Stop airdrop farmers
Catch coordinated wallet rings created to drain airdrop allocations at scale
Keep airdrop allocations, points balances, and reward distributions on real participants, and stop one person from controlling hundreds of fake wallets
Catch coordinated wallet rings created to drain airdrop allocations at scale
Catch fake wallets grinding protocol quests to inflate points balances ahead of token launches
Keep quest payouts, presale allocations, and reward distributions on real participants
Legitimate wallets connect and claim without KYC delays or iris scans
ShieldLabs recognizes the real visitor behind every anonymous session, so your team can stop coordinated wallet rings before allocations clear
Identify returning visitors and users across sessions, cleared cookies, incognito mode, rotated IP, and fresh wallet addresses
Detection of VPN, proxy, Tor, anti-detect browser, IP reputation and other risk signals on every visit, with 99.9% risk signal detection accuracy
A ready-to-use score reflecting the risk of each visit, with the weight of every signal behind it
High-Risk Events detected out of the box: multi-accounting, account sharing, impossible travel and account takeover, each with Medium or High confidence
See how much of your traffic is masked, with an overall quality score and a breakdown of the sources sending your visits
Easily integrate into any wallet connection, airdrop registration, or token claim flow
Get 5,000 free identifications
It identifies every visitor and returns their risk signals and a risk score
See how much of your traffic is masked, with an overall traffic score
Get the risk score, risk signals and High-Risk Events in your backend to stop fraud and abuse
{
"request_id": "0c284695-cf0b-4755-8beb-0a2e9536595e",
"visitor_id": "aa8c616a-8a25-4a5e-bee2-a9a08e5128a4",
"device_id": "6a45967d-1371-9652-ba99-b01ea3992208",
"user_hid": "u_9f2a41c7",
"public_ip": { "ip": "62.197.149.124", "country": "United States" },
"local_ip": { "ip": "45.83.91.7", "country": "United States" },
"connection_type": "vpn",
"os": "Windows",
"browser": "Chrome",
"device_type": "desktop",
"risk_score": 85,
"signals": [
{ "name": "antidetect_browser", "weight": 60 },
{ "name": "vpn", "weight": 15 },
{ "name": "timezone_mismatch", "weight": 10 }
]
}Free 5,000 one-time identifications, with transparent pricing that scales with your needs
A sybil attack is when one person creates multiple fake identities, wallets, or accounts to gain disproportionate influence on a network. In Web3 this usually means one user running many wallets to claim more than their share of a distribution.
ShieldLabs surfaces sybil activity through persistent visitor and user identification across sessions, regardless of wallet address, email, IP, or browser, so coordinated wallets resolve to one identity on the first visit.
Sybil resistance is the property of a system that prevents one entity from controlling multiple identities. Different mechanisms achieve it at different layers, each with its own trade-off.
ShieldLabs delivers device-intelligence sybil resistance, correlating coordinated rings to one identity without adding KYC friction for legitimate participants.
In crypto and Web3, a sybil attacker creates many wallets to exploit any system that distributes rewards per wallet. The wallets are built to look like distinct users so each one collects its own share.
Telltale signs cluster together: sybil wallets are usually funded from one source, share device fingerprints, route through the same VPN or anti-detect browser, and burst-claim within minutes. This differs from a 51% attack, which targets consensus through hash power or stake rather than fake identities at the application layer.
ShieldLabs correlates these wallets back to one persistent identity at connection time, surfacing the shared device and network signals that on-chain analysis alone misses.
Airdrop farming is the deliberate creation of many wallets and accounts to claim a future token airdrop multiple times. It is the most common shape of sybil attack on Web3 airdrop campaigns and the core mechanism behind airdrop abuse.
ShieldLabs links farmed wallets back to one persistent visitor and user through device fingerprinting, anti-detect browser detection, cross-layer mismatch, IP intelligence, and other risk signals on every wallet connection.
Operators detect sybil attacks at signup or wallet connection by combining several signals into one identity the moment a wallet connects, before tokens are minted or governance votes are cast. No single signal is conclusive, so they layer:
Layered together, these resolve dozens of wallets that look distinct back to one persistent identity, even when cookies are cleared and IPs rotate.
Effective sybil prevention combines three layers that work together at wallet connection, so risk is scored before any tokens move:
Anti-sybil checks at this layer scale to millions of wallet connections without iris scans or KYC-video friction, scoring each wallet before tokens are minted.
ShieldLabs delivers sybil resistance through device intelligence that fingerprints the wallet connection with no user-side action, while Proof-of-Personhood solutions prove a unique human at the cost of onboarding friction.
ShieldLabs returns High-Risk Events and a 0-100 risk score on every wallet connection from the Starter plan, self-serve up to Scale, and is ready for sybil attack prevention in 5 minutes.
ShieldLabs stops sybil farming by flagging risky wallets and helping block fraudulent and abusive traffic. It returns a 0-100 risk score, the signals behind it and High-Risk Events, and you choose the action for each wallet, for example requiring extra verification before allocating tokens, excluding a wallet from an airdrop, or allocating normally.
ShieldLabs gives you 5,000 free identifications, so you can see the results on your own traffic first.