Technical Definition

Sybil Attack

A Sybil attack is the creation of many fake or coordinated identities by a single entity to gain disproportionate influence in a system designed to give equal weight per participant — airdrops, governance votes, point programs, or social platforms.

By Crypto University Editorial
Airdrop FarmingProof of Personhood

Key Insight

Sybil activity distorts every "one person, one share" distribution in crypto. For honest traders, Sybil farming dilutes airdrop allocations and corrupts governance; for would-be Sybil farmers, modern detection now makes most attempts unprofitable.

Common Misconceptions

Underestimating modern Sybil detection — funding obfuscation alone is not enough.

Buying "pre-farmed" wallets that are already on blacklists.

Over-funding too many wallets and ending up with worse expected value than running a few real ones well.

Detailed Explanation

How It Works: An attacker generates dozens to thousands of wallets and performs the same qualifying actions on each (bridging, swapping, holding) to multiply their share of a future reward. Defenders use clustering analysis (funding sources, transaction graphs, timing) and on-chain reputation filters to identify and exclude these wallets.

FAQs:

  • Is Sybil farming illegal? Generally not, though it can violate platform terms of service.

  • Can a protocol claw back tokens? Most cannot recover already-distributed tokens; they can blacklist for future programs.

In Practice

Ahead of an expected airdrop, one person spins up 200 wallets, funds each through a privacy mixer, and performs identical activity. The protocol's Sybil filter clusters the wallets via shared funding patterns and disqualifies all 200.

Dig Deeper