始爆发，两条链的攻击规模均愈演愈烈。</p><p>此外，可以看到攻击发生时间有显著规律性，在每天UTC时间17点到0点攻击量级显著减少。疑似攻击者处于亚洲时区。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c303641993600eb4a8341ffe43f04addc8ba3cd367703b51f79bc7e84c9b65a2.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>截止12月2日，总共有 92 个独立地址受骗，累计被骗金额达到 164万USD。伴随着攻击者攻击目标的增加，可以预见，近期还会不断有大量用户被骗。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4dbdbe35d2be867a1531400bee455e17c95dde9a6d8fe5b2dc0eeade98f0607c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>此外，我们对攻击者的攻击成本进行了分析，目前总成本接近2.9W USD（50 BNB + 11 ETH），攻击者对BSC-USD和USDT非常偏爱，与稳定币的币种流通量和用户持有量有关</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/09323559696fb79deae0ea48136f31dafe9079919a4ffbb869207af1f5ee8741.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7a24a176a165ebdacf32ba481fd5d38eddfbb7e10e9e08bfcd6d9c0a460ed237.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">攻击者溯源</h2><p>我们对其中一个攻击者进行了链上溯源追踪，与两个主流中心化交易所关联，其完整过程如下图所示：</p><ol><li><p>其攻击资金的来源地址与OKX.com存在关联，攻击者通过使用Transit.Finance跨链桥将原始攻击资金从TRON链转移到BSC链上。</p></li><li><p>其盗取资金最终归集到Huobi.com，攻击者依然使用Transit.Finance跨链桥将盗取资金转移到TRON链上。</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f4d5c5e57501b09edbe281f62f98db4ae65b8b04147e332350c8617a880558ed.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>让我们进一步展开，针对盗取资金的流向进行溯源。</p><p>首先，受害者地址0xe17c2b2b40574d229a251fe3776e6da2cc46aa5e向攻击者地址0x720c1cfe1bfc38b3b21c20961262ad1e095a6867分两次，共转账1300U。</p><p>接着，攻击者地址将资金归集到地址0x89e692c1b31e7f03b7b9cbb1c7ab7872ddeadd49</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/31a6cc6d9fb5f46adf2adc5aa5079e256fe7a06fae12ee8e5b42413982affe1c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>攻击者在0x89e692c1b31e7f03b7b9cbb1c7ab7872ddeadd49地址上进行了资金的跨链转移，在txhash为0x72905bd839f682f795946d285500143ee7606e9690df2ad32968e878ad290d9f的交易中，如下图所示，将10561 USDT通过Transit.Finance的合约（0xb45a2dda996c32e93b8c47098e90ed0e7ab18e39）进行了Cross操作。在这笔交易的Event Logs中，可以看到资金去向了TRON链的USDT，对应地址是TLUKBw37BVWDZdhbGco2ZEfdMd5Cit8TMD，对应TRON链上的交易hash是：716507136ad28717ffd5f2f437af753ff96d344d2bcbe83f24d801db49f5a884</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/78a9a63b5523b71c10bda3e99bf3f84907000915ad18bd11809cc5b3ad4e5e0b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5cb0642f79baa6df7677efd3dd47e57a668d2c8a50016517a10aba5dc868735b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4df97a78f2774e75c3626b89b6408074c6455ed45e1c0020f6acd8fcbdddce76.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>最终，攻击者将 TLUKBw37BVWDZdhbGco2ZEfdMd5Cit8TMD 地址上的充值进了Huobi交易所。充值的入金地址分别是：TPtzsrCAG61QMwig3jZV8Px7Rd1WZVnRXG, TDp7r3S1hJeiNfH1CvCVXeY8notY47nagJ</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0250d4e664f6fa8bfd85d2376fa51b9ef86a75b7a790d5ef6efb1958dbe778ae.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8560aba8baf656f020c73d0007b50938ebc34fe2054f95de1dcb9d131f0e04e0.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">攻击原理分析</h2><p><strong>攻击者案例1：</strong></p><blockquote><p>EOA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0xBAA1451bE8C33998CD43F375c2e67E79c1a104AD">0xBAA1451bE8C33998CD43F375c2e67E79c1a104AD</a></p><p>CA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x7cebeb6035b231a73cb5fb4119c2fbbc04ec6fd1">0x7ceBeb6035B231A73CB5Fb4119c2FbBC04Ec6fD1</a></p></blockquote><p><strong>攻击者案例2：</strong></p><blockquote><p>EOA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x616384a80f32aDb65243522971aE2ba7664B62E3">0x616384a80f32aDb65243522971aE2ba7664B62E3</a></p><p>CA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x6f00Ed594A6AceEf0E1A6FE023Ecd5Eb96c8665a">0x6f00Ed594A6AceEf0E1A6FE023Ecd5Eb96c8665a</a></p></blockquote><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/073702431f157e82bbb9c8a0db5911cbf9ab43b231eaa07447710dfaa2fafce6.png" alt="黑客控制不同地址并通过合约批量转账0 BSC-USD给受害者地址" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">黑客控制不同地址并通过合约批量转账0 BSC-USD给受害者地址</figcaption></figure><p>针对bsc链上的token攻击主要包含BSC-USD、BUSD、USDC、ETH等，大部分是通过攻击合约批量调用transferFrom()函数，也有手动调用transfer()函数的情况和针对主币的情况，原理基本一致。以下用 BSC-USD 的一个攻击合约举例</p><p><strong>transferFrom()</strong></p><p>在攻击者调用攻击合约的一笔交易中，攻击合约只调用了 BSC-USD 的 transferFrom() 函数，通过对参数填充sender、recipient、amount可以实现操控任意地址间的0 USD转帐，同时产生授权Approval()与转账Transfer()的事件</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://phalcon.blocksec.com/tx/bsc/0x825a3281e1897239c01797e590d3d62c1f9ab4c323bd8484c142541ac77ad73e">Blocksec phalcon交易信息</a></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9935eaa4eb95b314705e3d1b88dbea9de2c12dec9d59e63e924fff37fe5000ea.png" alt="来自Blocksec phalcon区块链浏览器交易信息" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">来自Blocksec phalcon区块链浏览器交易信息</figcaption></figure><p>BSC-USD 的合约源码显示transferFrom()函数顺序调用了转账_transfer()与授权_approve()函数</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ca6b3a84d135abad1f102e27e7bf23b4189e9a0306aeaca0a25819995be1b164.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>_transfer()函数的作用很简单，首先排除交易中的全零地址，然后给发送方减钱，接受者加钱，最后记录转账事件。这里用到的加减函数add()/sub()是OpenZeppelin的safemath库，溢出会报错回退</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c6785bc41f98ab310281a83857ee1a28e87ab933e220cb0cd525e31c41e32a11.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>_approve()函数同样排除全零地址，修改授权值，这个函数的重点在transferFrom中调用approve的参数计算里，用到了<code>_allowances[sender][_msgSender()].sub(amount, &quot;BEP20: transfer amount exceeds allowance&quot;)</code> ，将已有的授权token数量减去转账数量，剩余的授权数量放入approve重新授权。这里用到的减函数sub是OpenZeppelin的safemath库，溢出会报错回退；<strong>但是如果整个流程的amount参数为零，没有任何检测机制能拒绝这笔交易，也就导致了链上大量的 0U 转账能正常发送，而黑客只需要付出手续费即可收获不菲的回报。</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/01dc8f530fadf572fa18ff643f83948831e03e6b55f32d05238e8bfede88dd52.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>transfer()</strong></p><p>调用transfer()函数的攻击方式原理一致，整个流程只有加减的溢出检测，没有对零转账的过滤。</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/582966ecaaa5b583351c832dd1d5809ef87e5ef05cc846fdca33ea67cf77826e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>BNB</strong></p><p>在token的攻击追溯过程中，我们还发现了通过0 BNB转账的首尾相同钓鱼攻击，原理与token钓鱼类似，构造首尾相同的地址进行钓鱼</p><p>攻击交易：<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/tx/0x5ae6a7b8e3ee1f342153c1992ef9170788e024c4142941590857d773c63ceeb3">https://bscscan.com/tx/0x5ae6a7b8e3ee1f342153c1992ef9170788e024c4142941590857d773c63ceeb3</a></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a99770d7acccaa39104ea1fbf720f68b488b069bd60d4cad29b09e294f1874b0.