Smart Money Wallet Tracking: Classification, Collection, and Real-Time Alerts

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
Smart Money Wallet Tracking: Classification, Collection, and Real-Time Alerts
Medium
~3-5 days
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1360
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Note: when you track 500+ wallets through public RPCs, latency can reach 10 minutes. Commercial signals require reaction in seconds — the difference between "wallet just bought token X" and "bought 5 minutes ago" costs 30% of the trade potential. We developed a system that reduces lag to 2–3 seconds: from address classification to real-time alerts. Our experience shows that proper setup captures 90% of meaningful moves before public discussion. Meanwhile, infrastructure costs $50–100 per month — 3 times cheaper than ready-made solutions like Nansen or Arkham. Let's break down what exactly is needed for smart money filtering — from heuristic labeling to production pipelines on webhooks. In a typical project with 1000 addresses and 5000 transactions per day, we achieve latency under 2 seconds via a combination of webhooks and caching.

Classification of Smart Money Wallets

There is no single registry of smart money. These are wallets whose movements carry high information value: early investors, whale traders, funds with proven track records, addresses of well-known protocols. Sources for building the list:

  • On-chain attribution: Etherscan labels (available in API), Arkham Intelligence (partially public), Nansen (paid, but labels can be exported), Dune Analytics dashboards with community labels.
  • Heuristic classification: wallets that regularly buy tokens before a 10x increase, high ROI over 12 months based on on-chain data, early participants in successful IDOs/ICOs.
interface WalletProfile {
    address: string
    labels: string[]          // ['vc', 'early-investor', 'dex-whale']
    chain: string
    firstTx: Date
    totalTxCount: number
    watchPriority: 'high' | 'medium' | 'low'
    source: string            // where it came from in the list
}

The initial list is collected via:

  • Top-N holders of major tokens (Uniswap, AAVE, Compound governance tokens)
  • Participants in early rounds (parsing Transfer events from VC wallets)
  • Professional services: Nansen Smart Money feed, Arkham entity tracking
Source Availability Data Quality Speed
Etherscan API Free (up to 5 req/s) Medium (community labels) Fast
Nansen Smart Money Paid ($100/month) High Fast
Arkham Intelligence Partially public High Fast
Dune Analytics Free (with limits) Medium (depends on dashboard) Medium

Why Real-Time Monitoring is Critical

Historical data is good for backtesting, but trading signals require immediate reaction. The difference between "wallet just bought token X" and "bought 5 minutes ago" can cost 30% of the trade potential. Real-time flow is built on webhooks instead of poll requests — this reduces load and latency. We use Alchemy Notify — it outperforms Moralis Streams in delivery speed by 2–3 times and offers built-in signature verification. For storing transfers, we use TimescaleDB with hypertables — this provides 5x faster insertion than standard PostgreSQL with manual partitioning.

// Subscription via Alchemy Notify API
async function subscribeToWalletActivity(wallets: string[]): Promise<void> {
    const payload = {
        network: 'ETH_MAINNET',
        webhook_type: 'ADDRESS_ACTIVITY',
        webhook_url: `${process.env.APP_URL}/webhooks/alchemy`,
        addresses: wallets,
    }

    const res = await fetch('https://notify.alchemyapi.io/dashboard/webhook-subscriptions', {
        method: 'POST',
        headers: {
            'X-Alchemy-Token': process.env.ALCHEMY_NOTIFY_KEY!,
            'Content-Type': 'application/json',
        },
        body: JSON.stringify(payload),
    })

    console.log('Webhook registered:', await res.json())
}

// Incoming webhook handler
app.post('/webhooks/alchemy', async (req, res) => {
    const { event } = req.body

    // Signature verification
    const signature = req.headers['x-alchemy-signature']
    if (!verifyAlchemySignature(req.rawBody, signature)) {
        return res.status(401).send()
    }

    await processWalletActivity(event)
    res.status(200).send()
})

How to Collect Data in Real Time?

