Decentralized Social Network Money Frauds/Scams including BitClout, Twetch, Steemit, PeakD

Overview

Decentralized Social Network Money Frauds and DAOs: BitClout, Twetch, PeakD, Steemit ...

Updates 4/29/2021

https://www.coindesk.com/wyoming-dao-llc-law-passed

https://coingeek.com/wyoming-senate-passes-dao-law/

Other Projects of Relevance and similar macro and crypto structure to BitClout:

  • DUST and AlgoRand

  • SingularityNET and AGI and Cardano

  • many many more

  • READ THE WHITE PAPERS

  • Look for the actual source code.

  • repeat until you give up or wake up

BitClout, PeakD, Twetch and Steemit are all ersatz Twitter-style cryptocurrency DAO platforms so similar in look and concept to one another that they are related, copying code and ideas from each other.

The main commonalities to these frauds is they are centralized and decentralized systems designed for:

  • extracting money from users for premium fees to execute blockchain transactions (for rudimentary versions of the same features users have today with Twitter itself and Google's content indexing, storage and delivery networks, for example)
  • persuading users or tricking them into downloading and distributing stripped binaries dissimulating as "open source" in a peer to peer dark-net running on laptops, mobile devices, servers, public cloud, etc.
  • harvesting unsuspecting users' fiat money and Bitcoin
  • remaining anonymous or, in some cases, openly acting to bridge gaps in law (see Wyoming DAO laws upcoming and refer to BitClout's Terms of Service and search for Wyoming)

They mislead users in many fraudulent ways, including promoting overloaded and confusing meanings of "decentralized" and "open source" and "currency." They use public and private blockchain tech and APIs, open source project code produced by companies such as Google, and content delivery and security (for themselves, not their victims) services such as Cloudflare, to perpetrate financial fraud in the open. BitClout has promoted itself as "open source" since launch, when in fact all of its core code remains closed source to this day (the explorer and the "desktop app" available on GitHub are peripheral).

Twetch is based on buying and spending Bitcoin SV and micro-fees for transactions, which themselves have fees and require use of software wallets and keys running in your web browser.

BitClout is based on charging Bitcoin fees and additional costs for any and all transactions involving BitClout (which, as on Twetch with BSV coin, is required to be spent and fees paid to spend it for every action in the app) or their Creator Coin token, and also manages keys and wallets in your web browser.

Both sites are released under the auspicious promise of being alpha or beta quality and the hottest new thing being developed too fast and furiously to be stable, secure or usable. Bluntly, that is bullshit; these are fraudulent scams from tip to toe that completely lack professionalism and security features for users; protecting the BitClout or Twetch operators and their data, not you and yours.

$BitClout

This project gathers BitClout's code and offers analysis of its APIs, 3rd party integrations and architecture.

BitClout is a pay-to-play social network and game. It is a scam if considered, sold or promoted as a financial investment. BitClout should be thought more of as a a game or a vending machine that accepts Bitcoin irreversibly in exchange for a game currency called BitClout and a token called Creator Coin. One can buy a token with BitClout. One can buy either with Bitcoin. But it is impossible to refund or withdraw Bitcoin back from the system, nor is there any declaration of intention to ever make it otherwise in the one-pager pdf or the terms of service (linked on the second screen of the Signup flow, avaialable at https://bitclout.com/terms-of-service, in the source code (in main.js) and documented here). BitClout is a game and it costs Bitcoin (and a valid phone number) to play.

Completing your profile, at minimum, requires a phone number that can receive text messages for confirmation. Allegedly one can pay ~$60 in Bitcoin as an alternative, but I have not tested that.

All image content posted by users is stored in and accessible via public cloud storage on imgur.com.

Registered users can like and follow each other, post their own and promote other accounts' content, and spend Bitcoin on BitClout, then send BitClout to other wallets on the BitClout network, all of which costs, at minimum, a verified phone number and the price of Bitcoin transaction fees at premium market rates plus a percentage increase (BitClout adds 1.5 * priority fee price currently, 4/23/2021) (once Bitcoin has been used to purchase BitClout).