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>构造地址后迷惑性非常高，一不小心就转错到黑客地址上</p><p>正常用户地址：<strong>0x69c</strong>b60065ddd0197e0837fac61f8de8e186c<strong>2a73</strong></p><p>黑客构造地址：<strong>0x69c</strong>22da7a26a322ace4098cba637b39fa0a4<strong>2a73</strong></p><h2 id="h-6-x-explore" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">6. X-explore 攻击检测</h2><p>目前X-explore可针对此类攻击行为进行实时的链上监测，为了避免危害进一步加剧，我们建议：</p><ol><li><p>钱包App通过颜色或其他提示帮助用户区分地址，并做好用户提醒；</p></li><li><p>用户在转账前仔细区分历史交易地址，逐字确认，最好自己存一份地址簿。</p></li></ol><p>与此同时，我们在 Dune 中开源了此次攻击事件的态势感知大图。</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dune.com/opang/first-and-last-address-construction">https://dune.com/opang/first-and-last-address-construction</a></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/2ce692d1a6e29dc01645901bad4b41dc1205c720654c6f171cda2bb07012aba3.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>敬请关注我们。</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/bcf15c102ad7ae92ddfb2f4ba8f9ccd634fb61eb623119bb66a3c4f810e8a473.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Address Poisoning  Attack, A continuing Threat]]></title>
            <link>https://paragraph.com/@x-explore/address-poisoning-attack-a-continuing-threat</link>
            <guid>Dp6IHi7znrBwaJCdtqF3</guid>
            <pubDate>Fri, 02 Dec 2022 13:52:26 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain.Abstract:The address poisoning attack on $0 USD transfers is savage in recent weeks. As of December 2, more than 340K addresses have been poisoned on the chain, totaling 99 victim addresses and more than 1.64M USD stolen. In this article, X-explore provides a comprehensive analysis of the attack landscape, traces the attackers on-chain, and also provides an in-depth analysis of how the attack is implemented. We would like to appe...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><h3 id="h-abstract" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Abstract:</h3><p>The address poisoning attack on $0 USD transfers is savage in recent weeks. As of December 2, more than 340K addresses have been poisoned on the chain, totaling 99 victim addresses and <strong>more than 1.64M USD</strong> stolen.</p><p>In this article, X-explore provides a comprehensive analysis of the attack landscape, traces the attackers on-chain, and also provides an in-depth analysis of how the attack is implemented.</p><p>We would like to appeal to wallet apps to step up risk alerts and ordinary users to be aware of such attacks when transferring tokens.</p><h2 id="h-1-background" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. Background</h2><p>Recently, our on-chain risk monitoring found that $0 USD transfers occur frequently on ETH and BSC chains. We took the following BSC chain transaction data as an example to illurstrate how is this going. After VICTIM A sends a normal transaction to send 452 BSC-USD to USER B, USER B will immediately receive 0 BSC-USD from ATTACKER C. At the same time, within the same transaction hash, USER A himself will uncontrollably transfer 0 BSC-USD to ATTACKER C (realizing a &quot;back and forth&quot; 0 BSC-USD transfer operation)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/70679530672881a3a2baca53efedf22ff2adaa5d70e0ff003a5b976e3fc1c0d1.png" alt="Phenomena appears in the list of user transactions" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Phenomena appears in the list of user transactions</figcaption></figure><p>Many users in the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.reddit.com/r/binance/comments/z2r1j3/is_this_an_attack_on_the_binance_chain_0_ust/">social media community</a> are unaware of this and fear that their wallet private keys have been compromised, and attackers are stealing assets.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f928841ccb8e9cb26100114ed6d2ae9cb03e49ac41aeec9a850819f534bafed8.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2-attack-intention" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. Attack Intention</h2><p>In fact, users who encounter this situation do not need to be nervous, everyone&apos;s assets are safe, the private key is not leaked, you just need to carefully confirm the address and not transfer the wrong address is fine. The hacker&apos;s methods are very simple:</p><ol><li><p>The hacker monitors the transfer information of several stablecoins on the chain and captures the transfer information that victim address A normally sends to user B.</p></li><li><p>The hacker carefully constructs a hacker address C with the same first and last digits as user address B, so that victim A and hacker address C transfer 0U to each other. (Here the attacker can use the pretty number generation tool Profanity to generate an address with the same first and last 7 digits as the user address in a few seconds)</p></li><li><p>The next time Victim A carelessly copies the address of the historical transaction, it is easy to copy it to the address C prepared by the hacker by mistake, thus transferring the funds to the wrong account</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c9e1af5c7f2a536a0d45fa285fa7a630d8b8d58f81d252e539daf1c2d56bcf15.png" alt="Victims transfer money to normal addresses" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Victims transfer money to normal addresses</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6720578a290930e8b137226ad52bd757be54ae15a59d5205f217d97572a5c697.png" alt="Hacking address to victims to turn $0" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Hacking address to victims to turn $0</figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ef360614a77a2a8e885a0810feefe1322180e0d812d1b81b5b284a101aefa571.png" alt="Victims transfer money to hacker addresses" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Victims transfer money to hacker addresses</figcaption></figure><p>We consider this attack to be an on-chain address poisoning attack:</p><ol><li><p>First, the hacker makes his address appear in the user&apos;s transaction history, luring the user into mistaking it for a trusted interaction address.