{"id":13630259,"url":"https://github.com/handshake-org/hs-airdrop","last_synced_at":"2026-02-18T04:35:29.771Z","repository":{"id":38435033,"uuid":"150429566","full_name":"handshake-org/hs-airdrop","owner":"handshake-org","description":"Decentralized airdrop to open source developers","archived":false,"fork":false,"pushed_at":"2024-02-26T12:42:28.000Z","size":229,"stargazers_count":1407,"open_issues_count":32,"forks_count":174,"subscribers_count":60,"default_branch":"master","last_synced_at":"2025-10-08T06:37:39.223Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/handshake-org.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-09-26T13:17:49.000Z","updated_at":"2025-10-04T13:58:25.000Z","dependencies_parsed_at":"2024-06-19T05:25:49.451Z","dependency_job_id":"be655389-658c-46dc-b56b-9b3faa6b6e86","html_url":"https://github.com/handshake-org/hs-airdrop","commit_stats":null,"previous_names":[],"tags_count":18,"template":false,"template_full_name":null,"purl":"pkg:github/handshake-org/hs-airdrop","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/handshake-org%2Fhs-airdrop","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/handshake-org%2Fhs-airdrop/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/handshake-org%2Fhs-airdrop/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/handshake-org%2Fhs-airdrop/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/handshake-org","download_url":"https://codeload.github.com/handshake-org/hs-airdrop/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/handshake-org%2Fhs-airdrop/sbom","scorecard":{"id":454255,"data":{"date":"2025-08-11","repo":{"name":"github.com/handshake-org/hs-airdrop","commit":"8b857e8099b32da84a9fa85cd37882a15922b376"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.3,"checks":[{"name":"Code-Review","score":2,"reason":"Found 6/25 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 12 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T09:09:07.697Z","repository_id":38435033,"created_at":"2025-08-19T09:09:07.697Z","updated_at":"2025-08-19T09:09:07.697Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29568742,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-18T04:18:28.490Z","status":"ssl_error","status_checked_at":"2026-02-18T04:13:49.018Z","response_time":162,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T22:01:36.231Z","updated_at":"2026-02-18T04:35:24.761Z","avatar_url":"https://github.com/handshake-org.png","language":"JavaScript","funding_links":[],"categories":["JavaScript"],"sub_categories":[],"readme":"# Handshake Airdrop\n\nRedemption tool for the Handshake network's decentralized airdrop to open\nsource developers.\n\n## A word of warning\n\nIn past weeks, it's become apparent that there are now various scams and\nphishing attempts targeting GitHub users. Handshake contributors will _never_\nask you for your private keys, and revealing your private key to _anyone_ is\nnot necessary to redeem the airdrop.\n\n`hs-airdrop` is the only tool recommended for airdrop redemption. Use anything\nelse at your own risk.\n\n## How It Works\n\nThe Handshake airdrop is a [merkle tree][tree] whose root is added to the\nconsensus rules of the Handshake protocol. This allows the owner of\nan eligible private key to publish a signed merkle proof on chain in order to\nredeem their airdrop. If your private key is not found by this tool in the\nmerkle tree, you are not eligible to claim HNS coins. A blinding factor (or\n[nonce][nonces]) was generated for each recipient to allow recipients to claim\ntheir coins anonymously. For a detailed description of the airdrop tree construction process,\nread [this comment](https://github.com/handshake-org/hs-airdrop/issues/35#issuecomment-586699876).\n\nPublic keys from open source developers were collected in the following ways.\nIf you are an open source developer that meets the requirements listed below\nyou may be able to claim __4,246.994314 HNS__ from this airdrop:\n\n* ~250,000 GitHub users with 15 or more followers during the week of __2019-02-04__\nwere identified and their PGP and SSH keys were downloaded. Out of those\n~250,000 users, ~175,000 of them had valid SSH and/or PGP keys at the time of\nthe merkle tree creation.\n\n* Roughly 30,000 keys from the PGP web-of-trust strong set have also been\nincluded in the tree.\n\n* Hacker News accounts which are linked with Keybase\naccounts are included in the tree provided they were ~1.5 years old during the\ncrawl.