Update 4/9/2021: Reclouting /retweeting functionality appeared overnight after some new code was deployed.

The following functions cost Bitcoin to get started. The prices are set by the current cost of Bitcoin transaction fees:

  • posting content
  • following an account
  • creating and saving or changing a profile image
  • creating and saving or updating profile content

All actions are really based on blockcypher.com and other vendors services, technology and APIs, which makes setting up the technology for BitClout primarily an orchestration of services and APIs tied together through a web UI. All of the strongest technical aspects of BitClout are based on Cloudflare, Angular, blockcypher.com, imgur.com, various 3rd party libraries (see below) and GoDaddy's https://domainsbyproxy.com (who have a subpoena policy posted on their public site) obscuring the owners and creators behind BitClout.

Admittedly, the mastery orchestrating the components of the BitClout "solution" and carrying it off so far is respectable.

The BitClout one pager / whitepaper (7 pages) is a masterwork of rhetoric: enthymemes and triggers to encourage readers to jump to conclusions, confirm biases and desired outcomes and act on positive emotional response rather than careful analysis.

Partial list of other projects and services referenced and used in BitClout's Angular code:

GitHub projects:

Other products, projects and services used in code and refrenced in code:

Possible source for BitClout's https://explorer.bitclout.com:

TODO - other related sites referenced in code:

Listing of BitClout's APIs as dervived from main.js: see https://github.com/scottstirling/bitclout/issues/20

BitClout Architecture Overview Diagram

Bitclout Architecture

Related work (began as a Reddit thread in r/Bitclout): https://www.reddit.com/r/BitClout/comments/mhpwjx/reverse_engineering_bitclout/

Increasing awareness of these scams, selected resources:

BitClout

PeakD

Steemit

Twetch

Related scam economy / BitClout ecosystem emerging in regulation vacuum

Other analysis and related info on my Twitter: https://twitter.com/scottmstirling

Comments
  • pull latest code from bitclout domain

    pull latest code from bitclout domain

    Last night the site updated and the reclout function has been implemented.

    This implies the code has changed abd there should be some new versions of files to pull down, diff and version.

    opened by scottstirling 1
  • Node management and scaling

    Node management and scaling

    Do you think it's possible to have aguess as to gitclout building from scratch + operating +scaling their blockchain node vs them using some big name (https://eos.io/, https://consensys.net/...)

    There is https://www.blockcypher.com/ mentioned in your Readme but you seem to think it's only used for transactions and not for the whole blockchain backend...

    What's your opinion or intuition on this ?

    opened by misner 3
  • Who is dan?

    Who is dan?

    This path is compiled into the main.js in 4 places and looks like an artifact from where it was built:

    ../../../../../../../../../../../home/dan/tmp/node-v10.16.3-linux-x64/lib/node_modules/browserify/node_modules/is-buffer/index.js

    opened by scottstirling 2
  • BitClout's APIs doc

    BitClout's APIs doc

    TODO: sort the paths below to their endpoints and POST/GET details

    api.bitclout path root: GET https://api.bitclout.com/api/v1

    POST https://api.bitclout.com/api/v1/block https://api.bitclout.com/api/v1/transaction-info

    bitclout.com admin paths: https://api.bitclout.com/admin or https://bitclout.com/admin

    (the full admin URL paths error HTTP 405 for GETs (vs any other URLs which 404) but will return 200 for OPTIONS, which indicates their presence):

    /admin - GET /admin/get-all-user-global-metadata /admin/get-mempool-stats /admin/get-user-global-metadata /admin/get-username-verification-audit-logs /admin/get-verified-users /admin/grant-verification-badge /admin/node-control /admin/pin-post /admin/remove-nil-posts /admin/remove-verification-badge /admin/reprocess-bitcoin-block /admin/swap-identity /admin/update-global-feed /admin/update-user-global-metadata

    bitclout.com paths:

