<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Building ChainAnalyzer]]></title><description><![CDATA[Behind-the-scenes log of building ChainAnalyzer: a multi-chain blockchain AML platform with MCP, x402 micropayments, and ML anomaly detection.]]></description><link>https://blog.chain-analyzer.com</link><image><url>https://cdn.hashnode.com/uploads/logos/69e516de13e74eec5835238e/6256f9fd-f8c1-4cc7-9d8a-a7bd713dbc5c.png</url><title>Building ChainAnalyzer</title><link>https://blog.chain-analyzer.com</link></image><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 18:37:47 GMT</lastBuildDate><atom:link href="https://blog.chain-analyzer.com/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[$5.3M Address Poisoning Network: Two Months Later]]></title><description><![CDATA[TL;DR

854 new operator wallets funded by the same Master Funder in the past 60 days

$16.8M USDT processed by the Ethereum collector from 1,450 unique senders

$1.2M USDC processed by the Polygon col]]></description><link>https://blog.chain-analyzer.com/address-poisoning-network-2-months-later</link><guid isPermaLink="true">https://blog.chain-analyzer.com/address-poisoning-network-2-months-later</guid><category><![CDATA[Web3]]></category><category><![CDATA[Security]]></category><category><![CDATA[aml]]></category><category><![CDATA[fraud detection]]></category><category><![CDATA[anti-fraud]]></category><category><![CDATA[defi]]></category><category><![CDATA[Ethereum]]></category><category><![CDATA[Polygon]]></category><category><![CDATA[Avalanche]]></category><dc:creator><![CDATA[Kenzo ARAI]]></dc:creator><pubDate>Sat, 25 Apr 2026 19:42:55 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69e516de13e74eec5835238e/a2da0300-c6c0-43cf-9357-65a499353183.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>TL;DR</h2>
<ul>
<li><p><strong>854 new operator wallets</strong> funded by the same Master Funder in the past 60 days</p>
</li>
<li><p><strong>$16.8M USDT</strong> processed by the Ethereum collector from 1,450 unique senders</p>
</li>
<li><p><strong>$1.2M USDC</strong> processed by the Polygon collector from 1,100 unique senders</p>
</li>
<li><p>Two addresses we previously labeled as "whale co-conspirators" are almost certainly <strong>exchange / OTC hot wallets</strong> — laundering starts at a CEX compliance gap, not a conspiracy</p>
</li>
<li><p>Wallet rotation theory <strong>confirmed</strong>: operator addresses turn over on a 2-3 month cycle, making static blacklists obsolete by design</p>
</li>
</ul>
<p>The investigation publicity did not deter the network. It accelerated.</p>
<hr />
<h2>Recap — What We Found in February</h2>
<p>In our <a href="https://chain-analyzer.com/news/address-poisoning-network">February 2026 investigation</a>, we traced:</p>
<ul>
<li><p><strong>264+ operator wallets</strong> distributing 50+ Unicode-impersonation fake token contracts (Cyrillic <code>UЅDT</code>, Lisu <code>ꓴꓢꓓt</code>, zero-width invisibles)</p>
</li>
<li><p><strong>6,892+ poisoned addresses</strong> across three chains</p>
</li>
<li><p><strong>$5.3M total capital moved</strong>, including <strong>176M yen of JPYC</strong></p>
</li>
