Attacker wallet pre-strike probe (low-gas failing txs)
Circle USYC's assessment for RD-F-159 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Mempool monitoring infrastructure required for this signal. USYC's permissioned architecture structurally limits probe effectiveness - failing txs from non-whitelisted addresses would revert on the Entitlements check immediately, providing limited reconnaissance value to an attacker. No probe pattern observed from public data. Licensed threat-actor cluster list required.
Sources #
- DocsUSYC Product StructuringUSYC product structuring - permissioned architecture; Entitlements blocks non-whitelisted callersretrieved 2026-05-16
Methodology #
Detect whether a wallet in a threat-actor cluster is sending low-gas or intentionally-failing transactions to this protocol (pre-strike reconnaissance pattern).
See the full factor methodology and distribution across all protocols →