What Is a Sybil Attack?
A sybil attack is one actor pretending to be many. In crypto that usually means hundreds of wallets, all funded from one source, all acting like independent users. Airdrop farmers, fake governance majorities, and inflated "community" metrics are the everyday versions. The name comes from a book about multiple personalities; the mechanic is older than blockchains.
How It Actually Works
- Creating wallets is free. The attacker needs a little gas and, often, a way to hide that the wallets share a funder. Mixers, chains of intermediate addresses, and timed activity dress the farm as a crowd.
- Airdrop campaigns try to reward real users and instead reward whoever ran the most wallets through the qualifying actions. Anti-sybil filters (clustering, activity heuristics, identity apps) catch the sloppy farms and miss the careful ones.
- In DAO votes, sybils only matter if voting is per-wallet rather than per-token. Token-weighted votes have a different problem: whales. One-wallet-one-vote has sybils. There is no free lunch.
Risks and Common Mistakes
- Trusting user counts, unique minters, or "holders" on a fresh token. Bubblemaps exists because lists of addresses hide clusters.
- Joining a proof-of-personhood scheme without reading what data it collects. Solving sybils by scanning faces or government IDs trades one problem for another; my KYC entry covers the data side.
- Running a farm yourself for "points." Besides the ethics, you are often just unpaid QA for a token that may never pay, and you may still get filtered. See points programs.
When It Matters
Reading any metric that counts wallets as people, judging airdrop eligibility drama, and staying calm when a protocol "cracks down on farmers." The honest question is always: what did they actually measure?
Related Terms
Glossary · Learn · Resource Library · Return to Official Home Page
Copyright © 2026 Crypto Guidance Inc.