How to Check if a Solana Token Is Bundled Before You Buy
Five on-chain signals that show whether a Solana launch was bundled: shared funding, same-block buys, wallet age, later behaviour and supply spread.

What a bundled launch actually is
A bundled launch is one where a single operator buys a large slice of a token's very first supply from many wallets they control, in the same moment the token goes live. Supply just means the total number of coins that exist.
Picture a ticket release at a small venue. One person turns up with twenty friends, hands each of them cash, and they all buy the second the doors open. The queue looks packed, but one person paid for every ticket.
The word bundle describes how those buys travel: packed together and submitted as one group so they land in the same block, one page of Solana's public record. That first page matters, because the earliest buys on a fresh launch are the cheapest that token will ever have. The operator's side of assembling one is covered in our walkthrough of creating and bundle buying on Pump.fun.
Why bother? Partly defence, since automated buyers will take the opening supply if the launcher does not. Partly positioning, since cheap early supply is worth much more later if the token gets attention.
You did not launch this token. You have a price chart, a holder count and a list of addresses, and you want to know whether that early buying was real interest or one person wearing twenty coats. For how the opening stretch plays out, see our guide to what happens after the bonding curve.
Bundled does not automatically mean scam
Bundling is a technique, and techniques do not have intentions. Ordinary reasons an operator bundles their own launch:
- The founder wants a position. Buying the first slice of your own token is normal and widely recommended.
- Defence against bots. Automated buyers race for the opening supply of anything new, and taking it yourself stops a machine reselling it to your buyers a minute later.
- Splitting a known allocation. Team, treasury and contributor portions often sit in separate wallets for bookkeeping, especially when the team says so publicly.
We wrote the operator's side of running many wallets in the multi-wallet management playbook for token launchers.
The problematic version is narrower. One party quietly holds a large share of the supply, the public holder list (the addresses that own some of the token) looks pleasantly spread out, and buyers price the token as if hundreds of independent people believed in it. Nobody lied outright, but the picture is wrong, and later buyers pay for the difference.
So the line is disclosure and proportion, not the technique. A team saying "we hold 12% across these wallets" is doing something different from a team holding 40% across wallets nobody can connect. Work out which you are walking into, then size your risk.
A cluster of related wallets is a signal, never proof of intent. Common funding shows a relationship and nothing more: it cannot tell you who controls the addresses or what anyone planned. Exchange wallets, market makers and payout services produce innocent clusters every day. Treat everything below as a reason to ask another question, not as a verdict.
Signal 1: wallets funded from one source
You run the first thirty or so buyers through a funding view, and one wallet at the top turns out to have sent the starting money to twenty-two of them. A funding wallet is the account that paid a wallet's first balance, the way one card tops up a stack of prepaid cards.
This is the hardest part to fake cheaply, which makes it the strongest single thing to look at. A wallet cannot buy until somebody sends it money, so twenty wallets buying at launch means twenty wallets funded beforehand, and the fastest route is one stash paying them all. Funding stays visible forever, since every transfer is public.
The innocent version: exchange hot wallets. Withdrawals from a big trading platform pay thousands of unrelated users from the same few addresses. Volume is the tell. An address that funded half a million wallets is infrastructure. One that funded exactly these nineteen an hour before launch, and nothing since, is not.
Signal 2: same block, same size
On screen this looks almost boring. Sort the earliest buys by time and you get a stack sharing one timestamp, with amounts near enough identical. Nine buys, one block, everything between 0.9 and 1.1 SOL.
Real early demand never looks like that. People find a token at different moments and buy amounts that reflect what they had and how confident they felt. The spread is messy because people are messy. Coordinated buys are uniform because they were configured, not decided: someone typed an amount into a field and it applied to every wallet.
The innocent version: unrelated bots can react to the same public event within milliseconds, which produces clustering in time. What it rarely produces is clustering plus near identical amounts plus a shared funder. One signal alone means little. Two or three stacked on the same wallets is when you slow down.
Signal 3: wallet age and first activity
Every wallet has a first transaction and that timestamp is public, so you can ask a blunt question: how long has this address existed?
A single fresh wallet tells you nothing. People make new wallets constantly, for privacy or a new phone. The cohort is the signal: fifteen addresses whose entire history began inside the same twenty-minute window, shortly before a token they all bought, all quiet afterwards. That is not fifteen people discovering crypto at once.
Wallets also collect residue: failed transactions, forgotten balances. A wallet created, funded, used once and abandoned has a history that fits on a postcard, and twenty postcards in the same handwriting is worth noticing.
The innocent version: onboarding waves. A community event or a wallet app promotion can produce hundreds of same-day accounts from unrelated people. Check whether the fresh cohort also shares a funder before leaning on this one.
Signal 4: who is still holding
The first three signals look backwards at the launch. This one looks at what happened since, which is why it pays to re-check a token a few days later.
Independent holders behave independently. Some take profit early, some hold too long, some forget they own it. Across thirty separate people you get a smear of behaviour with no shape. Supply that arrived as a bundle keeps behaving like a bundle: the whole set sits perfectly still while everything around it churns, or a big portion leaves at once. Both shapes point at one hand on the controls.
The innocent version: a block of untouched wallets can be a team honouring a public promise not to sell, which is a good sign. The question is whether the decision to move that supply belongs to one person or many.
Signal 5: supply concentration versus holder count
Holder count is the number everybody quotes and it answers the least useful question. A holder is any address with some balance, so two thousand holders sounds like a crowd.
Group those two thousand by funding source and the picture can invert. A high count can sit on top of a few connected clusters that own most of the supply while the rest share crumbs. A cluster here means addresses that look related, by shared funding, matching timing, or moving together.
So stop reading the count as a score. Look at the top of the list, ask which addresses are related, and add them up as one line. That combined number is the supply that can leave on the same afternoon. A shop with fifty customers where forty are the owner's relatives is not a busy shop.
The innocent version: concentration at the top is often published and dull. Locked team allocations, treasury reserves and exchange custody wallets hold large balances for reasons anyone can read. Work out what the big addresses are before counting them against the token.
| What you are looking at | Bundled launch pattern | Organic early demand |
|---|---|---|
| Funding | Many early wallets trace to one source that touches little else | Varied, unrelated sources and older wallets with history |
| Timing | Buys packed into the first block or two | Buys scattered across minutes and hours |
| Buy sizes | Near identical amounts, repeated | Uneven amounts, some tiny, some large |
| Wallet age | A cohort created shortly before launch | A mix of old, new and dormant wallets |
| Later behaviour | The set sits still together or exits together | Holders sell, add and forget at their own pace |
| Holder list | High count sitting on top of a few large clusters | Count and supply spread roughly agree |
Checking a token step by step
- Pull the holder list with the token holder snapshot tool and copy out the largest addresses plus any early buyers you can identify.
- Paste them into the free Wallet Scope bulk scanner to see each wallet's SOL balance next to its token holdings.
- Switch to the relationship view in the same tool. It shows which pasted addresses funded which others, answering Signal 1 without tracing transfers by hand.
- Note the clusters, check the early trade history for timing and buy sizes, and spot check a few wallet ages.
- Come back in a few days and see whether the clustered wallets moved together.
Both the bulk scan and the relationship view are free. The honest constraint: one run handles up to 100 wallets and 3 tokens, so a large holder set takes several passes. Deeper per-wallet profit and loss analysis is metered, with a few free lookups a day before it moves onto prepaid credits.
The 100-wallet cap is a real limit, not a footnote. A token with 2,000 holders will not fit in one pass, so prioritise: the top 30 holders by supply plus the earliest buyers you can identify beat a random sample of 100 small wallets.
What these signals cannot tell you
Everything above reads public on-chain data, a narrower window than it feels. These checks cannot prove intent. A cluster tells you addresses are connected, nothing about who owns them or what they plan next. Two friends splitting a purchase and one operator running twenty wallets can leave a similar trail.
They cannot see private arrangements. If ten separate people agreed in a group chat to buy together, the record shows ten unrelated wallets.
They cannot be complete. The 100-wallet limit per run means you are sampling a holder list rather than auditing it. An operator who funds through many hops, over weeks, from different sources will not show up as a neat cluster.
None of this prevents losses. Finding no bundle signals does not make a token safe, and tokens lose value for dozens of reasons unrelated to how they launched. For the wider set of launch risks, read our guide on how to check a Solana token for rug-pull risk.
This is educational material about reading public blockchain data, not financial advice. Never put in money you cannot afford to lose.
Frequently asked questions
Is a bundled token always a bad buy?
No. A founder taking the first slice of their own supply and saying so publicly is a normal launch. The risk case is undisclosed supply that nobody can connect from the holder list.
What is the difference between a bundle and a sniper buy?
A bundle is arranged from the inside by someone who knows the launch is coming, from wallets prepared in advance. A sniper is an outsider's bot reacting the instant a launch becomes visible. The launch side is covered in our Pump.fun bundle buy guide.
How many wallets counts as a lot?
No threshold works everywhere. Ask about share of supply instead. Ten wallets holding 3% between them is trivia. Four wallets holding 40% is the entire story.
Can bundling be hidden completely?
It can be hidden well enough that these checks miss it. Funding routed through intermediate wallets over weeks, mixed with unrelated activity, breaks the trail. A ten-minute check catches the obvious version, which is also the common one.
Can I check any of this for free?
Yes, for the parts that matter. The bulk wallet scan and the funding relationship view in the free Wallet Scope bulk scanner are free, capped at 100 wallets and 3 tokens per run. Only the deeper profit and loss layer is metered.
Does a high holder count mean a token is safe?
It means a lot of addresses hold some amount. Check how much supply the connected addresses at the top control first.
How soon after a launch should I check?
Funding, timing and age are visible immediately. The behaviour signal needs days, so look once early and once later.
What if I find a cluster?
Treat it as a question, not an answer. Look for a public explanation, work out what share of supply the cluster holds, then weigh it against everything else. Sometimes it is a treasury wallet nobody was hiding.


