Sybil attacks in airdrops
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 5 min
In short
A Sybil attack is one person creating many accounts or addresses to pose as many people and collect a reward multiple times. Airdrop teams screen for this and exclude what they find. Screening is discretionary, and addresses that merely happen to share a usage pattern have been excluded too.
Key points
- One person posing as many addresses to multiply a reward
- Teams detect it from transaction patterns and funding sources
- Exclusion is discretionary with no guaranteed appeal
- Gas already spent is not returned when you are excluded
Definition
An attack in which one actor creates many identities — accounts or addresses — to appear as many independent participants. In airdrops it refers to doing so in order to receive a distribution multiple times.
The name comes from distributed systems research: any scheme that counts participants breaks down if one actor can appear as many. Airdrops designed to give 'one share per user' inherit exactly that problem.
Detection relies mostly on on-chain data — addresses funded from a common source, transactions with near-identical timing and content, the same operations repeated in the same order, funds eventually consolidated into one address. These signals group addresses into clusters, and some projects have published their analysis and exclusion lists.
What matters is that this determination carries no procedural guarantees. The team sets the criteria, often without publishing them, and an appeals process is not assured. There are also reported cases of people who simply kept separate personal wallets being excluded for pattern similarity. Exclusion does not refund the gas and fees already paid.
Watch out for
- · Criteria are usually set afterwards, so no usage pattern can be confirmed safe in advance
- · Services offering to farm multiple addresses for you require handing over keys or funds
- · Using someone else's identity documents can breach Japanese law