What Is a Sybil Attack?

A Sybil attack is when one party forges many fake identities to gain disproportionate influence over a system that assumes each identity is a distinct participant — stuffing a vote, faking reputation, or claiming rewards many times. Named in a 2002 paper, it is the core threat to any open network of agents, where creating an identity is cheap. Resistance comes from making identities costly or verifiable: stake, proof of work, or an attested credential.

Attack
Many fake identities from one party
Named
Douceur, 2002
Resistance
Costly or verified identity — stake, PoW, attestation

Why open agent networks are exposed

Any system that gives one-identity-one-vote weight — reputation, governance, reward distribution, DePIN coverage — breaks if identities are free to mint. An attacker simply creates thousands and overwhelms the honest participants, who each have one.

The defences all raise the cost or the verifiability of being counted: economic stake that is slashable, proof of unique humanity or hardware, or an attested credential from a trusted issuer. For an agent network this is why identity and reputation cannot be purely self-asserted.

Related standards

Douceur, 2002 — The Sybil Attack

Questions

Why is it called a Sybil attack?

After a case study of a person with many identities; the attacker likewise presents many identities from one real entity.

Can it be fully prevented?

Not eliminated, only made expensive — the goal is to raise the cost of forging identities above the value of the influence gained.

Keep reading

related
How Is AI Agent Reputation Earned and Verified?
related
Verify, Don’t Trust: Verification for AI Agents
related
What Is DePIN (Decentralized Physical Infrastructure)?
related
What Is a Digital Signature?
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
Zero-Trust Architecture for AI Agents
Trust & the Record
What Is Agent Attestation?
Trust & the Record
What Is a Trust Graph for Agents?
Trust & the Record
What Is a Zero-Knowledge Proof?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Merkle Tree?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
What Is Confidential Computing?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
Trust & the Record
What Is Public-Key Cryptography?
Trust & the Record
What Is a Cryptographic Hash Function?
Trust & the Record
What Is Mutual TLS (mTLS)?
Trust & the Record
What Is Certificate Transparency?
Trust & the Record
Symmetric vs Asymmetric Encryption: What’s the Difference?
Trust & the Record
Hashing vs Encryption: What’s the Difference?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.