Original title: "PartyBid crowdfunding has the risk of "sybil attack", how should the NFT fragmentation protocol deal with it?" "
Original author: Crypto Ming, Huige, Ivan, DeBox Institute
The underlying protocol for using PartyBid crowdfunding to purchase NFT is NFT fragmentation, That is to divide a complete NFT into any number of equal parts, and holding these equal parts is equivalent to holding a part of the NFT. Tessera (formerly known as Fractional) is currently the leader in the NFT fragmentation market. PartyBid and Tessera have also received large financing led by A16z and Paradigm respectively.
According to Dune’s on-chain data, the activities of PartyBid and Tessera show a strong positive correlation. On the contrary, the activity is on the rise, indicating that the liquidity of NFT in the bear market may be mainly provided by some underlying protocols, and a model similar to NFT fragmentation is being recognized by users.
PartyBid's crowdfunding to buy NFT and Tessera's auction of NFT can realize the flow of NFT very well. This process is realized through DAO. However, the process is vulnerable to "sybil attacks". Witches can hold more than 50% of the total number of NFT fragmented Tokens to obtain superior voting rights, and then manipulate NFT auctions, while members participating in crowdfunding can only redeem part of the crowdfunding. raised funds.
Although there is currently no mature and available DID system to help identify user identities, specific to the PartyBid and Tessera projects, it is possible to use some on-chain tags (on-chain Data Kanban) and binding social media (Twitter, etc.) to help users identify possible Sybil attack risks.
You want to own BAYC, Doodles, Azuki these blue chip NFTs? Don’t need 80ETH, don’t need 10ETH, just spend 0.01ETH on PartyBid to participate in crowdfunding and you can become one of the holders of blue-chip NFT. Doesn’t it sound cool? This is due to the fragmentation of NFT-one of the mainstream liquidity protocols of NFT.
We all know that the non-homogeneous nature of NFT will lead to its poor liquidity, you can only buy and sell in units of the entire NFT, and you have to If you want to sell, someone must buy or make an offer, otherwise you can only keep placing orders and cannot sell. The NFT market is also gradually exploring how to improve the liquidity of NFT. At present, there are many liquidity agreements such as NFT leasing, NFT lending, NFT fragmentation, and NFT-Fi.

Table 1 NFT liquidity Overview of Protocol Projects
Among many NFT liquidity protocols, can NFT be like FT (homogeneous Token), only Part of the transaction, and can buy and sell at any time? Especially for blue-chip NFTs with extremely high floor prices, which cost dozens or hundreds of ETH, you can buy 0.1 BTC, but how do you buy 0.1 Cryptopunks? The NFT fragmentation protocol gives the answer.

Figure 1 Conceptual diagram of NFT fragmentation
On the surface, NFT fragmentation is to A complete NFT is divided into any number of equal parts, and holding these equal parts is equivalent to holding a part of this NFT.
From a technical point of view, NFT fragmentation is actually to transfer NFT into a new vault contract, and create any number of ERC20-Token at the same time, These Tokens can be distributed to any address, and can also be used for market making (AMM). Token holders have the right to vote on the asset activities in the vault contract. The larger the number of Tokens held, the greater the voting weight. higher.
Currently, the mainstream NFT fragmentation protocol applications in the NFT market include Tessera, Unicly, NFT20, ShardingDAO, and PartyBid. Among them, Tessera (formerly known as Fractional) is the leader of the NFT fragmentation protocol. The original Shiba Inu The Doge NFT of Doge Coin (Doge Coin) was fragmented in Tessera. The NFT was fragmented into 16,969,696,969 DOG Tokens. 9451 holders or owners of The Doge NFT. Tessera has raised $20 million in funding led by Paradigm.

Figure 2 The Doge NFT
PartyBid is a crowdfunding platform launched by PartyDAO through user crowdfunding Funds form a DAO to bid for NFT products. PartyDAO is a real DAO-driven community. Its members include Paradigm's research partner Dave White, Mirror's founder Denis Nazarov and other top leaders in the Web3.0 industry. Currently, PartyDAO has announced that they have received $16.4 million in financing led by A16z. With a valuation of 200 million US dollars, this is the highest valuation of a community-driven DAO so far.

