Due to time constraints in todays EcoSystem WG meeting I am posting the following & request for bounty.
GitCoin
GitCoin has built in tools (e.g. GitCoin Passport), but there are two short comings with the existing toolsets: 1) the operate behind the scenes in sort of a blackbox; and 2) the tools are for after the close of the round before matching funds are released and calculated (however, by then the damage is done)
-
This is easy to solve by making the results of the process more transparent. For example, with the release of funds disclose the tool/tools that were used and the results of running the tools for the round.
-
One of the purposes of quadratic funding is social signaling. In practice this doesn’t just apply to the matching funds, but the social signaling has a active role during the round - a project with significant number of donors receives more attention during resulting in even more donors.
GG20 ENS
We saw first hand in the GG20 ENS round a possible Sybil attack/airdrop farming - where ENS had a total of 7,576 donors the grantee had 6,000 donors within the 1st 48 hours of the round. I spoke with multiple grantees who were aware and bothered, but for a number of reasons preferred to remain silent than speak up. I’ll summarize the reason as follows: there is more incentive to remain silent about a potential Sybil/airdrop farming than speak up.
Nevertheless, I took it upon myself to reach out to GitCoin and within 24 hours they investigated and removed the grantee from the ENS round. In effect, my actions possibly resulted in an additional $10,000 of matching funds being available to the ENS grantees. While it is possible the existing tools may have discovered this, it wouldn’t have shifted the social signaling from the potential attack/airdrop farming to the rule abiding projects during the round.
Conclusion & Request for Bounty
Following discussions with other grantees who knew of the grantee but felt more benefit in staying quiet rather than speaking up, it is my opinion there needs to be incentive for the community to speak up when there are potential Sybils/airdrop farming taking place.
The existing tool(s) demonstrates the DAO’s & GitCoins commitment to uncovering Sybils/airdrop farming, but there is a short coming where they are limited to after the fact allowing potential attackers to capitalize on the social signaling during the round taking away attention and opportunity from the other projects.
As a supplemental tool to identify, fight & deter future Sybil attacks or airdrop farming, I am requesting a bounty for discovering & disclosing the issue on the GG20 ENS round, and moving forward a bounty for the grantees, and potentially the community, for identifying/disclosing potential Sybils/airdrop farming during the round, protecting DAO matching funds, and preserving the legitimacy of the social signaling during the GitCoin round itself.