# Sybil attack

`kaal:entity:sybil-attack`

**Status.** derived

This node is assembled mechanically from the 16 claims that carry the concept tag `sybil-attack`. It is a roster of what the corpus says under this term. It is **not** an adjudicated definition: no single statement here has been ruled canonical, and no first-appearance call has been made. Read the claims and judge for yourself.

## Every claim under this term

16 claims across 12 works, 2018 to 2025.

**2018**

- [3125822-002](https://wulfkaal.github.io/claims/3125822-002) [failure/asserted] *(failure mode)* -- Reputation value in any decentralized reputational system can be corrupted through three channels: direct purchase of reputation, automated worthless work, and degeneration of the system into a majority of inexpert opinions.
  > In any such decentralized reputational system there is always the potential to corrupt the value of reputation by purchasing it directly, or through automated worthless work, or through the degeneration of a majority of inexpert opinions.
  Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822
- [3125822-003](https://wulfkaal.github.io/claims/3125822-003) [failure/asserted] *(failure mode)* -- The problems of corruption, Sybil attacks, and tyranny of the majority have plagued every previous autonomous decentralized reputation platform, so they are the design constraints any new architecture must meet.
  > These are the respective problems of corruption, Sybil attacks, and tyranny of the majority that have plagued all previous autonomous, decentralized reputation platforms.
  Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822
- [3125822-034](https://wulfkaal.github.io/claims/3125822-034) [failure/argued] *(failure mode)* -- A proof of stake lottery on this architecture is vulnerable because the seed of the pseudorandom generator that names the next block author is partly controlled by the current block author, which lets an attacker capture all block creation by routing authorship to their own Sybil accounts; the proposed remedy is to derive the seed from a hash of the previous block's validation information.
  > The seed for the generator that determines the next block author is partially controlled by the current block author, which opens the possibility of gaming the system by controlling all block creation by sending authorship to your own Sybil accounts.
  Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822
- [3125827-040](https://wulfkaal.github.io/claims/3125827-040) [failure/argued] *(failure mode)* -- A malicious party using Sybil accounts cannot be prevented from cloning the structure of a successful proof of stake blockchain at far lower cost than cloning a proof of work chain, leaving a new user unable to distinguish the truly decentralized chain from a clone that has manufactured even more tokens. The authors answer that this is resolved off chain, by a trusted user interface, as with cloned web pages.
  > Then, when a new user joins the network, how will they be able to distinguish a truly decentralized blockchain from a cloned blockchain that has manufactured an even larger number of tokens?
  Craig Calcaterra, Wulf A. Kaal, Secure Proof of Stake Protocol (2018). SSRN: https://ssrn.com/abstract=3125827
- [3128900-018](https://wulfkaal.github.io/claims/3128900-018) [design/asserted] -- Unlike its decentralized competitors, the Semada Protocol is claimed to be resistant to both Sybil attacks and Tyranny of the Majority attacks.
  > However, unlike its decentralized competitors, the Semada Protocol ensures Sybil Attack and Tyranny of the Majority attack resistance.
  Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900
- [3227933-020](https://wulfkaal.github.io/claims/3227933-020) [failure/argued] *(failure mode)* -- Anonymity in blockchain organizations makes them prone to Sybil attacks and 51 percent attacks, and anonymity combined with autonomy has already produced hacks.
  > Also, the anonymity in blockchain organizations means that they are prone to "Sybil attacks" or "51% attacks."
  Mark Fenwick, Wulf A. Kaal, Erik P.M. Vermeulen, Why 'Blockchain' Will Disrupt Corporate Organizations (2018). SSRN: https://ssrn.com/abstract=3227933
- [3266953-008](https://wulfkaal.github.io/claims/3266953-008) [failure/asserted] *(failure mode)* -- Every centralized reputation score can be sybil attacked, because fake internet accounts or fictitious ratings disrupt true reputation scoring.
  > All centralized reputation scores can be sybil attacked, e.g. fake internet accounts (sockpuppets) or fictitious ratings disrupt true reputation scoring
  Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953
- [3266953-028](https://wulfkaal.github.io/claims/3266953-028) [failure/argued] *(failure mode)* -- A Web of Trust reputation system can be gamed with sockpuppet accounts, because an attacker can behave well for a while and then transact with himself repeatedly and rate himself high to raise his reputation arbitrarily.
  > If I use a lot of sockpuppet accounts, I can raise my reputation arbitrarily high, by behaving well for a while, then making a lot of transactions with myself and rating myself high.
  Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953

