Airdrop marketing: does it attract bots or real users?
The recurring complaint is familiar: a project launches an airdrop, sees its community numbers rise, watches the claim page fill with wallets — and then discovers that the apparent growth was mostly temporary.

Discord activity fades, Telegram becomes a stream of price speculation, and a large share of recipients sells as soon as the token becomes liquid.
This does not mean airdrop marketing is useless. It means that distribution is often mistaken for adoption. An airdrop can create awareness, bootstrap liquidity, and bring early users into a product. But unless the campaign is designed around continued participation, the project may be paying for a large audience that never had much intention of staying.
The distinction matters because the current scale of token distribution makes poor targeting expensive. In 2025, roughly $4.5 billion was distributed through token airdrops, while 64% of recipients reportedly sold on the day of the token generation event. That is not simply a market reaction. It is also a signal about the quality of the relationship formed before distribution — and about what the campaign promised, explicitly or otherwise.
The TGE dump is usually a design problem, not a character flaw
When most recipients sell at TGE, teams often describe them as mercenaries, tourists, or farmers. Sometimes that language is justified — Sybil networks and professional airdrop participants are real operational problems. But it is too convenient to place the entire explanation on user behavior.
A participant who sells immediately may have done exactly what the campaign taught them to do.
If the project communicates the airdrop as a reward for activity, but the activity consists of disconnected tasks — bridge funds, make a transaction, join a channel, complete a quest, invite friends — users learn that the objective is to qualify. They do not necessarily learn why the product matters, who it is for, or what they should do after claiming. The campaign optimizes for eligibility rather than product alignment.
That distinction becomes visible in the numbers. In the Uniswap airdrop, analysis from Dune Analytics found that 93% of original recipients sold all their UNI, with more than 75% selling within the first seven days. Only around 7% of wallets continued to hold the token. Uniswap remains a strong product and a significant protocol; the result should not be read as a verdict on its long-term relevance. It does, however, show that even a respected protocol can distribute tokens to a large group whose relationship with the asset is primarily financial.
The same pattern appears when a campaign attracts people who have no reason to use the product once the reward is paid. A user may complete a cross-chain transaction for an airdrop without caring about the underlying bridge, liquidity venue, or application. A contributor may join a community because access to a future allocation is implied, then disappear when the allocation becomes claimable. The traffic is real in the narrow sense — wallets connected, messages were sent, transactions occurred — but the intent behind that traffic is weak.
Airdrop traffic quality is therefore not measured by the number of wallets that arrive. It is measured by what those wallets do when there is no immediate reward attached.
An airdrop does not create loyalty by itself — it reveals whether the campaign has given people a reason to stay.
There is also a structural reason for selling pressure. Recipients often have different costs, expectations, and timelines. Some received tokens for genuine early use. Others spent money on gas, bridging, or capital allocation to qualify. Some are professional participants running many wallets. Once the token lists, each group faces a different decision, but all of them can sell into the same market at the same time.
If the project has not planned for that moment, the TGE becomes a liquidity event without a retention system. The campaign ends precisely when the most important user-behavior data begins to arrive.
The Sybil problem is larger than a few dishonest wallets
A Sybil attack is not just one person using two or three addresses. In a mature airdrop environment, it can involve coordinated clusters of wallets that share funding sources, transaction patterns, timing, infrastructure, and behavioral similarities. Some clusters are easy to identify. Others are deliberately designed to resemble independent users.
The consequences are straightforward: the project distributes a scarce asset to participants who have inflated activity without creating equivalent demand for the product. But filtering is not a simple matter of deleting every wallet with unusual behavior. Overly aggressive rules can remove real users, particularly in regions where people share infrastructure, use centralized exchanges as funding sources, or rely on mobile networks and common public endpoints.
Recent campaigns illustrate the scale of the problem.
During the Arbitrum airdrop, an analysis by X-explore identified 148,595 confirmed Sybil addresses that bypassed anti-Sybil measures and captured approximately 21.8% of the total airdropped tokens. The figure is significant not because it proves that every remaining wallet represented a valuable user, but because it shows how much distribution can be diverted even after a project has invested in detection.
Linea filtered roughly 800,000 Sybil wallets. Those addresses represented about 40% of the claimant pool in the cited analysis — 517,000 of 1.3 million eligible addresses were identified as Sybil activity — leaving approximately 749,000 genuine claimants. LayerZero’s anti-Sybil campaign, which included self-reporting and a bounty mechanism, also identified more than 800,000 Sybil addresses.
These cases point to two different lessons. First, basic eligibility rules are not enough. A wallet that has completed a required transaction is not automatically a genuine user. Second, the scale of filtering should be treated as a product and communications issue, not only as a technical one. Every exclusion decision affects sentiment, trust, and the credibility of the distribution.
The Irys incident reported in November 2025 made the concentration risk especially visible. A single cluster of 897 wallets, funded from the same source, claimed nearly 20% of the total airdrop. Even where the final allocation is later adjusted, an event like this can create a trust deficit between the team and the users who followed the rules in good faith.
