Who they are, and where the line is
The wallet identifies itself. Four of its 8 bounty descriptions instruct claimants to “tag @artlu.eth”, one is titled “catch artlu.eth casting this weekend”, and the handle @artlu99 is visible in two of the claim screenshots below. That is as far as this profile goes: on-chain behaviour, plus the public handle the wallet published about itself in its own bounty text. Nothing here comes from off-chain identity lookups.
What they liked making
Two modes, 769× apart in size, and nothing in between.
- Micro-bounties to test a hypothesis. Four bounties of ~0.001 ETH, all titled “try a new Farcaster client”, numbered (2), (3), (4) — three of them posted on a single day. The reward never changed; only the instructions did. Version 1 buried the requirements in a sentence; version 2 added a “to qualify:” block at the bottom; version 3 moved it to the top in capitals; version 4 led with the numbered list. This is someone debugging their own spec, in public, at a cost of a tenth of a cent per iteration.
- Whale bounties for real work. 0.7688, 0.7073 and 0.5000 ETH — the three largest bounties in poidh v1's entire 496-bounty history, all from this one wallet. Two are security work: find data leaks in a TypeScript+Vite+React+wagmi project, and break a Cloudflare + Dynamic Wallet gate on their own site. Of the ETH v1 ever offered for finding a vulnerability, 93.7% was theirs (bounties #192, #243, #432, 1.4760 of 1.5760 ETH).
The pattern underneath both: every bounty is about their own stack. Farcaster clients they want tried, a bot they want built, their own site they want broken, their own dropdown menu they want fixed. They never funded a meme.
| bounty | opened | ETH | outcome | title |
|---|---|---|---|---|
| #87 | 2023-10-18 | 0.0010 | paid | try a new Farcaster client |
| #92 | 2023-10-20 | 0.0010 | cancelled | try a new Farcaster client (2) |
| #93 | 2023-10-20 | 0.0010 | cancelled | try a new Farcaster client (3) |
| #94 | 2023-10-20 | 0.0010 | cancelled | try a new Farcaster client (4) |
| #107 | 2023-10-27 | 0.5000 | cancelled | catch artlu.eth casting this weekend |
| #192 | 2023-12-03 | 0.7688 | paid | find data leaks in web3 project |
| #243 | 2024-01-05 | 0.7073 | cancelled | Security Bounty 0.69+ ETH |
| #314 | 2024-02-06 | 0.0050 | cancelled | fix my janky React Radix dropdown menu |
2 paid out, 6 cancelled and refunded. That is 1.2153 ETH offered and taken back — not stinginess, but the arithmetic of asking for hard things: the two security bounties that did pay went to people who did the work, and the ones that didn't found no takers.
What they liked claiming
5 claims, 4 accepted — against a corpus rate of 278/722 (39%). Never a build bounty, never a big one. Two are chores for poidh itself (interact with its Twitter, record a walkthrough of cancelling a claim); three are community play — a new-year airdrop, a riddle, and a basketball video.
| claim | date | on | bounty | ETH | accepted | titled |
|---|---|---|---|---|---|---|
| 58 | 2023-10-18 | #86 | poidh twitter interaction | 0.0033 | accepted | IMG_7614.jpeg |
| 92 | 2023-10-31 | #110 | poidh cancel walkthrough | 0.0030 | accepted | Image.jpeg |
| 269 | 2024-01-03 | #234 | 🎊 a degen happy new year 🎊 | 0.0500 | no | eat ur eyes out dark mode-ooors |
| 270 | 2024-01-03 | #237 | ❓ poidh riddle of the week #8 ❓ | 0.0050 | accepted | LUCKY STRIKE |
| 330 | 2024-01-15 | #132 | get buckets | 0.0050 | accepted | getting buckets |
The one claim that was not accepted is the only one where they said what they'd do with the money: “if I win, the proceeds will be recycled into another bounty.” It lost a 17-way scramble for a 0.05 ETH new-year airdrop — the largest field of claimants on any bounty they ever touched.
Were they consistent or sporadic?
Sporadic, with a shape. 13 on-chain actions on 9 distinct days spread over 111 days — first 2023-10-18, last 2024-02-06. The median gap between two actions is 2.8 days and the longest is 33; more than half of everything they ever did happened in their first fortnight.
actions per month
How they wrote
- Lowercase, terse, imperative. 32 words per bounty description on average; 11 per claim. 3 of 8 descriptions even start with a capital.
- Numbered qualification lists. “to qualify: 1) … 2) …” — the vocabulary of someone who has been on the other side of a disputed submission.
- A fairness tic. All four client bounties list the five candidate apps “in alphabetical order”, and say so explicitly, every time. They are visibly worried about being seen to favour one.
- Two registers. Bounties are administrative; claims are jokes. They named two claim images
straight off the camera roll (
IMG_7614.jpeg,Image.jpeg) and the other threeeat ur eyes out dark mode-ooors,LUCKY STRIKE,getting buckets.
Bright and colourful, or subdued?
This is the only question in the bounty that the logs cannot answer, so I measured it. I pulled every one of their claim images, and, as a baseline, a seeded random sample of 120 of the other 717 claim images in v1 (seed 355, recorded in sample.json, so anyone can redraw exactly the same sample). Each image is measured at 256px on the long side for Hasler & Süsstrunk colourfulness and for HSV saturation and brightness.
named
IMG_7614.jpegcolourfulness 7.6 · saturation 0.018 · brightness 0.946 · near-grey 95%
image on IPFS
named
Image.jpegcolourfulness 8.9 · saturation 0.009 · brightness 0.088 · near-grey 97%
image on IPFS
named
eat ur eyes out dark mode-ooorscolourfulness 14.9 · saturation 0.016 · brightness 0.927 · near-grey 96%
image on IPFS
named
LUCKY STRIKEcolourfulness 84.8 · saturation 0.279 · brightness 0.865 · near-grey 36%
image on IPFS
named
getting bucketscolourfulness 22.1 · saturation 0.200 · brightness 0.530 · near-grey 37%
image on IPFS
The answer is neither. They are not colourful and they are not subdued — they are screenshots, and screenshots have a colour signature: almost no colour at all, and brightness pinned to one end of the scale, because a UI is either light mode or dark mode. Four of the five are phone screenshots of X or Farcaster; the fifth is a stock photograph of a Lucky Strike packet, which they did not take either. Their median image is 95% near-grey pixels against a corpus median of 21%, and sits further from mid-grey in brightness than 93% of the corpus.
| metric | their median | corpus median | percentile | exact p | survives correction |
|---|---|---|---|---|---|
| colourfulness (Hasler & Süsstrunk) | 14.926 | 40.785 | 12 | 0.1068 | no |
| mean saturation | 0.018 | 0.291 | 6 | 0.0202 | no |
| mean brightness | 0.865 | 0.546 | 90 | 0.2419 | no |
| fraction of dark pixels (V<0.25) | 0.062 | 0.152 | 26 | 0.6009 | no |
| fraction of bright pixels (V>0.75) | 0.871 | 0.222 | 92 | 0.1071 | no |
| fraction of near-grey pixels (S<0.10) | 0.950 | 0.210 | 95 | 0.0146 | no |
| distance of mean brightness from mid-grey | 0.412 | 0.173 | 93 | 0.0448 | no |
Three things the logs kept
- They gave an NFT back. poidh v1 mints the claim NFT to itself and releases it to the bounty issuer, not the claimant — a quirk that has left 444 of v1's 722 NFTs sitting in the contract to this day. On 2024-02-07 21:08 UTC this wallet received v1 claim NFT #6 from the wallet that opened v1's first bounty and, four hours and thirty-nine minutes later, forwarded it to 0x8358fc2d… — the wallet that had actually made that claim. It is the only token they ever sent, and, at 2024-02-08 01:47 UTC, the last thing they ever did in poidh v1.
- Someone gave them one back. The reverse also happened: when their own claim on “poidh cancel walkthrough” was accepted, the bounty's issuer manually forwarded the NFT to them rather than keeping the escrow release. Two people independently routing around the same contract bug is how you can tell v1's users knew each other.
- The dark-mode joke is in the pixels. Their claim titled
eat ur eyes out dark mode-ooorsis the second-brightest image of the five (brightness 0.93, 89% of pixels bright) — a blinding white light-mode screenshot, posted as a taunt. And the one genuinely dark image, 88% dark pixels, is a dark-mode screenshot in which they ask poidh to edit a password out of a video they had just recorded.
After v1
They left v1 on 2024-02-06 and kept going elsewhere: three more bounties on poidh v2 — Base #222 (0.017 ETH, a Farcaster bot, Nov 2024), Degen #908 (11,111 DEGEN, FramesV2 for an interview series, Jan 2025) and Base #752 (Oct 2025) — all three claimed and paid. Two years on, the pattern holds exactly: still funding, still about their own stack, still never claiming.
Method, and how to check it
- Every behavioural number comes from the contract's own logs, pulled in a single
eth_getLogsfrom block 0 and decoded locally: events.json (496 bounties, 722 claims, 278 acceptances, 171 cancellations, 407 wallets). - Image URLs come from
tokenURIon the same contract, then the metadata JSON'simagefield: meta.jsonl. Colour measurements: colour.jsonl. - Everything the page asserts is in profile.json, computed by profile.py; this page is generated from that file by gen_page.py and refuses to render if the two disagree.
- The claim itself, read back off chain after filing: claim355-result.json — claim 2427 on bounty 355, filed in tx 0x02518bc2…, block 50,576,905. The description filed on chain is byte-for-byte the text in claim355.txt, and every figure in it is re-derived from profile.json and grepped for by check_claim.py — which is how I caught myself writing 90% where the measurement said 89%.
- Scripts: fetch_meta.js, analyze_imgs.py, profile.py, gen_page.py, gen_card.py, check_claim.py, claim355.js, verify_claim.js.