New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Behavior-Based Security for the Next Billion On-Chain Users | Rodrigo - Webacy

Ethereum DenverMon, Mar 9, 2026, 12:00 AM

🚀 Get Ready for ETHDenver 2026! 🚀 We're already hard at work preparing for next year's biggest Web3 event! Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

Transcript

[music]

Hello everyone. Welcome to my talk. Uh thanks and feel remember for having me here. Uh so, I'm Rodrigo, staff engineer at Webacy. And today we are going to talk about behavior analysis basic for security for the next video on user chains.

So, first, let me introduce you uh how a token can be launched the first 60 seconds. So, at T T plus zero, the token is deployed. T plus three, you get in the spy wallets buying in the same block after the token has been launched. 8 seconds later, 12 more come and buy it. The The The The ones that were before are bundlers.

The next ones, as you will see here, will be like snipers. And now the developer wallet will get the means to his wallets. Now, after 30 seconds, social media link is posted. So, 50 retail sees see this link posted, pumps gets up, everyone's buying the token. So, they see opportunity.

So, after they see it, the liquidity gets pulled. So, 50k it's gone. So, here you can see a draft of how it a token might be working, like where the get deployed, all the pump is coming, and then when the retail enter, everything gets pumped. So, 89 wallets have been affected by the time the user checks it, and it's was over. So, everything you will see this after and it's reactive a reactive response.

So, the problem here is how to compete against reactive or a predictive market. So, when we when you normally use this type of attacks, if everything is reactive, like a user posts like, "Okay, I have been rug pulled." Or after that the hacker gets on a blacklist. So, you see the same hacker on an unknown exploitable website. So, everything that that's is reactive and is after the incident happens.

So, our approach is detect this before it happens in less than 60 seconds. All of this happens. So, the user the retail doesn't come to enter in this. So, if there is another rug pull rug pull every 2 minutes. More than 10,000 tokens deployed every day on Solana.

And as you see here, the first user report will be after 30 minutes. So, instead of seeing the report, why don't we look at the evidence before anything happens? So, I will tell you how a little bit how we work with six signals. This is not everything that we do, but just to give you an an idea. So, we build a high confidence score.

This confidence score is built by a lot of signals. Let's start about timing. As you saw the first two things that happened at T3 at T8 at T8 is who has been buying. Is it the same person? Where are the funds coming?

Then the coordination. Are these is the same people that are buying or are there like random people? Then rotation. How long have been the person holding this the the tokens after they have bought it or already in it? Then institutional filters.

What do we mean about this? Like the idea is always you will have like false positives and wallets will work as we detect, but sometimes you have to filter them because it's normal behavior for them. We'll talk about later. Then we analyze the deployer. Is this an unknown hacker?

Unknown person have done already a rug pull? And then where the money is coming? The fund flow. This one is very funny. So, you can see where and who is my moving the money.

So, with all this each one of these signals are uh per se nothing they will tell you about, but if you put them all together they will give you a probability very good if you are going to get it right. So, as I did as I mentioned each signal alone is suggestive, but combined they are predictive. So, timing analysis. So, from what we what we have seen on the dashboard you can see like there like the confirmed rug pulls is like in the first 10 to 10 seconds uh the they they they they get bought. Like if at the launch after launch but after 10 sec before 10 seconds the user gets bought 72% chance of being a rug.

And it gets lower after the time goes goes by. And for legitimate tokens as you see it's the opposite totally. So, you can see how behavioral is be pretty predictive in this case. So, So, as you see we analyzed more than 12 token 1,200 tokens and uh eight almost 80% of them with more for the for the more than five buys on the 10 seconds they are uh rug pull. So, that's first signal.

Signal number two. Coordination patterns. So, the idea here is are all of these wallets that buying this the same person? So, here is where we see like okay, where the fund the fund flow goes. So, the fund the who funded this wallet?

So, you can see here wallet A to E they all get funded by the same wallet. And all of them at the same block they buy to the token mint. So, basically this is not like all random thing. This is coordinated attack. So, here you can see like this is a behavior.

Maybe it's a bot automated that doesn't have to be with a rug pull, but it's a good signal. If you some If you combine all of them, you can see like 90% of rugs that all the more than three wallets buying the same block and funded by the same wallet, they are always rug pulls. So, normally they use more than eight wallets. So, because they trying to be dust wallets, so you don't see like all too many wallets have small amount of money, but actually the same person that has a lot of of the percentage holding.

