Data sources
Wallet Sleuth does not maintain its own blocklist. It combines open datasets and public APIs, records where every label came from, and shows that provenance on the label itself. This page lists each source.
Threat intelligence
These sources produce the risk labels described under Threat intelligence and taint.
| Source | What it provides | Chains | Refresh | Access |
|---|---|---|---|---|
| OFAC Specially Designated Nationals list, via the 0xB10C GitHub mirror | Addresses named in United States sanctions designations | EVM | Daily | Public, government data |
| AllenHark blacklist | Community-maintained list of pump.fun scammers and launchers | Solana | Daily | Public |
| Lazarus and DPRK research by tayvano | Incident write-ups for hacks, thefts and laundering attributed to North Korean groups and others. Only addresses whose role is explicitly adversarial are used; victims, signers and exchange deposit addresses are never labelled. | EVM and Solana | Daily | Public, CC0 |
| GoPlus Labs address security | Address flags including sanctions, mixers, phishing, drainers, honeypots and fake tokens, aggregating SlowMist and GoPlus data | Ethereum, Base | On demand per audited wallet | Public API |
| Chainalysis sanctions screening | Sanctioned-entity identification | All | On demand, when enabled for the deployment | Licensed API |
Daily sources are merged at a fixed time each day. An address a source no longer lists is removed for that source on the next run, with a safeguard that skips the removal pass when a download looks truncated.
Entity labels
These name an address as a business or service. They are shown for context and never raise risk.
| Source | What it provides | Chains |
|---|---|---|
| Blockscout address metadata | Public tags for exchanges, bridges, routers, custodians and similar | Ethereum, Base |
| Helius wallet identity | Named wallets and categories | Solana |
| Solscan labels | Account labels and tags, used as a fallback when enabled | Solana |
| Curated lists | Hand-maintained exchange hot wallets and infrastructure addresses, including the tradezon cex-list on GitHub for EVM | All |
Chain data
| Provider | Used for | Chains |
|---|---|---|
| Helius | Transaction history, enhanced transaction parsing, digital asset data, real-time webhooks | Solana |
| Alchemy | Transfer history, portfolio balances, real-time address activity, historical prices | Ethereum, Base |
| Blockscout | Token holder lists, contract detection, created-contract history | Ethereum, Base |
| Public RPC endpoints | Balances and contract reads with fallbacks | All |
Prices and liquidity
| Provider | Used for | Chains |
|---|---|---|
| Alchemy Prices | Current and historical token prices | All |
| Jupiter | Token prices | Solana |
| DexScreener | Pool liquidity, prices, launch pair detection | All |
| GeckoTerminal | Price fallback | All |
| CoinGecko | Price fallback | All |
Liquidity figures decide what counts as realizable value and whether a position is flagged illiquid. A price is only accepted from a pool with meaningful depth, so a token's toy pool cannot inflate a wallet's valuation.
Token checks
| Provider | Used for | Chains |
|---|---|---|
| GoPlus token security | Token contract flags such as mintability, ownership, trading restrictions and honeypot risk | Ethereum, Base |
| RugCheck | Token risk signals | Solana |
| On-chain reads | Mint and freeze authorities, proxy and owner slots, supply, bytecode function scans | All |
Optional user-connected data
Allium can be connected by a user to import wallet lists from saved queries and to supply historical holder data for reconciliation. It is never queried without the user's own key.
Disputes and corrections
A label is evidence with a source and a date, not a verdict. If you believe an address is labelled in error, check the source shown on the label first, since most corrections belong with the upstream list. To raise a concern about how Wallet Sleuth applies a label, contact admin@wisteriatechnologies.com.