\n\n\nThere are a few gotchas:\n\n* If you signed up for the HNS faucet at handshake.org, your GitHub key was\nremoved from the airdrop. The faucet payouts are recorded in\n[proof.json](https://github.com/handshake-org/hs-tree-data/blob/master/proof.json)\nand were included in early mainnet blocks already. Restore your seed phrase for\nthe address you registered on the website and you should have your HNS coins\nwaiting for you. You can use wallets like\n[hsd](https://github.com/handshake-org/hsd) or [Bob](https://bobwallet.io) for this.\n\n* If you met the criteria for a Github airdrop but did not have either a SSH or\nPGP key on your Github account at the time of snapshot/tree creation, you do not\nhave coins allocated to you in the merkle tree.\n\n* We do not allow standard PGP signatures on the\nconsensus layer. This is done for simplicity and safety. This means that a\nregular call to `$ gpg --sign` will not work for handshake airdrop proofs. As\nfar as SSH keys go, people typically do not sign arbitrary messages with them.\nBecause of this, we require a special tool to do both the signing and merkle proof\ncreation.\n\n* The Handshake airdrop tree was constructed ONE time and can not be changed\nwithout a hard fork. If you are not in the airdrop tree, you can not be added\nto it retroactively.\n\n* Airdrop proofs are not relayed in the same way as normal transactions. Therefore, the hash\nreturned by `sendrawairdrop` will not show up on most block explorers like\na normal transaction hash. To track your airdrop, search for your wallet address instead.\nYou will see a payment to your address included in the coinbase transaction of a block.\n\n\n## Privacy\n\nAn airdrop to GitHub and PGP users presents an obvious privacy concern: GitHub\nand PGP keys are generally tied to a person's real identity. While impractical,\na determined analyst could link an on-chain airdrop redemption to a\nperson's identity.\n\nTo solve the privacy issue in a non-interactive way, a 32 byte nonce has been\n[encrypted to][nonces] your public key (you will have to grind a file full of\nmany ciphertexts to find it). For EC keys, this nonce is treated as a scalar\nand is used to derive a new key from your old one. For RSA keys, a much more\n[complicated setup][goosig] is necessary. In either case, once your _new_ key\nis derived using this nonce, you will be able to find its corresponding leaf in\nthe merkle tree published above.\n\nPublishing a signed airdrop proof using this method _does not_ leak any\ninformation about your actual identity.\n\nThe full list of keys will be destroyed upon mainnet launch. Plaintext nonces\nare not saved at all during the generation phase. The ephemeral keys used for\nthe ECIES key exchanges are also not saved.\n\n_NOTE: since block height 52590 (29 January, 2021) the goosig feature is DISABLED.\nRead the discussion [here](https://github.com/handshake-org/hsd/pull/305).\nIf your airdrop key is RSA, you will have to claim with `--bare` (see below)_\n\n## Security\n\nIf you're uncomfortable having third party software access your PGP and SSH\nkeys, you are always able to generate this proof on an air-gapped machine. QR\ncode generation will be added to this tool for convenience (eventually).\n\nA community member created instructions for\n[how to use Docker as a pseudo-airgap](https://github.com/handshake-org/hs-airdrop/issues/106)\nwhen claiming. These instructions may be helpful for you but have not been verified by\nproject maintainers.\n\n## Fallback for HSMs\n\nNot everyone keeps their SSH and PGP keys on their laptop. In the event that\nyour key is not accessible by the signing tool, the signing tool can present\nyou with the raw data needed to be signed. Your regular key is _also_ included\nin the merkle tree (concatenated with a random nonce, seeded by the encrypted\nscalar to preserve privacy). Unfortunately, this will forgo the privacy\npreservation mechanism described above.\n\n## Accepted Key Algorithms\n\nTo simplify consensus implementation, we only allow the top 3 most popular key\nalgorithms used on github:\n\n- __RSA__ (1024 to 4096 bit modulus, e \u003c= 33 bits) - See the Handshake paper as\n  to why 1024 bit moduli are considered acceptable.\n- __Ed25519__\n- __P256__ (NIST curve)\n\n## Faucet Participants and Sponsors\n\nThis tool also allows for the creation of proofs for faucet recipients and\nsponsors. See the usage below for details.