    /404 - GET /add-stake /block-public-key /broadcast-bitcoin-txn /burn-bitcoin /buy-bitclout - GET /buy-or-sell-creator-coin-WVAzTWpGOFFnMlBvWXZhTFA4NjNSZGNW /buy-or-sell-creator-coin-preview-WVAzTWpGOFFnMlBvWXZhTFA4NjNSZGNW /check-login-user-stateless /create-follow-txn-stateless /create-like-stateless /create-user-stateless - OPTIONS, POST /creators - GET /get-app-state - OPTIONS, POST /get-block-template /get-exchange-rate - GET /get-follows-stateless /get-messages-stateless - OPTIONS, POST /get-notifications /get-posts-stateless /get-profiles - OPTIONS, POST /get-single-post /get-starter-bitclout - GET /get-txn /get-user-global-metadata /get-users-stateless - OPTIONS, POST /inbox - GET /log-in - GET /logout /miner-control /notifications - GET (notifications not implemented as of date 4/13/2021) /posts/new - GET (screen with form input to author new content post) /send-bitclout - GET (screen to Send $BitClout) /send-message-stateless /send-phone-number-verification-text /settings - GET (currently email is the only updatable setting) /signature /sign-up - GET (Sign up screen) /submit-phone-number-verification-code /submit-post /terms-of-service - GET /u/${profile} - GET (Profile screen) /u/${profile}/sell - GET (Sell ${profile} coin) /u/${profile}/trade - GET (Buy ${profile} coin) /update-bitcoin-usd-exchange-rate /update-profile - GET (Update Profile screen) /update-user-global-metadata /wallet - GET (Wallet screen)

    Some of the APIs require a special miner public key parameter unavailable to public users.

    Work in progress ...

    opened by scottstirling 7
  • Unminify: incorporate into a script to automate

    Unminify: incorporate into a script to automate

    Handy utility, undoes common obfuscation techniques and makes the src more readable: https://github.com/shapesecurity/unminify

    Adds about 100k more lines of code to the resulting output of main.js ... but definitely helps.

    $ npm install -g unminify $ npx unminify src/main.js > /tmp/main-unmin.js

    opened by scottstirling 0
  • Angular CLI version 11.1.2

    Angular CLI version 11.1.2

    Visible in "view source" after the tag:

    <app-root _nghost-blp-c73="" ng-version="11.1.2">

    Confirmed via Safari Developer mode that the iPhone / iOS UI is also rendered via Angular (and supports the PWA install option from Angular for iOS).

    documentation 
    opened by scottstirling 0
Releases(04-23-2021)
  • 04-23-2021(Apr 23, 2021)

    Code here is all caught up with the latest live code available. Check out https://github.com/bitclout/run for BitClout's own open source project.

    Source code(tar.gz)
    Source code(zip)
  • 04.10.2021(Apr 10, 2021)

  • 04.09.2021(Apr 9, 2021)

    Repository and product structure, contributors invited, docs started, code formatted and versioned. BitClout released new versions of main.js and styles.css last night so this release is to set a baseline for versioning prior to incorporating those updates from origin.

    Source code(tar.gz)
    Source code(zip)
Owner
Scott Stirling
Scott Stirling
This repo was made to bring to light all discord scams, and show how to tell if you are being scammed and how to remove malware from scams

DMV (Discord Malware Variants) is a repository made to bring light to harmful programs used by bad actors in order to steal sensitive information from

opsec-bot 26 Sep 5, 2022
decentralized social network using #nostr

Nauka Nauka is an attempt at creating a social network using the nostr protocol. For now it is just a nostr relay that runs on nodejs, but is going to

null 12 Aug 31, 2022
Post directly to your Steemit from Obsidian

Post directly to your Steemit from Obsidian

안피곤(anpigon) 9 Dec 22, 2022
🛡 Protect yourself from crypto scams online

Revoke.cash Browser Extension In many cases, phishing websites try to make you sign a token allowance while they pretend to be an NFT mint or other le

Revoke.cash 23 Dec 5, 2022
Lenster is a decentralized, and permissionless social media app built with Lens Protocol 🌿

Lenster Decentralized, and permissionless social media app ?? lenster.xyz » Discord • Issues ?? About Lenster Lenster is a decentralized, and permissi

Lenster 11.8k Jan 7, 2023
Decentralized video-sharing social media platform, built using Lens protocol. 🌿

Lenstube Decentralized video-sharing social media platform. lenstube.xyz About Lenstube is a decentralized video-sharing social media platform, built

Lenstube 2.4k Jan 1, 2023
Decentralized Social Media. Built using Next.js. Web3 integration with Moralis, Metamask and Ethers.js. Also uses Lens Protofcol to get the profile data.

