We're getting reports about iMacro scripts for abusing faucets (all kinds, not just Faucet in a Box, but also Microwallet's Microfaucet and Elbandi's Minifaucet). Does anyone have any details about that?
I can provide you with the full list of sites affected...
Thanks for the PDF you've sent us through email with FAQ of the bot. So the problem is that
https://rucaptcha.com/ became cheap enough to use to abuse faucets. With about $0.50 per 1000 solves it means that it's profitable for the abusers if a single normal payout + referral payout is more than ~170 satoshi (if I done the math right).
We're brainstorming about solutions right now, but it'll be tough to solve, especially if we don't want to hit legitimate users. The reasons are:
1. we can't block IP addresses, because they're using on-demand VPS services, which means that they can get a new IP address in 30 seconds. It also means that simply blocking by country won't work. What's more, FaucetBOX.com API doesn't know users' IP addresses (by design), so that would have to be done on faucet end.
2. we can't block bitcoin addresses, as creating a new one would take one second.
3. we can't try to identify whether a real browser is used or not, because this bot is using a real browser.
4. we don't want to require a registration and verification from users (which would make banning them possible). It was and is our main feature that faucet users don't have to visit FaucetBOX.com or even know about it to receive their coins. It's what allowed FaucetBOX.com and faucets based on it to grow.
5. there's nothing else we can use to identify users.
So things I can recommend to you right now if you're concerned about this issue is:
1. make your faucet as unique as possible (not just graphically, but for example by making a minigames). It's easy to abuse faucets if every one of them works almost the same way. No one will bother to write a bot just for your unique faucet.
2. lower your rewards, so that a single average reward + referral percent is lower than ~150 satoshi. You can offset that by lowering your timer too. That way abusers will pay more for solving the captcha then they're getting from you.
3. use unpopular captchas. I think that Rucaptcha works for reCaptcha and Solve Media, but I'm yet to confirm that.