Figure 3 Establishment of PartyDAO
This article mainly discusses the two projects Tessera and PartyBid. We can use Dune's data dashboard to understand the activity of PartyBid and Tessera.

Figure 4 Opensea, PartyBid, Tessera (Fractional) Active Data Kanban
< br>
Opensea is the main trading market for NFT, and the trading volume of Opensea also represents the popularity of the NFT market in the corresponding period. Judging from the data on the chain, the activity of PartyBid and Tessera has a negative correlation with the market heat of Opensea’s response. From June 2022 to the present, the popularity of the NFT market has declined severely, while the activity of PartyBid and Tessera has shown an upward trend instead. It shows that the liquidity of NFT in the bear market may be mainly provided by some NFT liquidity agreements. A model similar to NFT fragmentation is being recognized by users. Of course, it may also be related to project financing. The financing announced by PartyBid in June and Tessera announced in August financing. In addition, the activities of PartyBid and Tessera are also significantly positively correlated, which also shows that the two projects are closely related to the activities on the chain. For example, after PartyBid crowdfunding buys NFT, it can auction NFT through Tessera.
The PartyBid platform allows retail investors to initiate and participate in crowdfunding to buy NFT. After success, the contract will be fragmented into NFT, and participants will hold a part of the blue-chip NFT at this time . Holders can buy and sell the NFT fragmented tokens they hold by establishing liquidity. Of course, they can also call on members to sell the NFT through DAO auctions.
In the above description, we can see a widely used example, buy NFT in PartyBid crowdfunding, and then sell the NFT in Tessera In this way, the application example of DAO in the whole process of executing NFT market trading activities is realized, and the flow of NFT is perfectly realized. Therefore, it can be said that PartyBid and Tessera are complementary.

Figure 5 Overview of the whole process of PartyBid crowdfunding and Tessera auction
At present, many KOLs on Twitter are launching crowdfunding through PartyBid, trying to buy some blue-chip NFTs, such as Doodles, Azuki, etc., and the gameplay is also PartyBid crowdfunding plus Tessera’s bidding model, so for members participating in crowdfunding, is there any risk of being scammed or cheated by this model?
Here is a more common way, witch attack. Witch attack is also called Sybil attack, the name comes from the movie "Witch" (Sybil), which tells the story of a woman with 16 personalities in psychotherapy. The sybil attack in the blockchain refers to a malicious node illegally presenting multiple identities to the outside world. Specific to the application examples of DAO, DAO of Web3.0 brings like-minded people together through a common goal, and uses smart contracts to run voting, and then promotes community development in a bottom-up manner. In a DAO, a single user can own multiple wallets and hoard tokens to achieve 51% voting power, and then manipulate decisions.
Lido DAO Sells 10 Million LDOs to Dragonfly Capital Token Sybil attack appeared in the proposal, Dragonfly Capital holds 1.5 million LDO through its Dragonfly Liquid department Token The address in the proposal voted in favor of the proposal that was beneficial to itself. It once accounted for 99.35% of the entire voting weight and was almost passed. Although it was finally revealed by the community members based on the information on the chain, the proposal was eventually rejected by the community. Veto, but Sybil attacks like this are hard to guard against in the DAO voting and governance process.

