How bots exploit restaking and points programs before the token generation event
Why points are irresistible to farmers
Points have three properties farmers love: they are quantifiable, they are transferable in effect (the wallets can be sold or the allocation claimed), and their future value is speculated publicly, which lets the operator calculate ROI before farming. A points program with a hyped TGE is essentially posting a bounty for the most efficient farmer.
The actions that earn points are usually designed to be easy for real users: deposit tokens, hold positions, complete social quests, refer friends. Every one of these is automatable. Deposit and hold is a script. Social quests are an API call farm. Referrals are a sybil graph. The easier the program is for genuine users, the easier it is to farm at scale.
The anatomy of a points farm
A serious farming operation has three layers. The wallet layer is thousands of addresses, generated in bulk, funded just enough to participate, often through mixers or fresh exchange withdrawals to break clustering. The automation layer scripts every point-earning action: deposits timed to maximize multipliers, quest completions on schedule, referral chains constructed to look organic.
The extraction layer plans the exit before the TGE: how to claim allocations across thousands of wallets without triggering the project's sybil filters, how to consolidate without creating an obvious on-chain graph, when to sell. The farm is a business with unit economics, and the operator knows their cost per point and expected value per token.
Where detection fails
The classic failure is filtering at the TGE instead of during the program. By claim time, the farmer has months of history that looks like engagement, because it was engagement, just automated. Retroactive sybil analysis catches the lazy farms and misses the careful ones.
The second failure is underestimating the referral graph. Referral-based points create the strongest farming incentive, because each fake wallet multiplies the farmer's earnings. Projects that weight referrals heavily without strong identity checks are effectively paying farmers to build sybil networks. The on-chain referral graph is the single best detection surface, and it is the one most programs ignore until after the damage.
Designing points that resist farming
The strongest defense is making points non-farmable by construction: reward actions that are expensive to automate and cheap for humans. Time-locked participation (points accrue to wallets that held through volatility), governance participation that requires reading and judgment, and community contributions reviewed by humans all raise the automation cost.
Identity is the second lever, applied proportionally. Full KYC for every points earner kills genuine participation; tiered verification (higher point tiers require stronger identity) preserves the funnel while capping farm scale. The farmers will still operate, but their cost per point rises toward the expected token value, which is where the business dies.
Finally, keep the points formula secret and dynamic. Published formulas get optimized; rotating multipliers and unannounced bonus windows reward genuine ongoing engagement over scripted farming. Opacity is not a substitute for design, but it raises the reverse-engineering cost.
The honest conversation projects need to have
Every points program dilutes real users to the extent it fails against farmers. Projects owe their communities honesty about the expected farm rate and the defenses in place. The programs that announce aggressive sybil filtering and then visibly enforce it retain community trust; the ones that promise the moon and deliver a farmed leaderboard do not.
Measure the farm rate continuously, not just at TGE. Track wallet clustering, action timing distributions, and referral graph density throughout the program. A rising farm rate mid-program is the signal to tighten mechanics before the TGE, not after. The leaderboard is a live adversarial system; treat it like one.