Binance Square
#lastpixellive

lastpixellive

26 views
4 Discussing
Jc Harlston NBcA
·
--
A bot farm wrecked our airdrop. Twelve thousand accounts registered. Not one of them was a person. If you are running a giveaway through Telegram channels, the same thing can happen to you — and most projects never find out. Founders count the registrations, celebrate the growth, report it to investors. Then on listing day the farm sells everything at once and the price collapses on the real people who did show up. What happened to us, briefly: We set aside 10,000 free spots. Within 48 hours a farm had taken almost all of them. Ten referral links brought 300, 300, 300, 299, 299, 298 people each — ten real people do not land within three of each other. The captcha did not stop them. Cloudflare Turnstile was solved twelve thousand times; solving services cost about a dollar per thousand. They attached 12,680 wallets, every single address different. We got off lightly, because we have no token and nothing to sell. Projects with a token will not be that lucky. In the full write-up: how we identified them step by step, the SQL query you can run on your own project right now, and the one thing that finally cleared them off the board. [A BOT FARM ATE OUR AIRDROP — AND GOT NOTHING](https://www.binance.com/en/square/post/358756511214456) #Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive
A bot farm wrecked our airdrop. Twelve thousand accounts registered. Not one
of them was a person.

If you are running a giveaway through Telegram channels, the same thing can
happen to you — and most projects never find out. Founders count the
registrations, celebrate the growth, report it to investors. Then on listing
day the farm sells everything at once and the price collapses on the real
people who did show up.

What happened to us, briefly:

We set aside 10,000 free spots. Within 48 hours a farm had taken almost all of
them. Ten referral links brought 300, 300, 300, 299, 299, 298 people each — ten
real people do not land within three of each other.

The captcha did not stop them. Cloudflare Turnstile was solved twelve thousand
times; solving services cost about a dollar per thousand.

They attached 12,680 wallets, every single address different.

We got off lightly, because we have no token and nothing to sell. Projects with
a token will not be that lucky.

In the full write-up: how we identified them step by step, the SQL query you can
run on your own project right now, and the one thing that finally cleared them
off the board.

