ADVANCED

Funder Clustering: How One Actor Fakes a Crowd

Twenty 'different' wallets, one source of funds. How to detect manufactured demand that fools most multibuy signals.

· 8 min read · Blackhat Empire

The illusion of convergence

A multibuy alert fires: "12 wallets purchased $TOKEN." Twelve independent buyers converging looks like strong signal. But what if all twelve were funded, minutes earlier, from the same wallet? That's not twelve buyers — it's one actor wearing twelve masks, manufacturing the exact pattern that's supposed to be hard to fake.

This is funder clustering, and it's one of the most important advanced checks because it defeats the naive version of the signal everyone trusts.

How the trick works

  1. An actor controls a funding wallet.
  2. They spin up a batch of fresh wallets and send each a small amount from that one source.
  3. Each fresh wallet buys the token in the same window.
  4. To any tracker counting distinct buyers, this reads as a high-conviction multibuy.

The fingerprint: a cluster of buyers whose funding traces back to a shared parent, often with similar amounts and timing, frequently brand-new ("fresh") wallets.

How to detect it

  • Trace the funder. For each buyer in a multibuy, look at where its SOL/ETH came from. Common source across many buyers is the red flag.
  • Watch fresh%. A multibuy that's mostly fresh wallets deserves extra suspicion — real convergence usually includes some aged, established wallets.
  • Check timing and size symmetry. Identical amounts arriving at identical intervals is automation, not a crowd.

How we handle it

Our multibuy pipeline extracts the buyer wallets and looks for shared funding sources, so cloud-wallet farms get filtered before an alert is trusted. When you read a multibuy in the groups, glance at the wallet list yourself: a healthy one mixes labels and tiers; a farmed one is a wall of look-alike fresh wallets.

See the multibuy format and the Fresh/Smart fields in the Alert Types decoder.