</p></li><li><p>In addition, the hacker constructs an address that has the same first and last digits as the user&apos;s trusted address and is used by the user for the next transaction.</p></li></ol><p>Users are vulnerable to capital loss under double poisoning, and all on-chain users need to be on guard together!</p><h2 id="h-3-attack-trend" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. Attack Trend</h2><p>As of December 2, the number of attacks on the BSC and ETH chains exceeded 290,000 and 40,000, respectively, and the number of independent addresses affected by the attacks exceeded 150,000 and 36,000, respectively.</p><p>In terms of trends, the BSC chain has been exploding since Nov. 22, while the ETH chain has been exploding since Nov. 27, with the scale of attacks on both chains intensifying.</p><p>In addition, it can be seen that there is a significant regularity in the timing of the attacks, with a significant decrease in the volume of attacks between 17:00 UTC and 0:00 UTC each day. The suspected attackers are in the Asian time zone.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1d007ac835240038e4a30dab4d0901ad01da04c1866cf1c80cc9eccbbf21804a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>As of December 2, a total of 94 unique addresses have been scammed, with a <strong>cumulative total of</strong> <strong>1,640,000</strong> <strong>USD</strong>, and with the increase in attackers&apos; targets, it is expected that a large number of users will continue to be scammed in the near future.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/526abcab6a5fc98c6fbe080c53936fe249895c7107d10a5e31a39a2eaceaf373.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6afd27f575bdab9205ce9ce992bf48f2cf95f71407b522a8996387a761c490f4.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In addition, we analyzed the attacker&apos;s cost of attack and the total cost is currently close to 25,000 USD (46 BNB + 9 ETH), with the attacker having a strong preference for BSC-USD and USDT, related to the coin circulation and user holdings of the stablecoin.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/bbf77a142c1f497fa400d9cc5ad1bd87c5916882c45298a4b1159c38e32685b5.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/946b5de58e044f0001463c4ee3294320bb5315065389b3c8b46ebbca81ce0bf9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-4-attacker-traceability" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">4. Attacker Traceability</h2><p>We trace <strong>one of the attackers</strong>, associated with two major centralized exchanges, the complete process is shown in the figure below.</p><ol><li><p>The source address of its attack funds is associated with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://OKX.com">OKX.com</a>, and the attacker transfers the original attack funds from the TRON chain to the BSC chain by using the Transit.Finance cross-chain bridge.</p></li><li><p>The stolen funds are eventually attributed to <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://Huobi.com">Huobi.com</a>, and the attacker is still using the Transit.Finance cross-chain bridge to transfer the stolen funds to the TRON chain.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f4d5c5e57501b09edbe281f62f98db4ae65b8b04147e332350c8617a880558ed.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Let us expand further and trace the flow of the stolen funds to the source.</p><p>First, the victim address 0xe17c2b2b40574d229a251fe3776e6da2cc46aa5e transfers a total of 1300U to the attacker address 0x720c1cfe1bfc38b3b21c20961262ad1e095a6867 in two installments.</p><p>Next, the attacker address deposit the funds to address 0x89e692c1b31e7f03b7b9cbb1c7ab7872ddeadd49</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/31a6cc6d9fb5f46adf2adc5aa5079e256fe7a06fae12ee8e5b42413982affe1c.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The attacker performed a cross-chain transfer of funds at address 0x89e692c1b31e7f03b7b9cbb1c7ab7872ddeadd49, in a txhash of 0 x72905bd839f682f795946d285500143ee7606e9690df2ad32968e878ad290d9f in the transaction as shown below, passing 10561 USDT through the contract of Transit.Finance (0 xb45a2dda996c32e93b8c47098e90ed0e7ab18e39) was Crossed. In the Event Logs of this transaction, you can see that the funds went to the USDT of the TRON chain. The corresponding address is TLUKBw37BVWDZdhbGco2ZEfdMd5Cit8TMD, corresponding to the transaction hash on the TRON chain is: 716507136ad28717ffd5f2f437af753ff96d344d2bcbe83f24d801db49f5a884</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/78a9a63b5523b71c10bda3e99bf3f84907000915ad18bd11809cc5b3ad4e5e0b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5cb0642f79baa6df7677efd3dd47e57a668d2c8a50016517a10aba5dc868735b.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/4df97a78f2774e75c3626b89b6408074c6455ed45e1c0020f6acd8fcbdddce76.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Eventually, the attacker topped up the TLUKBw37BVWDZdhbGco2ZEfdMd5Cit8TMD address into the Huobi exchange. The deposit addresses for the top-ups are: TPtzsrCAG61QMwig3jZV8Px7Rd1WZVnRXG, TDp7r3S1hJeiNfH1CvCVXeY8notY47nagJ</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0250d4e664f6fa8bfd85d2376fa51b9ef86a75b7a790d5ef6efb1958dbe778ae.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/8560aba8baf656f020c73d0007b50938ebc34fe2054f95de1dcb9d131f0e04e0.