Sniper bots: speed changes the inventory offered to everyone else
Earliest execution can come from public automation, better infrastructure, atomic bundles, or privileged information. Reconstruct the launch before calling a fast wallet an insider—or treating later buyers as if they saw the same market.
The short answer
A sniper bot monitors for a launch or liquidity event and tries to execute before ordinary manual traders. Automation itself is not proof of manipulation. The market risk is adverse selection: early wallets may acquire cheap inventory, move the price, concentrate supply, and later sell into participants who entered after the advantage had already been exercised.
The investigation has two separate questions. First, what execution advantage did the wallets have? Second, who controlled or funded them, and what did they do with the inventory? Same-slot execution supports speed. It does not, by itself, prove private information, team control, or shared ownership.
Map the advantage before naming the actor
- Monitoring speed: software watches program logs, account changes, pool creation, or a public launch API continuously.
- Prepared execution: accounts, instructions, slippage bounds, and transaction templates are assembled before a manual trader could react.
- Delivery and priority: fast RPC paths, validator connections, priority fees, and tips can improve the chance or order of inclusion.
- Atomic coordination: a bundle can require several ordered transactions to land together or not at all.
- Privileged preparation: a launch time, mint, pool, or signed transaction is known before it becomes available to the public.
Only the last category necessarily depends on nonpublic access. Public APIs and automation can explain some very early fills. Treat “sniper” as a behavior label, then build the separate evidence required for an insider or team attribution.
Priority and bundles change execution, not identity
On Solana, a transaction can add an optional prioritization fee through its compute-unit price and limit. The official fee documentation describes this as a scheduling incentive; it does not guarantee the first fill. A failed transaction can still pay its fee. Compare requested compute, paid priority, landing slot, failures, and the liquidity state actually encountered.
Jito bundles are ordered groups of transactions that execute atomically—together or not at all—within a slot. That can support coordinated launch execution, but a bundle is not automatically malicious and does not identify its economic owner. Use the deeper guides to ordering and MEV and atomic bundles when reconstructing the fill path.
Define the launch window before calculating a sniper share
Resolve the exact event that made trading executable: curve initialization, first funded pool, market creation, migration, or another protocol-specific state transition. Then define the window in slots or transaction order—not an adjustable number of minutes chosen after seeing the chart.
For every early acquisition, record signature, slot, index where available, wallet, quote spent, tokens received, price impact, fee and tip evidence, failed attempts, and token balance after the transaction. A dashboard's “sniper percentage” is an inference. Its event, time window, entity clustering, and treatment of transfers must be known before the percentage is meaningful.
Address count is not participant count
Fresh wallets can make a concentrated early allocation look distributed. Trace their creation and funding, upstream funders, timing, transaction construction, shared fee payers, transfer chains, consolidation, and repeated appearances across launches. Apply the insider-cluster evidence ladder rather than merging wallets because their buys look similar.
Exchange withdrawals, common routers, launchpad defaults, and popular funding services create shared infrastructure without shared control. Preserve each link as observed, inferred, or unknown. Report both the raw-address concentration and the entity-adjusted estimate with your assumptions visible.
The outcome is inventory distribution, not just entry rank
Follow each early wallet through transfers, sales, liquidity provision, burns, consolidation, and remaining balance. Calculate cost basis, realized proceeds, current exposure, and the share of executable liquidity its unsold inventory represents. Early buying followed by independent long-term holding has a different market effect from coordinated selling into the first public wave.
Compare fill quality with the liquidity-depth workflow. A dramatic token count may come from a tiny initial reserve. Quote value, reserve state, price impact, and later sell capacity make the exposure comparable.
Use an evidence ladder
- Observed: transaction order, fees, instructions, token flows, funding edges, balances, and exits.
- Supported inference: automation from repeated low-latency behavior; likely coordination from funding, construction, and consolidation.
- Stronger attribution: signed ownership, disclosed bot operator, direct team funding, private launch material, or repeated exclusive pre-positioning tied to the same controller.
Research can identify persistent early-buyer cohorts without proving that the cohort caused a launch's success. One recent Pump.fun preprint found such cohorts, then reported that an activity-matched placebo had an even larger buyer-flow association. That is a useful warning: cohort selection and market conditions can explain apparent effects.
A launch reconstruction workflow
- Resolve the launch event. Save protocol, mint, pool or curve, initialization signature, executable state change, slot, and timestamp.
- Freeze the window. Choose an event-relative slot or order rule before inspecting wallet identities or outcomes.
- Rebuild early fills. Record transaction position, inputs, outputs, reserve state, priority, tips, failures, and atomic relationships.
- Test entity links. Trace funding, fee payment, construction, transfer, consolidation, and cross-launch recurrence with confidence labels.
- Follow the inventory. Calculate net holdings, realized exits, remaining overhang, and who supplied liquidity to those exits.
- Write the narrow conclusion. Separate automated early entry, coordinated control, privileged information, and market impact.
What belongs in the journal
Record the exact launch event and signature, fixed window rule, early transaction order, raw buyer addresses, quote and token amounts, reserve state, priority fees, tips, failures, bundle evidence, funding sources, entity links and confidence, transfers, sells, realized proceeds, remaining inventory, alternative public-speed explanations, data gaps, and the narrowest claim the evidence supports.
Primary sources
Measure the advantage
Fast is observable. Insider control needs more proof.
Preserve launch order, funding links, execution mechanics, and inventory outcomes separately so an early fill cannot substitute for an entity attribution.
Open the journal