How RINGER finds a ring.
RINGER detects coordinated wallet activity — “rings” — in prediction markets using only public data. Every finding is scored against nulls designed to kill it, and every CRITICAL finding is reviewed by a human before it publishes. Our findings are probabilistic statements about accounts, never people. This page is the working summary; the binding version, including every limit we know about, is the Methodology & Limits policy.
The entire input is public
We watch two public surfaces, continuously:
- The public money graph. Every USDC transfer, wallet creation, and funding event on Polygon is public. We read it the same way anyone with a block explorer can — we just read all of it, all the time.
- The public trade tape. Every Polymarket fill, position, and on-chain settlement is public. We collect it continuously, so we hold the time-series, not just the snapshot — 4.09M trades across 181,789 wallets at last count, with 1,579 settled markets resolved against venue-canonical outcomes and 18,719 wallets mapped in the funding graph.
RINGER holds no non-public data — no platform back-channel, no KYC records, no confidential sources. If a claim cannot be verified on Polygonscan or Polymarket, we do not publish it.
Method 1 — the funding graph
Wallets that share a personal (non-hub) on-chain funder are candidates for common operation. One address funding five fresh wallets in round tranches, which then trade the same markets the same way, is the classic operator-ring signature.
The method’s known blind spot, named in every report it affects: wallets funded through an exchange hot wallet share a funder with millions of strangers, so the graph comes back empty by construction. We exclude hub-scale funders rather than pretend the link means something.
Method 2 — the odds-anomaly joint gate
For a candidate group of wallets, we ask the question that actually matters: did they win bets they should have lost, together? A group is flagged CRITICAL only if it clears all of a set of joint gates, including:
Why the nulls matter more than the detector
Our research program spent months discovering, the hard way, all the ways a “signal” on this data can be fake: favorite-carry (buying favorites looks like skill), random co-entry (crowds pile onto big stories in the same hour), single-story luck, and reconstruction artifacts in public activity data. Every one of those failure modes now has a dedicated null or guard in the pipeline — and we publish which gates fired and where the composite sat against the null, so you can check our work. We built these nulls because they killed our own earlier hypotheses. They have teeth.
The stress test
“One in a million” claims deserve a hostile audit, so we gave our detector one. We ran the exact production pipeline over the very markets a flagged ring traded — the full recent-trader population of those markets: 21,633 wallets with settled positions, producing 54 candidate cohorts scored identically to the real thing.
- Best chance cohort: z = 2.04 — fully consistent with luck.
- The real ring: z = 4.77 — far outside anything 21,633 wallets betting the same markets produced by coincidence.
- At the CRITICAL bar — the bar that flags a ring: zero false positives.
Confidence tiers and human review
- CRITICAL — all joint gates clear. Every CRITICAL finding is reviewed by a human before anything publishes. No automated accusations, ever.
- ELEVATED — some gates clear; internal watchlist; described publicly, if at all, only as “possible coordination, unconfirmed.”
- INFO — data only.
A candidate that cannot clear the full gate set does not become a public CRITICAL, no matter how good the story would be. The scan runs daily, automatically — it is live now.
Evidence and reproducibility
Every published claim sits on an archived evidence snapshot — activity tape, funding transfers, on-chain settlement reads — stamped with SHA-256 integrity hashes and available on request. Every report states its numbers with the baseline that makes them checkable: a win rate ships with its expected-wins baseline, or it’s marketing, not evidence.
What we cannot do
The limits are not fine print — they are the product:
- We make probabilistic findings about accounts, never people. A “ring” is a term of art for a wallet set that clears a statistical gate — not a finding of common control, and never a finding about a human being.
- Intent is unobservable. A high-sigma anomaly is a pattern informed trading would produce; it is not proof information was held. We never state “insider trading” as fact about anyone.
- Coverage is incomplete, and we count conservatively. Where we cannot verify, we publish the smaller number.
- Each method has blind spots, and we name them. Detection absence is not innocence; detection presence is not guilt.
- This is information, not investment advice — and we don’t trade what we flag.
- We can be wrong, and when we are, we correct prominently and log it permanently.
The full versions: Methodology & Limits · Appeals & Corrections · The No-Trading Rule · Authorities & Press