A BOT FARM ATE OUR AIRDROP — AND GOT NOTHING

#Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive
Article
A BOT FARM ATE OUR AIRDROP — AND GOT NOTHINGHOW IT STARTED We launched Last Pixel: a social experiment shaped as a survival game. The rules are simple. A canvas of one million squares, one per person. Claim a square, then confirm you are still there before your window closes — 24 hours at the start, one minute at the end. Miss once and your square is dark forever. Whoever is still confirming after everyone else has quit takes the pool — a full canvas puts a million dollars in it. No skill. No strategy. No luck. Pure stubbornness. Remember that. Everything below turns on it. HOW WE RAN THE AIRDROP An empty canvas attracts nobody, so to seed it we set aside 10,000 free squares. Finish a short quest, get a square, pay nothing. We announced it in one of the largest airdrop communities: two million followers on Telegram and 1.6 million on X. The post cost $449. It went out at 13:42. HOW WE CAUGHT THEM What looked wrong first was not the volume. It was how even it was. The squares were going out too smoothly for a crowd of real people. We grouped accounts by the referral link that brought them in. Ten links ran far ahead of everything else. This is how many each one brought: 300 300 300 300 299 299 298 298 298 297 Ten people do not accidentally invite 300, 300, 300, 299, 299, 298. That is not statistics. That is a config file. Then we looked at the accounts themselves. Their Telegram IDs all sit between 1.3 and 2.0 billion — registrations from 2020 and 2021, not one recent among them. Not new users. Aged stock, bought in bulk. Then we checked the clock. The post went out at 13:42. The first of the ten distributor accounts appeared at 17:38, the tenth at 18:25 — three of them within two seconds of each other. At 19:01 the flood began. They read the post, spent four hours building the rig, and pointed it at us the same evening. THE OTHER SIGNALS The quest had one optional task: join our Discord. It gave nothing and counted for nothing — we marked it optional because it is the heaviest step with the smallest return. It was completed by 5,439 out of 5,439. Real people never hit a hundred percent. Not on the mandatory steps, and certainly not on the one with no reward. And the median time from registration to holding a square: 48 seconds. No human joins a channel, waits for the membership check, reads a quiz question and answers it inside a minute. THE RISK IN EVERY TELEGRAM AIRDROP Here is what is worth knowing if you hand out tokens. The post you pay for is an announcement to your audience and a tip-off to a farm operator at the same time. He reads those channels precisely because that is where giveaways get published. Assume he is on your recipient list before you have even clicked "pay." A captcha will not save you. Cloudflare Turnstile stood in front of registration the whole time and was solved twelve thousand times. That is not a complaint about Cloudflare: solving costs about a dollar per thousand, and every captcha goes the same way regardless of whose it is. As an anti-bot defense, the captcha is finished. FIGHTING THE FARM Once it was clear the airdrop had failed, we did two things in a row. First we cut the giveaway from 10,000 to 6,000 and stopped it. Then we logged everyone out. Every session, every cookie, all at once. To confirm your window you now had to sign in through Telegram again. The reasoning was narrow. They had automated registration completely — twelve thousand accounts proved it. But re-authentication is a different code path, and scripts built for signup runs usually do not have it: after registering they keep the cookie and reuse it forever. We were betting on the gap between "can create an account" and "can create an account twice." We deleted nobody. We asked everyone to log in again. THEY DID NOT COME BACK The window closed at 23:48 UTC. By then all 6,000 squares we had given away were dark. The first 5,439 went out before the logout, on their own: they simply never came back to confirm their first window. The last 553 went dark after it. Not one of those accounts signed back in. The script could pass a captcha twelve thousand times. Answer the quiz. Join the channel. Tick the optional box. Attach a fresh wallet. Confirm on schedule for two days straight. It could not sign in a second time. That is the whole defense. Not a smarter captcha. Not machine learning. Not a fraud score. A logout button. It cost us something too. The logout hit everyone indiscriminately, and a real player lost his square simply because he never noticed he had been signed out. We put it back and gave him a full fresh window. He did nothing wrong. Our defense did. WHAT THEY WERE ACTUALLY AFTER Their playbook never changes: complete the airdrop, attach a wallet, wait for the token, sell everything in the first hour after listing. The wallet is the whole point. It is where the tokens are supposed to land. Of 12,821 accounts, 12,680 attached one. Every address different, not one repeat in twelve thousand. That is not people. That is a generator. There is no token. There never was. The quest handed out a square: no market, no transfer, no resale. The only way to use it is to keep coming back for weeks and pressing a button. Twelve thousand aged Telegram accounts, burned for the right to babysit a button. And the proof that leaves no room for doubt: after the free squares ran out, another 6,686 accounts registered anyway. 6,656 attached a wallet. Zero completed the quiz. Zero got a square. They did not even try. Sign in, attach wallet, stop. They did not want a square. They wanted a row in the database with a wallet on it when the snapshot came. THE UNCOMFORTABLE PART Hundreds of new airdrops go through Telegram channels every day. Founders believe they have attracted real participants — people who will stay in the project, do something in it, hold on to something. They count registrations, celebrate the growth, report it to investors. In reality the giveaway goes to farms. And on listing day they sell all of it at once, collapsing the price on exactly the real people who did show up. We got off lightly: there was no token, so there was nothing to take. The farm burned twelve thousand accounts on us and got zero. Projects with a token will not be that lucky. Checking who is on your list costs one query: SELECT referred_by, count(*) FROM users GROUP BY 1 ORDER BY 2 DESC LIMIT 10; If you see 300, 300, 300, 299 in there, you already know what it means. And to whoever is running the farm: we know you are reading this. Get around this one too and we will write it up with the same numbers and the same detail. No hard feelings. That is the experiment. THE BOARD IS BLANK AGAIN This morning, out of a million squares, six are alive. Two days ago there were 6,000. Emptiness. So the honest pitch is not "come beat the bots" — the bots are gone. It is this: the canvas is empty, and it will not be this empty again. Whoever takes a square today is not joining a game in progress. They are the game in progress. A square is $4 — a symbolic price, the cost of a coffee. Paid entry is the only entry now. Registration closes in early September, and after that there is no way in at all. No skill. No strategy. No luck. Whoever gives up last wins — and right now almost nobody has started. Fill the canvas and the prize reaches a million dollars. The pool sits in a smart contract: neither we nor anyone else can withdraw it, and the payout is on-chain. The bots are gone. Come take their place. lastpixel.live #Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive

A BOT FARM ATE OUR AIRDROP — AND GOT NOTHING

HOW IT STARTED
We launched Last Pixel: a social experiment shaped as a survival game.
The rules are simple. A canvas of one million squares, one per person. Claim a
square, then confirm you are still there before your window closes — 24 hours at
the start, one minute at the end. Miss once and your square is dark forever.
Whoever is still confirming after everyone else has quit takes the pool — a
full canvas puts a million dollars in it.
No skill. No strategy. No luck. Pure stubbornness.
Remember that. Everything below turns on it.
HOW WE RAN THE AIRDROP
An empty canvas attracts nobody, so to seed it we set aside 10,000 free squares.
Finish a short quest, get a square, pay nothing.
We announced it in one of the largest airdrop communities: two million followers
on Telegram and 1.6 million on X. The post cost $449.
It went out at 13:42.
HOW WE CAUGHT THEM
What looked wrong first was not the volume. It was how even it was. The squares
were going out too smoothly for a crowd of real people.

We grouped accounts by the referral link that brought them in. Ten links ran far
ahead of everything else. This is how many each one brought:
300 300 300 300 299 299 298 298 298 297

Ten people do not accidentally invite 300, 300, 300, 299, 299, 298. That is not
statistics. That is a config file.
Then we looked at the accounts themselves. Their Telegram IDs all sit between
1.3 and 2.0 billion — registrations from 2020 and 2021, not one recent among
them. Not new users. Aged stock, bought in bulk.
Then we checked the clock.
The post went out at 13:42. The first of the ten distributor accounts appeared
at 17:38, the tenth at 18:25 — three of them within two seconds of each other.
At 19:01 the flood began.
They read the post, spent four hours building the rig, and pointed it at us the
same evening.
THE OTHER SIGNALS
The quest had one optional task: join our Discord. It gave nothing and counted
for nothing — we marked it optional because it is the heaviest step with the
smallest return.
It was completed by 5,439 out of 5,439.
Real people never hit a hundred percent. Not on the mandatory steps, and
certainly not on the one with no reward.
And the median time from registration to holding a square: 48 seconds. No human
joins a channel, waits for the membership check, reads a quiz question and
answers it inside a minute.
THE RISK IN EVERY TELEGRAM AIRDROP
Here is what is worth knowing if you hand out tokens.
The post you pay for is an announcement to your audience and a tip-off to a farm
operator at the same time. He reads those channels precisely because that is
where giveaways get published. Assume he is on your recipient list before you
have even clicked "pay."
A captcha will not save you. Cloudflare Turnstile stood in front of registration
the whole time and was solved twelve thousand times. That is not a complaint
about Cloudflare: solving costs about a dollar per thousand, and every captcha
goes the same way regardless of whose it is. As an anti-bot defense, the captcha
is finished.
FIGHTING THE FARM
Once it was clear the airdrop had failed, we did two things in a row.
First we cut the giveaway from 10,000 to 6,000 and stopped it.

