Spark Program | CKB Wallet Behaviour Intelligence

Hi xingtianchunyan,

Research conclusion

The study does not establish a verified human/bot/exchange identity classifier. It establishes a reproducible CKB-native behavioural-analysis workflow, a frozen observational cohort, and evidence-supported structural patterns whose interpretation is explicitly bounded by the available data.

1. Executive Summary

This report responds to the Committee’s request to develop the observed PCA/HDBSCAN groups into an evidence-supported research deliverable, reconcile dataset counts and limitations, and map the original deliverables to the revised output.

The original objective included identity-oriented wallet classification. The completed research does not provide independent ground-truth labels sufficient to validate identities such as human, automated, exchange, protocol owner, or token user. Accordingly, those claims are not carried forward. The defensible output is a CKB-native behavioural-analysis workflow based on observable transaction, Cell, capacity, lineage and script evidence.

For interpretation, PCA4 is used as the reference representation. It contains 513 complete-case wallets described by ten capacity, lineage and script predictors. HDBSCAN assigned 484 wallets to three groups of 84, 78 and 322 addresses, with 29 noise points. PCA4 was robust under the declared resampling procedure (mean ARI 0.9423; mean AMI 0.9097), but the partition remains representation-dependent.

Only the 84-wallet low target-consumed-capacity structure persists exactly across PCA3, PCA4 and PCA6. The 78-wallet script-family subgroup is separated by PCA4 but merges with the larger group in PCA3 and PCA6. The 322-wallet PCA4 group remains uninterpreted because no feature reaches the declared interpretation threshold.

The engineering output is also publicly deployed. The production API is reachable through Cloudflare and HTTPS, performs frozen wallet analysis, exposes behaviour results, enforces the configured CORS policy and rate limiting, and uses the verified frozen SQLite dataset as a read-only source for reproducible frozen analysis.

2. Research Objective and Revised Scope

2.1 Original objective

The original project sought to extract CKB-native wallet behaviour features and use them to classify or characterize wallet activity, including identity-oriented categories. Historical proxy metadata existed for some wallets, but the audit found that it could not be treated as verified identity ground truth.

2.2 Revised scientific claim

The revised research claim is narrower: observable CKB activity can be reconstructed into support-aware behavioural features, and unsupervised analysis can reveal repeatable feature-space structures within the frozen cohort. Those structures may be described only to the extent supported by direct on-chain evidence. They are not identities and are not a universal taxonomy of CKB wallets.

2.3 Proposed acceptance scope

A reproducible CKB-native behavioural-analysis workflow and frozen observational cohort, together with support-aware features, PCA diagnostics, representation-sensitive unsupervised structure discovery, raw evidence review, bounded group interpretations, and a publicly accessible Wallet Behaviour Registry API.

3. Reproducibility and Audit Pin

Item Pinned value
Audit branch fix/data (read-only evidence audit)
Audit commit 3ffa0873a230edae6a181e1c5144ffb635dd7af6
Production main commit observed during deployment 188df135ffd78cebaf7aaf4df81f5554519bd025
Observation interval [2026-08-01 00:00 UTC, 2026-08-31 00:00 UTC)
Blocks 20,025,197-20,311,450
Frozen population 1,172 addresses
Dataset SQLite SHA-256 e74b12f269c5b5bbc9acb4d39d11e9259769b01299ec0c310d91fd38d43ff322
SQLite integrity ok
PCA assignment artifact SHA-256 bdb45952b7dd13ef083b1627bacd1c2ca50ac1c5633086aa0040d6feebdc3ce5
Evidence-review artifact SHA-256 ce9c58cbe4248b747a6ea7a73077e36e6d6d6ef7cb0a082db389cdfbffb50733

4. Dataset and Methodology

4.1 Frozen population

The frozen population contains 1,172 addresses assembled from overlapping historical local sources. It is not a probability sample of all CKB wallets. Population state records include 939 complete, 6 partial, 224 retry-exhausted and 3 invalid addresses. There are 1,169 valid observation rows.