\n\n## Usage\n\nIf you are unfamiliar with sending blockchain transactions, you can learn what\n\"transactions\" are and what \"fees\" mean on\n[bitcoin.org](https://developer.bitcoin.org/devguide/transactions.html).\nThe `--fee` argument sends an exact amount of HNS coins (default 0.1 HNS) to the\nHandshake network to include your claim into the blockchain. You will receive\n4,246.994314 HNS coins (minus fee amount) to your address.\n\nThe passphrase requested during the claiming process is for decrypting your SSH/PGP key.\n\n```\n$ hs-airdrop -h\n\n  hs-airdrop (v0.7.0)\n\n  This tool will create the proof necessary to\n  collect your faucet reward, airdrop reward, or\n  sponsor reward on the Handshake blockchain.\n\n  Usage: $ hs-airdrop [key-file] [id] [addr] [options]\n         $ hs-airdrop [key-file] [addr] [options]\n         $ hs-airdrop [addr]\n\n  Options:\n\n    -v, --version         output the version number\n    -b, --bare            redeem airdrop publicly (i.e. without goosig)\n    -f, --fee \u003camount\u003e    set fee for redemption (default: 0.1)\n    -d, --data \u003cpath\u003e     data directory for cache (default: ~/.hs-tree-data)\n    -h, --help            output usage information\n\n  [key-file] can be:\n\n    - An SSH private key file.\n    - An exported PGP armor keyring (.asc).\n    - An exported PGP raw keyring (.pgp/.gpg).\n\n  [id] is only necessary for PGP keys.\n\n  [addr] must be a Handshake bech32 address.\n\n  The --bare flag will use your existing public key.\n  This is not recommended as it makes you identifiable\n  on-chain.\n\n  This tool will provide a JSON representation of\n  your airdrop proof as well as a base64 string.\n\n  The base64 string must be passed to:\n    $ hsd-rpc sendrawairdrop \"base64-string\"\n\n  Examples:\n\n    $ hs-airdrop ~/.gnupg/secring.gpg 0x12345678 hs1q5z7yyk8xrh4quqg3kw498ngy7hnd4sruqyxnxd -f 0.5\n    $ hs-airdrop ~/.ssh/id_rsa hs1q5z7yyk8xrh4quqg3kw498ngy7hnd4sruqyxnxd -f 0.5\n    $ hs-airdrop ~/.ssh/id_rsa hs1q5z7yyk8xrh4quqg3kw498ngy7hnd4sruqyxnxd -f 0.5 --bare\n    $ hs-airdrop hs1q5z7yyk8xrh4quqg3kw498ngy7hnd4sruqyxnxd\n```\n\n## Update: Since block height 52590 (29 January, 2021) the goosig feature is DISABLED.\n\nRead the discussion [here](https://github.com/handshake-org/hsd/pull/305).\nIf your airdrop key is RSA, you **MUST** generate your claim with `--bare`.\nOtherwise, you will get the error [`bad-goosig-disabled`](https://github.com/handshake-org/hs-airdrop/issues/131).\n\n### Notes\n\nNote that if you ran `hs-airdrop` before mainnet, you will need to upgrade to\nthe latest version of hs-airdrop and clear the cache (`rm -rf ~/.hs-tree-data`).\nThe usual error thrown in this case is `Invalid checksum: tree.bin`.\n\nThe JSON returned by this tool will include your HNS address encoded as separate\nhash and version values. These values can be\n[encoded back into an HNS address](https://github.com/handshake-org/hs-airdrop/issues/36)\nfor verification before broadcast.\n\nUsers have occasionally reported issues downloading the tree data from GitHub.\nIf you get an error like the following, you may just need to wait a few minutes\nand try again:\n\n```\nAttempting to create proof.\nThis may take a bit.\nDecrypting nonce...\nDownloading: https://github.com/handshake-org/hs-tree-data/raw/master/nonces/111.bin...\nError: Client network socket disconnected before secure TLS connection was established\nat TLSSocket.onConnectEnd (_tls_wrap.js:1084:19)\nat Object.onceWrapper (events.js:273:13)\nat TLSSocket.emit (events.js:187:15)\nat endReadableNT (_stream_readable.js:1085:12)\nat process._tickCallback (internal/process/next_tick.js:63:19)\n```\n\n\n## License\n\nMIT License.\n\n- Copyright (c) 2018-2020, Christopher Jeffrey (https://github.com/chjj)\n- Copyright (c) 2018-2020, Handshake Contributors (https://github.com/handshake-org)\n\nSee LICENSE for more info.\n\n[tree]: https://github.com/handshake-org/hs-tree-data\n[nonces]: https://github.com/handshake-org/hs-tree-data/tree/master/nonces\n[goosig]: https://github.com/handshake-org/goosig\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhandshake-org%2Fhs-airdrop","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhandshake-org%2Fhs-airdrop","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhandshake-org%2Fhs-airdrop/lists"}