Live Client · zScore in Production
Pre-Distribution Intelligence · 499 Wallets

Citrea Found Out Who Would Sell
Before It Sent a Single Token

Citrea brought ZeruAI its entire governance wallet scope and asked one question: who here is real. zScore scored all 499 wallets, mapped the coordination between them, classified what each one does with tokens it receives, and returned a deterministic allocation policy.

Delivered before distribution, not measured after it

59%Would sell within a day285 of 499 wallets, median 99.35% sold
68Critical-risk wallets13.6% of scope, named before distribution
61.1%Quality concentration305 wallets sit in bands 700–900
97.0%Still eligible after filtering484 of 499, only 15 excluded

The four passes run over every wallet in scope

1

Score

499 wallets graded on behavioural depth

2

Risk

39,477 pairs tested for coordination

3

Dumping

447,671 receipt events matched to sells

4

Allocation

One exclusion rule, then continuous weights

The Problem — A Wallet List Is Not a Community

Every Wallet Looked Eligible
Three in Five Were Going to Sell the Same Day

Citrea had a governance scope of 499 wallets. On a spreadsheet they are indistinguishable: every one has a history, a transaction count, a balance. That is the only view most protocols ever get before they distribute.

What the behavioural scan found: 285 of those wallets sell almost everything they receive within 24 hours, with a median of 99.35% of receipts sold and a median hold time measured in seconds. 68 carried critical risk labels and 17 coordination clusters were sitting inside the list.

The information needed to price a distribution correctly already exists on-chain. It is simply not read before the tokens go out.

285
Immediate dumpers
59.0% of the wallet scope
17
Coordination clusters
23 critical links inside them
25
Probable bots
5.0% of the wallet scope
0.0003h
Median hold time
Receipt to first matched sell

Flagging Is Cheap. Evidence Is Not.

  • 39,477 wallet pairs were evaluated for shared funding anchors, behavioural alignment and timing. Only 88 survived the thresholds as real edges, and only 23 of those were strong enough to call critical.
  • Cluster membership alone never flags a wallet. A strict sybil call requires sybil probability, cluster risk, node-pair strength and multiple corroborating links to agree. That is why the strict set is 12 wallets, not 68.
  • The output is a review queue, not a verdict. Risk labels are governance triage. They tell a protocol where to look first, with the reason codes attached, rather than handing down an unexplained ban.
The Evidence — What the Scan Returned

Quality Was Concentrated
and So Was the Sell Pressure

305 of 499 wallets sit in the 700–900 bands, and they carry $1.82B of the $1.91B in lifetime volume across the whole scope. A flat distribution would have treated them identically to the 17 wallets in the bottom band.

61.1%Concentrated Quality499 wallets · bands 700–900 share

305 wallets in bands 700–900 account for almost all measurable depth: 224 and 220 distinct protocols used, 56 chains, all 9 behavioural sectors.

59.0%Same-Day Exit Behaviour499 wallets · immediate dumper share

285 wallets classified Immediate Dumper: at least 70% of received quantity sold inside 24 hours across five or more receipt events. Their median is 99.35%.

23Surviving Coordination39,477 pairs · critical links retained

Critical suspicious links left after 39,477 candidate pairs were reduced to 88 retained edges. Each one is a pair the thresholds could not explain away.

Where the Wallets Are, Where the Value Is

Wallet count by band, against lifetime volume in millions USD

What Each Wallet Does With Tokens It Receives

499 wallets · 447,671 candidate receipt events matched to sells

Immediate Dumper285 wallets59.01%
Holder123 wallets25.47%
Gradual Seller56 wallets11.59%
Insufficient Data19 wallets3.93%

Classification is rule-based and reported with its own coverage. Quantity matching covered 46.7% of received volume, below the 60% the method prefers, so the sold shares here are the conservative reading.

The Output — An Allocation Policy, Not an Opinion

One Rule Removed 15 Wallets

The deliverable is not a risk score to interpret. It is a deterministic policy: one published exclusion rule, then a continuous weight for every wallet that passes it. Run it twice on the same data and it returns the same allocation.

FindingValueWhat It Means
Wallets scored and profiled499Full governance scope, every wallet behaviour-covered
Concentration in bands 700–90061.1%305 wallets carry $1.82B of the $1.91B lifetime volume
Critical-risk wallets6813.6% of scope, flagged before any tokens moved
Strict probable sybil122.4% of scope, held to a four-signal evidence bar
Wallets that sell within 24 hours28559.0% of scope, median 99.35% of receipts sold same day
Wallets excluded by policy153.0% removed by one deterministic rule, 484 stay eligible

The Exclusion Rule

A wallet is excluded only when a low score and hard behavioural evidence agree. One signal on its own is never enough, which is why 484 of 499 wallets stayed eligible.

exclude if final_score ≤ 590.18 (p25)
and (high_bot or strict_immediate_dumper)
  • high_bot requires both bot probability and combined risk to clear their bars at once. Either one alone leaves the wallet eligible.
  • strict_immediate_dumper requires a long receipt history, near-total selling inside 24 hours, and high quantity coverage on the match. A thin history cannot trigger it.
  • Exact thresholds are delivered to the client and held out of public copy, so the rule cannot be reverse-engineered into an evasion guide.

The Weighting

Every eligible wallet gets one continuous index, then a share of the pool proportional to it. No tiers, no buckets, no discretionary adjustment.

alloc_index = 0.55 × quality
+ 0.20 × contribution
+ 0.25 × retention

weight = alloc_index / Σ alloc_index

A wallet holding 0.3155% of the summed index is recommended 0.3155% of the pool. Median eligible score was 739.61, against 527.99 for the excluded set.

Allocation universe after the rule ran

Eligible · 484 wallets

97.0%

Receive a policy-weighted share

Excluded · 15 wallets

3.0%

Receive nothing, with the reason recorded

What This Means for Your Protocol

What the Citrea Engagement Shows

  • 01

    The sell-side of a distribution is knowable in advance. 59% of Citrea’s wallet scope was classified as same-day sellers from receipt-to-sell history that already existed. Nothing had to be distributed first to learn it.

  • 02

    Precision matters more than volume of flags. 39,477 pairs were tested and 23 critical links survived. A system that flags generously is easy to build and useless to act on, because the protocol cannot defend a single exclusion.

  • 03

    The deliverable has to be executable. Citrea did not receive a risk dashboard to interpret. They received one published exclusion rule, a continuous weight per wallet, and the reason code behind every exclusion, so the allocation can be defended line by line.

What ZeruAI Provides

zScore is a behavioral reputation score (0–1,000) for every EVM wallet, derived from on-chain activity across 40+ chains. Queryable via API. Mintable as an on-chain credential. Integrated at the distribution layer, not after.

Citrea used it as a pre-distribution intelligence package: score bands, a coordination graph, dumping classification, and a deterministic allocation policy delivered as one engagement.

Behavioral Fingerprinting

Tx patterns, timing, value flow, network behavior

Network Clustering

Graph analysis to identify coordinated wallet clusters

Deterministic Policy Output

One exclusion rule, one continuous weight per wallet

Method and limits

Figures are from the Citrea intelligence package delivered on 23 February 2026, across a scope of 499 scored and profiled wallets. Risk and dumping labels are evidence-backed classifications intended for governance triage, not legal attribution. Denominators differ by pipeline and are stated with each figure. Quantity coverage in the dumping pass was 46.7%, below the 60% the method prefers, so sold-share figures are conservative. These are findings delivered before distribution; they are not outcomes measured after one.