The Saint Eclectic Profile picture
Dec 16, 2021 27 tweets 20 min read Read on X
The @DegenTrashPanda mint was paused to address vulnerabilities in the Candy Machine NFT deployment protocol

CMv2 was rewritten in a frenzy of coding by @redacted_j and just 2 weeks later, the mint is now reopened

Some background on CMv2 & why you should be excited for DTP🧵👇 Image
The DTP mint kicked off late November. Shortly after it was discovered that many super rare & mythic tokens were being sniped by a botter. The community investigated, went through the details & took action.
Several factors created conditions that supported the botting:
1. There was a full week between the FLP lottery & mint
2. A market to trade DTP tokens was created on dexlabs

This gave time for the botter to acquire a large # of tokens in preparation for the mint
3. The size of the mint (20k tokens)..
4. .. & the fact it was open indefinitely meant that people were didn't have to mint quickly (though this may not have mattered since they utilized DDoS attacks)
5. Lastly & crucially, the metadata & order of the CM was retrievable
#5 is the key flaw of CM v1 that allowed sniping. The order mattered less in previous mints because they used to sell out within seconds, making it difficult to snipe.

Though of course those mints were still susceptible to bots flooding transactions like @AuroryProject Image
In this case the botter used DDoS attacks to slow down the CM and lock minters out when a super rare was approaching, creating 400+ transactions in 30 seconds right before successfully minting the Crown Admiral.

After this the bot transactions went quiet for 14 minutes then... Image
... the bots fired up again and sent 500+ transactions in 40 seconds to jam the CM in anticipation of snagging this Acid Panda token which it then successfully minted. Image
Given the severe botting the mint was paused on November 29 to allow this exploit to be rectified.

2 weeks later...
... Enter Candy Machine v2. Written in a coding frenzy by @redacted_j, working with Brett from @civickey to implement the Captcha to gatekeep minting entries.
CMv2 uses recent blockhash for random selection of arweave URLs.

After you fill out the captcha it grants temporary program derived address (PDA) for a short duration.

The PDA is owned by the Civic identity program and when you mint the PDA is "punched" & invalidated.
This is pretty effective at stopping bots because on top of the randomness and PDA, CMv2 only allows instructions in the transaction from only the token program and the Candy Machine - preventing cherry picking attacks.
The biggest challenge of CMv2 is keeping CPU usage low with the random selection of arweave urls so @redacted_j implemented a method to speed up entry assignment - making CMv2 fairly viable and cheap. Still, you may notice some lag while using it!
CMv2 was first deployed and tested on the "People Nipple Cats" which was a test mint.

Needless to say, I miiiiiiiiiiiiiiiinted.

(Bonus: the art references previous disaster project @TheBearGangNFT) Image
It didn't take long for the bots to start arriving, but so far CMv2 was able to deal with them pretty well.
So where does this leave us?
- 14173 tokens have been minted with ~6k to go
- Most of the ill gotten gains have been sold back into the market to holders who want to participate in the project
- 114 DTP tokens still held by the botter
- Mint is now open for you to safely proceed
Since the mint has restarted, it's nice to see people starting to mint super rares & mythics after this joy was robbed from the rest of us - people old and new to Solana NFTs.
While its been relatively quiet, rest assured @pit_the_panda has been busy implementing. After all the Joker is a madman but he always seems to have a plan.

So after all of the hype, drama & controversy why should you still be excited?
1. @DegenTrashPanda remains an NFT project with a unique & innovative approach to blockchain gaming built by some of the best devs. CMv2 was written in 2 weeks meaning the team were able to get the help of industry-leading resources Image
2. The project is an entry point into the Degeniverse - a fun & irreverent brand underpinned by detailed 3D art (by Monoleaf? @monoliff) and represents exposure to one of the first major NFT projects that helped cement Solana as a viable blockchain for NFTs Image
3. By owning a DTP you gain access to the @DegenDAOO a strong and active community of builders, creatives, investors & pioneers on the Solana blockchain.

While there are a couple of channels that require you to have a Degen Ape, most are open to trash pandas Image
So far we've had IRL communities spring up in HK, Singapore, UK and the SF Bay area. Online we've started a parents channel, health & fitness and a gaming channel.

This is the community you join by hopping into the Degeniverse.
4. You have sideshow tickets to an entertaining rollercoaster ride. A shared experience.

NFTs with real life performance art mixed into a napalm cocktail delivered by flamethrower.

And we haven't even started the blockchain game yet. Image
So what now?

There are ~6k tokens left to mint, so get to it!