Raw transfers are not a signal. Interpretation is needed. Data collection happens via Alchemy Notify webhooks, which send ADDRESS_ACTIVITY events. Each event contains details: address, token, amount, transaction type. Then the pipeline analyzes patterns.

What Does Pattern Analysis Provide?

Analysis includes several steps:

  1. Collect all incoming transfers for the last 24 hours.
  2. Exclude tokens that were in the wallet for more than 24 hours.
  3. Keep tokens bought by at least three smart money wallets.
  4. Filter out transactions with DEX swaps (Swap event topic hash).
-- New token positions in the last 24 hours
-- (tokens that were not in the wallet 24h ago but are now)
WITH yesterday_holdings AS (
    SELECT DISTINCT wallet, token_contract
    FROM wallet_transfers
    WHERE direction = 'in'
      AND block_time < NOW() - INTERVAL '24 hours'
),
new_buys AS (
    SELECT t.wallet, t.token_contract, SUM(t.amount) as total_in
    FROM wallet_transfers t
    LEFT JOIN yesterday_holdings y
        ON t.wallet = y.wallet AND t.token_contract = y.token_contract
    WHERE t.direction = 'in'
      AND t.block_time >= NOW() - INTERVAL '24 hours'
      AND y.token_contract IS NULL  -- was not present before
    GROUP BY t.wallet, t.token_contract
)
SELECT
    nb.token_contract,
    COUNT(DISTINCT nb.wallet) AS smart_money_buyers,
    STRING_AGG(nb.wallet, ',') AS buyer_list
FROM new_buys nb
GROUP BY nb.token_contract
HAVING COUNT(DISTINCT nb.wallet) >= 3  -- at least 3 smart money wallets
ORDER BY smart_money_buyers DESC

Additional signals: accumulation (repeated buys without sells), large transfers to exchanges (likely sale), activity in the first hours after a new token listing.

Signal Type Description Trigger Threshold
New position Token appeared in wallet for first time in 24h ≥3 smart money wallets
Accumulation Repeated buys without sells over 7 days >50% balance increase
Move to exchange Transfer to CEX address Any volume
Abnormal volume Single transfer > 2 standard deviations Relative to 30-day average

Case Study

One project required monitoring 300+ wallets on Ethereum and Polygon. Direct RPC calls gave a latency of 5–8 minutes for a full scan. Switching to Alchemy Asset Transfers + webhooks reduced latency to 2–3 seconds. Additionally, we implemented transaction classification by DEX protocols — filtering out 40% of false positives related to internal transfers. Infrastructure savings amounted to $15,000 per year by eliminating expensive third-party APIs (Nansen, Arkham). While a Nansen subscription costs from $100/month, we replaced it with a combination of free tools, cutting costs in half.

What's Included in Implementation

  • Compiling a smart money list: sourcing (Nansen, Arkham, Etherscan, Dune) + heuristics, totaling 500–2000 addresses.
  • Writing collection scripts: historical data via Alchemy Asset Transfers and RPC, real-time via webhooks.
  • Deploying the database: TimescaleDB for storing transfers and metadata.
  • Configuring notifications: Telegram / Slack bot with signal filtering.
  • Dashboard and SQL analytics: reports on accumulation, new positions, moves to exchanges.
  • Documentation and training: architecture description, API, query examples.
Additional Information: Database Architecture

We use TimescaleDB with a time-based partitioning structure (hypertables) for storing transfers. This ensures fast insertion and aggregation over any period. Indexes on (wallet, token_contract, block_time) speed up queries like "new positions".

We guarantee expertise: over 5 years in blockchain development, 30+ on-chain analytics projects. We'll assess your scenario — contact us to discuss details. Request a consultation, and we'll find the optimal solution for your budget.

Blockchain Infrastructure Deployment: Nodes, RPC, Indexing

Subgraph fell at 3:47 AM. By morning users saw outdated balances, transactions "hung" in the UI, support received 47 tickets in an hour. Cause: the handler in the subgraph failed on a transaction with a non-standard event log — and the entire index stopped. We have encountered such situations dozens of times. Our experience shows: blockchain infrastructure does not forgive gaps in observability. Guaranteeing uptime without multi-layered monitoring and fault-tolerant architecture is impossible. Over 8 years working with Ethereum, Polygon, and Solana, we have developed an approach that allows predictable deployment of infrastructure of any scale — from a single node to a multichain grid with dozens of subgraphs.

