Solana WET presale hijacked by Sybil wallets as HumidiFi resets launch

Solana WET presale hijacked by Sybil wallets as HumidiFi resets launch

Source: Cointelegraph

Published:2025-12-05 12:45

BTC Price:$91172

#Solana #SybilAttack #Presale

Analysis

Price Impact

Med

A sybil attack on a presale event within the solana ecosystem, even with the team's swift corrective action, raises concerns about security and fair token distribution, which can affect investor confidence in new solana projects.

Trustworthiness

High

The news comes from cointelegraph, a reputable crypto news source, and is backed by confirmations from the project team (humidifi) and blockchain analytics platform (bubblemaps).

Price Direction

Neutral

While the incident initially creates negative sentiment regarding security, humidifi's decisive action to reset the launch and exclude the attacker, along with plans for a new public sale, mitigates much of the potential long-term damage to confidence in the solana ecosystem itself. it highlights a risk but also shows a quick response.

Time Effect

Short

The immediate sentiment might be slightly negative due to the security incident, but the project's quick and effective response to nullify the attack and plan a legitimate relaunch means the impact on sol's price is likely short-lived, as the issue is being directly addressed.

Original Article:

Article Content:

Ezra Reguerra 1 minute ago Solana WET presale hijacked by Sybil wallets as HumidiFi resets launch Bubblemaps CEO Nick Vaiman said Sybil attacks are rising across presales and airdrops, calling on teams to use KYC or algorithmic detection. Listen 0:00 News COINTELEGRAPH IN YOUR SOCIAL FEED A Solana presale event encountered distribution issues after a bot farm reportedly used over 1,000 wallets to snipe nearly the entire Wet (WET) token sale in seconds. Hosted through the decentralized exchange aggregator Jupiter, the presale sold out almost instantly. But genuine buyers effectively had no chance to participate because a single actor dominated the presale, according to organizers. Solana automated market maker (AMM) HumidiFi, the team behind the presale, confirmed the attack and scrapped the launch entirely. The team said it would create a new token and hold an airdrop to legitimate participants while explicitly excluding the sniper. “We are creating a new token. All Wetlist and JUP staker buyers will receive a pro-rata airdrop. The sniper is not getting shit,” HumidiFi wrote. “We will do a new public sale on Monday.” Source: Jupiter Bubblemaps identifies alleged sniper after tracing over 1,000 wallets On Friday, the blockchain analytics platform Bubblemaps announced that it had identified the entity behind the presale attack, having observed unusual wallet clustering during the token sale. In an X thread, the company reported that at least 1,100 out of the 1,530 participating wallets displayed identical funding and activity patterns, suggesting that a single actor controlled them. Bubblemaps CEO Nick Vaiman told Cointelegraph that their team analyzed presale participants using their platform and saw patterns, including new wallets with no prior onchain activity, all being funded by a handful of wallets. These also received funding in a tight time window with similar Solana ( SOL ) token amounts. “Despite some of the clusters not connected together onchain, the behavioral similarities in size, time, and funding all point to a single entity,” Vaiman told Cointelegraph. Bubblemaps said that the sniper funded thousands of new wallets from exchanges, which had received 1,000 USDC ( USDC ) before the sale. The analytics company said one of the clusters “slipped,” allowing them to link the attack to a Twitter handle, “Ramarxyz,” who also went on X to ask for a refund. Bubblemaps demonstrated the wallets participating in the presale. Source: Bubblemaps Related: Pepe memecoin website exploited, redirecting users to malware: Blockaid Sybil attacks must be treated as a “critical” security threat The attack follows other Sybil attack incidents in November, where clusters controlled by single entities sniped token supplies. On Nov. 18, a single entity claimed 60% of aPriori’s APR token airdrop . On Nov. 26, Edel Finance-linked wallets allegedly sniped 30% of their own EDEL tokens . The team’s co-founder denied that they had sniped the supply and claimed they had put the tokens in a vesting contract. Vaiman told Cointelegraph that Sybil attacks are becoming more and more common in token presales and airdrops. However, he said the patterns are “different every time.” He said that for safety, teams should implement Know Your Customer (KYC) measures or use algorithms to detect sybils. He said they could also manually review presale or airdrop participants before allocating tokens. “Sybil activity needs to be treated as a critical security threat to token launches,” Vaiman told Cointelegraph. “Projects should have dedicated teams or outsource Sybil detection to professionals who can assist.” Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users # Blockchain # Cryptocurrencies # Altcoins # Wallet # Tokens # Data # DeFi # Solana # Tokenomics Add reaction