Then if you're up for the adventure, stick around and welcome to the Degeniverse. Image
Big thanks to @redacted_j & @Lumina191 who helped with some of the background research and details!

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with The Saint Eclectic

The Saint Eclectic Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @sainteclectic

Jun 23, 2022
So the big #Solana announcement is here. What is SMS?

@solana Mobile Stack: a web 3 layer built on android allowing devs to create apps on the new… Solana phone: Saga 📱📈#blockchain #crypto Image
The phone will ship in 1Q23 and is the flagship product for Solana’s mobile endeavors Image
Three features that power the Saga:
- Seed Vault
- Mobile Wallet Adapter
- Solana Pay for Android (pay with any token anywhere)

All designed for you to be able to access and use your keys for blockchain transactions on the go Image
Read 5 tweets
Mar 25, 2022
1/ At $50m The @CashioApp exploit was the 2nd largest heist on @solana & 13th largest hack overall. Despite this its been radio silence for hours.

@Saber_HQ have been working on it but have not been contacted by the exploiter.

Can anyone help? What we know & some thoughts🧵👇
2/ After the exploiter minted 2billion CASH they drained the CASH deposits of USDT & USDC ($26m) & swapped their remaining CASH tokens for ($25m) through @Saber_HQ crashing CASH's price to 0.

They now had~$50m of USDC/USDT/UST, $21m of which was swapped to ETH & wormholed to ETH
3/ All this was detailed by @0xavarek in this detailed thread:


The attacker's SOL wallet was funded by @sideshiftai a non-KYC dex who could potentially help but have been mostly silent on twitter.
Read 16 tweets
Mar 24, 2022
1/ Yesterday it emerged that the @CashioApp hackers wallet being funded by "sWZs" which was the same address that funded the Balloonsville NFT rugger.

This is @sideshiftai's no-dox wormhole Dex, meaning they are probably unrelated...
@Saber_HQ @simplyianm @SBF_FTX @aeyakovenko Image
2/ .. & they both just used that exchange to fund their activities

It's been 24 hours later and not much has emerged or been announced. There are many anxious investors in the Cashio, Saber & Sunny discords.
3/ Spreading risk is impt. Unfortunately in this instance many people have lost a large amount of USD (some upwards of millions) & it has been difficult for many to stay calm.

The hacker sent back amounts <$100k but not directly to user wallets (to LP-related side wallets)
Read 8 tweets
Mar 23, 2022
In the last hour 100+ @DegenTrashPanda have been swept, raising the floor from 2.6◎ to 3◎. As you know, DTP is the companion Degeniverse project to @DegenApeAcademy.

Some observations & upcoming catalysts around the DTP game & $RAIN token 🦝💦🧵👇 #solana #solananfts #nfts Image
Over the last hour, wallet 8igPE has picked up over 100 Degen Trash Pandas. This is a different individual to the ones that bought 26 Degen Apes overnight.
8igPE holds 244 DTP as of writing along with 6 Panda Rugs & 84 Degen Apes - a big believer in the Degeniverse while also owning various other Solana NFTs like @TaiyoRobotics @SolanaMBS & @catalinawhales Image
Read 16 tweets
Mar 23, 2022
A little bit of action this evening on the @DegenApeAcademy front with 26 apes being sold in quick succession over the last 3 hours to GMos & 10 individual buyers, bringing the floor to 58SOL🧵👇 #solana #solananfts #nfts #degenape Image
The ape buying was kicked off by wallet GMos 3 hours ago - with it buying 16 apes and transferring them to 2T5k, an account that holds $1.08m worth of @genopets GENE tokens & 24 @Gyris_official NFTs.
nfteyez.global/accounts/2T5kb… Image
Since then there have been another 10 sales mostly on @MagicEden in the 55 to 65 SOL range.

All of these went to 10 different buyers, with the pink lady sailor heading @9x9x9eth's way. ImageImage
Read 5 tweets
Dec 31, 2021
Solanart was one of the first major NFT exchanges on #Solana. It has a record of behavior that does not live up to community standards.

We should demand better if we are serious about improving Solana and the onboarding of the next wave of users.🧵👇 #nft #solanacommunity Image
Recently many have alleged that Solanart engage in shady, neglectful & cash grabbing behavior. I first covered this topic 3 months ago.

With many new entrants to Solana, not everyone was aware of this.

Interestingly, new stories have come to light.
I will focus on the facts in this thread.

The intention is to share information, then you be the judge as a community and decide what is acceptable for our ecosystem.

Thank you to all of you who reached out - you are making the community a better place.
Read 47 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(