Then we logged everyone out. Every session, every cookie, all at once. To
confirm your window you now had to sign in through Telegram again.
The reasoning was narrow. They had automated registration completely — twelve
thousand accounts proved it. But re-authentication is a different code path, and
scripts built for signup runs usually do not have it: after registering they keep
the cookie and reuse it forever.
We were betting on the gap between "can create an account" and "can create an
account twice."
We deleted nobody. We asked everyone to log in again.
THEY DID NOT COME BACK
The window closed at 23:48 UTC.
By then all 6,000 squares we had given away were dark. The first 5,439 went out
before the logout, on their own: they simply never came back to confirm their
first window. The last 553 went dark after it. Not one of those accounts signed back in.
The script could pass a captcha twelve thousand times. Answer the quiz. Join the
channel. Tick the optional box. Attach a fresh wallet. Confirm on schedule for
two days straight.
It could not sign in a second time.
That is the whole defense. Not a smarter captcha. Not machine learning. Not a
fraud score. A logout button.
It cost us something too. The logout hit everyone indiscriminately, and a real
player lost his square simply because he never noticed he had been signed out.
We put it back and gave him a full fresh window. He did nothing wrong. Our
defense did.
WHAT THEY WERE ACTUALLY AFTER
Their playbook never changes: complete the airdrop, attach a wallet, wait for
the token, sell everything in the first hour after listing. The wallet is the
whole point. It is where the tokens are supposed to land.
Of 12,821 accounts, 12,680 attached one. Every address different, not one repeat
in twelve thousand. That is not people. That is a generator.
There is no token. There never was.
The quest handed out a square: no market, no transfer, no resale. The only way
to use it is to keep coming back for weeks and pressing a button.
Twelve thousand aged Telegram accounts, burned for the right to babysit a button.
And the proof that leaves no room for doubt: after the free squares ran out,
another 6,686 accounts registered anyway. 6,656 attached a wallet. Zero completed
the quiz. Zero got a square.
They did not even try. Sign in, attach wallet, stop.
They did not want a square. They wanted a row in the database with a wallet on it
when the snapshot came.
THE UNCOMFORTABLE PART
Hundreds of new airdrops go through Telegram channels every day.
Founders believe they have attracted real participants — people who will stay in
the project, do something in it, hold on to something. They count registrations,
celebrate the growth, report it to investors.
In reality the giveaway goes to farms. And on listing day they sell all of it at
once, collapsing the price on exactly the real people who did show up.
We got off lightly: there was no token, so there was nothing to take. The farm
burned twelve thousand accounts on us and got zero. Projects with a token will
not be that lucky.
Checking who is on your list costs one query:
SELECT referred_by, count(*) FROM users
GROUP BY 1 ORDER BY 2 DESC LIMIT 10;
If you see 300, 300, 300, 299 in there, you already know what it means.
And to whoever is running the farm: we know you are reading this. Get around this
one too and we will write it up with the same numbers and the same detail. No
hard feelings. That is the experiment.
THE BOARD IS BLANK AGAIN
This morning, out of a million squares, six are alive.
Two days ago there were 6,000.
Emptiness.
So the honest pitch is not "come beat the bots" — the bots are gone. It is this:
the canvas is empty, and it will not be this empty again. Whoever takes a square
today is not joining a game in progress. They are the game in progress.
A square is $4 — a symbolic price, the cost of a coffee. Paid entry is the only
entry now. Registration closes in early September, and after that there is no
way in at all.
No skill. No strategy. No luck. Whoever gives up last wins — and right now almost
nobody has started.
Fill the canvas and the prize reaches a million dollars. The pool sits in a
smart contract: neither we nor anyone else can withdraw it, and the payout is
on-chain.
The bots are gone. Come take their place.
lastpixel.live
#Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive
We gave away 6,000 free squares. A bot farm took every single one. Then we grouped the accounts by referral link. Here is how many people each of the top ten brought: 300 300 300 300 299 299 298 298 298 297 Ten people do not accidentally invite 300, 300, 300, 299. That is not statistics. That is a config file. They solved our captcha twelve thousand times. Answered the quiz. Attached 12,680 wallets, every address different. They got nothing — there is no token, and a square cannot be sold. Then we logged every account out. To confirm your window you had to sign in again. All 553 remaining bot squares went dark. Not one signed back in. Full breakdown with every number, and the query you can run on your own project: [How we caught them — and how to check your own airdrop:](https://app.binance.com/uni-qr/cart/358756511214456?l=en&r=PW2IUK25&uc=web_square_share_link&uco=qKQLNnPIASdmxtGc7dJNAg&us=copylink) #Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive
We gave away 6,000 free squares. A bot farm took every single one.
Then we grouped the accounts by referral link. Here is how many people each of the top ten brought:
300 300 300 300 299 299 298 298 298 297
Ten people do not accidentally invite 300, 300, 300, 299. That is not statistics. That is a config file.
They solved our captcha twelve thousand times. Answered the quiz. Attached 12,680 wallets, every address different.
They got nothing — there is no token, and a square cannot be sold.
Then we logged every account out. To confirm your window you had to sign in again. All 553 remaining bot squares went dark. Not one signed back in.
Full breakdown with every number, and the query you can run on your own project:
How we caught them — and how to check your own airdrop:
#Airdrop #Sybil #Web3Security #BotFarm #LastPixelLive
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number