ππ¦ΈββοΈ [monthly report - (June, July,) August 2021]

@keys-defender activity report for the month of (JUNE, JULY and) AUGUST
Β
Β

K E Y S Β P R O T E C T I O N:
@keys-defender's actions when a key leak is detected on the Hive blockchain:
- (automatically) puts funds in savings, including new incoming transfers [active key]
- (automatically) resets leaked keys [owner key]
- (automatically) warns the user via instant wallet memo or auto-reply [all other keys]
Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β [These can be verified on https://hiveblocks.com/@keys-defender]
- (manually) reach out to the owner on discord and hive chat, if the handle matches
Β
PRIVATE KEY LEAKS detected, and where possible protected:
JUNE: (7 leaks)
- Chain: steem (steem only account =[ ), type: ACTIVE key, operation: transfer- Estimated Account Value: $ 2.47
- Reputation: 48
- Followers: 63
- Account age: Joined 3/2021
@keys-defender's disclosure: kd-key-leak-ywn0axzlaxzhbmnlc3blzgvzc3rlzw0
- Estimated Account Value: $ 6.36
- Reputation: 48
- Followers: 12
- Account age: Joined 5/2021
- Estimated Account Value: $ 2.83
- Reputation: 45
- Followers: 9
- Account age: Joined 5/2021
- Estimated Account Value: $ 246.15
- Reputation: 58
- Followers: 105
- Account age: Joined 4/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2v1y2xpzdq5c3rlzw0
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 5/2021
@keys-defender's disclosure: kd-key-leak-cg9zdgluz21hag11czi0m3n0zwvt
- Estimated Account Value: $ 280.69
- Reputation: 64
- Followers: 145
- Account age: Joined 8/2020
@keys-defender's disclosure: kd-key-leak-ywn0axzlbg95zmvybwhpdmu
- Estimated Account Value: $ 0.8
- Reputation: 40
- Followers: 18
- Account age: Joined 6/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2noyxjsb3r0zwtzdgvlbq
JULY: (5 leaks)
- Estimated Account Value: $ 0.8
- Reputation: 40
- Followers: 18
- Account age: Joined 6/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2noyxjsb3r0zwtzdgvlbq
- Estimated Account Value: $ 6.58
- Reputation: 44
- Followers: 5
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-cg9zdgluz2zha3jpahvzywluaxn0zwvt
- Estimated Account Value: $ 0.06
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3n1ymlozwtvmtizagl2zq
- Estimated Account Value: $ 246.59
- Reputation: 58
- Followers: 105
- Account age: Joined 4/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2v1y2xpzdq5c3rlzw0
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3nhagfyyw1lzwhpdmu
AUGUST: (34 leaks!!!!)
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2hpc2nvb2xuzxnzagl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2prc2q4oghpdmu
- Estimated Account Value: $ 1
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2thdhp1cjroaxzl
- Estimated Account Value: $ 0.2
- Reputation: 30
- Followers: 9
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb21pcmlhbwlyagl2zq
,
- Estimated Account Value: $ 0.08
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2020
@keys-defender's disclosure: kd-key-leak-bwvtb3lvdw5nlte4agl2zq
- Estimated Account Value: $ 46.34
- Reputation: 55
- Followers: 7
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-ywn0axzla2fyb2nvbnqymdexagl2zq
- Estimated Account Value: $ 0.01
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2r1bgfhbm95zhvsywhpdmu
- Estimated Account Value: $ 0.76
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3zuyzgxagl2zq
- Estimated Account Value: $ 28.96
- Reputation: 53
- Followers: 28
- Account age: Joined 6/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2fzywqwnmhpdmu
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2fzdwxlagl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3n0cmf3adhtzxjlbgxoaxzl
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb25vd2eyagl2zq
- Estimated Account Value: $ 0.13
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3zjmjiwoghpdmu
- Estimated Account Value: $ 0.66
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2thbgxlbi0wnghpdmu
- Estimated Account Value: $ 33.64
- Reputation: 53
- Followers: 10
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2rsbw1xymhpdmu
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3rpzw50bte4nwhpdmu
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2zyaxr6amftzxmxowhpdmu
- Estimated Account Value: $ 1.98
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3y0dwdobms0zwxoaxzl
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2m0zxnzexy0ew5lagl2zq
- Estimated Account Value: $ 0
- Reputation: 28
- Followers: 1
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2nqywjlbgxlcmezagl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-cg9zdgluz2vhcmxhywhoaxzl
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3dhenphdhvydgxlagl2zq
- Estimated Account Value: $ 0.59
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2nhbgxpzte2agl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 6
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-cg9zdgluz3nhaxbozxiynghpdmu
- Estimated Account Value: $ 0.95
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3jvc3nlcmvzagl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 7/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3noywszc3azyxizagl2zq
- Estimated Account Value: $ 85.89
- Reputation: 54
- Followers: 3548
- Account age: Joined 9/2017
@keys-defender's disclosure: kd-key-leak-cg9zdgluz2fuyw5kamfkagfvagl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2dvb2rkyxl5zwvoaxzl
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
@keys-defender's disclosure: kd-key-leak-bwvtb2hpdgxhbmqymwhpdmu
- Estimated Account Value: $ 28.98
- Reputation: 25
- Followers: 2
- Account age: Joined 1/2019
@keys-defender's disclosure: kd-key-leak-cg9zdgluz2t3awouehl6agl2zq
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
- Estimated Account Value: $ 7163.36
- Reputation: 71
- Followers: 909
- Account age: Joined 7/2017
@keys-defender's disclosure: kd-key-leak-ywn0axzlampwcmfjagl2zq
- Estimated Account Value: $ 53.61
- Reputation: 48
- Followers: 22
- Account age: Joined 5/2021
@keys-defender's disclosure: kd-key-leak-bwvtb3bvcgnvcm4ynghpdmu
- Estimated Account Value: $ 0
- Reputation: 25
- Followers: 0
- Account age: Joined 8/2021
NOTE: @keys-defender still scans the STEEM blockchain because your private keys are shared across the two chains unless you reset your password at https://wallet.hive.blog/@your-username-here/password ! - do it!
Cold scan
- 3x MEMO KEYS
- 39x POSTING KEYS
- 2x ACTIVE KEYS
- 1x ACTIVE KEY
- 55x POSTING KEYS
- 13x MEMO KEYS
+ Live scan: o a a a a a a p p a a p p a a a p p p p p a p p p p p p m m p p p a p o p m a m m p p p p p p p p p p p p p p p p p p a m p m m m m m p m p p p p m p p m p a p p p a a Β (june) `a m m m p a m` Β (july) `m p m m m` Β (august) `m m m m m a m m m m m m m m m m m m m m p m m p m m p m m p p a m m`
Β
= TOT: 242
Β Β (65 memo keys, 151 posting keys, 24 active keys, 2 owner keys)
What's going on @steemmonsters @splinterlands ??
About 90% of the leaks this month are from new Splinterlands users. Please instruct them on how to use their keys!

PHISHING LINKS detected (and auto-replied to): Β June & July: HUNDREDS
Β
SCAM LINKS:
- new reports: June: 6, July: 2, August: 1
- detected (and auto-replied to) on Hive: Β 0

CODE INJECTIONS detected on Hive: Β June: 5, July: 1
1. @shoutmon (Splinterlands dev) - a few XSS tests -> eg. https://hive-db.com/block/55208602
2. False positive, just a copy and paste or autogenerated post: https://hiveblocks.com/exxp/@omardothussain/thefutureofcryptoknowledgeontheblockchainweveripediacofounder-mahbodmoghadamep1-18q0zzjysctvxmjqm194
Β
UNSAFE LINKS detected:
- Shortened links: 20.8/h -> ~14,976/month. Auto-replies/warnings throttled 1/20.
- HTTP links: 51.8/h -> ~37,296/month. Auto-replies/warnings throttled 1/20.
NOTE: links that do not use a secure protocol (https) and shortened links (eg. bit.ly) are NOT a threat per se but can lead to theft of credentials if misused or used in a malicious attack.



O T H E R Β A C T I V I T I E S: Β --> This section will eventually be moved to @hive-defender

Confirmed re-posting authors: Β 0
Got some hits to review. No one is monitoring my bot's (a bit noisy) warnings.. :(

Downvotes of @keys-defender (and its trail) against abusers: Β
The auto-votes against @crystalan
that had been farming comments for months stopped on June 3rd because of its ceased activity
Not many manual downvotes lately. Got a few logs for suspicious votes to review.
Β
@keys-defender currently follows the hiveflagreward team's downvote trail
@keys-defender is downvoting: farming waves, phishing waves and old hive haters.
Β
Followers of my downvote-trail: Β 7 Β (plus their own trail - about $ 10 downvote power in total) -> PLEASE JOIN
DEVELOPMENT UPDATE:
(june, july, august)
- Moonwalk feature - rescan of previous 1000 blocks triggered by an accepted phishing report on chain
- On-chain command to rescan a target range of blocks against phishing
- Utility (!leak discord command) to publish a leak post after manual review (eg. avoid duplicates)
- Witness node automatically changed if the one in use is having issues
- Switched to use another witness node for cold-scans in order to avoid throttling (ie. 503 api responses) cold scan = when for some reason I have to rescan a set of previous blocks
- Utility (!lookup discord command) to generate html snippets for each leak for my (time-consuming) monthly report.
- Bug fixes (eg. some rare hangs in the block streaming logic)
Β
- Future development -
As before..
- Mute lists and tests in testing community using @key-defender.shh - blocktrades's fix was released and my features seems working - further tests required
- Formula to counteract exact votes (plus UI?) -- ** deferred **
- Universal script to use new banlists. + other improvements + PR for condenser
- Allow community to remove entries from ban lists
- pwnd emails check (quick feature)
- Abuse reports (rewarded) and separate abuse lists (plagiarism, farming, etc)
- Tech-only proposal to cover expenses ??
- Old (huge) backlog
π
- XSS vulnerabilities in #########.com
- XSS vulnerabilities in hive-db.com
- XSS vulnerabilities in scribe.hivekings.com
- XSS vulnerabilities in hiveblockexplorer.com
- Malicious ads redirecting all Steemit iOS users to a phishing site
- Reverse tabnabbing and clickjacking in steem.chat and steeemit registration page
Other contributions:
- Universal script to prevent phishing in all Hive frontends
- Commands for community reports and ban lists
Keys-Defender features:
- Phishing protection [live scan of commentsa and posts to warn users against known phishing campaigns and compromised domains, scan of memos]
- Re-posting detection [mitigates the issue of re-posters]
- Code injections detection [live scan of blocks for malicious code targeting dapps of the Hive ecosystem]
- Anti abuse efforts [counteracts spam from hive haters and milking campaigns]
To support this project:

Follow my curation trail on hive.vote to upvote all my posts with a fixed weight.
Β Β Β Β Β Β Β If you like what I'm doing please upvote, delegate π or auto-vote π my posts. Thx! π
It has to be drilled into new users that they need to protect their keys. They should load them into Keychain and keep a good backup. Have there been any new phishing campaigns?
!PIZZA
@keys-defender! I sent you a slice of $PIZZA on behalf of @steevc.
Did you know you can now buy Rising Star packs with $PIZZA? (3/10)
@steevc No new phishing campaigns in August that I'm aware of. At least not on Hive. It's mostly Splinterlands users leaking their memo key in wallet transfers or their posting key in account-update2 operations.
Great job @keys-defender, joined your downvote trail, not much but hope it helps.
Cheers
Hi @keys-defender!
I'd like to introduce you to our new project coming to Hive this September.
Lootjoy is a provably fair and transparent gaming platform powered by the Hive blockchain that allows its users to win NFTs from a wide variety of popular collections across a selection of major blockchains. This Septmeber we'll be giving our players the ability to win a selection of Splinterlands cards from our exclusive loot crates.
You can find out more in our introduction post:
https://peakd.com/splinterlands/@lootjoy/introducing-lootjoy-provably-fair-nft-loot-boxes-built-on-the-hive-blockchain
Keep up to date with our launch by following us on Hive or Twitter
Join us on Discord here