Prediction-market integrity intelligencePublic data only · Wallets, not people
RINGER.report
Policy · standing & public

Methodology & Limits

TL;DR

RINGER detects coordinated wallet activity (“rings”) in prediction markets using only public data: the Polygon blockchain and Polymarket’s public trade tape. Two methods: a funding-graph that links wallets by who first funded them, and an odds-anomaly detector that asks whether a group of wallets won bets they statistically should have lost. Every finding is scored against nulls designed to kill it, and every CRITICAL finding is reviewed by a human before it publishes. Our findings are probabilistic statements about accounts, never people. We cannot see intent, we cannot see everything, and we can be wrong — this page says exactly how, and what we do about it.


What we measure

RINGER watches two public surfaces, continuously:

  1. The public money graph. Every USDC transfer, wallet creation, and funding event on Polygon is public. We read it the same way anyone with a block explorer can — we just read all of it, all the time.
  2. The public trade tape. Every Polymarket fill, position, and on-chain settlement (the CTF payoutNumerators that decide who actually won) is public. We collect it continuously so we have the time-series, not just the snapshot.

That is the entire input. RINGER holds no non-public data, no platform back-channel, no KYC records, no subpoenaed anything. If a claim in a RINGER report cannot be verified on Polygonscan or Polymarket, we do not publish it.

The two detection methods

Method 1 — funding graph (v1). Wallets that share a personal (non-hub) on-chain funder are candidates for common operation. One address funding five fresh wallets in round tranches, which then trade the same markets the same way, is the classic operator-ring signature. The method’s known blind spot: wallets funded through an exchange hot wallet share a funder with millions of strangers, so the graph comes back empty by construction. We exclude hub-scale funders rather than pretend the link means something — and we name this blind spot in every report it affects.

Method 2 — odds-anomaly joint gate (v2). For a candidate group of wallets, we ask the question that actually matters: did they win bets they should have lost, together? A group is flagged CRITICAL only if it clears all of a set of joint gates, including:

Why the nulls matter more than the detector. Our research program spent months discovering, the hard way, all the ways a “signal” on this data can be fake: favorite-carry (buying favorites looks like skill), random co-entry (crowds pile onto big stories in the same hour), single-story luck, and reconstruction artifacts in public activity data. Every one of those failure modes now has a dedicated null or guard in the pipeline, and we publish which gates fired and where the composite sat against the null — so you can check our work. We built these nulls because they killed our own earlier hypotheses. They have teeth.

Confidence tiers and human review

Findings are tiered:

A candidate that cannot clear the full gate set does not become a public CRITICAL, no matter how good the story would be.

Evidence and reproducibility

Every published claim sits on an archived evidence snapshot — activity tape, funding transfers, on-chain settlement reads — stamped with SHA-256 integrity hashes and available on request. Every report states its numbers with the baseline that makes them checkable (a win rate ships with its expected-wins baseline, or it’s marketing, not evidence). When our numbers move between runs, we say where and why.


The hard limits

This section is not fine print. It is the product.

1. We make probabilistic findings about accounts, never people. A RINGER “ring” is a term of art: a set of wallet addresses that clears a joint statistical detection gate. It is not a finding of common control, and it is never a finding about a human being. We publish addresses and the Polymarket usernames the platform itself attaches to them. We do not name real people, and we do not speculate about who is behind an address. “Funding-linked,” “consistent with coordination,” “statistically anomalous” — those are the strongest claims our evidence supports, and they are the only claims we make.

2. Intent is unobservable. What any account holder knew, and how they knew it, is not on the blockchain. A 4.77-sigma anomaly is a pattern that informed trading would produce; it is not proof that information was held. We never state “insider trading,” “fraud,” or “criminal” as fact about anyone. That determination requires access and intent evidence — subpoena-power territory that belongs to regulators and platforms, not to us.

3. Coverage is incomplete, and we count conservatively. Public activity data is not a guaranteed-complete lifetime record — we have documented reconstruction gaps and phantom-cost-basis artifacts in our own prior forensics, and we guard against them. Concretely: we score foresight, not profit (the dominant bought outcome versus the on-chain winner); pre-resolution sells and REDEEM/MERGE exits are unobserved, so we claim no dollar-P&L unless we can prove it; markets unresolved on-chain at read time are omitted, never proxied from prices; and where public reporting names more accounts than we can independently resolve, we analyze only the ones we resolved and say so. Where we cannot verify, we publish the smaller number.

4. Each method has blind spots, and we name them. The funding graph cannot see through exchanges. The odds-anomaly gate needs settled positions, so it is retrospective by nature and can miss a ring that hasn’t won yet or exited early. A sophisticated operator who randomizes timing, sizing, and funding paths can evade behavioral signatures. Detection absence is not innocence, and detection presence is not guilt.

5. This is information, not investment advice. RINGER sells detection — integrity intelligence about market activity — never trade signals. We tested whether patterns like these could be traded profitably and published the null: they can’t be, at any meaningful size. Nothing we publish is a recommendation to buy, sell, follow, copy, or fade anything. (And we don’t trade what we flag — see the No-Trading Rule.)

6. We can be wrong, and here is how we say so. A statistical detector on incomplete public data will eventually flag a false positive. When we’re wrong, we correct prominently, we annotate the original, and we log it permanently — see Appeals & Corrections. We also publish our null results, our blind spots, and the cases where our reconstruction came out smaller than the public headline. A finding you can’t appeal, reproduce, or watch us correct isn’t intelligence; it’s an accusation. We publish intelligence.


RINGER analyzes public on-chain and prediction-market data. Informational only — not trading advice. Statistical pattern on public data.

Last updated: 2026-07-09