What is a sybil attack? Airdrop farming explained
A sybil attack is one actor posing as many identities. What airdrop farming is, how teams filter sybil wallets, and what each extra wallet costs a farmer.
A sybil attack is one person or group running many fake identities to take a share meant for many separate people: votes, reputation, or an airdrop. In crypto the identities are wallets, which cost nothing to create, and each wallet one operator controls is a sybil. Cherry (cherry.fun), the wallet-to-wallet messenger and community app for crypto, gives token teams gated rooms and airdrop campaigns, and each of its checks puts a cost on every extra wallet a farmer adds.
How a sybil attack works
John Douceur of Microsoft Research described the problem in The Sybil Attack, a paper at the first International Workshop on Peer-to-Peer Systems in 2002. Douceur concluded that without a logically centralized authority to vouch for identities, “Sybil attacks are always possible” except under extreme and unrealistic assumptions. The name comes from Sybil, a book about a woman diagnosed with dissociative identity disorder.
What airdrop farming is
Airdrop farming is on-chain activity aimed at qualifying for a future token distribution, spread across many wallets so one person collects many allocations. Each of those wallets is a sybil.
How teams filter sybil wallets
For the ARB airdrop, whose claims opened on 23 March 2023, the Arbitrum Foundation scored wallets on activity before a snapshot taken on 6 February 2023 and subtracted a point when all of a wallet’s transactions fell within 48 hours. It also mapped Arbitrum One transactions as a graph, collapsed large, densely connected clusters into a single recipient, and excluded addresses flagged as sybils in Hop’s bounty program.
Hardware is another filter. Solana Mobile’s docs call the Seeker Genesis Token, minted once per Seeker, an anti-sybil measure, and tell developers to record each token’s mint address so a reward is claimed once per device. Proof-of-personhood schemes aim higher: one identity per human, confirmed by a credential or an in-person check instead of by what a wallet holds.
Example on Cherry: what each extra wallet costs
A Cherry airdrop campaign pays SOL or an SPL token, one claim per wallet, and runs its checks when the wallet claims. The team can require all checks or any one:
| Check the team sets | What each extra wallet costs |
|---|---|
| Wallet age, a minimum in days | Time: a wallet made for the drop is too young |
| A whitelist of wallets | Selection: only wallets you listed can claim |
| Token balance or NFT holder | Capital: the minimum, held at claim time |
Domain, set to .skr | Hardware: the name comes with a Seeker phone and cannot be sold |
| Membership of a paid room | Money: an entry fee |
| Messages sent in your room, since a date | Effort: a real conversation history |
| Your own check, answered by your server | Whatever your own scoring sees |
Room rules set the same costs at the join screen: a minimum token balance, a .skr or .sol domain, or paid entry. On top, brand-new wallets cannot post in public groups or leave reviews.
For a Seeker audience the check is the .skr domain. The Seeker Genesis Token stays Solana Mobile’s tool: a Cherry rule names one mint or collection, and every Seeker mints its own. Seeker Club, gated by “Hold a .skr domain”, had 8,717 members in October 2026, and a campaign with the same check reaches Seeker owners.
The airdrop guide walks through setting one up.
What no check proves
None of these proves one human. One person can own several Seekers, or several aged, funded wallets, and ten funded old wallets that each pass the rules claim ten times. The checks raise the cost of each extra wallet, and a farmer with enough capital and time can still pay it.
Related terms
- Crypto snapshot
- Seeker Genesis Token
- .skr domain
- Soulbound token
- Airdrops on Cherry : every claim check and how they combine
- Anti-spam on Cherry : the limits on new wallets
FAQ
How do airdrops detect sybil wallets?
Many teams study past on-chain behaviour: for the 2023 ARB airdrop, the Arbitrum Foundation docked a point when all of a wallet’s transactions fell within 48 hours and collapsed dense transaction clusters into a single recipient. Others ask for something that is hard to multiply, such as wallet age, a held balance, a device-bound token or a proof of personhood. None of these proves that each wallet belongs to a different person.
Sources
Try Cherry
Sign in with a wallet, DM any address, and join token-gated and paid communities. No phone number, email, or KYC.