4.2 Feature representation

The High-Confidence representation used for PCA contains ten complete-case predictors from capacity, lineage and scripts. Temporal, lifecycle, topology and transaction-template features are not part of this representation. Feature support and missingness are tracked explicitly so unsupported observations are not silently converted into behavioural claims.

4.3 PCA and clustering

PCA3, PCA4 and PCA6 are different dimensional representations, not three competing wallet taxonomies. HDBSCAN was applied to each representation. PCA4 is used as the interpretive reference because it produced a robust three-group partition under the declared resampling test. PCA3 and PCA6 each produced two groups.

PCA4 parameter Value
Retained variance 80.3800%
Distance Euclidean
min_cluster_size 25
min_samples 10
cluster_selection_method eom
Eligible wallets 513
Assigned wallets 484
Noise 29
Groups 3
Bootstrap 100 deterministic 80% subsamples
Mean ARI 0.9423
Mean AMI 0.9097
Stability classification ROBUST

5. PCA4 Reference Groups

PCA4 group Addresses % of 513 cohort Interpretation
0 84 16.37% LOW_TARGET_CONSUMED_CAPACITY_STRUCTURE
1 78 15.20% SCRIPT_TYPE_DIVERSE_STRUCTURE (narrow registry-relative meaning)
2 322 62.77% UNINTERPRETED
Noise 29 5.65% Unassigned

5.1 Group-defining features

The standardized difference below is (group mean - cohort mean) / cohort sample standard deviation. It is an effect-size description, not an identity score or classifier coefficient.

Group Feature Group median Other assigned median Std. difference Evidence
0 target_consumed_capacity 0 shannon 4.989x10^12 -2.124 Strong
0 capacity_repeat_ratio 0 1.0 -1.321 Strong
0 target_net_capacity_delta +3.119x10^12 0 +1.291 Strong
0 lineage_depth 1 2 -0.736 Moderate
1 type_family_count 1 0 +1.961 Strong, registry-limited
1 unique_type_script_count 1 0 +0.913 Moderate
1 target_consumed_capacity 3.968x10^12 1.073x10^12 +0.337 Weak secondary
2 type_family_count 0 1 -0.501 Weak
2 target_consumed_capacity 4.989x10^12 0 +0.436 Weak
2 unique_type_script_count 0 1 -0.316 Weak

5.2 Group 0 - Low target-consumed-capacity structure

All 84 Group 0 wallets have raw target_consumed_capacity = 0. The extractor calculates this feature by selecting resolved input Cells controlled by the target lock and summing their capacities. The directly supported interpretation is therefore that no target-controlled input capacity was consumed by these addresses during the fixed observation window. Their median target-created capacity is positive and their median net-capacity delta is approximately +3.119x10^12 shannon.

This does not establish low balance, low wealth, passive ownership, or a wallet identity. Plausible alternatives include receive-only activity during August, recently activated or intermittent addresses, longer holding periods, spending outside the window, protocol/timelock constraints, or sparse observations. Because CKB since semantics are not modeled, the analysis cannot determine whether a Cell remained unconsumed by choice or because of a constraint.

5.3 Group 1 - Script/type-family structure

Group 1 is distinguished primarily by recognized type-family presence relative to zero recognized families in Group 2. The registry recognizes exact (code_hash, hash_type) pairs for SECP256K1_BLAKE160, SECP256K1_MULTISIG, NERVOS_DAO, TYPE_ID and XUDT. Seventy-seven of 78 Group 1 wallets have type_family_count = 1; 73 contain recognized NERVOS_DAO family evidence and four contain recognized XUDT family evidence. Seventy-four have exactly one unique type-script hash.

The label ‘diverse’ must therefore be read narrowly and statistically. It does not establish that the group consists of token users, DeFi wallets, protocol-owned wallets, or any economic identity. Only four Group 1 wallets show the recognized XUDT family, and typed-asset Feature V2 never reaches SUPPORTED in the frozen population.

