Social graph analysis: how onchain relationships expose sybil clusters

Short answer: Sybil operators control many wallets, but those wallets have to interact, and the interaction pattern forms a graph that looks nothing like real users. Funding chains, synchronized activity, and star-shaped transfer topologies reveal the cluster behind the wallets. Social graph analysis does not need to identify the human; it needs to prove the wallets are one operation, and the graph does that at scale.

Why wallets cannot hide their relationships

Every sybil cluster has a supply chain. Wallets need funding, and funding comes from somewhere: a central wallet, an exchange withdrawal split many ways, or a chain of hops designed to look organic. Real users fund wallets irregularly from personal sources. Sybil wallets get funded in batches, in similar amounts, within tight time windows, because the operator is efficient and efficiency is visible onchain.

The second unavoidable relationship is behavior. The wallets in a cluster do the same things at the same times: claim the same airdrop, interact with the same contracts, bridge the same amounts. A thousand real users have a thousand different patterns. A thousand sybil wallets have one pattern with noise, and the noise is thinner than the operator thinks.

Reading the funding graph

Start with the funding topology. Star patterns, one wallet funding dozens, are the crudest and still common. More sophisticated operators use chains or trees, but the graph still converges: follow the funding back far enough and the branches meet. Peeling chains, where a large amount is split into smaller ones through a series of hops, have a recognizable shape that differs from normal user transfers in amount regularity and timing.

Time is the second dimension. Wallets funded within minutes of each other, that then act within minutes of each other, are not independent no matter how the funding was routed. The operator's schedule is the cluster's fingerprint. Real users do not coordinate their onchain activity to the minute across hundreds of wallets.

Behavioral clustering beyond funding

Funding analysis catches the lazy operators. The careful ones fund wallets from exchanges, breaking the visible chain. For them, use behavioral clustering: contract interaction sequences, gas price strategies, token holding durations, and activity timestamps. Wallets that interact with the same contracts in the same order with the same timing are running the same script, and the script is the identity.

Combine the layers. A wallet that was exchange-funded but behaves identically to fifty others is still sybil; the funding layer was just laundered better. No single signal is decisive, which is why the graph approach wins: it accumulates weak signals across funding, timing, and behavior until the cluster is undeniable.

Acting on clusters without punishing real communities

The risk is false positives against genuine communities: a DAO's members, a gaming guild, a group of friends who all joined the same protocol the same week. These look clustered too. The difference is in the organic texture: real communities have varied funding sources, varied activity beyond the shared contracts, and social signals like governance participation that sybil wallets never bother with.

Score clusters, do not binary-label wallets. A high-confidence cluster gets excluded from the airdrop or reward; a medium-confidence cluster gets challenged with a proof-of-humanity step. And publish the methodology in general terms. When operators know that funding timing and behavioral sync are scored, some will try to add noise, but noise at scale is expensive, and expensive is the point.

See your own numbers.

A free bot-traffic audit shows the human-automated split in your live traffic - no code changes, no commitment.

Get a free bot-traffic audit

Do allowlists stop mint bots?

They stop the lazy ones. A strict allowlist with real verification, wallet age, activity history, or off-chain identity, filters out stages one and two. Determined operators buy or farm allowlisted wallets, which is why the allowlist is the start of the defense, not the whole of it.

Should mints just accept that bots will get some supply?

Some leakage is realistic, but 'accept' is the wrong frame. Every percentage point of supply that reaches real collectors instead of bots is community goodwill and secondary-market health. The projects that treat bot defense as ongoing maintenance keep more supply in the right hands than the ones that ship one check and move on.

>