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-5-analysis-of-the-principle-of-the-attack" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">5. Analysis of the Principle of the Attack</h2><p><strong>Attacker Case 1:</strong></p><blockquote><p>EOA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0xBAA1451bE8C33998CD43F375c2e67E79c1a104AD">0xBAA1451bE8C33998CD43F375c2e67E79c1a104AD</a></p><p>CA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x7cebeb6035b231a73cb5fb4119c2fbbc04ec6fd1">0x7ceBeb6035B231A73CB5Fb4119c2FbBC04Ec6fD1</a></p></blockquote><p><strong>Attacker Case 2:</strong></p><blockquote><p>EOA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x616384a80f32aDb65243522971aE2ba7664B62E3">0x616384a80f32aDb65243522971aE2ba7664B62E3</a></p><p>CA: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/address/0x6f00Ed594A6AceEf0E1A6FE023Ecd5Eb96c8665a">0x6f00Ed594A6AceEf0E1A6FE023Ecd5Eb96c8665a</a></p></blockquote><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/073702431f157e82bbb9c8a0db5911cbf9ab43b231eaa07447710dfaa2fafce6.png" alt="Hackers control different addresses and transfer 0 BSC-USD to victim addresses in a batch through contracts" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Hackers control different addresses and transfer 0 BSC-USD to victim addresses in a batch through contracts</figcaption></figure><p>The token attacks on the bsc chain mainly include BSC-USD, BUSD, USDC, ETH, etc. Most of them are through the batch call of transferFrom() function by the attack contract, but there are also cases of manual call of transfer() function and the case for the main coin. The principle is basically the same. The following is an example of an attack contract with BSC-USD.</p><p><strong>transferFrom()</strong></p><p>In a transaction where the attacker calls the attack contract, the attack contract only calls the transferFrom() function of BSC-USD, and by filling the parameters with sender, recipient, and amount, it can manipulate the 0 USD transfer between any addresses, and at the same time generate the events of AuthorizeApproval() and TransferTransfer().</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://phalcon.blocksec.com/tx/bsc/0x825a3281e1897239c01797e590d3d62c1f9ab4c323bd8484c142541ac77ad73e">https://phalcon.blocksec.com/tx/bsc/0x825a3281e1897239c01797e590d3d62c1f9ab4c323bd8484c142541ac77ad73e</a></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9935eaa4eb95b314705e3d1b88dbea9de2c12dec9d59e63e924fff37fe5000ea.png" alt="From Blocksec phalcon blockchain browser transaction information" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">From Blocksec phalcon blockchain browser transaction information</figcaption></figure><p>The source code of the BSC-USD contract shows that the transferFrom() function calls the _transfer() and _approve() functions in sequence.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ca6b3a84d135abad1f102e27e7bf23b4189e9a0306aeaca0a25819995be1b164.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The _transfer() function has a simple function. First, it excludes all-zero addresses from the transaction, then it subtracts money for the sender and adds money for the receiver, and finally it records the transfer event. The add and subtract functions used here add()/sub() are OpenZeppelin&apos;s safemath library, and overflow will report an error revert.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c6785bc41f98ab310281a83857ee1a28e87ab933e220cb0cd525e31c41e32a11.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>The _approve() function also excludes the full zero address and modifies the authorization value. The focus of this function is in the parameter calculation of the transferFrom call to approve, which uses<code>_allowances[sender][_msgSender()].sub(amount, &quot;BEP20: transfer amount exceeds allowance&quot;)</code> , to subtract the number of existing authorization tokens from the transfer The remaining authorization amount is put into approve and re-authorized. The subtraction function sub() used here is OpenZeppelin&apos;s safemath library, and overflow will report an error revert; <strong>however, if the parameter amount of the whole process is zero, no detection mechanism can reject the transaction, which also leads to a large number of $0 transfers on the chain that can be sent normally, and the hacker only needs to pay a fee to reap a significant return.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/01dc8f530fadf572fa18ff643f83948831e03e6b55f32d05238e8bfede88dd52.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>transfer()</strong></p><p>Call transfer () function of the attack in the same way as the principle, the whole process only adds or subtracts the overflow detection, there is no filtering of the zero transfer.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/582966ecaaa5b583351c832dd1d5809ef87e5ef05cc846fdca33ea67cf77826e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>BNB</strong></p><p>In the process of token attack tracing, we also found the first and last identical phishing attack through 0 BNB transfer, the principle is similar to token phishing, constructing the first and last identical address for phishing.</p><p>Attack Transactions: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bscscan.com/tx/0x5ae6a7b8e3ee1f342153c1992ef9170788e024c4142941590857d773c63ceeb3">https://bscscan.com/tx/0x5ae6a7b8e3ee1f342153c1992ef9170788e024c4142941590857d773c63ceeb3</a></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a99770d7acccaa39104ea1fbf720f68b488b069bd60d4cad29b09e294f1874b0.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>After constructing the address is very confusing, accidentally transferred to the wrong hacker address</p><blockquote><p>Normal user address: <strong>0x69c</strong>b60065ddd0197e0837fac61f8de8e186c<strong>2a73</strong></p><p>Hacker construction address: <strong>0x69c</strong>22da7a26a322ace4098cba637b39fa0a4<strong>2a73</strong></p></blockquote><h2 id="h-6-x-explore-attack-detection" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">6. X-explore attack detection</h2><p>X-explore currently provides the real-time on-chain monitoring for such attacks. In order to avoid further harm, we recommend that:</p><ol><li><p>The Wallet App helps users distinguish addresses through color or other prompts, and does a good job of alerting users.</p></li><li><p>Users should carefully distinguish and double check historical transaction addresses when transferring funds, preferably by keeping an address book on their own.</p></li></ol><p>In the meantime, we developed and revealed this address poisoning attack on data basis as the reference, which are supported by Dune.</p><p>dune dashboard: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dune.com/opang/first-and-last-address-construction">https://dune.com/opang/first-and-last-address-construction</a></p><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/bcf15c102ad7ae92ddfb2f4ba8f9ccd634fb61eb623119bb66a3c4f810e8a473.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Sybil Attack WARNING--Mycelium]]></title>