5.4 Group 2 - Uninterpreted

Group 2 contains 322 wallets. All have nonzero target-consumed capacity and zero recognized type-script families, but no feature reaches the declared absolute-effect interpretation threshold of 1.0. Transaction counts and structural behaviour vary materially inside the group. The partition is stable in PCA4 feature space, but the evidence does not justify a coherent behavioural or identity label. UNINTERPRETED is therefore retained.

6. Representative On-chain Evidence

Representative records were selected as central, boundary and extreme observations for each PCA4 group. The evidence below connects the statistical descriptions to inspectable transaction/Cell activity without converting those observations into identity claims.

Group Role Address (abbrev.) Observed evidence
0 Central ckb1qzda…ljv3p 3 tx; 0 target consumed; 15,212,499,995,740 shannon target created; no target type families.
0 Boundary/extreme ckb1qzda…9csl 8 tx; 0 target consumed; 1,510,000,000,000 shannon target created; repeat ratio 0.875.
1 Central ckb1qzda…90ve 2 tx; 400,000,000,000 consumed; 200,000,000,000 created; recognized NERVOS_DAO family.
1 Boundary ckb1qzda…yhsp 16 tx; DAO family; consumes target outpoints and creates DAO-typed and untyped target outputs.
1 Extreme ckb1qrgq…p36 23 tx; 23 unique type-script hashes; 0 recognized families; demonstrates within-group heterogeneity.
2 Central ckb1qzda…5up2 4 tx; consumed = created = 8,394,507,982,524 shannon; no type scripts.
2 Boundary/extreme ckb1qzda…4txw 42 tx; 6,353,979,805,794 consumed; 2,910,501,990,466 created; no type scripts.

6.1 Inspectable transaction examples

Group 0 central: 0xdaf29fa1dee922b7fc3048c60d92c596a17f7e6af2f0cf699162a7ec97797f63. Block 20,177,298; creates target Cell #0 with 5,331,999,997,870 shannon and consumes no target-controlled input.

Group 0 boundary/extreme: 0xc268bd9e798870434b4749d6040552a93a9051f89634544bec08eb81f82a7477. Block 20,028,186; creates target Cell #0 with 340,300,000,000 shannon and consumes no target-controlled input.

Group 1 central: 0x0a6ef471086e5187c92d4edfbe98dfc7ba6e53e6962a19feef4d50bcd1d94279. Block 20,236,679; consumes a 200,000,000,000-shannon target outpoint and creates a target output with the same capacity carrying the recognized DAO type script.

Group 1 boundary: 0x7d878af03d93dcb446ca92e81d1610a4be8c7b2e5510e04cc01e0c928c818b8a. Block 20,199,905; consumes two target outpoints and creates a DAO-typed target output plus an untyped target output.

Group 2 boundary/extreme: 0x519820dea22762c7017d1e5e4567ee67c76e756e4411d7aba171ced2d019292f. Block 20,202,807; consumes four target outpoints totaling 1,017,535,636,593 shannon and creates target output #1 with 20,035,632,873 shannon.

7. PCA3/PCA4/PCA6 Cross-Representation Analysis

The representations produce 2/3/2 groups respectively. The key invariant is the exact 84-wallet low-consumed-capacity group. The PCA4 script-family subgroup does not survive as a separate group under PCA3 or PCA6.

PCA4 assignment PCA3 G0 PCA3 G1 PCA3 noise Total
Group 0 84 0 0 84
Group 1 0 78 0 78
Group 2 0 322 0 322
PCA4 noise 0 26 3 29
PCA4 assignment PCA6 G0 PCA6 G1 PCA6 noise Total
Group 0 84 0 0 84
Group 1 0 78 0 78
Group 2 0 321 1 322
PCA4 noise 0 26 3 29

PCA3 and PCA6 are nearly identical (ARI 0.9920; AMI 0.9812). PCA4 versus PCA3 has ARI 0.4821 and AMI 0.6055; PCA4 versus PCA6 has ARI 0.4785 and AMI 0.5966. Thus PCA4’s three-way structure is robust under its tested resampling procedure but is not invariant to the number of retained principal components.

