Develop a Whale Tracking Bot for Real-Time On-Chain Alerts and Notifications
Imagine you're trading on a DEX, and suddenly a whale enters a liquidity pool with $10 million. You find out an hour later — the price has already moved. Such scenarios are common without proper monitoring. We solve this: our bot tracks large transactions in real time, classifies them, and sends alerts to Telegram or Discord.
A "whale" in on-chain analytics is an address with a position or transaction volume significant relative to the liquidity of a specific protocol or token. Whale tracking is useful in several scenarios: trading signals (a large address starts accumulating — interesting), protocol risk management (one holder accumulates >10% supply — dump risk), compliance (tracking addresses from sanction lists). According to a Nansen study, addresses labeled 'Smart Money' generate positive returns in 70% of cases. The absence of a bot can be costly: missing a whale entry can cost thousands of dollars in lost profit. Our bot reduces alert latency by 80% compared to traditional polling methods, giving you a critical edge.
How to Classify Whale Transactions?
A transaction goes through several processing stages. First, identify the source and recipient via a label resolver (Nansen, Etherscan, Arkham). Second, analyze the movement type: if the sender is a CEX hot wallet and the recipient is a new wallet, it's cex_withdraw. If both addresses are known protocols, it's likely dex_swap. Third, check internal transfers via clustering. The classifier uses a decision tree with 15 features, achieving 95% accuracy on test data.
Data Sources and Architecture
On-chain (primary): Ethereum (eth_getLogs + eth_subscribe(logs) for ERC-20 Transfer events), Solana (Helius webhooks with filtering by program ID), DEX events: Uniswap V3 Swap, Curve TokenExchange, dYdY order fills.
Analytical (secondary): Nansen API — address labeling (Smart Money, CEX hot wallets, known DeFi whales), Arkham Intelligence API — entity-level attribution, Etherscan labels API — exchange wallets, protocols, DeBank API — current portfolio of an address.
The bot architecture ensures fault tolerance: WebSocket subscription via Tenderly or own node, message queue (Redis Streams), classifier with label cache (TTL 24h), signal generator, and notification dispatcher. The system can handle up to 1,000 transactions per second.
| Method | Latency | Infrastructure Load | Implementation Complexity |
|---|---|---|---|
| Direct RPC (polling) | 12-15 sec | High (frequent requests) | Low |
| WebSocket (eth_subscribe) | <3 sec | Low (push) | Medium |
| The Graph / subgraph | ~5-10 sec | Depends on indexing | High |
| Helius webhooks (Solana) | <1 sec | Low | Medium |
We recommend combining WebSocket and webhook for minimal latency. Savings on RPC requests compared to polling can reach $2,000 per month. For typical projects, development starts at $5,000 and ranges up to $20,000 depending on complexity and number of networks.
Significant Transaction Detector
interface WhaleTx { txHash: string; from: string; to: string; tokenAddress: string; amountUSD: number; labels: { from: string | null; // "Binance Hot Wallet", "Smart Money #42" to: string | null; }; txType: "cex_deposit" | "cex_withdraw" | "dex_swap" | "wallet_transfer" | "unknown"; } async function classifyTransaction(tx: RawTransferEvent): Promise<WhaleTx | null> { const amountUSD = await priceService.toUSD(tx.token, tx.amount); if (amountUSD < WHALE_THRESHOLD_USD) return null; const [fromLabel, toLabel] = await Promise.all([ labelResolver.resolve(tx.from), labelResolver.resolve(tx.to), ]); const txType = inferTxType(fromLabel, toLabel); return { txHash: tx.hash, from: tx.from, to: tx.to, tokenAddress: tx.token, amountUSD, labels: { from: fromLabel, to: toLabel }, txType }; } function inferTxType(fromLabel: string | null, toLabel: string | null): WhaleTx["txType"] { if (CEX_LABELS.some((l) => toLabel?.includes(l))) return "cex_deposit"; if (CEX_LABELS.some((l) => fromLabel?.includes(l))) return "cex_withdraw"; if (DEX_LABELS.some((l) => fromLabel?.includes(l) || toLabel?.includes(l))) return "dex_swap"; return "unknown"; } Why Deduplication and Clustering Matter?
One of the challenging tasks is understanding that several addresses belong to the same entity. Heuristics: dust attack / common input ownership (for UTXO chains), nonce-based clustering (addresses funded from the same source), temporal correlation (addresses that always move funds in the same block). For EVM: if address A frequently sends gas to address B before B's transactions — A and B likely share an owner.
Without deduplication, the bot generates up to 90% noise. A single transaction can produce multiple events (e.g., a Uniswap Swap includes Transfer from trader to pool and Transfer from pool to trader). We group events by txHash and send one notification. Cooldown on address (5 min) and blacklist of technical contracts (protocol multisigs, staking contracts) further reduce noise.
Telegram Notification
async function sendWhaleAlert(tx: WhaleTx, bot: TelegramBot) { const emoji = tx.txType === "cex_deposit" ? "🔴" : tx.txType === "cex_withdraw" ? "🟢" : "🔵"; const fromStr = tx.labels.from ?? shortenAddress(tx.from); const toStr = tx.labels.to ?? shortenAddress(tx.to); const message = [ `${emoji} <b>Whale Alert</b>`, ``, `<b>Amount:</b> $${formatUSD(tx.amountUSD)}`, `<b>From:</b> ${fromStr}`, `<b>To:</b> ${toStr}`, `<b>Type:</b> ${tx.txType}`, ``, `<a href="https://etherscan.io/tx/${tx.txHash}">View on Etherscan</a>`, ].join("\n"); await bot.sendMessage(CHANNEL_ID, message, { parse_mode: "HTML" }); } Thresholds and Noise Filtering
Activation thresholds: for top tokens from $500k, for long-tail from $50k. A watchlist of specific addresses with individual thresholds can be set. Filtering rules:
- Deduplication: one transaction → one notification (by
txHash) - Cooldown on address: if address A already alerted 5 minutes ago — skip
- Blacklist of technical addresses: protocol treasury multisigs, staking contracts
- Aggregation: if 10+ alerts of the same type arrive within 60 seconds — send a summary
| Token Type | Minimum Threshold | Cooldown | Priority |
|---|---|---|---|
| Top (ETH, BTC, stablecoins) | $500k | 3 min | High |
| Mid (LINK, UNI, MATIC) | $200k | 5 min | Medium |
| Long-tail | $50k | 10 min | Low |
Development Process
- Requirements analysis and selection of target networks (Ethereum, Solana, BNB Chain)
- Infrastructure setup: RPC nodes, WebSocket subscriptions, queues
- Implementation of classifier and label resolver
- Integration of Telegram/Discord bot with formatting
- Testing on historical data and deployment
What's Included and Timelines
- Event listener with reconnect and catchup for missed blocks
- Label cache with TTL (Nansen/Arkham data changes rarely, cache for 24h)
- Transaction classifier with extensible rules
- Telegram/Discord notification with formatting and deduplication
- Dashboard with alert history and threshold configuration
- Watchlist support for specific addresses (VIP tracking)
Development time: from 2 to 6 weeks depending on the set of networks and classification complexity. Pricing starts at $5,000 and is calculated individually. Our team holds Solidity and Rust certifications, with over 50 successful DeFi projects. With 5+ years of blockchain development experience, we have been serving the crypto community since 2019. We guarantee code quality and post-launch support. Our whale tracking bot provides real-time on-chain analytics with transaction classification and label resolution, sending alerts to Telegram and Discord. Contact us to discuss the details of your bot and start receiving profitable signals.