            <link>https://paragraph.com/@x-explore/sybil-attack-warning-mycelium</link>
            <guid>UquEkfSVNUMA8eHlkFfx</guid>
            <pubDate>Mon, 07 Nov 2022 12:15:03 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. Conclusion: X-explore announces a Sybil attack warning. The Mycelium project has been suffering from large Sybil attacks since last month. More than 90% of the addresses of the NFT OG given by the Mycelium project on the Arbitrum chain are low quality address and more than 60% of addresses are considered as sybils.1. Project OverviewDomain: Defi / Dex Website: https://mycelium.xyz/ Chain: Arbitrum/ETH Participated Addresses: 236...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p><strong>Conclusion:</strong> X-explore announces a Sybil attack warning. The Mycelium project has been suffering from large Sybil attacks since last month. More than 90% of the addresses of the NFT OG given by the Mycelium project on the Arbitrum chain are low quality address and more than 60% of addresses are considered as sybils.</p><h2 id="h-1-project-overview" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. Project Overview</h2><p><strong>Domain:</strong> Defi / Dex</p><p><strong>Website:</strong> <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mycelium.xyz/">https://mycelium.xyz/</a></p><p><strong>Chain:</strong> Arbitrum/ETH</p><p><strong>Participated Addresses:</strong> 2369 Arbitrum, 623 ETH</p><p><strong>NFT Contract Address</strong>: 0xcf72978cf3f17a6194a394888a1d7a4e6effa405</p><p>Mycelium was formerly known as Tracer DAO. In August 2022, TracerDAO was upgraded and transitioned to Mycelium. Mycelium has launched the first perpetual future contract &quot;Mycelium Perpetual Swaps&quot; on Arbitrum chain.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/211c6858090404bc1d07b82f297fbe11472e42759df90d8e3e87abebba822a8e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>After TracerDao migrated to MYC, Mycelium officially launched the following activities until now. Users can swap TCR tokens and MCY tokens on 1:1. After the swap is successful, they can receive an NFT issued by the Mycelium project for free. The Mycelium does not set any entry requirement on the amount of swap so that users can use a tiny amount of TCR token to swap MYC token while returning a Mycelium OG NFT at almost zero cost. Addresses holding OG NFT have a greater chance of getting airdrops in the future. This zero-entry requirement breeds the econnoisseur to pour into the Mycelium project.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/95317996b327aa8ccc14fd598d97f9db5026daff119048f90f2e7872249d8b3f.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-2-sybil-attack-data-analysis" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. Sybil Attack Data Analysis</h2><p><strong>2.1 MYC Token Amount</strong></p><p>We found that the amount of MYC tokens swapped by most addresses that obtained Mycelium NFT on the Arbitrum chain is extremely small, and users spend almost 0 costs to get an NFT for free. Therefore, we speculate that those users who transacted a tiny amount of MYC tokens are probably the econnoisseur. Compared with the Arbitrum chain, the quality of addresses on the ETH chain is much better. The users on ETH tend to purchase and hold a bulk of MYC tokens.</p><p>Based on the statistics we have, a total of over 60% (about 1500) Arbitrum addresses got free NFT for less than 10 MYC tokens, around 0.5 USD. Compared to the Arbitrum chain, only about 10% of ETH addresses swapped MYC tokens for less than 10, and more than 80% of ETH addresses purchased more than 100 MYC tokens when they received the MOGs.</p><p>As shown in the figure below, on the Arbitrum chain, there are more than 60% of users with about 1,500 addresses traded less than 10 MYC tokens. it is worth mentioning that since October 20, the number of low-quality addresses with small MYC transactions in exchange for AMOGs NFT has suddenly increased, and the proportion has soared to more than 90%. we deduce that these addresses are most likely wool users. Compared with the Arbitrum chain, the address quality on the ETH chain is relatively premium, and both the percentage of low-quality users and the absolute number have been far lower than that of the Arbitrum chain.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6791ca4032d2e36a56907e369817824ece2f263cc5a0062c07ba78a605609134.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>2.2 Token Balance Status</strong></p><p>More than half of Aribtrum&apos;s obtained AMOGs addresses have a balance of less than $5, which further suggests that the quality of the addresses obtained for AMOGs NFT is poor.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/897aa9627cecd23c4ec7afcce693e527a959544608870e884ba539943a298bb1.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-3-sybil-attack-example" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. Sybil Attack Example</h2><p>We discovered that on October 27th, there were Sybil attacks on the Arbitrum chain, with a total group size of 35, for the following reasons.</p><ol><li><p>Same source of fund: the address is 0x641C00A822e8b671738d32a431a4Fb6074E5c79d</p></li><li><p>Same Swap method: both swapped USDT for WETH at Uniswap, swapped WETH for TCR at Sushiswap on the same day on October 27, and finally exchanged TCR for MYC and got AMOGs NFT on the same day</p></li><li><p>Highly consistent on other behavior: all are small swaps, and all are involved in GMX staking and other coins Elk, VSTA, SPA token transactions</p></li></ol><p>As shown in the figure:</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3c90a4ee3317c966bc58f3fdbb16118cd336a64798513d972dea676ee02a71dc.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-4-x-explore-comment" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">4. X-explore Comment</h2><p>The project owner needs to design reasonable campaign rules to attract users and avoid a large influx of econnoisseur. Mycelium has no limit on SWAP amount, causing econnoisseur to receive NFT OG at a few cents cost. X-explore suggests that establishing the prescreen steps of the address is needed for future airdrops on Mycelium.</p><p>For more, please follow x-explore. Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/7cbc8965cc1421a198c690b7784aaa88b61a8deb8390b24b65c0e58eeb40113b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[FTX&3commas API theft on-chain traceability AND Bittrex attack warning]]></title>