<li><p>A <strong>single Master Funder</strong> at <code>0x54cdcbdb…</code> — 16,226 AVAX balance, 1,585 lifetime recipients, ~53% confirmed operators</p>
</li>
<li><p>Two laundering collectors on Ethereum (\(2.67M USDT) and Polygon (\)788K USDC)</p>
</li>
<li><p>A proven relay pattern: <strong>victim → look-alike → relay → collector, 34 minutes end-to-end</strong></p>
</li>
</ul>
<p>The question we left open: <em>does this network dismantle itself after exposure, or does it keep running?</em></p>
<p>We came back two months later. Here's what we found.</p>
<hr />
<h2>Methodology</h2>
<p>On 2026-04-20, we re-pulled on-chain state for every address flagged in the February report — using <strong>Routescan</strong> (Avalanche, keyless), <strong>Etherscan V2</strong> (Ethereum and Polygon, free API key),<br />and <strong>ChainAnalyzer's Neo4j graph</strong> for cross-chain correlation.</p>
<p>Every number in this post is <strong>reproducible against public on-chain data</strong> as of 2026-04-20 06:45 UTC.</p>
<hr />
<h2>Headline Deltas</h2>
<table>
<thead>
<tr>
<th>Address</th>
<th>Role</th>
<th>Feb 17, 2026</th>
<th>Apr 20, 2026</th>
<th>Delta</th>
</tr>
</thead>
<tbody><tr>
<td><code>0x54cdcbdb…</code></td>
<td>Master Funder</td>
<td>16,226 AVAX</td>
<td><strong>12,254 AVAX</strong></td>
<td><strong>−3,972 AVAX</strong> disbursed</td>
</tr>
<tr>
<td><code>0x54cdcbdb…</code></td>
<td>Recipients</td>
<td>1,585 (cumulative)</td>
<td><strong>2,439+</strong></td>
<td><strong>+854</strong> new destinations</td>
</tr>
<tr>
<td><code>0xbca34ed5…</code></td>
<td>ETH Collector</td>
<td>$2.67M USDT</td>
<td><strong>$5.97M USDT</strong></td>
<td><strong>+$3.30M (+124%)</strong></td>
</tr>
<tr>
<td><code>0xa6380bfd…</code></td>
<td>POL Collector</td>
<td>249K POL + $788K USDC</td>
<td>511K POL + $348K USDC</td>
<td>+262K POL, −$440K (laundered)</td>
</tr>
<tr>
<td><code>0xa081aa46…</code></td>
<td>POL mass-poison funder</td>
<td>$12.55</td>
<td><strong>23,435 POL (~$24K)</strong></td>
<td><strong>+1,870×</strong></td>
</tr>
<tr>
<td><code>0x3bce63c6…</code></td>
<td>"142K AVAX whale"</td>
<td>141,904 AVAX</td>
<td>168,901 AVAX</td>
<td>+27K AVAX</td>
</tr>
<tr>
<td><code>0x9f8c163c…</code></td>
<td>"Top source"</td>
<td>(5,077 AVAX traced)</td>
<td><strong>1,688,967 AVAX (~$42M)</strong></td>
<td>full profile now visible</td>
</tr>
<tr>
<td><code>0xb2de52d8…</code></td>
<td>Primary operator</td>
<td>Active until 2026-02-15</td>
<td><strong>Dead</strong> since 2026-02-15</td>
<td>✅ rotated out</td>
</tr>
<tr>
<td><code>0x03309000…</code></td>
<td>Active operator</td>
<td>Active 2026-02-17</td>
<td><strong>Depleted on 3 chains</strong>, last TX 2026-04-15</td>
<td>✅ rotated out</td>
</tr>
<tr>
<td><code>0x4226dd74…</code></td>
<td>Main deployer (39 contracts)</td>
<td>1.46 AVAX, active</td>
<td><strong>Still active</strong> (2026-04-20 06:39)</td>
<td>Zero new deployments</td>
</tr>
<tr>
<td><code>0x64424853…</code></td>
<td>Lisu deployer</td>
<td>Active</td>
<td><strong>Dormant</strong> since 2025-12-23</td>
<td>Retired</td>
</tr>
</tbody></table>