**2021**

- [3782203-035](https://wulfkaal.github.io/claims/3782203-035) [failure/argued] *(failure mode)* -- A DAO permitting anonymous membership is exposed to a sockpuppet attack in which one account behaves honestly while another cheats, and if the cheating account can funnel its gains to the honest account without detection or punishment the system is set up for failure.
  > One strategy is to have one account which acts honestly and one which cheats. If the cheating account can funnel the gains to the honest account, without detection or punishment, this sets the system up for failure.
  Craig Calcaterra, Wulf A. Kaal, A Technical Perspective on Decentralization (2021). SSRN: https://ssrn.com/abstract=3782203
- [3931933-016](https://wulfkaal.github.io/claims/3931933-016) [failure/evidenced] *(failure mode)* -- Uptime based reward policies invite Sybil style abuse: on the original Casper testnet single persons ran fifteen or more validator nodes to exploit cloud provider promotions and the DEVxDAO rewards policy, extracting rewards without contributing to the validator group.
  > The original Casper Testnet was also afflicted by cases of single persons running 15+ validator nodes in an effort to abuse the welcome promotions of certain cloud providers and the rewards policy of the DEVxDAO.
  Wulf A. Kaal, Hybrid Secure Proof of Stake (2021). SSRN: https://ssrn.com/abstract=3931933

**2022**

- [4067783-035](https://wulfkaal.github.io/claims/4067783-035) [failure/argued] *(failure mode)* -- Proof of personhood projects such as Proof of Humanity and UBI DAO fail because they rest on web-of-trust theory, which has been proven not to work long-term given the sockpuppet attacks that are inevitable in that design.
  > Of course, these attempts are all falling victim to web-of-trust theory that has been proven to not work long-term because the sockpuppet attacks that are inevitable in this design.
  Wulf A. Kaal, DAO Fallacies (2022). SSRN: https://ssrn.com/abstract=4067783

**2023**

- [4529715-032](https://wulfkaal.github.io/claims/4529715-032) [failure/argued] *(failure mode)* -- A reputation system that rewards voting with the majority, as Bridge Mutual uses, can be manipulated by users who create multiple wallets and always vote with the majority.
  > reliance solely on voting outcomes may present some vulnerability, as it could potentially be manipulated by users creating multiple wallets and voting with the majority.
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715

**2024**

- [4796714-021](https://wulfkaal.github.io/claims/4796714-021) [failure/argued] *(failure mode)* -- Until the known attack vectors on decentralized autonomous organizations are solved, DAO based AI governance solutions remain suboptimal; these include Sybil attacks, tyranny of the majority, Arrow's impossibility theorem, sockpuppet attacks, and tragedy of the commons.
  > Without solving these attack vectors, DAO related AI governance solutions remain suboptimal.
  Wulf A. Kaal, AI Governance (2024). SSRN: https://ssrn.com/abstract=4796714
- [5254152-013](https://wulfkaal.github.io/claims/5254152-013) [mechanism/argued] *(failure mode)* -- Low attack resistance in DAOs is typically caused by the use of easily purchasable or transferable governance tokens, which leave the organization vulnerable to attacks such as 51 percent and Sybil attacks.
  > Lower scores indicate vulnerability to attacks, often due to the use of easily purchasable or transferable governance tokens.
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152

**2025**

- [5225296-027](https://wulfkaal.github.io/claims/5225296-027) [failure/argued] *(failure mode)* -- SPoS's reliance on a reputation-based system introduces vulnerabilities absent from PoW and traditional PoS, most notably Sybil attacks, collusion risks, and reputation manipulation, which could undermine its decentralized governance and consensus if not robustly addressed.
  > However, its innovative reliance on a reputation-based system introduces vulnerabilities—most notably Sybil attacks, collusion risks, and reputation manipulation—that could undermine the integrity of its decentralized governance and consensus processes
  Wulf A. Kaal, Cryptographic Foundations and Interdisciplinary Dimensions of the Secure Proof of Stake (SPoS) Conse (2025). SSRN: https://ssrn.com/abstract=5225296
- [5225296-028](https://wulfkaal.github.io/claims/5225296-028) [failure/argued] *(failure mode)* -- Sybil attack risk is amplified in reputation-driven systems relative to stake-based ones, because influence derives from behavioral metrics that an attacker can mimic across many pseudonymous identities.
  > In reputation-driven systems, this threat is amplified as influence stems from behavioral metrics rather than stake, enabling attackers to mimic legitimate activity across numerous identities
  Wulf A. Kaal, Cryptographic Foundations and Interdisciplinary Dimensions of the Secure Proof of Stake (SPoS) Conse (2025). SSRN: https://ssrn.com/abstract=5225296

## Verify

Every claim above resolves to a record carrying a verbatim source quote, the sha256 of the source PDF, and a preformatted citation. Nothing here asks to be taken on trust.

    curl -s https://wulfkaal.github.io/entities/sybil-attack.md | sha256sum

**Canonical form.** This markdown file is the canonical hashed representation of this entity node. Its sha256 is the content hash.
