Coder Social home page Coder Social logo

forta-starter-kits's Introduction

forta-starter-kits

forta-starter-kits's People

Contributors

0xtaf avatar dikel avatar macbeth98 avatar notyouraveragedev avatar rcantu92 avatar stoqnkpl avatar vxatz avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar

forta-starter-kits's Issues

There are more builders than Flashbot that forta doesn't detect.

The Flashbot transaction detector is specific for flashbot, but there are more block builders in the space that forta should monitor. i would say that some generalized name could be "block builder transaction detector"
The other players in the ethereum ecosystem are:

Beaver Build
Seems new but is used a lot, they don’t even have a webpage.
Url: https://beaverbuild.org/

Titan Builder
Url: https://www.titanbuilder.xyz/

Rsync Builder

Builder0x69
Url: https://docs.builder0x69.io/

Also block builders are now in ethereum but soon will be in other chains as the efforts to modify the "geth" of each chain to "mev-geth" sucess, is a matter of time.

High number of drops for April

Hi vasilis,

I have been watching the performance for this bot for the month of April and it looks like it has a high number "tx_drops" for BSC chain, this issue might be also extending to the rest of the chains. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

FP mitigation on flashbot bot

Could we filter out just plain EOA to EOA value tx on the flashbot bot? I understand it has caused some FPs downstream on the attack detector.

Pig butchering label

Hi vasilis,

I Just analized 18 addresses with the pig butchering label.

Just a heads up, 14 were addresses where funds were drained but not the address that was approved. Anyway these are pig butchers too.

I believe there are other addresses involved in a pig butcher scam, let me briefly explain:

  • First the target receives funds from a CEX.

  • Then the target approves an EOA.

  • It may be the case where the target is fully drained and then repeat the process where the scammer is funded by a CEX, then drained again by the same EOA, etc.

  • However, it may be the case where the scammer gives away some sort of fake yield in USDT to the target. I believe this may sound like a sweetener to the target in a way that the person believes that the scammer is really investing funds. Then, the target is funded again by a CEX and then fully drained. These addresses, where fake yields were sent, are different from the ones that are used to fully drained the target. Let me attach you an example, (https://etherscan.io/address/0x57964769fe6ee9a814f3b353fbc11025312edc46#tokentxns). I'm mentioning this because it would be good to label these as pig butchers too.

Native Ice Phishing Detection Bot - August high drop Rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in ETH and BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

FP issue (contract creation bug) - ice phishing bot

Hi Vasilis,

Let me share another set of FPs I have found. In this case, the scam detector bot seems to be flagging addresses that are creating token contracts, opening pools in uniswap, then adding and removing liquidity. It seems like rug pulls but the scam detector is identifying this as ice phishing.

  1. Example1:
    Forta alert: https://explorer.forta.network/alert/0x228958ebd084fe1b60306ad673896118238ba8d76b8f37539319bc4ac3ca51cd
    Etherscan link: https://etherscan.io/address/0xa1d600554f118a7a876dd2362cfe80d805959b8a

2 Example2:
Forta alert: https://explorer.forta.network/alert/0xcfafa4b4d8d020e70f6339f3a1070fd48756309e43bab5593448d4b7e534e0ab
Etherscan link: https://etherscan.io/address/0x6138916d226ffba30ac7e38a83f5448be326355a

3 Example3:
Forta alert: https://explorer.forta.network/alert/0xadb78dda5ee6588455c0cff9eec348b12152fe1561ca0d7c4671c0e23b9db1a5
etherscan link: https://etherscan.io/address/0xf3d54f2106c3ad43bbcbdc2a8d0dc4b4ae4471de

Large Profit Bot - August high drop rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in ETH and BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

Fp mitigation - ice phishing

FN case

Hi there,

Seems like the pig butcher should have labeled this one.

Victim was funded by CEX with usdt and stolen as soon as funded.

Thanks

Private key Compromise | Tornado cash funding | Victim Identifier high August Drop rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in ETH and BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

Private key Compromise https://app.forta.network/bot/0x6ec42b92a54db0e533575e4ebda287b7d8ad628b14a2268398fd4b794074ea03
Tornado cash funding
https://explorer.forta.network/bot/0x617c356a4ad4b755035ef8024a87d36d895ee3cb0864e7ce9b3cf694dd80c82a
Victim Identifier
https://app.forta.network/bot/0x441d3228a68bbbcf04e6813f52306efcaf1e66f275d682e62499f44905215250

High Gas Use - August Drop Rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in ETH and BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

FP issue (USDT) - ice phishing bot

Hi Vasilis,

I have observed that the scam detector triggered many ice phishing alerts which I assessed like False positives. Apparently in many cases the bot is flagging addresses that seem to be stealing USDT but they are not.

Let me give you an example:

  1. Forta alert here: https://explorer.forta.network/alert/0xeab4a1b5236c7de40fa4aba959e7c5ca59fa3f7fd734526ca30e1559618e89a8
    Etherscan address here:
    https://etherscan.io/address/0x08a34cac368f1206a30803787d5e00cf4265c347

As you can see in this example, "targets" seem to be approving the suspected address and then funds are being sent to 0x4baE69a92C1F812Cb2B74fcd2f3E664aEa435c46. What is very strange is that in most of the cases, targets are interacting in many opportunities with the mentioned address which seems like something illogical.

Attaching you some other examples here:

Ice Phishing Detection Bot August Drop Rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

High drop rate in May for the asset-drained bot

Hi Vasilis, the asset-drained bot has some high drop rates in the month of may, in the BSC chain (though it only has one node assigned). Would appreciate you taking a look at it, and conisdering sharding. Thank you!

flashloan-detection-bot August Drop Rate

Hi!
I have been watching the performance for this bot for the month of August and it looks like it has a high drop rate in BSC. I would appreciate if you can check it out, and consider sharding as a potential solution to mitigate this.

FN on multichain drain

0xf947dfa6387710dd316cb9b1afec82d1f49d187426c8f6370000cddc2bec945d should have triggered; could you pls investigate why it did not?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.