            <link>https://paragraph.com/@x-explore/ftx-3commas-api-theft-on-chain-traceability-and-bittrex-attack-warning</link>
            <guid>gLly4xM6kxnAaDdlKaVo</guid>
            <pubDate>Mon, 24 Oct 2022 13:30:18 GMT</pubDate>
            <description><![CDATA[This article is jointly published by X-explore and WuBlockchain. X-explore found that the attackers in the FTX&3commas API theft also attacked Binance US and Bittrex exchanges, stealing 1053ETH and 301ETH respectively. At present, the attack on Bittrex is still in progress, and it is suspected of using the NXT/BTC trading pair to attack.1. BackgroundIn order to help users and marketmakers to conduct high-frequency & quantitative transactions, exchanges provide API interfaces for transaction, ...]]></description>
            <content:encoded><![CDATA[<p>This article is jointly published by X-explore and WuBlockchain.</p><p>X-explore found that the attackers in the FTX&amp;3commas API theft also attacked <strong>Binance US</strong> and <strong>Bittrex</strong> exchanges, stealing <strong>1053ETH</strong> and <strong>301ETH</strong> respectively. At present, <strong>the attack on Bittrex is still in progress</strong>, and it is suspected of using the <strong>NXT/BTC</strong> trading pair to attack.</p><h2 id="h-1-background" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">1. Background</h2><p>In order to help users and marketmakers to conduct high-frequency &amp; quantitative transactions, exchanges provide API interfaces for transaction, asset query and withdraw. Also, the DEX platforms such as DYDX also provide API interface.</p><p>Therefore, many trading robot services can conduct quantitative trading, grid trading and historical data simulation test via API interfaces in the market. The well-known platforms are: 3Commas, Cryptohopper, Quadency. Meanwhile, these APIs can implement tax calculation functions and generate annual tax reports for users. The well-known platforms are: TokenTax and CoinTracker.</p><p>On October 21st, a <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/907370528/status/1583428185672548357">Twitter user</a> claimed that his FTX account was stolen on October 19, and he lost $160W through API interface in the DMG/USD trading pair.</p><p>On October 24th, FTX founder <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/SBF_FTX/status/1584304082671767552">SBF tweeted</a> that FTX will provide about $6 million in compensation to account holders affected by the phishing incident and posted 3 attacker addresses.</p><pre data-type="codeBlock" text="a) 0x6D3e6Ba1b510287141b27F763A86E04c72a001D1
b) 0xaB8bd0D4Eda57cd9EE5A058e498A791dF13dFA65
c) 0x87c828593984381E50D55F755B8462e074047Cf7
"><code><span class="hljs-selector-tag">a</span>) <span class="hljs-number">0</span>x6D3e6Ba1b510287141b27F763A86E04c72a001D1
<span class="hljs-selector-tag">b</span>) <span class="hljs-number">0</span>xaB8bd0D4Eda57cd9EE5A058e498A791dF13dFA65
c) <span class="hljs-number">0</span>x87c828593984381E50D55F755B8462e074047Cf7
</code></pre><p>X-explore do an in-depth analysis on chain.</p><h2 id="h-2-on-chain-traceability-analysis" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">2. On-chain traceability analysis</h2><h3 id="h-21-ftx-attacker-address-iocs" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.1 FTX ATTACKER ADDRESS IOCs</h3><p>The attacker used multiple addresses and interacted with multiple exchanges, which we describe one by one:</p><p><strong>ATTACK WITHDRAW ADDRESSES FROM FTX:</strong></p><p>In SBF twitter, the attacker gains 600W. In fact, the 3 addresses provided by SBF have a total of about 2000 ETH. Through on-chain mining, we added 2 related attackaddresses which withdraw ETH from FTX.</p><pre data-type="codeBlock" text="0x6D3e6Ba1b510287141b27F763A86E04c72a001D1 (890 ETH)
0xaB8bd0D4Eda57cd9EE5A058e498A791dF13dFA65 (824 ETH)
0x87c828593984381E50D55F755B8462e074047Cf7 (1112 ETH)
0xeEc49F195096389E725ade6aAb49Db779EF3b881 (972 ETH)
0xcA92077aCD49b523045754C1fE3Ccc1D7710b119 (170 ETH)
"><code><span class="hljs-number">0</span>x6D3e6Ba1b510287141b27F763A86E04c72a001D1 (<span class="hljs-number">890</span> ETH)
<span class="hljs-number">0</span>xaB8bd0D4Eda57cd9EE5A058e498A791dF13dFA65 (<span class="hljs-number">824</span> ETH)
<span class="hljs-number">0</span>x87c828593984381E50D55F755B8462e074047Cf7 (<span class="hljs-number">1112</span> ETH)
<span class="hljs-number">0</span>xeEc49F195096389E725ade6aAb49Db779EF3b881 (<span class="hljs-number">972</span> ETH)
<span class="hljs-number">0</span>xcA92077aCD49b523045754C1fE3Ccc1D7710b119 (<span class="hljs-number">170</span> ETH)
</code></pre><p><strong>ATTACK PERSONAL ADDRESSES:</strong> The attacker uses many addresses to transfer ETH. We provide some of them.</p><pre data-type="codeBlock" text="0xdd7D5f5eCE60b859430C7a56e3d5942238141560
0x948d5194E37F022cBD7b26B6c0560fE804bA7F6f
0xaeECB7860Eb6D7929Be5Bb34Ce94F21Befc6ead3
0x929c271d123041A142bF1575ea0026F1D8Fa7C49
0xf261F3c80d1226583EaeCbdA62DDefFD676E237a
0x1321af1a1b26374807e8cc31838A2c914031DA86
"><code></code></pre><p><strong>ATTACK DEPOSIT ADDRESSES IN CEX:</strong></p><p>Attacker deposits ETH to CEX. We provide CEX deposit addresses. All deposits to FTX are a small amount of ETH, which is used as the starting capital for the attack. All deposits to BINANCE and FIXFLOAT is a method for attackers to use CEX for money laundering.</p><pre data-type="codeBlock" text="0x133824f213778Ac5193a2bC8b2e987E9dDd739B1 (FTX Deposit 19.9 ETH)
