The @DegenTrashPanda mint was paused to address vulnerabilities in the Candy Machine NFT deployment protocol
CMv2 was rewritten in a frenzy of coding by @redacted_j and just 2 weeks later, the mint is now reopened
Some background on CMv2 & why you should be excited for DTP🧵👇
The DTP mint kicked off late November. Shortly after it was discovered that many super rare & mythic tokens were being sniped by a botter. The community investigated, went through the details & took action.
Several factors created conditions that supported the botting: 1. There was a full week between the FLP lottery & mint 2. A market to trade DTP tokens was created on dexlabs
This gave time for the botter to acquire a large # of tokens in preparation for the mint
3. The size of the mint (20k tokens).. 4. .. & the fact it was open indefinitely meant that people were didn't have to mint quickly (though this may not have mattered since they utilized DDoS attacks) 5. Lastly & crucially, the metadata & order of the CM was retrievable
#5 is the key flaw of CM v1 that allowed sniping. The order mattered less in previous mints because they used to sell out within seconds, making it difficult to snipe.
Though of course those mints were still susceptible to bots flooding transactions like @AuroryProject
In this case the botter used DDoS attacks to slow down the CM and lock minters out when a super rare was approaching, creating 400+ transactions in 30 seconds right before successfully minting the Crown Admiral.
After this the bot transactions went quiet for 14 minutes then...
... the bots fired up again and sent 500+ transactions in 40 seconds to jam the CM in anticipation of snagging this Acid Panda token which it then successfully minted.
Given the severe botting the mint was paused on November 29 to allow this exploit to be rectified.
... Enter Candy Machine v2. Written in a coding frenzy by @redacted_j, working with Brett from @civickey to implement the Captcha to gatekeep minting entries.
CMv2 uses recent blockhash for random selection of arweave URLs.
After you fill out the captcha it grants temporary program derived address (PDA) for a short duration.
The PDA is owned by the Civic identity program and when you mint the PDA is "punched" & invalidated.
This is pretty effective at stopping bots because on top of the randomness and PDA, CMv2 only allows instructions in the transaction from only the token program and the Candy Machine - preventing cherry picking attacks.
The biggest challenge of CMv2 is keeping CPU usage low with the random selection of arweave urls so @redacted_j implemented a method to speed up entry assignment - making CMv2 fairly viable and cheap. Still, you may notice some lag while using it!
CMv2 was first deployed and tested on the "People Nipple Cats" which was a test mint.
Needless to say, I miiiiiiiiiiiiiiiinted.
(Bonus: the art references previous disaster project @TheBearGangNFT)
It didn't take long for the bots to start arriving, but so far CMv2 was able to deal with them pretty well.
So where does this leave us?
- 14173 tokens have been minted with ~6k to go
- Most of the ill gotten gains have been sold back into the market to holders who want to participate in the project
- 114 DTP tokens still held by the botter
- Mint is now open for you to safely proceed
Since the mint has restarted, it's nice to see people starting to mint super rares & mythics after this joy was robbed from the rest of us - people old and new to Solana NFTs.
While its been relatively quiet, rest assured @pit_the_panda has been busy implementing. After all the Joker is a madman but he always seems to have a plan.
So after all of the hype, drama & controversy why should you still be excited?
1. @DegenTrashPanda remains an NFT project with a unique & innovative approach to blockchain gaming built by some of the best devs. CMv2 was written in 2 weeks meaning the team were able to get the help of industry-leading resources
2. The project is an entry point into the Degeniverse - a fun & irreverent brand underpinned by detailed 3D art (by Monoleaf? @monoliff) and represents exposure to one of the first major NFT projects that helped cement Solana as a viable blockchain for NFTs
3. By owning a DTP you gain access to the @DegenDAOO a strong and active community of builders, creatives, investors & pioneers on the Solana blockchain.
While there are a couple of channels that require you to have a Degen Ape, most are open to trash pandas
So far we've had IRL communities spring up in HK, Singapore, UK and the SF Bay area. Online we've started a parents channel, health & fitness and a gaming channel.
This is the community you join by hopping into the Degeniverse.
4. You have sideshow tickets to an entertaining rollercoaster ride. A shared experience.
NFTs with real life performance art mixed into a napalm cocktail delivered by flamethrower.
And we haven't even started the blockchain game yet.
So what now?
There are ~6k tokens left to mint, so get to it!
Then if you're up for the adventure, stick around and welcome to the Degeniverse.
Big thanks to @redacted_j & @Lumina191 who helped with some of the background research and details!
1/ At $50m The @CashioApp exploit was the 2nd largest heist on @solana & 13th largest hack overall. Despite this its been radio silence for hours.
@Saber_HQ have been working on it but have not been contacted by the exploiter.
Can anyone help? What we know & some thoughts🧵👇
2/ After the exploiter minted 2billion CASH they drained the CASH deposits of USDT & USDC ($26m) & swapped their remaining CASH tokens for ($25m) through @Saber_HQ crashing CASH's price to 0.
They now had~$50m of USDC/USDT/UST, $21m of which was swapped to ETH & wormholed to ETH
3/ All this was detailed by @0xavarek in this detailed thread:
2/ .. & they both just used that exchange to fund their activities
It's been 24 hours later and not much has emerged or been announced. There are many anxious investors in the Cashio, Saber & Sunny discords.
3/ Spreading risk is impt. Unfortunately in this instance many people have lost a large amount of USD (some upwards of millions) & it has been difficult for many to stay calm.
The hacker sent back amounts <$100k but not directly to user wallets (to LP-related side wallets)
In the last hour 100+ @DegenTrashPanda have been swept, raising the floor from 2.6◎ to 3◎. As you know, DTP is the companion Degeniverse project to @DegenApeAcademy.
Some observations & upcoming catalysts around the DTP game & $RAIN token 🦝💦🧵👇 #solana#solananfts#nfts
Over the last hour, wallet 8igPE has picked up over 100 Degen Trash Pandas. This is a different individual to the ones that bought 26 Degen Apes overnight.
8igPE holds 244 DTP as of writing along with 6 Panda Rugs & 84 Degen Apes - a big believer in the Degeniverse while also owning various other Solana NFTs like @TaiyoRobotics@SolanaMBS & @catalinawhales
A little bit of action this evening on the @DegenApeAcademy front with 26 apes being sold in quick succession over the last 3 hours to GMos & 10 individual buyers, bringing the floor to 58SOL🧵👇 #solana#solananfts#nfts#degenape
The ape buying was kicked off by wallet GMos 3 hours ago - with it buying 16 apes and transferring them to 2T5k, an account that holds $1.08m worth of @genopets GENE tokens & 24 @Gyris_official NFTs. nfteyez.global/accounts/2T5kb…
Since then there have been another 10 sales mostly on @MagicEden in the 55 to 65 SOL range.
All of these went to 10 different buyers, with the pink lady sailor heading @9x9x9eth's way.