<p>Three things happened in parallel: aggressive new operator recruitment, continued laundering of victim funds into collectors, and systematic retirement of old operator wallets exactly as<br />wallet-rotation theory predicted.</p>
<hr />
<h2>1. The Master Funder Keeps Recruiting</h2>
<p>We pulled the most recent 10,000 transactions from <code>0x54cdcbdb…</code>. After filtering to outflows since 2026-02-17:</p>
<ul>
<li><p><strong>1,119 outbound AVAX transfers</strong></p>
</li>
<li><p><strong>49,441 AVAX sent total</strong> (~\(1.24M at \)25/AVAX)</p>
</li>
<li><p><strong>854 unique destination addresses</strong> — none of which received funds before 2026-02-17</p>
</li>
</ul>
<p>To put that in scale: the February investigation covered <strong>1,585 lifetime recipients</strong>. In the two months since, the Master Funder added another <strong>854 recipients</strong> — <em>an expansion of 54% of<br />the prior lifetime count, in 60 days.</em></p>
<h3>Top 10 New Destinations (Since Feb 17)</h3>
<table>
<thead>
<tr>
<th>Destination</th>
<th>AVAX received</th>
<th>First TX</th>
<th>Last TX</th>
<th>TX count</th>
</tr>
</thead>
<tbody><tr>
<td><code>0x33a089cb…</code></td>
<td><strong>9,722</strong></td>
<td>2026-03-02</td>
<td>2026-03-02</td>
<td>1</td>
</tr>
<tr>
<td><code>0xf57a1140…</code></td>
<td><strong>9,297</strong></td>
<td>2026-03-13</td>
<td>2026-03-13</td>
<td>1</td>
</tr>
<tr>
<td><code>0x6f7e6fdf…</code></td>
<td><strong>7,622</strong></td>
<td>2026-04-02</td>
<td>2026-04-02</td>
<td>1</td>
</tr>
<tr>
<td><code>0xd7b9b792…</code></td>
<td>3,677</td>
<td>2026-03-10</td>
<td><strong>2026-04-19</strong></td>
<td>38</td>
</tr>
<tr>
<td><code>0x0808469a…</code></td>
<td>1,794</td>
<td>2026-02-20</td>
<td>2026-03-10</td>
<td>13</td>
</tr>
<tr>
<td><code>0xeae12a48…</code></td>
<td>1,389</td>
<td>2026-04-10</td>
<td>2026-04-10</td>
<td>2</td>
</tr>
<tr>
<td><code>0xe36d6080…</code></td>
<td>1,061</td>
<td>2026-03-04</td>
<td>2026-04-02</td>
<td>3</td>
</tr>
<tr>
<td><code>0x6632f500…</code></td>
<td>1,032</td>
<td>2026-02-24</td>
<td>2026-03-06</td>
<td>3</td>
</tr>
<tr>
<td><code>0x89b8678f…</code></td>
<td>856</td>
<td>2026-04-03</td>
<td>2026-04-18</td>
<td>10</td>
</tr>
<tr>
<td><code>0x951aa58d…</code></td>
<td>844</td>
<td>2026-02-17</td>
<td><strong>2026-04-17</strong></td>
<td>7</td>
</tr>
</tbody></table>
<p>The single-TX recipients receiving 7,000–10,000 AVAX in one shot look like fresh operator-funding events. The multi-TX recipients (38 transactions over a month) are mid-tier active operators.</p>
<p>The investigation exposing this network didn't slow it down. <strong>If anything, Master Funder activity accelerated.</strong></p>
<hr />
<h2>2. The "Top Source" Was Not a Co-Conspirator</h2>
<p>In February we noted a funder at <code>0x9f8c163c…</code> that had sent 5,077 AVAX to the Master Funder but which we hadn't fully traced. Two months of additional data make clear: <strong>this address is<br />almost certainly an exchange or OTC hot wallet</strong>, not part of the criminal network.</p>
<p>Evidence:</p>
<ul>
<li><p>Current balance: <strong>1,688,967 AVAX (~$42M)</strong></p>
</li>
<li><p>First traceable activity: <strong>2021-09-06</strong> — pre-dates the entire poisoning operation by 4+ years</p>