0xcE7aB58A1CDBA37c17E7d8C4569ec6803b8126eF (FTX Deposit 20.09 ETH)
0xC3Bb6dA4182175f9316f3a705D22Ee382Fb825bB (FTX Deposit 66.41 ETH)
0x2B390759EE8b5222AE59BBAa92d2c904ec09FdB2 (FTX Deposit 20 ETH)
0x0Ee325A15FC9257166089335C98d344E8dBfa5fc (BINANCE Deposit 500 ETH)
0x6108c4D519CEAF61022DC57512Df5c9D1059bB44 (FixedFloat Deposit 45 ETH)
0x44a4718064E383ad30b56349fC5F1845C721D056 (FixedFloat Deposit 45 ETH)
(Other FixedFloat 40+ Addresses with Deposit 45 ETH Each)
"><code><span class="hljs-number">0</span>x133824f213778Ac5193a2bC8b2e987E9dDd739B1 (FTX Deposit <span class="hljs-number">19.9</span> ETH)
<span class="hljs-number">0</span>xcE7aB58A1CDBA37c17E7d8C4569ec6803b8126eF (FTX Deposit <span class="hljs-number">20.09</span> ETH)
<span class="hljs-number">0</span>xC3Bb6dA4182175f9316f3a705D22Ee382Fb825bB (FTX Deposit <span class="hljs-number">66.41</span> ETH)
<span class="hljs-number">0</span>x2B390759EE8b5222AE59BBAa92d2c904ec09FdB2 (FTX Deposit <span class="hljs-number">20</span> ETH)
<span class="hljs-number">0</span>x0Ee325A15FC9257166089335C98d344E8dBfa5fc (BINANCE Deposit <span class="hljs-number">500</span> ETH)
<span class="hljs-number">0</span>x6108c4D519CEAF61022DC57512Df5c9D1059bB44 (FixedFloat Deposit <span class="hljs-number">45</span> ETH)
<span class="hljs-number">0</span>x44a4718064E383ad30b56349fC5F1845C721D056 (FixedFloat Deposit <span class="hljs-number">45</span> ETH)
(Other FixedFloat <span class="hljs-number">40</span>+ Addresses with Deposit <span class="hljs-number">45</span> ETH Each)
</code></pre><h3 id="h-22-other-cex-attack-analysis" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2.2 Other CEX attack analysis</h3><p><strong>2.2.1 Binance US</strong></p><p>Based on the second address (0xaeECB7860Eb6D7929Be5Bb34Ce94F21Befc6ead3) published by twitter, we found an API theft attack against Binance US. The attack occurred between October 13th and October 17th, and a total of 1053 ETH was stolen. Associated attacker address 0xaeECB7860Eb6D7929Be5Bb34Ce94F21Befc6ead3. According to the flow of funds, we can see that most of the stolen funds are collected to various exchanges through one or more transfer jumps.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3771181c5eeb148f812e0b073871e0ba8c67280d722884d97d6087ba8ede861d.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Furthermore, we found that the attackers were suspected of using SYS/USD trading pair for asset transfers. It generates a large number of transactions in a short period of time, and the attacker&apos;s on-chain withdrawal time all occurs within a short period of time after the transaction ends.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5f02a949d676d7266132496d9ad5c843f55328b10b626155a87be3d63e45690a.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>2.2.2 Bittrex</strong></p><p>Based on the first address (0x6D3e6Ba1b510287141b27F763A86E04c72a001D1) published by twitter, we found an API theft attack against Bittrex. The attack occurred between October 23 and October 24, and a total of 301ETH were stolen. The associated attacker addresses are as follows.</p><pre data-type="codeBlock" text="0xD72ca629b850D3BB0bb07BfE160dEB9D83aCd66E
0xcAdc25c58d1106587235B0e0F5Df58F7B2480391
0xdD7BBF14960fFaBE66911A689c27ff095b9393b7
0x81866E125A6a750EE7BCB891e924e549768D28B0
0x2a03C993d5d448dCBB5284d58920Ca48E9D366E4
0x7dDB99087304D9A5E029ddeC1771E95df7b07002
"><code></code></pre><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/6b89c9d869f32048d68c5b4e4fe506801b0a66059aa91ee347de216f022f9881.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://global.bittrex.com/home/markets">spot trading volume ranking</a> currently displayed on BITTREX, NXT Token ranks second. This currency is only listed on BITTREX and Poloniex, and there is basically little trading volume before October 23. It is very likely that the attacker use the NXT/BTC trading pair to attack.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/cffdd0f852860d6b80176e525992e53d417753468da136cc33aae30938988e54.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/ec57d948db2c7517972b02f9e1b50981276483e0d264c00b16ae363d8f337e64.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-3-x-explore-comment" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">3. X-explore Comment</h2><p>This incident revealed a new way of theft, in which attackers complete the transfer of assets between different accounts by controlling transactions. It can bring a lot of reflection to the exchange.</p><ol><li><p>Basic security: From a security perspective, the least credible is human nature. Therefore, exchanges need to design more secure product logic to ensure that users are not damaged by phishing attacks without affecting the user experience.</p></li><li><p>Spot token security: In order to provide users with more trading options, the top exchanges have launched a large number of tokens. After the market popularity of some tokens passed, the trading volume dropped sharply, but the exchanges did not delist them. According to <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://coinmarketcap.com/rankings/exchanges/">CoinMarketCap data</a>, Gateio exchange and MEXC exchange both support 1000+ trading spot pairs.</p></li><li><p>Transaction security: Based on FTX&apos;s DMG/USD trading pair transaction volume line, when the attack occurs, the transaction volume increases by a thousand times, and the currency price fluctuates by 2-3 times, which is a significant abnormal transaction event.</p></li></ol><p>For more info, please subscribe: Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a> Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/fe86208f61d9c05b4259adf5a88a669fb626a28573ba6bf931f0fad0b62f318f.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[APTOS Source Analysis and Sybil Attack Alert for Binance Users]]></title>
            <link>https://paragraph.com/@x-explore/aptos-source-analysis-and-sybil-attack-alert-for-binance-users</link>
            <guid>pttBVBmdAJpu6nl4ngZL</guid>
            <pubDate>Thu, 20 Oct 2022 05:29:04 GMT</pubDate>
