Wallet clustering: how a fleet gets identified

A volume bot vendor has an obvious incentive not to write this page. We are writing it because the alternative is letting you buy something under a false impression. Coordinated wallets leave patterns, the analysis tooling that reads those patterns is public and improving, and the honest question is not whether a fleet is detectable but how much effort detection takes and who is willing to spend it.

Volion Research Updated Jul 30, 2026 4 sections

What identifies a fleet

Five signals do most of the work: funding lineage, where the SOL in each wallet came from; wallet age, whether the addresses existed before the campaign; timing regularity, how mechanically spaced the trades are; amount patterning, whether trade sizes repeat or cluster unnaturally; and behavioural narrowness, whether a wallet only ever touches one token and then goes quiet forever.
SignalWhat it revealsEffort to reduce
Funding lineageAll wallets trace to one sourceHigh
Wallet ageAddresses created in one batchHigh
Timing regularityTrades on a mechanical intervalLow
Amount patterningRepeated or narrowly clustered sizesLow
Behavioural narrownessOne token, then silenceVery high
The two low-effort rows are what most tools randomise. The high-effort rows are the ones that actually identify a fleet, and they are largely structural.

Note the asymmetry. Randomising trade sizes and jittering timing is straightforward and every competent tool does it, which is exactly why those signals carry little weight for an analyst. Funding lineage and wallet age are structural properties of how a fleet comes into existence, and they are far harder to disguise because the chain records the entire history permanently.

Funding lineage is the hard problem

Every wallet needs SOL before it can trade, and the transfer that funded it is a permanent public record. If 500 wallets were funded from one address within a short window, the graph connecting them is trivial to construct. Routing through intermediate hops lengthens the graph but does not break it, because the hops are also recorded. This is the signal that makes fleets identifiable in practice.

Chain analysis of this kind is not exotic. Following funding edges backward from a set of trading wallets to a common ancestor is a standard query, and the tooling to do it is publicly available. A fleet that was funded in one batch from one source looks like exactly what it is.

Mitigations exist and all of them cost something. Funding across a longer period, from multiple sources, through varied paths, using wallets that already have unrelated history, raises the analytical effort considerably. Each of those steps also adds fees, delay and operational complexity, which is why almost nobody does them thoroughly. Being straightforward about that trade-off is more useful to you than a claim of undetectability that collapses under the first serious look.

What this means for expectations: assume that a determined analyst can identify a campaign, and that a casual observer probably will not bother. Buy accordingly.

Who is actually looking, and what they do about it

Three groups: discovery platforms, which have direct incentive to discount coordinated activity in their rankings; chain analysts and commentators, who publish findings publicly and can turn a campaign into a reputational problem; and individual traders using cluster-visualisation tools, which are now consumer-grade rather than specialist. The consequences differ from filtered signal to public exposure.

Platform filtering is the quietest consequence and the most common. If a ranking discounts activity it believes is coordinated, the campaign simply underperforms and nobody tells you why. This is the outcome to plan around, and it is one reason to treat volume as one input rather than the whole strategy.

Public exposure is rarer and more damaging. A visible cluster on a token with real attention can become the story about that token, which is worse than no attention. The projects that suffer here are the ones that ran a fleet and then made claims about organic growth, because the contradiction is checkable by anyone.

Consumer tooling is the trend that matters most going forward. Cluster visualisation used to require analytical skill and now takes a browser tab, so the population capable of spotting a fleet is much larger than it was. Assuming this gets easier rather than harder is the correct planning assumption.

What follows for how you use this

Use volume for what it demonstrably does: making genuine on-chain activity legible to systems that read the chain. Do not use it as a substitute for having something worth finding, and do not pair it with claims of organic growth that the chain contradicts. Expect effectiveness to decline as filtering improves, and treat any vendor promising undetectability as a source to distrust generally.

Three practical positions follow from the analysis above.

  • Configuration matters less than you would like. Randomising sizes and spacing timing is worth doing and addresses the weakest signals. It does not address funding lineage, which is the one that identifies fleets.
  • Consistency of story matters more than configuration. A campaign that is never contradicted by public claims causes far less trouble than a well-randomised one paired with assertions about organic demand.
  • Diminishing returns are structural. Both platform filtering and public tooling improve over time, and neither trend reverses. Plan on today's effectiveness being an upper bound.

If reading this makes the product sound less impressive than a competitor's pitch, that is the intended effect of accuracy. Our measured cost and failure data is on the measurement page, and the honest limits of volume as a mechanism are set out on the safety page.

The campaign settings that shape a fleet footprint, and what each one costs, are on the Solana volume bot overview.

Where the fleet trades changes how legible it is. On a Pump.fun launch the whole holder set is new, so a cluster of freshly funded wallets is less conspicuous but the token page makes every reply and holder change public. On an established Raydium, PumpSwap, Meteora or Orca pool there is an existing trader base to stand out against, and DexScreener holder-distribution filters read that contrast directly.

Questions

Can a volume bot be undetectable?
No, and any vendor claiming otherwise is either mistaken or misleading you. Funding lineage and wallet creation history are permanent public records. Good tooling raises the effort detection requires; nothing removes the evidence.
What is the strongest signal that identifies a fleet?
Funding lineage. Every wallet needs SOL before it can trade, and that transfer is recorded permanently, so a set of wallets funded from a common source within a short window forms a graph that is straightforward to reconstruct.
Does randomising trade sizes help?
It addresses one of the weaker signals, and it is worth doing. It does not address funding lineage or wallet age, which are the signals that actually identify a fleet, so the protection it offers is limited.
What happens if a fleet is detected?
Most commonly nothing visible: a ranking discounts the activity and the campaign quietly underperforms. Less commonly, a public cluster analysis becomes the story about the token, which is worse than having received no attention at all.
Is detection getting easier?
Yes. Cluster visualisation tools that once required analytical skill are now consumer-grade, and platform filtering improves for obvious commercial reasons. Treating current effectiveness as an upper bound rather than a baseline is the correct assumption.