How bots exploit restaking and points programs before the token generation event

Short answer: Points programs promise future tokens for current engagement: deposit assets, complete quests, climb the leaderboard, earn points. For bot operators, points are a farmable asset with a known future value, which makes them worth industrial-scale exploitation. Sybil networks spin up thousands of wallets, automate the point-earning actions, and accumulate positions that dilute every real user's eventual allocation. By the time of the token generation event, the leaderboard reflects bot efficiency more than community engagement. The programs that survive are the ones designed as adversarial systems from day one.

Why points are irresistible to farmers

Points have three properties farmers love: they are quantifiable, they are transferable in effect (the wallets can be sold or the allocation claimed), and their future value is speculated publicly, which lets the operator calculate ROI before farming. A points program with a hyped TGE is essentially posting a bounty for the most efficient farmer.

The actions that earn points are usually designed to be easy for real users: deposit tokens, hold positions, complete social quests, refer friends. Every one of these is automatable. Deposit and hold is a script. Social quests are an API call farm. Referrals are a sybil graph. The easier the program is for genuine users, the easier it is to farm at scale.

The anatomy of a points farm

A serious farming operation has three layers. The wallet layer is thousands of addresses, generated in bulk, funded just enough to participate, often through mixers or fresh exchange withdrawals to break clustering. The automation layer scripts every point-earning action: deposits timed to maximize multipliers, quest completions on schedule, referral chains constructed to look organic.

The extraction layer plans the exit before the TGE: how to claim allocations across thousands of wallets without triggering the project's sybil filters, how to consolidate without creating an obvious on-chain graph, when to sell. The farm is a business with unit economics, and the operator knows their cost per point and expected value per token.

Where detection fails

The classic failure is filtering at the TGE instead of during the program. By claim time, the farmer has months of history that looks like engagement, because it was engagement, just automated. Retroactive sybil analysis catches the lazy farms and misses the careful ones.

The second failure is underestimating the referral graph. Referral-based points create the strongest farming incentive, because each fake wallet multiplies the farmer's earnings. Projects that weight referrals heavily without strong identity checks are effectively paying farmers to build sybil networks. The on-chain referral graph is the single best detection surface, and it is the one most programs ignore until after the damage.

Designing points that resist farming

The strongest defense is making points non-farmable by construction: reward actions that are expensive to automate and cheap for humans. Time-locked participation (points accrue to wallets that held through volatility), governance participation that requires reading and judgment, and community contributions reviewed by humans all raise the automation cost.

Identity is the second lever, applied proportionally. Full KYC for every points earner kills genuine participation; tiered verification (higher point tiers require stronger identity) preserves the funnel while capping farm scale. The farmers will still operate, but their cost per point rises toward the expected token value, which is where the business dies.

Finally, keep the points formula secret and dynamic. Published formulas get optimized; rotating multipliers and unannounced bonus windows reward genuine ongoing engagement over scripted farming. Opacity is not a substitute for design, but it raises the reverse-engineering cost.

The honest conversation projects need to have

Every points program dilutes real users to the extent it fails against farmers. Projects owe their communities honesty about the expected farm rate and the defenses in place. The programs that announce aggressive sybil filtering and then visibly enforce it retain community trust; the ones that promise the moon and deliver a farmed leaderboard do not.

Measure the farm rate continuously, not just at TGE. Track wallet clustering, action timing distributions, and referral graph density throughout the program. A rising farm rate mid-program is the signal to tighten mechanics before the TGE, not after. The leaderboard is a live adversarial system; treat it like one.

See your own numbers.

A free bot-traffic audit shows the human-automated split in your live traffic - no code changes, no commitment.

Get a free bot-traffic audit

Do allowlists stop mint bots?

They stop the lazy ones. A strict allowlist with real verification, wallet age, activity history, or off-chain identity, filters out stages one and two. Determined operators buy or farm allowlisted wallets, which is why the allowlist is the start of the defense, not the whole of it.

Should mints just accept that bots will get some supply?

Some leakage is realistic, but 'accept' is the wrong frame. Every percentage point of supply that reaches real collectors instead of bots is community goodwill and secondary-market health. The projects that treat bot defense as ongoing maintenance keep more supply in the right hands than the ones that ship one check and move on.

>