            <description><![CDATA[Overview: X-explore analyzed the source of funds for all APTOS topping up to Binance. We found that 65% of the funds were deposited to the sybil address, accumulating over 6.3M APT Token, or over $50M in profit based on $8. This brought about severe selling pressure, causing the price of the currency to go all the way down. Meanwhile, we analyzed the correlation between the total amount of deposits and the coin price. This article is jointly published by X-explore and WuBlockchain.Project Int...]]></description>
            <content:encoded><![CDATA[<p><strong>Overview</strong>: X-explore analyzed the source of funds for all APTOS topping up to Binance. We found that 65% of the funds were deposited to the sybil address, accumulating over 6.3M APT Token, or over $50M in profit based on $8. This brought about severe selling pressure, causing the price of the currency to go all the way down. Meanwhile, we analyzed the correlation between the total amount of deposits and the coin price. This article is jointly published by X-explore and WuBlockchain.</p><h2 id="h-project-introduction" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Project Introduction</h2><p>Aptos, a leader of new public chains that is specialized into a modular public chain project, has recently launched its mainnet. Aptos is a Layer1 public chain project initiated by members of the original Facebook/Libra team, with the goal of building the most secure and scalable Layer1 blockchain. The Aptos ecosystem currently has established over two hundred projects. In March, Aptos already received two rounds of funding totaling $350 million from a16z, FTX Ventures, Jump Crypto, Multicoin Capital, Three Arrows Capital, Binance Labs and other investors.</p><p>Yesterday (October 18) Aptos officially announced the airdrop program: users who completed the Aptos Incentive Test Network application or minted the APTOS:ZERO Test Network NFT are eligible to claim APT tokens. A total of 20,076,150 APTs will be airdropped to 110,235 participants.</p><p>According to WuBlockchain Twitter, Aptos saw a huge crash after Binance went live (19th, 1:00 AM UTC), someone put up a sell order of 189,567 APTs for $13 USD, suspected to be a project or sybil attacker crash, which we have analyzed in depth.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7e47cbb6f21f85a41427d231bdab9a1c8a5191d52f99d5f00fce43fc16288431.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-funding-analysis" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Funding Analysis</h2><p>The chart below shows the component analysis of the source of funds deposited by all users of the Binance exchange. As of 12:00PM UTC on October 19, Binance has accumulated 28,000 users deposited over 16,300,000 APT. Of these, 4,120,000 were deposited by market makers, and nearly 40%, or over 6,300,000, were deposited by X-explore as sybil addresses.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b093154624108632927a2cfe7484d25060afb5e5fb17e7a53d8b27acd79937de.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Market maker deposits are mainly concentrated before the opening of the market and within one hour after the opening of the market.</p><p>As time goes by, the total amount of deposits keeps decreasing, but the ratio of Sybil addresses to ordinary users&apos; deposits remains basically the same, with Sybil users accounting for more than 65% of total deposits. The following addresses are the addresses of large sybil groups that deposit more than 50K APT in Binance.</p><pre data-type="codeBlock" text="0xa790b09cae194cf6f17f12da81ef137878664675c44a486e69844a3942c2cc29
0xc60bd606076dd3f4f18318bfbf3dea38fdddc8599b632b0b0c5a6ce4431dcb0e
0x10f0b3ee9c7faecc47301ba1437b98a0434e2b3f627e35e3885ade8d2962f386
0xb00986514903bbbf2eb24263189750cf3692dc29773fe498052c85bfaec9aaf2
0x9251b53515da4a0073c89f539087f9d7431896c65c3d2f24b34663d4cf594583
0xf4d5e40b1054512e9b9f58e5f461cf7894544fb0897d4387743d1aceffb6395f
0xdac7d74eeec88ec6966db806e8b08f88de50895ebbbe2893b91a52d771a9f99b
"><code></code></pre><p>In addition, we have an interesting finding: <strong>There is a significant correlation between the price of APT in Binance and the volume of deposits.</strong></p><ol><li><p>APT suffered a sustained plunge after the opening quotation, falling from $13 to as low as $6.7. This was probably due to the huge amount of deposits from the airdrop addresses.</p></li><li><p>Starting from 3:00 UTC, the deposit volume started to decrease and the selling pressure gradually decreased, bringing a rally in the coin price, up to around $9.</p></li><li><p>From 6:00 UTC, the amount of deposits remained constant and the rate of reduction slowed down . These are the other reasons for the drop in the price of the coin.</p></li><li><p>At 8:00 UTC, the deposit volume was halved again and the coin price thus rebounded again.</p></li></ol><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fd1b609e1f165e0ec14361440392801940b9da1bd347dada7f8a089ab4d59c76.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-x-explore-reviews" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">X-explore Reviews</h2><p>Aptos was too hasty in marketing the airdrop campaign. A huge number of Sybil addresses flocked into the exchange to cash out their coins because the release of the airdrop was setup before the listing of the main exchanges and Aptos did not make Sybil attack screening, which brought great selling pressure on Token and caused the price to plummet in the early days of the launch. Obviously, it is not friendly for real users.</p><p>We hope that all project parties will adopt a more robust marketing approach to avoid such incidents from happening again.</p><p>For more info, please subscribe:</p><p>Mirror: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/x-explore.eth">https://mirror.xyz/x-explore.eth</a></p><p>Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/x_explore_eth">https://twitter.com/x_explore_eth</a></p>]]></content:encoded>
            <author>x-explore@newsletter.paragraph.com (X-explore)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/be49be399700447b5e8a75becbf04217cd0a86ea64a5e6f7619bdf0e2b4c4e5d.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>