[sighs]

As I mentioned, five wallets, same founder, same block, one attacker. Signal three. Deployer profiling. So, as we analyze all the blockchain and a lot of things that happen, we already know hackers that have been working in other chains or where the money are they moving. So, normally for this type of rug pulls, a behavior that we normally see is like they are like serial serial deployers with call them because they deploy as much as token as they can and then you can see like if they deploy more than 10 tokens at the same like range, you are trying to get someone scammed.

Like this is basically your pattern. So, math talks for for itself. So, here you can see it. Uh an average deployer deploys 14 tokens in 24 hours. So, legitimate normal legitimate projects don't deploy more than two tokens, maybe one for for governance, the other one for token economics.

So, that's more than normal behavior for any of the projects. Then, fund flow tracing, as I mentioned before. Where did the money is coming from? Like this is like following the the gold coins. Okay.

So, we as I mentioned, we know a lot of bad bad actors that we already label. Like I like OFAC sanction, known hackers, known drainers, like previous rug pulls. So, we already know them. So, the question is now, what are they doing? Where are they moving the funds?

Because sometimes you have to do a run off of the funds on or you want to use them. So, you may send it to a mixer. Yeah. Normally, you use it so we cannot trace it. But normally, mixers can give you some hints on where the money is going.

Like it's not totally like uh obfuscated, let's say. So, after that, after the mixer, it gets claimed by a wallet that hasn't It's a fresh wallet. So, if it's a fresh wallet, deploying a fresh contract, it can give you a little bit of uh hacker or sketchy vibes, let's say. And then they start doing the deployment. As I mentioned before, more than 12 tokens and then they see like, "Okay, all my analysis was right."

So, the prediction was correct. And normally, all of these rugpulls come from unfunded wallets that get the first transaction from a mixer or or anything that you don't need to do a KYC, basically, because they don't want to know who they are. So, you can like start predicting where the mixer send the money and what they're doing and you can behave and see, "Okay, this will be a no hack." Single file and six, let's say. Okay, so I mentioned retention.

So, normal projects doesn't back the rugpull. So, the if the they hold the top 10 holders have all the 50 buyers at launch have Let's say at the first time of the the launch, 45% of the holdings and after 10s 10 minutes or as we mentioned, two to three minutes, they drop it to 12%. You It's a rug. But normal projects, they hold the tokens because they know that it's a project they want to distribute the tokens to a tokenomics and they're like they're more or less legit. So, if we start seeing higher drops of retention of the holdings, you can see start seeing signals that is uh uh they're trying to do a pump and dump.

So, I also mentioned noise removal. So, some of the bad behaviors and patterns I already mentioned, they're normal behaviors for some of known institutional things. For example, launch pools like pump and fund, they do launch a lot of tokens through a a same wallet, but this is normal because we label them. So, they they are not trying to do rug and pulse. They rug pulse.

So, the idea is to check all the sex wallets. For example, they send it to do transactional wallets, so they send to in the same block. So, you can start like, "Okay, this is a known bridge." And you can like remove them from this analysis. So, now what you can build what we with a API that we work for example.

So, with all the risk tag you do, for example, if you're building a block score block scanner like Etherscan, for each one of the tokens you can see a transaction simulation like give a transaction risk, a token risk, the cold the deployer risk, and everything. So, you can show the users before analyzing which token to buy or analyzing all the tokens they have in the wallet. Then, another thing that is cool that we all we built with all this information is the the rip deeper risk. So, you can see if beforehand if a token will be de-pegged. So, the idea is like all these stable coins we can predict in the market like, "Okay, don't buy this coin because it's going or don't use it that much because it's going to be de-pegged and you will lose value in the money."

Then, as we bought cash, Mintlify, they use it. And you can see like this is real time, less than 200 milliseconds, and before the user uses, the idea is to prevent them to get hacked or rugged and sign any uh weird thing. So, what do we suggest? Uh so, here is more complicated, but yeah. For your users, if you're building an API an an app or anything for a retail, please analyze whatever token you're launching, trying to see like of okay, I'm building a DEX.

If I'm listing a token, let's analyze all of these patterns before listening. If you want to have a DEX that doesn't get people rugged, let's say. But, if you are normal buyer, please check these five six signals so you don't get rugged. Uh and here you can see our partners and my question way knowing all of this I have give you, what are you going to build with it? So, thank you very much.

I'm Rodrigo. That's my information. Any questions?

Automatic transcript — names and jargon may be misspelled.