Figure 6 Example of Lido DAO being attacked by a Sybil
It can be seen that during the DAO governance voting process, Sybil attacks are a common occurrence. Going back to the NFT crowdfunding and bidding process of PartyBid and Tessera, the successful users who participated in the crowdfunding and purchased NFT became members of the NFT crowdfunding DAO when they claimed the fragmented Token, and subsequently bid for NFT on Tessera Among them, only DAO members are eligible to bid for NFT, so this gives witches a good opportunity to attack.
Sybil attack mode 1: When the NFT crowdfunding amount is higher than the floor price of this type of NFT, the initiator will use the crowdfunding amount at a price higher than the floor price Buy your own NFT at a certain price. This type of attack requires the initiator's wallet address to have at least one NFT with a higher price.
Sybil Attack Mode 2: The attacker can use multiple wallets to participate in crowdfunding, holding more than 50% of the total number of fragments to gain an advantage in voting rights, and then manipulate the NFT auction. According to Tessera's auction rules, the witch can control the bidding reserve price, and at the same time control the time to choose the bidding, and finally get the NFT at a price far lower than the floor price of this type of NFT, while the members participating in the crowdfunding can only redeem a small amount raised funds.
For example, Xiao Ming is a KOL. He initiated crowdfunding on PartyBid and wants to buy an Azuki with 10ETH. When the crowdfunding amount meets 49% of the Azuki floor , Xiao Ming quickly made up the remaining 51% of the crowdfunding amount through his 20 wallet addresses. After the purchase was successful, Xiao Ming held more than 50% of the fragmented Azuki. At this time, although other members set the NFT auction reserve price on Tessera, since they hold 49% of the Azuki fragments in total, there is no more than 50% limit, so as long as Xiao Ming does not participate in setting the auction low price, the next bid cannot be made , this Azuki will be temporarily locked in the contract (vault).
After waiting for 3 months, the floor price of Azuki suddenly rose back to twice that of when I bought it. At this time, Xiao Ming felt that he could sell this Azuki. So I used my own fragmented Azuki address to set the auction reserve price very low (the more you hold, the greater the weight of setting the auction reserve price), and since the auction bidding process is only 3 days, members will not be notified when the auction starts, and finally NFT With the bidding reserve price of 3ETH, Xiao Ming got the Azuki, and then sold it in the NFT market at a price of 20ETH. At this time, the DAO treasury of the crowdfunding members is only 3ETH, of which 1.5ETH is the corresponding proportion of Token held by Xiao Ming. Other crowdfunding participants have shrunk by 66.7% compared to the initial payment amount of 10ETH, and compared with the actual transaction price of 20ETH sold by Xiao Ming, it has shrunk by 85%. Finally, Xiao Ming completed the Sybil attack.
In this case, the Sybil attacker may not be the initiator of the crowdfunding, and only needs to meet more than 50% of the NFT fragmented Token positions to attack, so Witches can collect chips by establishing a liquidity pool of NFT fragmentation Token.
Some time ago, V God proposed a non-transferable Token called Soulbound Token (soul binding), which will be used to create Web3 user identity system. After the concept of SBT was proposed, the DID track began to become one of the hot spots of public attention. DID (Decentralized Identifier) is a user's decentralized identity.
The DID system will use multi-dimensional information, such as on-chain activity data, social media activities, etc., to form a comprehensive image of Web3 users. DID can reduce the risk of sybil attacks by distinguishing real users from potential bots. If an account address lacks a diverse real history, we can immediately identify them as bots.
Although there is currently no mature and available DID system for everyone to use, but specific to the PartyBid and Tessera projects, you can use some on-chain tags and bind social media The way to help users identify the possible risks of Sybil attacks.
For example, PartyBid classifies the addresses participating in crowdfunding, and at the same time makes a data board, the information includes how many times the address has participated in crowdfunding, except crowdfunding , Have you ever participated in the interaction of Uniswap or Opensea, and how much do these addresses account for in the total crowdfunding? Do these addresses have frequent transfer transactions with each other?
Let participants bind their own social media accounts (such as Twitter, etc.), etc., and even if a user finds that the crowdfunding activity has been attacked by a witch, they can report it Ways to label this NFT crowdfunding or certain suspicious addresses, so that participants can understand this fact.
Tessera's auction process can also use these methods to defend against witches.
Through the above means, the cost of sybil attacks and the risk of attack failure can be greatly increased, and sybil attacks can be effectively prevented to a certain extent.
This article is from a contribution and does not represent the views of BlockBeats.
Original link a>
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia