The sentence that gets a memo into trouble is almost always the same shape. "This wallet belongs to a well known market maker." It arrives in the second paragraph, it is never sourced, and by the time the position is being discussed at committee it has hardened into a fact that nobody in the room can trace back to anything.
Attribution is a probabilistic claim about identity built from circumstantial evidence. Written that way it is defensible and useful. Written as a bare assertion it is a liability, and the liability shows up at exactly the wrong moment, which is when the position is losing money and somebody asks how you knew.
What the identifier on screen actually supports
Start with the thing you are attributing, because most notes get this wrong before they get to the interesting part. The Whale Finder stream at capture displayed addresses in truncated form, entries such as 0xf70da978 and 8fSnLTnRVi, alongside the action and the instrument. Those are display strings. They are not identifiers.

A memo records the full address, the chain, and the venue on which the activity was observed, because the same short prefix can exist on multiple chains and the same entity routinely operates different addresses in different formats. It also records the observation window, since a wallet's behaviour is only evidence for the period you actually watched. Whale Alpha's coverage spans DEX perpetuals on Hyperliquid, GMX, Drift and dYdX plus prediction market wallets on Polymarket and Opinion Trade, and an attribution supported by activity on one of those venues is not automatically supported on the others.
Ranking the evidence by what it survives
Not all attribution evidence is the same strength, and a memo should say which class each piece belongs to rather than presenting a pile of indicators as though they were interchangeable.
- Direct disclosure. The entity published the address itself, in a filing, a contract, a governance post or its own documentation. This is the only class that stands on its own, and it is rarer than the frequency of confident attributions in the market would suggest.
- Structural linkage. The address is a known contract, a documented vault, or sits in a funding path that is itself directly disclosed. Strong, but it degrades quickly with each hop, and a memo should state how many hops away from the disclosed anchor the claim sits.
- Behavioural fingerprint. Timing patterns, size conventions, instrument preferences, or activity that maps onto a known mandate. This is genuine evidence and it is also the class most vulnerable to the analyst finding the pattern they went looking for.
- Third party label. A vendor tag, a social media attribution, or a chart circulating on a research channel. Treat this as a lead, never as a source, and check whether it is circular. A surprising amount of attribution consensus traces back to one unsourced post that everybody subsequently cited.
- Coincidence with a disclosed event. The wallet acted shortly before something the entity later announced. This is the weakest class and the most seductive, and on its own it supports no attribution at all.
The rule to hold yourself to is that classes do not add up to a higher class. Four pieces of behavioural fingerprint evidence do not become structural linkage. They become well documented behavioural evidence, which is a different and lower claim.
Fixed language, with an action limit attached
Confidence words drift if every analyst picks their own. Fix four tiers in the research standard, define the evidence each requires, and attach a position consequence to each, so that the confidence level does actual work rather than decorating the note.
Confirmed requires direct disclosure. The note may name the entity in plain terms. Probable requires structural linkage with the hop count stated, or behavioural evidence across multiple independent dimensions and a sustained observation window. The note names the entity with the qualifier attached, every time, including in the summary line where qualifiers usually get dropped. Possible covers single dimension behavioural evidence or a corroborated third party label, and the note refers to the wallet by address with the candidate identity mentioned once as an open question. Speculative covers everything else, and speculative attributions do not belong in a memo that supports a position at all.
The action limit is the part that makes this more than vocabulary. A position whose thesis depends on an attribution below the probable tier should be capped, and the cap should be written in the note rather than negotiated later. If the identity claim is doing real work in the thesis, then the strength of the identity claim is a risk parameter, and it should be sized like one.
The test that decides whether the identity matters
Before the memo goes anywhere, remove every mention of the entity name and read what is left. If the thesis still stands on the observable behaviour, the size, the persistence, the cross venue exposure, the timing relative to the instrument, then the attribution is colour and the position is defensible without it. Write it that way, with the identity in a clearly marked subsection, and the challenge at committee becomes a question about the evidence rather than an argument about the conclusion.
If the thesis collapses without the name, you have a position that rests entirely on an unproven identity claim, and you should know that about yourself before somebody else points it out. That is not automatically a reason not to take it. It is a reason to size it as what it is and to say so in writing.
There is a related discipline about what the note claims to know. Attribution to an institution is a different claim from attribution to a named individual, and notes should stay on the institutional side. There is also a boundary worth stating explicitly in the standard: observing public on chain activity is one thing, and constructing a thesis that presumes knowledge of an entity's undisclosed intentions is another. Your compliance function will have views on where that line sits in your jurisdiction, and the time to get those views is while you are writing the standard rather than while you are defending a specific position.
The paragraph that makes it survive a challenge
Every attribution in the file should carry a short block containing the full address and chain, the observation window, the evidence classes relied on with one line each, the confidence tier, the action limit, and one item that is almost always missing: what would falsify it. An analyst who can state what observation would cause them to withdraw the attribution has done the work. One who cannot has formed a belief.
Add a review date and treat attributions as perishable. Entities rotate addresses, wallets change hands, and infrastructure gets reused. An attribution that was probable eighteen months ago on evidence nobody has revisited is not probable now, it is stale, and stale attributions have a way of being quoted back with all their original confidence and none of their original support.