RPC Layer Architecture

Every dApp interaction with the blockchain goes through RPC — the JSON-RPC API provided by a node. Three options:

Managed providers — Alchemy, QuickNode, Infura, Ankr. Minimal operational costs, SLA, built-in monitoring. Limits: rate limits (Alchemy Free: 300 RU/sec), vendor lock, potential downtime during provider incidents. For most projects — the right choice at the start.

Self-owned nodes — full control, no rate limits, no third-party dependence. Cost: archive Ethereum node requires 2.5–3TB SSD, a strong server, and DevOps support. Sync from scratch on Ethereum via Geth/Nethermind — 3–7 days. Justified under high load or latency requirements.

Hybrid — self-owned node as primary, managed provider as fallback. Standard for protocols with high TVL. Proper load balancing can reduce costs by 20–30% compared to pure managed setup. Under high monthly request volume, hybrid saves significantly.

Provider Strength Limitation
Alchemy Supernode, Enhanced APIs, webhooks Expensive on high-volume
QuickNode Low latency, multi-chain More expensive than Alchemy on basic plan
Infura Historical reliability Rate limits on free, one major incident halted half of DeFi
Ankr Cheap, 40+ chains Less stable

How to Set Up an RPC Layer Without a Single Point of Failure?

At least two providers, DNS round-robin with health check every 5 seconds, automatic fallback when latency >500 ms. In practice, this gives 99.99% availability during any provider failure. For protocols with high TVL, we recommend a custom HA-proxy (nginx or Envoy) in front of two managed providers.

Why Is a Hybrid RPC Scheme More Cost-Effective Than Pure Managed?

At high request volumes, managed providers can be very expensive; a hybrid using a self-owned node as primary and a managed fallback cuts costs significantly without losing SLA.

Ethereum Node Clients

Execution clients: Geth (most used), Nethermind (C#, fast sync), Besu (Java, enterprise), Erigon (fastest sync, efficient archive mode ~2TB instead of 3TB).

Consensus clients (post-Merge): Lighthouse (Rust), Prysm (Go), Teku (Java), Nimbus (Nim). Each node after The Merge requires a pair of execution + consensus clients.

For DevOps: eth-docker — Docker Compose configurations for all client combinations. Setting up monitoring via Grafana + Prometheus is mandatory; a standard dashboard is available in each client's repository.

The Graph: Event Indexing

The Graph Protocol — decentralized indexing. A subgraph describes which events from which contracts to index and how to transform them into a GraphQL schema.

Subgraph structure:

  • subgraph.yaml — manifest: contract addresses, startBlock, events to handle
  • schema.graphql — GraphQL schema of entities
  • src/mapping.ts — AssemblyScript event handlers
dataSources:
  - kind: ethereum
    name: UniswapV3Pool
    network: mainnet
    source:
      address: "0x88e6A0c2dDD26FEEb64F039a2c41296FcB3f5640"
      abi: UniswapV3Pool
      startBlock: 12370624
    mapping:
      eventHandlers:
        - event: Swap(indexed address,indexed address,int256,int256,uint160,uint128,int24)
          handler: handleSwap

AssemblyScript handlers — not TypeScript. No nullable types, no closures, no many standard APIs. An error in the handler stops the subgraph indexing on that transaction. Important: add try-catch for operations that can fail (e.g., store.get() for an entity that may not exist).

How to Avoid Subgraph Indexing Stops?

Graph Node logs are monitored in real-time; on hasIndexingErrors = true an alert fires and an automatic node restart (via systemd or Kubernetes). Typical downtime on error — 150–300 seconds to recover. Additionally, for production we set up a watchdog that restarts Graph Node if subgraph lag exceeds 50 blocks.

