← back to blog

How Sybil Detection Actually Clusters Wallets (And How Honest Multi-Wallet Users Stay Clean)

Somewhere inside an exchange’s compliance team, or a protocol’s allocation review the week before a token launch, eleven wallets just got flagged together. None of them share a name. None of them share an email. None of them ever logged into the same account. What they share is a pattern: they funded themselves from the same source address, they moved within the same three minute window, and they claimed the same testnet quest in the same order. Individually, any one of those eleven wallets looks like an ordinary user. Together, they stopped looking like eleven different people.

That’s how wallet clustering actually works, and it’s worth understanding in detail if you run more than one wallet for genuine reasons.

The setup

Start with why any of this exists. An airdrop is a limited pool of tokens, and a protocol handing that pool out wants it to reach as many genuine, separate users as it can, not a handful of people each pretending to be twenty. Every wallet that gets counted as a duplicate of another is, in effect, a real user somewhere else getting a smaller share. So before the tokens ever move, most serious protocols run some version of the same question over their entire user base: does this look like one person operating many wallets to multiply their share.

That question is the reason sybil detection exists, and it shapes almost everything that happens next, from how a protocol scores usage, to how aggressively it filters wallets right before a snapshot, to how much of the total supply gets reserved for a later clawback round aimed at wallets it catches after the fact.

What a graph actually sees

Here’s the part that surprises people the first time they hear it: none of this starts from identity. Nobody is checking a passport, and nobody needs to. What a chain analyst actually builds is a graph, a map of relationships, where wallets are dots and every transaction between them is a line. The graph doesn’t know or care who a wallet belongs to. It only knows that a line connects two dots, and that certain shapes, certain dense little clusters of dots that all move together, are far more likely to belong to one operator than to a dozen strangers who happen to like the same protocol.

A graph with thousands of wallets on it looks like noise until you start coloring in the dense little knots, and those knots are what get a second look.

The funding fingerprint

Of every signal in that graph, one is by far the loudest: where the money came from in the first place. When many wallets are funded from a single source address, especially in a tight burst, that’s the single strongest, most common tell in the entire toolkit. It makes sense why: funding many wallets from one place is administratively convenient, and convenience is exactly what shows up as a bright, obvious cluster on the graph.

Ten wallets that each received a small, similar amount from the same address within the same hour draw a shape that a dozen genuine strangers, funding themselves independently over months, essentially never draw by accident. The graph isn’t offended by convenience, it just notices it, often before a single testnet action even happens.

Timing as a signature

Money isn’t the only fingerprint. Time is another. Actions taken minutes apart across many different wallets, repeated across weeks, form a rhythm that two genuinely independent people almost never share by coincidence. Real, unrelated humans don’t swap on the same protocol within the same three minute window every week for months. They have different schedules, different time zones, different reasons for logging on.

When that rhythm shows up across a dozen wallets instead, it reads as coordination even if not one of those wallets shares any other data point with the others. The more weeks the rhythm repeats, the more confident the signal gets.

Gas and behavior patterns

Then there are the smaller, quieter details most people never think about at all: identical gas settings across wallets, the same price bid down to a fraction of a unit. Identical transaction ordering, the exact same three actions in the exact same sequence, every time. Identical click paths through the same decentralized app, as if each wallet were following a script rather than a person making independent decisions in their own order.

No single one of these details proves anything on its own. Plenty of honest users share a wallet’s default gas setting purely by coincidence. Stacked together across many wallets, though, they start to look less like coincidence and more like a signature, the digital equivalent of eleven people filling out the same form in the same handwriting.

Where the money reconverges

Here’s the detail that undoes almost everyone who tries to separate wallets carefully upstream: eventually the money has to go somewhere. Every wallet, sooner or later, needs to cash out, and when the outputs of many different wallets all drain back into one destination, whether that’s one exchange deposit address or one final wallet, all the careful separation built up earlier gets erased in a single line on the graph.

The beginning of the story can look perfectly separate: ten unrelated origins, ten unrelated timelines. The ending very often doesn’t, because ten different rivers still only empty into one sea, and analysts watch the sea just as closely as the source.