DecentraGram Decentralized Social Media. Built using Next.js. Web3 integration with Moralis, Metamask and Ethers.js. Also uses Lens Protofcol to get t

Didier Peran Ganthier 8 Dec 20, 2022
Projeto desenvolvido no ignite - Baseado em DT Money

Projeto My Wallet - Baseado no Dt Money Projeto prático na trilha de React - Ignite Sobre Instalação Sobre Aplicação abrangendo diversos conceitos e f

Maurício L S Filho 3 Mar 15, 2022
BCash is an app to help you keep track of who you owe and who owes you money in an easy way. Split your tabs and more.

BCash BCash is an app to help you keep track of who you owe and who owes you money in an easy way. Split your tabs and more. Routes for develpment: lo

Cuitlahuac Maldonado 3 Aug 11, 2022
Tiny JavaScript library (1kB) by CurrencyRate.today, providing simple way and advanced number, money and currency formatting and removes all formatting/cruft and returns the raw float value.

Zero dependency tiny JavaScript library (1kB bytes) by CurrencyRate.today, providing simple way and advanced number, money and currency formatting and removes all formatting/cruft and returns the raw float value.

Yurii De 11 Nov 8, 2022
To understand the history of SACCOs, a Savings and Credit cooperative otherwise known as a Sacco is a type of corporation that aims at pooling money together.

To understand the history of SACCOs, a Savings and Credit cooperative otherwise known as a Sacco is a type of corporation that aims at pooling money together. Depending on the Saccos, there are different types of supplies of merchandise. These include and are not limited to recognition servers, sedimentation, and call home eggs installation. More to these items include check glades, bankers, checks standing orders and safe detentions, and salary progress.

incredicoder 2 Oct 19, 2022
Simple but Complete & Fast network monitor for your home network

netmon Netmon is an opensource project for protecting and monitoring your home network. Netmon is written to run on a Raspberry PI and is optimized to

Tommaso Ventafridda 9 Jul 6, 2022
A social network to connect web3 users and their communities.

Introduction This project is built using react, tailwindcss and Moralis (documentation) for our backend. We are also heavily using the built-in Morali

null 8 Jan 5, 2023
Clubhouse is a new type of social network based on voice—where people around the world come together to talk, listen and learn from each other in real-time.

Awesome Clubhouse The clubhouse is a new type of social network based on voice—where people around the world come together to talk, listen and learn f

Ehsan Ghaffar 27 Nov 9, 2022
Flare - Social Network for Developers

Flare - Social Network for Developers The social networking developers have been longing for. View Demo · Report Bug · Request Feature Flare - Social

Adithya Sreyaj 101 Dec 28, 2022
A social network that simulates a personal blog, where people post "What's on your mind?". Tweteroo is a Twitter clone.

Tweteroo About A social network that simulates a personal blog, where people post "What's on your mind?". Tweteroo is a Twitter clone. ?? Features ☑️

Luiza Santiago 5 Apr 13, 2022
A social network where you can share posts, view your profile metrics and follow other users.

Getting Started with Create React App This project was bootstrapped with Create React App. Available Scripts In the project directory, you can run: np

Rui Neto 16 Aug 21, 2022
A social network app cloned from Instagram built with Next.Js, Socket.IO and a lots of other new stuff.

Instagram Noob ⚡ A social network app cloned from Instagram built with Next.Js, Socket.IO and a lots of other new stuff. Live Demo: https://instagram-

Hung Minh 20 Oct 19, 2022
tRPC test & precursor to a billion dollar social cat network

CatMash What is this? Have you ever wanted to rank 11,000 cat pictures by cuteness? Of course you have. That's what we're doing here. This is an app b

Christopher Ehrlich 6 Dec 18, 2022