8. Authoritative Dataset Count Reconciliation

Different headline counts refer to different scopes. The frozen dataset contract and SQLite-backed audit are the authoritative basis for this report. Wallet-transaction participation counts repeat a shared transaction for each participating wallet, while distinct transaction counts deduplicate by transaction hash. The global normalized cache additionally includes previous-output transactions needed for resolution.

Metric Count Scope
Frozen population 1,172 Population contract
Observation rows 1,169 Valid addresses with observation records
Complete / partial / retry exhausted / invalid 939 / 6 / 224 / 3 Population state
Wallet-transaction participation 51,816 Transaction counted per participating wallet observation
Distinct participating transactions 47,145 Unique transaction hashes in observations
Normalized/shared-cache transactions 91,974 Global transaction + previous-output cache
Participation-weighted input rows 92,515 Inputs repeated by wallet participation
Participation-weighted applicable inputs 56,407 Inputs requiring previous-output resolution
Resolved applicable cohort inputs 56,407 Complete cohort resolution
Shared-cache total inputs 196,308 All globally cached transactions
Shared-cache applicable inputs 160,200 Complete + incomplete
Shared-cache resolved inputs 159,235 Complete
Shared-cache unresolved/incomplete 965 Cache-only rows outside final participating cohort
Shared-cache Cell/output rows 173,990 Global normalized output cache
Shared-cache typed output Cells 7,601 Non-null type-script hash
Distinct cached type-script hashes 115 Global cache

9. Limitations and Interpretation Boundaries

Non-representative sampling. The cohort was assembled from overlapping historical local sources and is not a probability sample of all CKB wallets. Group proportions must not be generalized to the ecosystem.

Identity labels. Legacy proxy metadata remains for 425 wallets (222 bot_like, 203 human_like), with 747 unlabeled. These fields were excluded from Feature V2, PCA, HDBSCAN, GMM and interpretation and cannot validate identity claims.

Typed assets. Typed-asset semantic support is insufficient: 1,164 wallets are INSUFFICIENT_EVIDENCE, five PARTIAL, three invalid/unresolved and zero SUPPORTED. A type script is not automatically a token, and even recognized XUDT code hashes do not establish ticker, decimals, issuer, owner identity or economic intent.

CKB since semantics. Relative and absolute since semantics are not modeled. Timelocked or protocol-constrained Cells may appear long-lived or unconsumed; the study cannot always distinguish enforced lifetime from discretionary wallet behaviour.

Observation window and missingness. The study uses one 30-day window. There are 227 failed and six partial population records, and the 513-wallet PCA cohort is support-selected rather than the full population.

Dependence and model sensitivity. Shared transactions make wallet observations statistically non-independent. Post-hoc activity effects are low under the declared thresholds but independence from activity is not established. HDBSCAN and GMM disagree materially, and PCA4 remains representation-dependent.

10. Public Wallet Behaviour Registry API

The research output is accompanied by a public API deployment. The public registry is available at api.afriai.xyz behind Cloudflare and Nginx with HTTPS. The classifier service remains private to the Docker network; the registry is the only application service published through the host reverse proxy.

Production check Observed result
Public health endpoint HTTP/2 200; service status ok
HTTPS / origin TLS Operational through Cloudflare
HTTP redirect HTTP → HTTPS 301
Allowed CORS origin https://afriai.xyz receives Access-Control-Allow-Origin
Disallowed origin No CORS permission header for https://evil.example
Preflight OPTIONS returns 204
Frozen wallet analysis Public POST returns wallet-behaviour-v2 analysis
Behaviour retrieval Public behaviours endpoint returns rule evidence
Rate limiting Configured analysis bucket reaches HTTP 429 with Retry-After
Frozen SQLite SHA-256 verified; PRAGMA integrity_check = ok; read-only mount
Containers Registry and classifier observed healthy during deployment validation

Public API: https://api.afriai.xyz
API documentation: CKB Wallet Behaviour Registry API
Health endpoint: https://api.afriai.xyz/api/v1/health

The public API is a verification surface for the engineering deliverable. It does not alter the scientific interpretation: API outputs describe observable behaviour and feature support, not identity or ownership.

11. Revised Deliverable Matrix

Original deliverable Current/replacement deliverable Status Verification / remaining work
Open-source repository CKB-native research + local/public services COMPLETE Commit-pinned source and tests; confirm intended public release commit.
Extraction pipeline Explorer-backed, cache-first transaction/Cell reconstruction COMPLETE UNDER REVISED METHODOLOGY Tests, frozen DB and cache counters.
Feature engineering Nine support-aware Feature V2 families COMPLETE UNDER REVISED METHODOLOGY Feature artifacts and tests.
~500 human-like wallets Historical proxy metadata only INVALIDATED AS IDENTITY CLAIM Independent ground truth unavailable.
~500 automated/exchange-like wallets No valid replacement labels NOT SCIENTIFICALLY ESTABLISHED Independent ground truth required.
Supervised identity classifier Label-free behavioural analysis PROPOSED REPLACEMENT Committee acceptance decision.
Human/bot/exchange scores No identity scores NOT SCIENTIFICALLY ESTABLISHED Would require ground truth and a new validation study.
Confidence metrics Structural membership/stability only COMPLETE UNDER REVISED METHODOLOGY Must not be framed as identity confidence.
Accuracy/F1/confusion matrix Historical proxy agreement invalidated NOT APPLICABLE TO REVISED CLAIM Cannot be repaired without verified labels.
Behavioural analysis Feature V2 + PCA + HDBSCAN/GMM + evidence review COMPLETE Offline verifier and research artifacts.
Frozen dataset 1,172-wallet Dataset V1 COMPLETE SHA-256 + SQLite integrity.
Research report Final report + evidence clarification COMPLETE This report and repository artifacts.
Public API Wallet Behaviour Registry V2 COMPLETE Public HTTPS endpoints.
API documentation Public documentation page COMPLETE Public docs endpoint.
Standalone demo Not required for final implementation path NOT PROVIDED Public API documentation is the verification interface; no separate demo claim is made.
Live arbitrary-wallet analysis Low-volume live analysis PARTIAL / IMPLEMENTED WITH LIMITS Further high-activity/load validation remains.
High-volume live analysis Not demonstrated OUTSTANDING Pagination/load/whole-analysis timeout validation.
Production hardening HTTPS, CORS, rate limiting, health checks, retry bounds IMPLEMENTED FOR CURRENT DEPLOYMENT Continue operational monitoring and hardening as usage grows.

12. Proposed Revised Research Deliverable

The proposed replacement deliverable is a reproducible CKB-native behavioural-analysis workflow and frozen observational cohort, together with support-aware features, PCA diagnostics, representation-sensitive unsupervised structure discovery, raw evidence review, and explicitly bounded interpretations.

  • Frozen 1,172-wallet Dataset V1 and observation contract.
  • Cache-first transaction, Cell, script and previous-output reconstruction.
  • Feature V2 with explicit support and missingness semantics.
  • Predictor quality, missingness, activity, redundancy and stability validation.
  • High-Confidence 513 x 10 complete-case representation.
  • PCA diagnostics and bootstrap stability.
  • HDBSCAN grid, resampling stability, GMM sensitivity and UMAP visualization-only outputs.
  • PCA4 cohort-specific reference partition.
  • Two cautiously supported structural descriptions and one uninterpreted group.
  • Representative addresses with transaction hashes and Cell evidence.
  • Exact PCA3/PCA4/PCA6 membership crosswalk.
  • Dataset-count reconciliation and explicit limitations.
  • Offline hash, integrity, contract, alignment and test verification.
  • Public Wallet Behaviour Registry API and documentation.

