Sleuth Home App Method API
Method

How Sleuth reads a token

Every number in a report comes from a rule on this page. The last section lists what those rules get wrong.

Sources

  • Solana mainnet through Helius: mint accounts, token accounts, transaction history and the DAS asset index.
  • DexScreener for prices, pools, volume, public token profiles and same-ticker search.
  • IPFS and launchpad hosts for the metadata file a token points at. Sleuth fetches it over HTTPS from public addresses only.
  • RED-COHORT-2026-v1, a public catalogue of sniper wallet cohorts. The catalogue section gives the details and the credit.

Every address in a report links to Solscan, so each figure can be checked by hand.

Launch forensics

Sleuth reads the token's first successful transactions, up to 300, until they cover at least twelve seconds. For each wallet it tracks the position through the window. "Bought" is the largest position a wallet held at once, so a wallet that flips many times counts once. A group figure (bundle or snipers) is the most the group held at once, so tokens passed from one group member to another count once too. Pools, bonding curves and vaults are programs and never count as buyers.

  • Dev. The wallet that paid for the transaction that created the token. On a launchpad that relays creation, this is the launchpad's wallet.
  • Bundle. Other wallets that bought in the creation block, the same slot as the create transaction.
  • Snipers. Wallets whose first buy landed within ten seconds of creation, after the creation block.
  • Insiders. Early buyers linked to the dev through funding: funded by the dev, funded by the dev's own funder, or the dev's funder themselves. Links through exchange wallets never count.
  • Holds now. Each wallet's current share of supply, from the holder snapshot or a direct balance check.

Sleuth also reads the dev's last 100 transactions and lists other tokens it created there.

Holders

Sleuth reads every token account for the mint and groups accounts by owner. Tokens with more than 100,000 accounts get an even sample across 16 address ranges. Sleuth merges in the true 20 largest accounts, so top holder figures stay exact.

A wallet address lies on the ed25519 curve. Pools, bonding curves and vaults use program addresses off the curve, so Sleuth tests every owner and lists programs apart. Wallets on a small ignore list of known bots and routers are left out of rankings too.

Funding and clusters

Sleuth traces the dev, the early buyers and the top holders. For each one it finds the earliest transaction that sent the wallet SOL, or the first transaction another wallet paid for. That record never changes, so Sleuth stores it.

Each funder gets an activity check over its last 1,000 transactions:

  • Busy: 1,000 transactions inside 72 hours, which is how exchanges and bridges look. Their customers never form a cluster.
  • Active: 1,000 transactions over a longer span. Clusters through it carry medium confidence.
  • Quiet: fewer transactions. Clusters through it carry high confidence.

Wallets linked through a shared funder form a cluster. A top holder that is itself a busy wallet counts as an exchange and leaves the concentration figures.

Bot filter checks

Sniper terminals publish the fields they filter new tokens on. Sleuth marks a check pass or fail only where a terminal documents a threshold:

  • Mint authority and freeze authority revoked (GMGN).
  • Top 10 holders under 30% of supply (GMGN).
  • Dev plus bundle at most 15% of supply at launch (OpenLiquid).
  • X, Telegram or website present in the mint metadata (OpenLiquid).
  • No older token with the same ticker (OpenLiquid copycat detection).

Dev holding, snipers, insiders and the deployer's other launches have no published threshold, so Sleuth reports the value only.

Metadata, market and tickers

  • Metadata. The links and description the token's metadata file states at mint. Sleuth shows them as the token states them and does not vouch for them.
  • Market. DexScreener figures across all pools. Turnover is 24 hour volume divided by fully diluted value. Past ten, the volume likely comes from bots trading with themselves.
  • Same ticker. Other Solana tokens that use the same symbol, from DexScreener search. Sleuth cannot know which one a project calls official. Take the address from the project's own site.
  • Known contracts. A short list of verified mints and impostors from our launch research marks those addresses directly.

Sniper catalogue

Sleuth bundles RED-COHORT-2026-v1, a public catalogue of wallets that bought early together on pump.fun from June 11 to 25, 2026. It lists 1,012 cohorts found across 166,098 launches, plus raw observations of early co-buying for 17,204 wallets.

  • Cohort label. The wallet belongs to one of the catalogue's cohorts.
  • Known early buyer. The raw observations show the wallet among the first buyers of three or more launches.
  • Bought together. Two or more wallets of one cohort sit among the early buyers Sleuth read. The study counted the first ten buyers its collector saw, which can come minutes after creation, so Sleuth applies the pair rule to its own on-chain window.
  • Catalogue record. For launches the study covered, a report shows when the catalogue saw each cohort buy, timed from on-chain creation.
  • Wallet profiles list the wallet's cohort, the other cohort members and the launches they hit together.

Snipers rotate wallets, and the catalogue covers two weeks. A wallet missing from it can still be a sniper.

Source: Kamat, A. U. (2026). RED-COHORT-2026-v1: Catalogue of 1,012 Persistent Wallet Cohorts on the Solana Pump.fun Bonding-Curve Marketplace, version 1.1.0. Zenodo. doi:10.5281/zenodo.20978741. Licensed CC-BY-4.0. Companion paper: Kamat, A. U. (2026), Coordinated Sniper Cohorts on Pump.fun, working paper. Sleuth dropped transaction signatures, indexed cohort hits by mint and reduced the raw observations to per-wallet counts. The author redacted one offensive vanity address, and Sleuth leaves it out.

Risk level

Each flag carries a level: danger, warning, note or pass. Any danger flag makes the risk high. Two or more warnings make it medium, and one makes it low. With none, it is minimal.

Known limits

  • A shared funder suggests common control and still needs confirmation: two people can withdraw from the same private wallet.
  • Bundle and sniper wallets can belong to the team or to strangers running bots. Funding links separate some of them, and exchange-funded wallets stay unlinked.
  • A dev who funds side wallets through an exchange leaves no link Sleuth can see.
  • On the busiest launches, 300 transactions can cover less than ten seconds. The report then says how many seconds it read.
  • The deployer check reads 100 transactions. Older launches by the same wallet stay out of view.
  • The busy-wallet rule can misjudge a quiet exchange wallet or a heavy trader.
  • Wallets that sold and closed their token account leave no trace in a past-holder scan.
  • A clean report covers token settings and wallet links. It says nothing about a team's intent or future sells.