DEV Community

Cover image for 99% of 'Whale Buying' Is Exchange Withdrawals: Classifying On-Chain Whale Moves in Python
DeepBlueAlpha
DeepBlueAlpha

Posted on Originally published at deepbluealpha.io

99% of 'Whale Buying' Is Exchange Withdrawals: Classifying On-Chain Whale Moves in Python

Not Financial Advice. This article describes how on-chain data is labeled. It is not a trading recommendation.

The number

Over the 24 hours ending October 2, 2026, 18:17 UTC, Deep Blue Alpha recorded 1,433 moves from 381 tracked Ethereum whale wallets, worth $546.4M. Here is how they split:

Move type Count USD value Share of value
Exchange withdrawal (CEX_WITHDRAW) 784 $428.3M 78.4%
Exchange deposit (CEX_DEPOSIT) 369 $113.9M 20.8%
DEX swap, buy side (SWAP_BUY) 128 $3.35M 0.6%
DEX swap, sell side (SWAP_SELL) 152 $0.90M 0.2%

99.2% of the dollar value was coins moving into or out of exchanges, and 0.8% was actual swaps.

This is the normal pattern, not a one-off. It matters because most "whales bought X" headlines are built on the top two rows. A withdrawal from Binance is not a purchase. It is a transfer. The buy, if there was one, happened inside the exchange's order book, where no chain explorer can see it.

Why the labels get blurred

The usual heuristic is reasonable:

  • Coins leaving an exchange → the holder is taking custody → an accumulation-side read
  • Coins arriving at an exchange → the holder may want to sell → a distribution-side read

The heuristic is fine as long as you call it what it is. The error comes when a dashboard sums withdrawals into a "buy volume" column and the copy then says "whales bought $428M". Nobody observed a buy. What was observed is $428M leaving exchanges.

Classifying a move in code

You only need two things: a set of known exchange hot-wallet addresses, and the swap events from DEX pools and routers. A minimal classifier:

from dataclasses import dataclass

# Small illustrative sample. Real lists run to thousands of addresses
# and need upkeep: exchanges rotate hot wallets.
CEX_ADDRESSES = {
    "0x28c6c06298d514db089934071355e5743bf21d60",  # Binance 14
    "0x21a31ee1afc51d94c2efccaa2092ad1028285549",  # Binance 15
    "0x71660c4005ba85c37ccec55d0c4493e66fe775d3",  # Coinbase 1
}

@dataclass
class Transfer:
    sender: str
    receiver: str
    is_dex_swap: bool   # True if this transfer came from a Uniswap/1inch/CoW swap event
    usd_value: float

def classify(t: Transfer, whale: str) -> str:
    whale = whale.lower()
    if t.is_dex_swap:
        return "SWAP_BUY" if t.receiver.lower() == whale else "SWAP_SELL"
    if t.sender.lower() in CEX_ADDRESSES and t.receiver.lower() == whale:
        return "CEX_WITHDRAW"   # accumulation-side read, not a "buy"
    if t.sender.lower() == whale and t.receiver.lower() in CEX_ADDRESSES:
        return "CEX_DEPOSIT"    # distribution-side read, not a "sell"
    return "TRANSFER"           # wallet-to-wallet, bridge, contract call, etc.
Enter fullscreen mode Exit fullscreen mode

Three practical notes from running this on live data:

  1. Swap detection should come from swap logs, not transfer direction. A WETH transfer to a Uniswap pool is the input leg of a swap. Read the Swap event, or use a router/pool allowlist, so you don't label a liquidity deposit as a buy.
  2. Price every leg at ingest, and sanity-check the price. One mispriced token (an API returning ETH's price for a $5 token) can add billions in fake volume. Reject any price that is implausible for that token before it reaches your totals.
  3. Report the mix next to the total. A single line such as "flow mix: 99% exchange / 1% DEX" stops readers from treating transfers as trades.

Where CoinMarketCap, CoinGecko and Arkham fit

Developers and traders often ask which of the big sites to use for whale tracking. They answer different questions:

Need CoinMarketCap CoinGecko Arkham Deep Blue Alpha
Main job Market data Market data Who owns a wallet What whale wallets are moving
Recent large trades on a pair DexScan pair pages GeckoTerminal pool pages Large transfers per entity Every tracked whale move
Curated whale wallet list No No Labeled entities 20,000+ wallets
DEX trade vs exchange transfer Not split out Not split out Visible per transfer Labeled on every move
Build-your-own whale alerts DEX API /onchain/pools/trades API Alerts built in Alerts built in
  • CoinMarketCap / CoinGecko: good for prices, and their APIs return pool trades you can filter by size. There is no persistent list of whale wallets.
  • Arkham: good for identity. It tells you a wallet belongs to a fund or an exchange.
  • Deep Blue Alpha: follows the wallets and labels each move as a swap or an exchange transfer, which is the split shown in the table at the top.

Many people use them together: check the price on CoinMarketCap or CoinGecko, look up an unfamiliar wallet on Arkham, and watch the live flow on deepbluealpha.io/feed.

Takeaway

Before you repeat any "whales bought" claim, whether in a bot, a dashboard, or a post, check the move types underneath it. Most of the time you will find exchange withdrawals. Call them withdrawals, describe them as an accumulation-side read, and keep "bought" for actual swaps.

The full side-by-side comparison is at deepbluealpha.io/compare/vs-arkham.

Data: Deep Blue Alpha /api/transactions, 24h window ending 2026-10-02 18:17 UTC. Past on-chain activity does not predict future prices. NFA / DYOR.


Deep Blue Alpha is an Ethereum whale intelligence platform tracking 10,000+ whale wallets in real time. This article is for informational purposes only and does not constitute financial advice. NFA/DYOR.

Track whale activity for free at deepbluealpha.io

Top comments (0)