</li>
<li><p>2.7M AVAX inflow + 2.4M AVAX outflow in the last ~10,000 transactions alone</p>
</li>
<li><p>Behavior pattern today: hundreds of zero-value <code>transfer</code> calls per day, occasional <code>execute</code> calls on a router, small payments to fresh addresses — <strong>classic CEX hot-wallet idle /<br />withdrawal fingerprint</strong></p>
</li>
<li><p>Active on Ethereum and Polygon too — cross-chain hot wallet footprint</p>
</li>
</ul>
<p>The 5,077 AVAX it once sent to the Master Funder was, in all likelihood, a <strong>regular withdrawal from a centralized exchange</strong>. The operator walked up to a CEX counter, withdrew AVAX, and walked away.</p>
<p>That's not a conspiracy. <strong>That's a compliance gap at the exchange.</strong></p>
<p>Similarly, <code>0x3bce63c6…</code> ("142K AVAX whale") — balance 168,901 AVAX, active today (last TX 2026-04-20 06:40 UTC), same hot-wallet fingerprint. Its 40 AVAX contribution to the primary operator in February was likely another exchange withdrawal.</p>
<blockquote>
<p><strong>Conclusion:</strong> there is no whale co-conspirator. The laundering-side money originates at one or two major exchanges that have poor outbound AML controls. This is actionable — and probably<br /><strong>SAR-worthy</strong> if you're an agency.</p>
</blockquote>
<hr />
<h2>3. The Collectors Are Busier Than Ever</h2>
<h3>Ethereum Collector <code>0xbca34ed5…</code></h3>
<table>
<thead>
<tr>
<th>Metric</th>
<th>Feb 17</th>
<th>Apr 20</th>
</tr>
</thead>
<tbody><tr>
<td>USDT balance</td>
<td>$2,665,507</td>
<td><strong>$5,970,800 (+124%)</strong></td>
</tr>
<tr>
<td>USDT received since Feb 17</td>
<td>—</td>
<td><strong>$16,865,450</strong> from 1,450 unique senders (2,574 TXs)</td>
</tr>
<tr>
<td>USDT sent out since Feb 17</td>
<td>—</td>
<td>$15,134,814 (5,693 TXs)</td>
</tr>
<tr>
<td>Last activity</td>
<td>—</td>
<td>2026-04-20 06:38 UTC</td>
</tr>
</tbody></table>
<p>In two months, this address handled <strong>\(16.9M USDT inflow from 1,450 senders</strong> and \)15.1M outflow. Net +$1.73M. At this velocity, the collector processes more USDT in <strong>one week</strong> than its entire Feb 17 balance.</p>
<h3>Polygon Collector <code>0xa6380bfd…</code></h3>
<table>
<thead>
<tr>
<th>Metric</th>
<th>Feb 17</th>
<th>Apr 20</th>
</tr>
</thead>
<tbody><tr>
<td>USDC balance</td>
<td>$788,521</td>
<td>$348,256 (−56%)</td>
</tr>
<tr>
<td>POL balance</td>
<td>249,588</td>
<td><strong>511,722 (+106%)</strong></td>
</tr>
<tr>
<td>USDC received since Feb 17</td>
<td>—</td>
<td><strong>$1,201,642</strong> from 1,100 unique senders (2,111 TXs)</td>
</tr>
<tr>
<td>USDC sent out since Feb 17</td>
<td>—</td>
<td>$1,633,777 (3,399 TXs)</td>
</tr>
<tr>
<td>Last activity</td>
<td>—</td>
<td>2026-04-20 06:40 UTC</td>
</tr>
</tbody></table>
<p>The USDC balance dropped because <strong>they're laundering it downstream</strong>, not because victim flow stopped. <strong>1,100 unique senders in two months</strong> is up from 715 total in February. The relay pattern (victim → relay → collector within ~34 minutes) is still producing the majority of those inflows.</p>
<hr />
<h2>4. