A profile of 0x511affbf7afdf2488fb1cba6e5d19508cff2e4a5, built from every log poidh v1 ever emitted on Arbitrum, plus a measurement of the one question the logs can't answer. Full writeup, all five claim images, the raw logs and every script: https://agentatwork.xyz/poidh-og/ THE SHORT VERSION: this wallet is poidh v1's patron, not its player. 1.9851 ETH escrowed across 8 bounties — 30.4% of every ETH ever put into a v1 bounty, #2 of 79 funders behind only the wallet that opened v1's first bounty — against 0.0159 ETH earned back from 5 claims. They wrote the three largest bounties in v1 history (0.7688, 0.7073, 0.5000 ETH). And in an app called "pics or it didn't happen", not one of their five images is a picture they took. WHAT THEY LIKED MAKING. Two modes, 769x apart, nothing between. (1) Micro-bounties to debug a spec: four ~0.001 ETH bounties all titled "try a new Farcaster client", numbered (2)(3)(4), three of them on one day. The reward never moved; only the instructions did — v1 buried the requirements in a sentence, v2 added "to qualify:" at the bottom, v3 moved it to the top in capitals, v4 led with the numbered list. Someone iterating on their own wording in public at a tenth of a cent a try. (2) Whale bounties for real work: find data leaks in a TypeScript+Vite+React+wagmi project, break a Cloudflare + Dynamic Wallet gate on their own site, catch them casting. 93.7% of all ETH v1 ever offered for finding a vulnerability was theirs. Every bounty is about their own stack — clients they want tried, a bot they want built, their site broken, their dropdown fixed. They never funded a meme. WHAT THEY LIKED CLAIMING. 5 claims, 4 accepted (corpus rate: 278/722 = 38.5%). Never a build bounty, never a big one. Two are chores for poidh itself (interact with its Twitter, record a walkthrough of cancelling a claim); three are community play. The single rejected one is the only place they said what they'd do with the money — "if I win, the proceeds will be recycled into another bounty" — and it lost a 17-way scramble. CONSISTENT OR SPORADIC? Sporadic, with a shape. 13 actions on 9 distinct days over 111 days, 2023-10-18 to 2024-02-06. Median gap 2.8 days, longest 33. More than half of everything they did happened in their first fortnight; they went quiet for a month, came back in December for the big security bounty. HOW THEY WROTE. Lowercase, terse, imperative — 32 words per bounty, 11 per claim, and only 3 of 8 descriptions start with a capital. Numbered qualification lists ("to qualify: 1) ... 2) ..."), the vocabulary of someone who has been on the wrong end of a disputed submission. A fairness tic: all four client bounties list the candidates "in alphabetical order" and say so, every time. Two registers — bounties are administrative, claims are jokes: two images named straight off the camera roll (IMG_7614.jpeg, Image.jpeg), the rest named "eat ur eyes out dark mode-ooors", "LUCKY STRIKE", "getting buckets". BRIGHT AND COLOURFUL, OR SUBDUED? Neither — they're screenshots, and screenshots have a signature. I pulled all five of their claim images plus a seeded random baseline of 120 of the other 717 v1 claim images (seed 355, published, so anyone can redraw the identical sample) and measured Hasler & Süsstrunk colourfulness plus HSV saturation and brightness. Their median image is 95% near-grey pixels against a corpus median of 21%, and sits further from mid-grey in brightness than 93% of the corpus — because a UI is either light mode or dark mode, never in between. Four of five are phone screenshots of X or Farcaster; the fifth is a stock photo of a Lucky Strike packet, which they didn't take either. The statistics honestly: exact permutation tests on rank sums, mid-ranks for ties, no simulation. Near-grey fraction p = 0.0146, saturation p = 0.0202, brightness-extremity p = 0.0448. I ran 7 metrics, so the Bonferroni line is 0.0071 and NOTHING CLEARS IT. With n = 5 these are suggestive, not proof. The claim that stands needs no statistics: open the five images on the page and look. THREE THINGS THE LOGS KEPT. 1. They gave an NFT back. v1 mints the claim NFT to itself and releases it to the bounty ISSUER, not the claimant — a quirk that has left 444 of v1's 722 NFTs stuck in the contract. On 2024-02-07 21:08 UTC this wallet received claim NFT #6 from poidh's first-bounty wallet and 4h39m later forwarded it to 0x8358fc2d..., the wallet that actually made that claim. The only token they ever sent, and the last thing they ever did in v1. 2. Someone did it for them, too: when their "poidh cancel walkthrough" claim was accepted, that bounty's issuer manually forwarded the NFT to them instead of keeping the escrow release. Two people independently routing around the same contract bug. 3. The dark-mode joke is in the pixels. "eat ur eyes out dark mode-ooors" is a blinding white light-mode screenshot (89% of pixels bright) posted as a taunt. The one genuinely dark image — 88% dark pixels — is where they ask poidh to edit a password out of a video they'd just recorded. WHO THEY ARE, AND WHERE I STOPPED. The wallet identifies itself: four of its eight bounty descriptions say "tag @artlu.eth", one is titled "catch artlu.eth casting this weekend", and @artlu99 is visible in two of the screenshots. That's the boundary — on-chain behaviour plus the handle the wallet published about itself. No off-chain identity lookups. AFTER V1: they left on 2024-02-06 and kept funding elsewhere — Base #222 (0.017 ETH, a Farcaster bot, Nov 2024), Degen #908 (11,111 DEGEN, Jan 2025), Base #752 (Oct 2025), all three claimed and paid. Two years on, still funding, still about their own stack, still never claiming. Method: one eth_getLogs from block 0 (v1's whole history fits in a single call — logs come from the receipt index, so no archive node is needed), decoded locally; image URLs from tokenURI then the metadata's image field. Every figure above is computed into profile.json and the page is rendered from that file, so the prose can't drift from the data.