FAQ

What Is a Sybil Address? How Airdrops Filter Them Out

Airdrop hunters often hear about being "flagged as a Sybil": a project decides that a set of addresses belongs to one person and cuts or cancels their allocation. Based on the Arbitrum Foundation's published airdrop docs and Sybil detection methodology, this guide explains what a Sybil address is, how projects identify them and how to avoid being caught up in it.

What Is a Sybil Address? How Airdrops Filter Them Out

What a Sybil address is

The term comes from a Sybil attack: one party posing as many to win an outsized share of a vote or a distribution. The Arbitrum Foundation defines Sybil accounts as accounts controlled by one entity trying to create the false appearance of many entities through deceptive on-chain activity, in order to unfairly game the $ARB airdrop.

Projects care because airdrops often hand out governance power too. As Arbitrum explains, Sybil accounts receiving an outsized share would concentrate voting power and undermine the DAO's decentralization; filtering them keeps the initial distribution as fair as possible.

How projects identify them

The Arbitrum Foundation published its Sybil detection methodology on GitHub, which serves as a typical example:

  • Funding relationships: two transfer graphs, one from ordinary transfers carrying ETH, the other from "funder" edges (the first ETH transfer into an address) and "sweep" edges (the last ETH transfer out of it).
  • Clusters: the graphs are partitioned into connected subgraphs, and large subgraphs are broken down further with the Louvain community detection algorithm.
  • Flagging patterns: for example, transferring funds within a cluster of more than 20 addresses, being funded from the same source, or showing similar activity.
  • Excluding entities first: bridges, exchanges, smart contracts and similar addresses are removed before the analysis to avoid false positives.

Arbitrum's airdrop rules also state that addresses identified as Sybils in the Hop protocol bounty program were disqualified.

Methods differ between projects and are rarely published in full, but the approach is similar: follow where funds come from and go to, and check whether a group of addresses behaves like one operator.

How to avoid being flagged

  • One person, one account: many airdrop and points programs treat multi-accounting as a violation; see why DePIN node accounts get banned. Spreading your funds across wallets for safety is one thing; farming the same campaign with several wallets is another.
  • Avoid batch operations: funding many addresses with gas from one source, running the same actions at the same time and then sweeping everything back to one address is exactly the pattern these methods look for.
  • Stay away from farming and "anti-Sybil" services: they do what the rules prohibit, and never hand over a private key or seed phrase to one.
  • Read each project's rules: eligibility, prohibited behaviour and appeal channels are whatever the official docs say.

If you are flagged

Whether there is an appeal or review is up to the project. Appeal only through official channels, ignore anyone in your messages offering to "remove a Sybil flag", and never pay or share your seed phrase for it.

Related reading: what Web3 points are and whether they become tokens, what an airdrop is and how to claim safely, testnets, points and airdrop participation.

Sources

Arbitrum 基金会:女巫账户 / Sybil accounts Arbitrum 基金会:女巫检测方法(GitHub)/ Sybil detection methodology Arbitrum 基金会:空投资格与分配 / Airdrop eligibility and distribution