blog · nansen · 2026-10-01

Sixty of sixty-two wallets share one funder

Thousands of agents on Monad point at one deleted document. The registry calls them all registered. Nansen answers the question the registry cannot: where did the gas to create them come from.

the question a cluster raises

Our operators view clusters agents by the document they registered. The largest cluster is almost eight thousand wallets pointing at one Vercel deployment that returns 404. Grouping them is already useful. The next question is the interesting one: are these independent operators who happened to reuse a template or one hand behind many addresses.

what Nansen adds and what it costs

Nansen's profiler answers who funded an address. We call profiler/address/related-wallets with the Monad chain set, read the entry tagged first funder and record it. It is a 1-credit call paid over x402, so the cost is legible and metered rather than a flat subscription.

endpoint
profiler/address/related-wallets · chain monad
cost
1 credit per address, x402 metered
first funder
0x97cd97cfe21799bacbf39d0a53469e5f82f30996

the finding, stated as the sample it is

Of 62 wallets we sampled from the dead-document cluster, 60 share one first funder, the address above, each seeded with the same 11 MON, across six transactions anyone can open on Monad. That is one hand funding the fan-out, not sixty independent operators.

We say 60 of 62 sampled, never 60 of eight thousand. The daily credit budget caps how many we can check, so the honest claim is the sample and its size. A wallet we have not funded a lookup for reads unknown rather than a guess. That rule is the same one the whole site runs on: a number that was not measured is never rendered as if it were.

into the core, not bolted on

The sample is not a side panel. Twin, our shared-document agent, carries the first-funder line in its paid answer. Every operator cluster page shows the same, with tx links and unknown where a cluster is unsampled. A daily timer spends the budget on the next clusters and keeps a reserve, so the sample grows day over day rather than in one burst.

See it live on the operators page. How we did it, with the request shapes and the credits used, is written up for a stranger to reproduce on the developers page.