Bitcoin Forum
June 16, 2026, 07:21:58 PM *
News: Latest Bitcoin Core release: 31.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: What's the course of action when you notice possibly abusive peers?  (Read 56 times)
slimond1975 (OP)
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
June 15, 2026, 02:35:25 PM
 #1

Sorry posted in the wrong forum, this must be the correct one.

Hello, as a home lab hobbyist I was digging around my network and noticed the bitcoin-core node I run has a lot of peers from the same /64 IPv6 netblock.
These connections all have different subversion values, which confuses me.
I uploaded to gemini the output from getpeerinfo and they flagged a few things, 1) all these connections were inbound 2) these connections have sent very little data to me, but I've sent them a lot (no inv or tx or any data really).

Anyone got any advise?
Satofan44
Sr. Member
****
Offline

Activity: 420
Merit: 1110


Don't hold me responsible for your shortcomings.


View Profile
June 15, 2026, 07:30:14 PM
Merited by ABCbits (1)
 #2

Sorry posted in the wrong forum, this must be the correct one.

Hello, as a home lab hobbyist I was digging around my network and noticed the bitcoin-core node I run has a lot of peers from the same /64 IPv6 netblock.
These connections all have different subversion values, which confuses me.
I uploaded to gemini the output from getpeerinfo and they flagged a few things, 1) all these connections were inbound 2) these connections have sent very little data to me, but I've sent them a lot (no inv or tx or any data really).

Anyone got any advise?
You can simply ban them, there is no reason to overthink it. I think you should watch this thread as we have recently discussed a particular group of peers that are misbehaving in a parasitic way, and users were sharing with me various methods through which they can be identified and banned.

https://bitcointalk.org/index.php?topic=5585202

In your case, you can simply ban every peer that you see from that netblock. It won't affect you negatively in any way. It may be that someone is running a lot of sybil nodes for Bitcoin Knots or for some other shady purpose.


Here is the command that you are looking for: https://bitcoincore.org/en/doc/31.0.0/rpc/network/setban/, and you can find other command at this link.

ABCbits
Legendary
*
Offline

Activity: 3640
Merit: 10115



View Profile
Today at 07:32:09 AM
 #3

2) these connections have sent very little data to me, but I've sent them a lot (no inv or tx or any data really).
It may be that someone is running a lot of sybil nodes for Bitcoin Knots or for some other shady purpose.

Most likely it's spy node that collect nodes data, such as IP address and list of transaction on mempool. One of their goal is determine which node initially broadcast the TX.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
slimond1975 (OP)
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
Today at 07:39:15 AM
 #4

Thanks for the link. I'm a curious person so monitored the node a bit more closely and gemini is blowing mind here with some supposed surveillance network theory(!).
Apparently this /64 ipv6 block is using about 120 different subversions on short lived connections, rotating through them throughout the day to avoid some bitcoin core limit or something.
I've sent something like 200GB to them and they about 2GB to me, or something like that. Assume gemini is correctly interpreting this stuff.
I can't be the only one seeing this netblock, what's the etiquette about sharing this IP block here?

I could maybe should ban them, but kinda interested in what they're doing.

Will my banning them share this info with other nodes which may end up banning them, or is it a manual thing node operators have to do?

Thanks again
ABCbits
Legendary
*
Offline

Activity: 3640
Merit: 10115



View Profile
Today at 08:17:01 AM
 #5

I can't be the only one seeing this netblock

Related thread i found, Loads of fake peers advertised on bitcoin network.

what's the etiquette about sharing this IP block here?

It should be acceptable. Thread i mentioned above share the IP address without getting deleted or banned.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
slimond1975 (OP)
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
Today at 09:13:11 AM
 #6

The block highlighted is this:

Code:
2602:f5c0:0:ace::/64
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!