Sybil scoring: separating real users from wallet farms in airdrops
The economics of the wallet farm
An airdrop worth a few hundred dollars per wallet is worth hundreds of thousands to a farmer running a thousand wallets. The setup cost is low: wallets are free, funding can be automated, and the interaction scripts that qualify wallets are shared openly. When the expected value per wallet exceeds the farming cost, farms appear.
This is why eligibility criteria alone do not work. Every criterion you publish becomes a farming checklist: minimum transactions, minimum balance, specific protocol interactions. Farmers optimize against the published rules. The defense has to measure things the farmer cannot cheaply fake at scale.
Onchain signals that matter
Funding patterns are the richest signal. A thousand wallets all funded from the same source, in similar amounts, in a short window, are obviously one operation. Real users fund wallets from exchanges at different times in different amounts. Graph analysis of funding sources catches what per-wallet checks miss.
Timing correlation is the second pillar. Farmed wallets interact with protocols in synchronized batches because the farmer runs scripts on a schedule. Real users are gloriously asynchronous. When hundreds of wallets perform the same sequence of transactions within the same hour, week after week, you are looking at infrastructure, not a community.
Behavioral signals from the claim flow
The claim process itself is a detection surface. Device fingerprints, IP addresses, and claim timing across wallets reveal coordination that onchain data might miss. A thousand claims from a handful of devices in a single afternoon is a confession.
Design the claim flow to collect these signals naturally: require a fresh session, add small proof-of-humanity steps that are trivial for individuals and expensive at scale. The goal is not to make claiming hard. It is to make claiming hard to automate a thousand times.
Scoring, not binary classification
Binary sybil or not-sybil decisions create two failure modes: farmers who slip through and real users who get excluded. Scoring avoids both. Every claimant gets a sybil score, and the distribution design uses it: full allocation below a threshold, reduced allocation in the gray zone, exclusion at the extreme.
The gray zone is where the real work happens. Manual review of high-value gray-zone wallets, community appeals for false positives, and transparent criteria for the thresholds. A scoring system with an appeals process keeps the community's trust in a way that silent mass-exclusions never do.
What to do about the farmers you find
Exclusion from the distribution is the baseline. Consider going further: publish aggregate statistics about detected farms, which deters the next operation, and share intelligence with other projects, since farmers reuse infrastructure across airdrops. The farming ecosystem is small and its operators are repeat players.
Also plan for the farmers to adapt, because they will. Sybil scoring is an ongoing operation, not a one-time filter. Review the score distributions after every campaign, look for new patterns in the wallets that scored clean, and update the signals. The projects that keep the most tokens with real users treat sybil defense as permanent infrastructure.