← back to blog

What On-Chain Reputation Scores Actually Measure

Every few months a new “on chain reputation score” shows up, usually attached to a claim that it will fix airdrop farming, credit markets, or Sybil resistance in one shot. None of them do that on their own. They’re heuristics built on public transaction data, and once you know what goes into the math, the marketing around them gets a lot less mysterious.

This isn’t a defense or a takedown of any particular score. It’s a look at the actual inputs, because that’s what determines whether a score means anything for a given use case.

There’s no single “reputation” being measured

The phrase “on chain reputation” gets used for at least three different things, and they don’t overlap as much as people assume.

The first is identity-style scoring: is this address controlled by a real, unique human, distinct from other addresses. Gitcoin Passport and similar tools work in this lane, aggregating “stamps” from off-chain accounts (GitHub, ENS, Coinbase KYC, BrightID) and on-chain activity into a single number used mostly to gate quadratic funding rounds and some airdrops.

The second is credit-style scoring: does this wallet’s DeFi history suggest it repays loans, avoids liquidations, and holds positions responsibly. RociFi, ARCx, and Spectral-style credit scores fall here, built from lending protocol event logs (Aave, Compound, MakerDAO) rather than general transaction history.

The third, and the one most relevant to airdrop eligibility, is activity-and-authenticity scoring: does this address look like a real, independent, engaged user of a protocol or ecosystem, as opposed to one of five thousand near-identical addresses created to farm a token distribution. This is the one projects build in-house, usually undisclosed in detail, and it’s the one that decides who gets an allocation and who gets filtered before the snapshot even matters.

These three types answer different questions with different data. A wallet can score well on identity uniqueness and still get filtered by an activity heuristic, or vice versa.

What actually feeds the score

Strip away the branding and most activity-based reputation systems pull from a short list of on-chain facts, because that’s all a blockchain actually records.

Wallet age and first-transaction date. Every address has a public creation timestamp implied by its first transaction. Wallets funded and active for years look categorically different from wallets that appeared two weeks before a snapshot.

Transaction count and gas spent. How many times, over what period, and how much actual ETH or L2 gas was burned doing it. A wallet with three transactions and a wallet with three hundred read very differently even if both technically “used” the app.

Protocol and contract diversity. How many distinct, unrelated contracts has the address touched. A wallet that only ever called one airdrop-farming dApp looks different from one that also swaps on a DEX, bridges, mints NFTs, and interacts with lending markets, because farming bots are usually built to do one narrow thing efficiently.

Funding source. Where the wallet’s initial ETH or gas token came from. This is one of the most heavily weighted signals, because it’s also one of the hardest to fake without leaving a pattern. More on this below.

Balance history and holding behavior. Does the wallet hold assets or immediately route everything back out. Pure pass-through wallets, where tokens or airdrops are claimed and instantly swept to another address, are an easy pattern to flag.

Cross-chain and bridging activity. Genuine multi-chain users tend to have organic, staggered bridging history. Bots that need to appear multi-chain often bridge the same amount, at the same interval, across a batch of wallets, at nearly the same time.

Off-chain attestations. Things like Gitcoin Passport stamps, POAP attendance, ENS ownership, or KYC’d exchange withdrawals get folded into some scores as a costly-to-fake signal, since acquiring them individually per wallet takes real time or money.

None of these signals is decisive alone. Reputation scoring is almost always a weighted composite, and the weights are usually kept private specifically so they’re harder to reverse-engineer and game.

The clustering problem: how funding source gives wallets away

The single most common way chain analysis links wallets isn’t clever cryptography. It’s shared funding.

If fifty wallets all received their initial gas from the same centralized exchange withdrawal, the same faucet, or worse, directly from one funding wallet in a repeated pattern, that’s a cluster. Chain analysis firms and in-house project analytics teams look for exactly this: address A sends 0.01 ETH to addresses B through Z within a short time window, then B through Z all interact with the same contract in a similar sequence. That’s not proof of malicious intent by itself, but it’s a strong enough correlation that most sybil-detection systems treat it as a primary signal, not a footnote.

Timing correlation compounds it. Wallets that all execute their “qualifying” transaction within seconds of each other, in the same order, using the same gas price down to the wei, look like they’re driven by the same script rather than five hundred independent people who happened to show up. Behavioral fingerprints, like identical transaction sequencing or identical contract call parameters across addresses, get picked up the same way.

This is also where infrastructure enters the picture, and it’s worth being direct about what proxies and anti-detect browsers do and don’t solve. A different IP per wallet, a different browser fingerprint per wallet, and separated cookies and storage address the browser and network layer of correlation. They don’t touch the on-chain layer. If twenty wallets funded from the same source execute identical transactions in identical order, no proxy setup changes that data, because it never touched the network layer in the first place. Good infrastructure hygiene (unique residential IPs per identity, real device fingerprints instead of spoofed ones, wallets that aren’t all funded from one visible source) reduces the number of correlation signals available to an analyst. It doesn’t erase the on-chain footprint, and it doesn’t guarantee a wallet passes any given project’s filter, because most teams combine several signal types specifically so no single defensive measure covers all of them.

What a high score doesn’t mean

A high reputation score is not a guarantee of an allocation, a payout, or any return. Projects run their own filters on top of whatever public or third-party score exists, and those filters change per snapshot, often without being published in advance. A wallet that scores well on Gitcoin Passport can still be excluded from an unrelated project’s airdrop because that project weighted its own heuristics differently.

It’s also not a measure of trustworthiness in any general sense. These scores measure patterns in publicly observable transaction data. They can’t see intent, they can’t confirm a human is behind an action rather than a script running a human-like schedule, and they produce false positives against real users with unusual habits (new wallets, infrequent traders, people who only use one chain) as often as they catch real farms.

Scores are also not static or permanent. A wallet’s reputation, in any of the three senses above, is recalculated from whatever data exists at the time it’s queried, and both the underlying activity and the weighting model can change between one snapshot and the next.

The practical takeaway

Treating airdrop eligibility as operations work rather than a lottery means paying attention to what actually generates a defensible on-chain history: genuine, staggered protocol usage across a wallet’s own lifetime, funding that doesn’t trace back to one visible source shared across many addresses, and behavior that doesn’t look identical across a batch. None of that is a workaround for any platform’s terms, and none of it changes the basic fact that these scores are heuristics, not verdicts, built by teams who reserve the right to change the rules per drop.

Reviews of the tools that sit around this (anti-detect browsers, RPC providers, wallet software, airdrop trackers) go up on this site as they get tested, with the same approach: what the tool actually does, not what the marketing claims.

Read more breakdowns like this one on the Airdrop Farming home page.

Get new guides and videos first — join the Telegram channel.

need infra for this today?