Sybil clusters

How sybils operate

Three traits almost every sybil cluster shares. These are the patterns investigators look for when tracing wallets across a chain.

01

One operator, many wallets

A single person (or a small team) controls dozens to thousands of addresses, each dressed up to look like an independent, ordinary user.

02

Manufactured activity

Wallets are drip-fed identical amounts, run the same swaps, and bridge on the same days — just enough on-chain history to pass an eligibility filter.

03

Built to farm rewards

The goal isn't to use the product. It's to multiply one person's share of an airdrop, a grants pool, or an incentive program.

Case study · Arbitrum airdrop, March 2023

What a real sybil attack looks like

When Arbitrum launched the ARB token, analysts at X-explore and WuBlockchain ran the entire recipient list through a community-detection model. The result is the clearest public picture of sybil farming to date.

253M ARB tokens claimed by sybils ≈ 21.8% of the entire airdrop
148,595 Sybil addresses identified out of 624,136 wallets analyzed
~4,000 Sybil communities coordinated wallet clusters
279,328 Multi-account addresses ≈ 47.96% of tokens — 557M ARB

Four tricks used to dodge detection

Via exchanges 2,997 addresses

Addresses withdrew tiny, near-identical amounts from Binance (0.00114–0.00116 ETH, ~$2) over a 5-day window — then behaved in lockstep.

Via bridges 1,114 addresses

Addresses crossed to Arbitrum through the HOP bridge with fixed ~0.0025 ETH (~$4) deposits, and together collected 1.08M ARB.

Via smart contracts 9,483 addresses

Donor addresses funded thousands of wallets through the Disperse contract — one seed paid 1,274 airdrop wallets — netting 10.98M ARB.

Single actors 198–202 addresses

Wallets run by one attacker earned 174,375 and 204,250 ARB by staying active after the snapshot and mirroring behaviour across Optimism.