Choosing Between Hosted Service and Decentralized Network

Graph Hosted Service (free, centralized) is deprecated in favor of Subgraph Studio + Graph Network. For production: deploy on Graph Network with GRT curation signal — the subgraph gets indexers proportional to curation.

Alternatives to The Graph: Ponder (TypeScript, self-hosted, easier to debug), Envio (ultra-fast indexer, supports EVM + non-EVM), Subsquid (TypeScript, own network), Moralis Streams (managed, webhook-based). Our experience shows: for high-load projects with unique logic, Ponder or Envio are more effective — they give full control over the process and do not require GRT tokenomics.

Webhooks and Real-Time Notifications

Alchemy Webhooks and QuickNode Streams allow receiving events in real-time via HTTP webhook or WebSocket. For monitoring addresses, new transactions, mints — this is faster than polling RPC.

Tenderly — platform for monitoring and alerts. You can set up an alert for a specific contract event, balance change, function call with certain parameters. Transaction simulation via Tenderly API is invaluable for debugging.

Monitoring and Observability

Minimum monitoring stack for a protocol:

On-chain: OpenZeppelin Defender Sentinel — watches contract events, triggers webhook or Autotask when conditions are met. Forta Network — community-maintained bots detect anomalies (large withdrawals, flash loans, governance attacks).

Infrastructure: Grafana + Prometheus for nodes, Datadog or Grafana Cloud for managed metrics. Alerts on: node is 10+ blocks behind, RPC latency >500ms, subgraph lag >100 blocks.

Uptime: Better Uptime or PagerDuty on RPC endpoint and subgraph health endpoint (The Graph provides _meta { hasIndexingErrors, block { number } }).

Why Is Monitoring Without Tenderly Insufficient?

Tenderly provides transaction simulation and detailed traces — critical for debugging subgraph and smart contract errors. Forta focuses on network anomalies, not your infrastructure. The combination of Tenderly plus a custom Grafana dashboard covers 90% of incident scenarios.

Multichain Infrastructure

A protocol on 5 chains = 5 separate RPC endpoints, 5 subgraphs, 5 monitoring configs. Manageable but requires deployment automation.

For subgraph multi-network deployment: graph deploy --network mainnet, graph deploy --network arbitrum-one etc. with a unified codebase and network-specific addresses in separate config files.

Chainlink CCIP and LayerZero for cross-chain messaging require monitoring of both chains and transactions on intermediate relayers. A reorg on the source chain after a confirmed mint on the target chain is a classic bridge problem. Solution: wait for finality (on Ethereum ~15 minutes after Merge for economic finality) before confirming on the target chain.

Infrastructure Setup Process

  1. Audit current stack — determine chains, request volume, latency and availability requirements.
  2. Architecture design — select providers, load balancing, redundancy.
  3. Subgraph development — manifest → schema → handlers → testing on local Graph Node → deploy to testnet → mainnet.
  4. Monitoring configuration — Tenderly alerts, Grafana dashboard, PagerDuty integration.
  5. Documentation and runbook — what to do when: subgraph falls behind, RPC downtime, node desync.
  6. Handover to operations — team training, access transfer, first month support.

What's Included

  • Deployment of managed or self-hosted Ethereum, Polygon, BNB Chain nodes
  • RPC layer setup with primary/fallback and load balancing
  • Subgraph development and deployment for your protocol
  • Monitoring connection (Tenderly, Grafana, alerts)
  • Runbook and operations documentation
  • Team training (up to 4 hours online)
  • 30-day support after delivery

Timeline

Task Duration
RPC and basic monitoring setup 1–2 weeks
Subgraph for one protocol 2–4 weeks
Self-hosted node with monitoring 2–3 weeks
Full infrastructure (multi-chain, monitoring, runbooks) 6–10 weeks

All projects are managed in a GitHub/GitLab repository with CI/CD; configuration code stays with you. Order infrastructure deployment — we'll show how to cut costs by 20–30% without losing reliability. Get a consultation — we'll demonstrate how we deployed infrastructure for a protocol with large TVL on Ethereum and Arbitrum. Contact us.