That deficit has practical consequences. Excluded users may not return to the product. Legitimate recipients may become suspicious of future campaigns. Community moderators then spend weeks explaining allocation logic instead of helping users understand the protocol. The campaign’s operational cost extends well beyond the token amount.
What a stronger Sybil review looks for
No anti-Sybil system is perfect, and sophisticated clusters continue to find workarounds. They may use different funding sources, mobile proxies, common exchange routes, or wallet histories that appear independent when viewed through a single signal. The goal is not to find a magical test. It is to combine imperfect signals and make the decision process more proportionate.
A serious review can examine:
- Funding relationships — wallets funded by the same address or through the same narrow path deserve scrutiny, although shared exchange infrastructure should not automatically be treated as proof of abuse.
- Transaction timing — large groups performing the same tasks at nearly identical intervals can indicate coordination.
- Behavioral similarity — identical contract interactions, transaction values, gas choices, and route selection may reveal scripted activity.
- Wallet age and history — newly created addresses with no meaningful history are not necessarily fraudulent, but they carry less evidence of independent product use.
- Cross-campaign overlap — participation in several unrelated campaigns can be a useful signal when combined with other data.
- Product depth — repeat usage, meaningful volume, governance contribution, liquidity provision, or continued interaction can provide stronger evidence than a single qualifying transaction.
- Human review and appeals — edge cases need a path for explanation, particularly when the project’s rules were ambiguous or changed during the campaign.
The last point is frequently underestimated. If users cannot understand why they were excluded, the campaign becomes a dispute about legitimacy rather than a discussion about the product. Clear criteria will not satisfy everyone, but opaque criteria almost guarantee friction.
Naked airdrops have a weak retention profile
The strongest evidence against simple token distribution is not just the amount of selling. It is what happens months later.
A study on Web3 user retention found that points-based systems retained 10% of users after 11 months, compared with only 0.5% for a “naked” airdrop — tokens distributed directly without holding incentives or a broader participation structure. The difference is substantial, even if the exact outcome varies by product and campaign design.
Paraswap offers another useful warning. In its 2021 airdrop campaign, only approximately one in 300 users — around 0.33% — remained active on the platform a year later. This is not evidence that every token campaign produces the same result, but it demonstrates how quickly a large acquisition number can collapse when recipients are not converted into repeat users.
The issue with a naked airdrop is that it separates the reward from the behavior the project actually wants. If the goal is recurring trading, the campaign should not end at the first claim. If the goal is governance, the recipient must understand the decisions they can influence. If the goal is liquidity, users need a reason to provide it beyond a one-time points calculation.
Points systems are not automatically better. They can also create artificial behavior, generate leaderboard anxiety, and encourage participants to optimize for metrics rather than product value. But they provide something a direct distribution does not: a period in which the project can observe whether interest persists, refine its segmentation, and communicate a reason for continued participation.
The difference is not simply that points delay the reward. They create an opportunity for alignment.
A user who has returned to the product ten times, referred a colleague who remains active, contributed useful feedback, or participated in governance has given the project more information than a wallet that completed one transaction and disappeared. That information can improve allocation quality — provided the team measures meaningful behavior instead of treating every interaction as equivalent.
The metric that matters is not “number of participants”
A campaign can report millions of wallets and still have poor acquisition economics. For an airdrop marketing strategy, the more useful questions sit further down the funnel:
1. How many eligible wallets performed a meaningful action after the initial task?
2. How many returned without a new reward being announced?
3. How many used the core product rather than only campaign-specific contracts?
4. How many remained active after TGE?
5. How concentrated was activity among wallets with similar funding and behavioral patterns?
6. What percentage of the community was still contributing after the campaign’s main reward was distributed?
These measures also need a time horizon. Activity in the first week can be distorted by speculation, fear of missing an allocation, or the need to complete a final task. A more honest view often comes at 30, 90, and 180 days — long enough for the initial incentive to lose some of its influence.
Retention should also be segmented. A trader, a liquidity provider, a developer, and a community contributor may have very different useful behaviors. Reducing them to a single “active wallet” metric creates the same problem as counting every social-media follower as a potential customer.
Advanced filtering begins with product behavior
Many campaigns still treat on-chain activity as a proxy for user quality. That is understandable: transactions are measurable, comparable, and easy to put into a dashboard. But transaction volume alone is a poor substitute for intent.
A wallet can generate many low-value transactions while contributing almost nothing to the protocol. Conversely, a user may make relatively few transactions because the product is designed for occasional use, or because transaction fees are high. If the campaign rewards only frequency, it can penalize the users the product was actually built to serve.
A better approach is to define the behaviors that represent genuine product value before designing the campaign. Those behaviors might include:
- completing an end-to-end workflow rather than a single isolated transaction;
- returning over several weeks without a new task announcement;
- using more than one core feature;
- supplying liquidity that remains available beyond the reward window;
- participating in governance with reasoned proposals or votes;
- contributing documentation, code, moderation, or user support;
- referring users who themselves remain active.