13. Remaining Work

The core revised research deliverable is complete. The remaining work is engineering hardening rather than missing scientific evidence.

Area Status / remaining work
High-activity live collection Not yet proven at production scale.
Whole-analysis deadline / total transaction cap Not established in the audited production patch; large wallets may exceed the registry timeout while continuing to occupy a classifier slot.
Load and timeout validation Broader automated production tests remain desirable.
Public authentication / abuse controls Current deployment uses rate limiting but no user authentication layer.
External replication Replication on a new cohort/window would be required to test generalization of PCA4 structures.
Identity classification Would require independently verified labels and a separate supervised study.

14. Claim-Safety Summary

Claim Assessment Safe statement
PCA4 discovered three wallet types. False PCA4 produced three cohort-specific feature-space groups plus noise.
PCA4 produced three structural groups. Qualified PCA4 HDBSCAN assigned 484 of 513 High-Confidence wallets to three representation-specific groups.
Groups represent all CKB wallets. False They describe a non-random frozen observational cohort.
Group 0 means low-balance wallet. False It means no target-controlled input capacity was consumed during the fixed window.
Group 1 means token user. Unsupported It has more recognized type-family evidence, primarily DAO.
Same three groups exist in PCA3/PCA6. False PCA3/PCA4/PCA6 yield 2/3/2 groups.
Groups are independent of activity. Unsupported Post-hoc activity effects were low; independence was not established.
PCA4 is stable. Qualified Robust under 100 tested 80% resamples, but representation-dependent.
Groups are identities. False No identity ground truth or ownership attribution exists.
Groups are observable structural patterns. Qualified Exploratory structures in a support-selected representation over one fixed window.

15. Commit-Pinned Research Evidence

Experiment contract: ckb-intel/ckb_data/exploratory_ml_phase2_v1/experiment_contract.json at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
HDBSCAN assignments: ckb-intel/ckb_data/exploratory_ml_phase2_v1/hdbscan_memberships.csv at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Selected configurations: ckb-intel/ckb_data/exploratory_ml_phase2_v1/hdbscan_selected_runs.json at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Stability report: ckb-intel/ckb_data/exploratory_ml_phase2_v1/cluster_stability_report.json at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Feature profiles: ckb-intel/ckb_data/exploratory_ml_phase2_v1/group_feature_profiles.csv at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Activity dependence: ckb-intel/ckb_data/exploratory_ml_phase2_v1/activity_dependence_report.csv at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Representative evidence: ckb-intel/ckb_data/exploratory_ml_phase2_v1/evidence_review_records.csv at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Interpretation mapping: ckb-intel/ckb_data/exploratory_ml_phase2_v1/archetype_interpretations.json at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub
Dataset contract: ckb-intel/ckb_data/feature_engineering_v2/dataset_v1_snapshot/dataset_contract_v1.json at 3ffa0873a230edae6a181e1c5144ffb635dd7af6 · FadhilMulinya/ckb-intel · GitHub

16. Conclusion

The completed work supports a revised acceptance scope centered on reproducible CKB-native behavioural analysis rather than verified wallet identity classification. PCA4 provides a robust cohort-specific reference partition, but only the 84-wallet low-consumed-capacity structure persists exactly across PCA3, PCA4 and PCA6. The script-family subgroup is representation-dependent, and the largest PCA4 group is intentionally left uninterpreted.

The result is therefore deliberately narrower than the original identity objective, but it is directly auditable: the frozen dataset is hash-verified, the methodological artifacts are reproducible, representative addresses are connected to transaction/Cell evidence, the limitations are explicit, and the engineering output is available through a public API. Committee acceptance of this revised scope remains a committee decision; this report does not treat acceptance as already granted.

Best,
Fadhil

2 Likes