How do sybil attacks work on allowlists?

Short answer: Sybil attackers mass-produce identities - wallets, accounts, social profiles - to capture allowlist spots meant to be scarce. Each identity meets the letter of the entry rules while a single operator collects hundreds of allocations. Scarce access becomes farmed inventory, resold or used to dominate the mint.

The identity supply chain

Farms age wallets with small transactions, run Twitter and Discord accounts with generated engagement, and pass KYC-lite checks with synthetic documents. The cost per convincing identity keeps falling; the value per allowlist spot does not.

Why rules-based gating fails

Every published rule is an automation target. Require a retweet and farms retweet. Require wallet age and farms wait - they can afford to. Static criteria select for patience and capital, not humanity.

Behavior over checklists

Allowlist defense that works scores identity cohesion: does this wallet, this account, this session behave like one person with a history, or like a slot in a production line? The farm can fake any single signal; it struggles to fake a plausible life.

See your own numbers.

A free bot-traffic audit shows the human-automated split in your live traffic - no code changes, no commitment.

Get a free bot-traffic audit