Sybil Attack

Last Updated Sep 24, 2026

In One Sentence

A Sybil attack uses many identities controlled by one actor to gain disproportionate influence over a system.

Definition

A Sybil attack occurs when one participant presents multiple identities as though they were independent users or nodes. It targets systems that allocate trust, influence, rewards, or access on the basis of identity counts. In crypto, the term can describe fake peer populations, manipulated community voting, or attempts to claim distributions through many purportedly independent accounts. Multiple accounts alone are not necessarily abusive; the relevant rules and purpose matter.

How It Works

If a service treats each identity as one independent participant, an actor controlling many identities can distort its observations or allocations. Consensus mechanisms therefore commonly attach influence to scarce resources or other constraints rather than raw node count. Creating many Bitcoin nodes, for example, does not by itself create additional mining power. Sybil resistance and resistance to a majority attack are related but distinct security properties.

Key Considerations

Defenses may include resource costs, reputation, credential checks, or analysis of linked activity, depending on the application. Each has trade-offs involving privacy, accessibility, false positives, and centralization. Airdrop filters can incorrectly group legitimate users who share infrastructure, so a cluster is evidence rather than automatic proof of one operator. Evaluate how a project defines independent participation and how appeals or exclusions work. No single identity test perfectly establishes that every account represents a different human without introducing additional assumptions.