The tooling and the arms race

None of this is done by hand. Protocols, exchanges, and chain analysis vendors run heuristic clustering algorithms over public chain data, the same data anyone can see on a block explorer, just processed at a scale no person could manage manually. A handful of specialist firms build risk scoring products specifically for this, and protocols license that scoring the way a bank might license a fraud detection service.

It never really stops evolving. Every season a new signal gets discovered, folded into the model, and applied retroactively to wallets that thought their history was already settled. Detection a season ago isn’t detection today, and it won’t be detection next season either. It only ever gets a wider set of signals to weigh.

What happens to a flagged cluster

Flagging isn’t the end of the story, it’s the start of a decision. Some protocols simply zero out every wallet in a flagged cluster and move on, treating the whole group as one entity that gets one share, or no share at all. Others take a softer route, capping the reward per cluster instead of removing it entirely, on the theory that even a real operator with several honest wallets should still get counted once, not many times over.

A few run a manual review queue, where a flagged cluster can appeal and explain the shared funding, though that process is slow, inconsistent between protocols, and offers no guarantee either way. None of these outcomes are announced in advance, and a wallet usually only learns which policy applied to it after the tokens have already been distributed to everyone else.

The false positive problem

This is where the picture gets genuinely uncomfortable, because the same patterns that flag a farm also describe a lot of completely honest situations. A small family that shares one exchange account. A tiny team that funds its shared treasury from one place. A friend group that all got into a protocol together and naturally moved in similar timeframes because they heard about it from the same conversation.

None of that is a sybil operation. All of it can trigger the exact same signals. The graph, on its own, has no way to tell the difference between coordinated abuse and ordinary shared circumstance. That ambiguity isn’t a bug the industry has quietly fixed, it’s a permanent, structural feature of scoring behavior instead of identity.

The “looks like one person” bar

Which is why it matters to be precise about what this actually is. None of it proves identity, and none of it is really trying to. It’s a probability score, a confidence level that a given cluster of wallets is more likely one operator than many, and every protocol sets its own threshold for how confident is confident enough to act on.

Some thresholds are conservative and only catch the most blatant, mechanical patterns. Others are aggressive and catch a wider net, including some genuinely honest wallets caught in the wrong shape at the wrong time, which is exactly why some protocols run an appeals process for wallets that got filtered out unfairly.

How honest multi-wallet users reduce accidental linkage

For someone who genuinely has more than one wallet for real, separate reasons, a personal wallet, a trading wallet, a small team’s wallet, the honest goal isn’t to defeat a detection system. It’s to avoid accidentally recreating the exact pattern that system was built to catch.

That mostly comes down to letting real separation actually be separation: funding from more than one source over real stretches of time rather than one convenient burst, and letting each wallet’s activity reflect what that wallet is actually for, rather than mirroring the others action for action. A personal wallet behaves like a person’s actual habits. A team treasury behaves like a team’s actual schedule. None of that is a trick, and none of it is designed around what any specific detector looks for. It’s closer to just not manufacturing the coincidence in the first place, because the coincidence, not the number of wallets, is what actually draws attention.

The limits of any of this

It’s worth being blunt about the ceiling here too. Nothing here, and nothing available anywhere, promises invisibility from analysis that has enough data and enough motivation behind it. Clustering techniques keep improving, the data set only ever grows, and a determined enough look, with enough time and enough resources, will eventually surface structural patterns that genuinely exist. This isn’t an argument for outrunning that permanently, because no honest argument can promise that, and anyone selling a guaranteed method to beat detection forever is selling something that doesn’t exist.

Why this keeps mattering

Every season, detection gets a little sharper, because every season it has a larger, richer data set to learn from. The honest way to hold up under that isn’t a new evasive trick. It’s simpler and less exciting than that: actually operating the way separate, real usage would look in the first place. That’s a slower, less flashy answer than most people want, but it’s the one that keeps holding up season after season, long after any particular trick has been noticed and closed.

For more breakdowns like this, and the tools we actually use for keeping wallets organized across a season, head over to Airdrop Farming.

Get new guides and videos first — join the Telegram channel.

need infra for this today?