com.achivx/stablescan

Stablecoin Scanner

Stablecoin risk for agents: freezes, OFAC, exposure, allowances, transfers, graph. 7 chains.

1.4.0
Version
remote
Transport
8
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 8 tools scanned
  • metadata: scanned

No findings.

Tools (8)

  • get_address_approvals

    Open ERC-20 and Permit2 allowances one address has granted on one chain, one row per spender and token with the raw value, unlimited/oversized/old flags, spender_class and a band (critical|high|low|expired|none): unlimited to a flagged or unknown spender is the main drain vector, a known service spender (DEX router, Permit2) is normal, an expired Permit2 sub-allowance reads 'expired'. Use it when the question is what a wallet has approved and who could pull its stablecoins. Not for a risk tier — the band is informational and never moves get_address_risk. Not for issuer freezes: get_address_compliance. Not for taint: get_address_exposure. address is the allowance owner (the granter), never the spender. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. A heuristic band over decoded on-chain Approval facts, not an AML or legal determination.

  • get_address_compliance

    Issuer freeze/seize facts for one address on one chain, plus the OFAC SDN flag: freeze[] (one row per freeze-capable stablecoin, status frozen|seized|clear|unknown, with frozen_usd6 = the balance locked now where it was read), not_freezable[] (stablecoins whose issuer cannot freeze on this chain, e.g. the Binance-Peg wrappers on BNB Chain — enforcement is off-chain), frozen_elsewhere[] (the same address bytes under a standing freeze on another indexed chain; EVM and Tron share them, Solana never) and freeze_proposals[] (issuer multisig proposals naming the address, USDT on Ethereum and Tron: executed ones, pending only where the operator publishes them). Use it when the question is whether an issuer or OFAC acted on this address, or how much is frozen. Not for a risk tier: get_address_risk. Not for taint distance: get_address_exposure. Not for when the OFAC list was refreshed: get_sanctions_status. Decoded on-chain issuer acts with provenance, no heuristics. 'unknown' means no act name

  • get_address_exposure

    Taint exposure of one address on one chain: a bounded backward walk over the value graph to the nearest OFAC-sanctioned or hack/drainer/mixer root, answered as a class (sanctioned|direct|indirect|negligible|unknown|none), the nearest hop and a value-proportional haircut fraction. Use it to explain how closely an address is tied to a sanctioned or hack root and by how much value. Not for one go/no-go tier — get_address_risk already includes this walk. Not for the counterparties themselves or a chosen depth, token or window: get_wallet_graph_walk. Not for issuer freezes: get_address_compliance. 'unknown' means the walk did not complete — OFAC list unloaded, time_budget, frontier_cap, Solana coverage pending or partial, short history, or no hack/drainer/mixer label loaded for this chain — never a false 'none'; incomplete_reasons names which (time_budget may complete at a quieter moment, frontier_cap repeats). Depth is fixed at 3 hops and the walk never crosses chains: ask again with chain

  • get_address_risk

    Unified risk tier for one address on one chain — unknown|none|low|medium|high|severe — from decoded facts (OFAC listing, issuer freeze/seize on this chain, exposure to a sanctioned or hack root) and attributed labels with provenance (labels alone cap at medium; a lone-source accusation adds no tier). Use it for one go/no-go read before accepting or sending funds. Not for freeze proposals, frozen balances or a freeze on another chain (frozen_elsewhere): get_address_compliance. Not for taint hops or the haircut: get_address_exposure. Not for open allowances: get_address_approvals. 'unknown' means the check did not finish, never 'checked clean'; evidence and incomplete_reasons name the cause (e.g. time_budget: the exposure walk was cut, a quieter moment may complete it). The freeze input is this chain's per-token status alone: frozen/seized argues for high, and an 'unknown' status or a pair whose freeze history is not backfilled turns a would-be 'none' into 'unknown' — so a Solana tier, w

  • get_recent_transactions

    Recent stablecoin transfers on one chain, newest first, filterable by payer and/or recipient, cursor-paginated. Use it for the latest transfers of an address or of the whole chain, with a tx_hash to cite. Not for who an address settles with over time: get_wallet_graph_walk. Not for how fresh the feed is: get_sync_status. Not for any verdict about an address: get_address_risk. Answer: items[], each row tx_hash, log_index, block_number, block_time (RFC 3339), payer, recipient, amount {amount (minor units, string), decimals, token (symbol)}, token (the contract address), finality, and usd_amount where priced. The chain is the one asked for — rows do not repeat it. payer and recipient narrow together; omit both for the chain-wide feed; pass next_cursor back unchanged as cursor for older rows, and a page without it is the last. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Plain on-chain Transfer facts, no scoring.

  • get_sanctions_status

    OFAC SDN list coverage as this scanner holds it: evm_count, solana_count, tron_count and total addresses loaded (the free public 0xB10C list of US-Government public-domain data), updated_at of the last refresh (null until the first ingest) and the source. Use it to date the sanctions input behind a verdict, or to tell a clear OFAC flag from an unloaded list. Not for whether one address is listed: get_address_compliance (the flag) or get_address_risk (the tier). Not for indexer freshness: get_sync_status. No parameters; one answer covers every chain. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools. Verify against the official SDN list before acting on it; not legal advice.

  • get_sync_status

    Indexer freshness for one chain: freshness_seconds (the age of the newest indexed transfer; null when it could not be read for this answer), the indexer's head and finalized blocks, its safe block and its lag in blocks (lag_blocks = head_block - last_indexed_block). Use it before trusting how recent an address answer is, or to tell an empty feed from a stalled indexer. Not for how fresh the OFAC list is: get_sanctions_status. Every address verdict already carries freshness_seconds, so call this only for the block numbers or for a chain you have not asked about yet. On Solana (chain -1) safe_block is the finalized slot, and lag_blocks is near 0 by construction and never negative, so it is not a freshness signal there: read freshness_seconds. On the EVM chains and Tron a negative lag_blocks means the node's head went back. chain is the only parameter; omit it for Base. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools.

  • get_wallet_graph_walk

    Bounded walk over the indexed settlement graph of one stablecoin from one wallet on one chain: payer<->recipient hops with value-weighted scores, entity-aware node keys, a stop at known services and sanctioned-node markers. Use it to explain who an address settles with and through which hops. Not for a verdict: get_address_risk. Not for the taint class or haircut: get_address_exposure. Not for a flat list of transfers with tx hashes: get_recent_transactions. token is required and must be a stablecoin enabled on that chain (a refusal names them); hops=0 with stop_on_sanctioned=true is the cheapest check of the subject itself; subjects over the degree gate (~50k edge-rows) return hop 1 only with frontier_truncated=true. Heavy read: under load it answers busy or timeout — retry with backoff, a narrower window or a lower frontier_cap. No auth; 1200 requests/min shared by all tools. An explainability primitive, not a detector verdict, identity/control assertion, AML decision or legal advice