Over 21,000 Sybil wallets were used to fake on-chain activity in sophisticated ways.
An unidentified individual was found to have created an entire ecosystem, including 21,877 Sybil wallets, their own tokens, and even a decentralized exchange (DEX) to fake on-chain activity.
DeFi analyst reveals fake on-chain activity scheme
According to DeFi analyst @lingland09, the individual funded each of his wallets with a small amount of Ether (ETH) and then deployed a smart contract for a non-open-source token called Gem (GEM).
Warning: One person owns 21,877 sybil wallets #zkSync
Let’s expose the Sybil tactics of this guy who funded all his wallets with a very small amount of Ether, and then he deployed the non-open source Gemstone ($GEM) token. - Lingland 09. (@lingland09) September 10, 2023
After the token launch, the schemer developed a personal DEX and slowly passed transactions between his wallets to create the illusion of real activity. These transactions were cleverly spread across different months, weeks, and days to mimic the behavior of other L2 projects.
Once operational, the DEX was used to add liquidity to the GEM token with a funding of 80 ETH, artificially inflating the token’s value.
@lingland09 revealed that “he exchanged the $gem tokens he claimed from 21877 wallets with the gem/eth pair and received a profit value of 0.6-0.7 eth.”
This person also used the same liquidity over and over again, avoiding any negative impact of price slippage. As a result, they managed to execute transactions on the zkSync Era network with minimal fees.
The individual also created a trading bot to automate the process, generating 10 transactions on the zkSync Era network with a total transaction volume of $10,000. It is worth noting that analysts were only able to track down some of the fake wallets.
@lingland09 said, “Zkscan Explorer only supports 1k pages of history per contract. Therefore, I was only able to track down 10k wallets associated with this person’s actions.”
However, @the_matter_labs was able to identify all 21,877 fake Sybil wallets associated with the $gem token contract.
Suspicious activity related to alleged fake airdrop
The motives behind these actions are unclear. However, analysts speculate that this person is a “professional airdrop hunter” who may be preparing fake airdrops by creating activity on the zkSync Era network.
Airdrops are a common marketing tactic in the cryptocurrency world that are used by Sybil attackers to defraud users. Airdrops involve distributing free tokens or coins to generate interest. In a Sybil attack, an attacker creates multiple fake accounts impersonating real users with the goal of exploiting other users.
A recent example of this is Arbitrum’s March ARB governance token airdrop, which ran into issues due to an increase in Sybil activity caused by ineffective detection rules. According to crypto security researcher X-explore, over 279,328 identical addresses and 148,595 Sybil addresses exploited the flaws. #伪造钱包 #链上活动