This does not mean every action should receive the same weight. It means the scoring model should reflect the project’s operating reality. A protocol that needs durable liquidity should not primarily reward short-term volume. A DAO that needs contributors should not use wallet age as its central measure of commitment. A consumer application should care whether users complete the intended journey, not merely whether they connected a wallet.
There is a human side to this design. Users can tolerate complicated campaigns when the logic feels coherent. They become frustrated when a project asks for weeks of activity and then allocates rewards according to an opaque formula that appears to favor scale, capital, or hidden criteria. The result is not merely negative sentiment on social media. It is a breakdown in the trust required for future participation.
Use multiple evidence layers instead of one decisive score
A practical model can separate eligibility, quality, and allocation.
Eligibility answers whether the wallet performed the required actions and met the published campaign conditions.
Quality estimates whether the behavior resembles genuine product use. This is where funding links, timing, feature usage, repeat visits, and contribution history may be considered.
Allocation determines how the available tokens are distributed among eligible users. It may include caps, diminishing returns, cohort adjustments, or separate pools for different user roles.
This separation makes disputes easier to handle. A wallet can be eligible but receive a smaller allocation because activity was concentrated in one narrow pattern. Another may qualify for a contributor pool because its value was not primarily financial. Without these layers, teams often end up using one opaque score to answer three different questions.
The system should also be tested before launch. Historical data, simulated clusters, and adversarial reviews can expose obvious loopholes. If the team cannot explain how a group of coordinated wallets might exploit the rules, it should expect those wallets to find the weakness after launch.
The strategic pivot is from distribution to continuity
The most sustainable web3 airdrop campaigns are designed backward from the user behavior expected after distribution. That changes the campaign brief.
Instead of asking, “How do we get as many wallets as possible?”, the team asks:
- What should a valuable user do in the first week?
- What should bring them back in the first month?
- Which actions indicate that the product has solved a real problem?
- Which parts of the community need tokens, access, status, or direct support?
- What happens if the token price falls immediately after TGE?
- Can the product still retain users when the financial incentive becomes less attractive?
These questions lead to different mechanics. A project might distribute a portion of the allocation immediately and reserve another portion for continued use. It might create separate rewards for users, developers, moderators, liquidity providers, and governance contributors. It might use a vesting structure, but only if the conditions are transparent and do not feel like an attempt to trap recipients.
Post-airdrop incentives should not be confused with endless rewards. Sustainability requires the project to understand what it can afford and what behavior it can support. If every useful action depends on token emissions, the community may be trained to wait for the next subsidy. Once the treasury reduces incentives, activity can disappear again.
The better objective is to move users from incentive-led participation to product-led participation. The token can open the door, but the product, community, and governance experience must provide a reason to remain inside.
Communication is part of that transition. Before TGE, teams should be explicit about eligibility, timing, allocation logic, claim costs, restrictions, and the role of the token. After TGE, they should publish what they are measuring — not only price, volume, and wallet count, but repeat usage, contributor activity, liquidity duration, and retention by cohort.
That transparency will not prevent every disagreement. It does make the disagreement more manageable. Users are more likely to accept a result they dislike when the rules were understandable, stable, and applied consistently.
The real test of an airdrop begins after the claim window closes — when the project has to earn attention without paying for every visit.
The economics should be evaluated with the same caution. Crypto airdrop ROI is not the value of tokens distributed divided by the number of wallets acquired. The calculation needs to include filtering, infrastructure, moderation, support, liquidity effects, legal and operational work, and the value of users who remain active. It should also account for the cost of attracting low-intent participants, because a noisy community can consume more resources than a smaller, better-aligned one.
There is no universal retention target that makes a campaign successful. A high-frequency trading protocol, a developer platform, and a governance community will naturally show different patterns. What matters is whether the campaign produces enough durable behavior to justify its cost and whether that behavior supports the project’s actual strategy.
Airdrops can attract real users — but they cannot manufacture intent
The evidence does not support the most dramatic conclusion that airdrops are only for bots. Genuine early adopters do remain active, and distribution can help a new protocol gain awareness, liquidity, and a first group of users. But the evidence is equally clear that a large wallet count is not proof of successful acquisition.
The reported figures are difficult to ignore: 93% of original Uniswap recipients sold all their UNI; 21.8% of the Arbitrum distribution was captured by confirmed Sybil addresses in one analysis; Linea filtered hundreds of thousands of wallets; and naked airdrops showed a 0.5% retention rate after 11 months in the cited study. Separately, around 88% of airdropped tokens have been reported to lose value within three months of launch — a reminder that the distribution event can create more supply and attention than the ecosystem is ready to absorb.
The operational answer is not to abandon incentives. It is to make them answerable to the product. Filter for patterns rather than relying on a single wallet rule. Reward meaningful behavior rather than transaction volume alone. Design for the months after TGE. Give legitimate users a clear explanation of how decisions were made. And measure whether participation continues when the reward is no longer the main reason to show up.
Airdrop marketing works best when it accelerates an existing relationship instead of pretending to create one from nothing. The question for any team planning a campaign is therefore less “How many wallets can we attract?” and more “What kind of users will still find this product worth using when the tokens are no longer the story?”