Skip to content

Use case · Web3 Sybil

Stop one person from claiming your giveaway as thousands of fake people.

A sock puppet attack is one person secretly running many fake accounts to look like a crowd (a Sybil attack). When you hand out tokens or votes per wallet (the accounts that hold crypto), a single farmer can stand up thousands and drain the share meant for real people. Root Herald ties each claim to a real, physical device: the cheap cloud-server fakes get rejected outright, and what's left has to be actual hardware you can spot in clusters.

Economics

Where the reward outruns the cost.

A fake built on a rented cloud server costs about $0.10. A real-device fake costs $30–$200. When a single giveaway allocation can be worth six or seven figures, even the expensive fakes can pay off. We won't pretend hardware alone wins that fight. But it clears out the cheap flood and puts a real price on every fake that's left.

Web3 Sybil airdrops

MYX $1.7M/wallet · LayerZero ZRO ~$15K peak · typical L2 $500–$5K

Partial
$30 floor

Per-identity yield

$500 – $1,700,000

Rational ceiling

$500 typical, $1M+ at top events

Partial mitigation only. Forces farms physical + detectable; doesn't solve $1M-per-wallet airdrops alone.

What Root Herald removes

The cheap path, gone.

The default rule (rootherald:builtin:strict-hardware, our "real physical chips only" policy) turns away every fake built on a cloud server or software emulator. When LayerZero threw out 803,000 wallets, most were exactly these cloud-server clusters, the kind that can never pass a real-hardware check.

Rented cloud servers

A cloud server dressed up as a PC can't prove there's a real chip behind it. Amazon, Azure, and Google virtual machines all fail the check and are turned away.

Software emulators

A 'chip' that's really just software running in a container can't prove it's a physical part. Rejected. It even labels itself as a fake.

One chip, many claims

Route a thousand fake sign-ins through one real machine and they all collapse to a single anonymous device ID: one physical computer, counted once.

What remains

The honest residual.

Two kinds of attack still get through strict rules when a single claim is worth enough:

Refurbished-device farm.At $30–$200 a machine, a determined farmer can buy 100–1,000 before shipping and setup eat the profit. But they leave a trail: the same make, model, and firmware showing up across dozens of "different users" on one network is a cluster your own analytics can catch, using the anonymous device ID we return.

Paid real people.Pay 1,000 genuine people $5 each to claim. Every device is real and every claim is valid. Cryptography can't tell these apart. Behavioral signals, identity checks, and wallet-graph analysis (mapping which crypto accounts move funds together) have to carry this one.

The pitch

The hardware signal your wallet analysis is missing.

Root Herald adds a hard-to-fake, hardware-backed device signal at the moment someone claims — before there's any blockchain activity to analyze. For a giveaway: tie each device to the wallet it claims from (one allocation per device, or weight by how many distinct devices back a wallet); keep every device-to-wallet pair over the claim window; and surface the clusters where one device claims through many wallets, or many devices share the same network and hardware profile.

Layer Root Herald under your existing checks.

Free up to 10K device checks a month. Verify the device when someone claims, tie the anonymous device ID to their wallet, and watch the clusters surface.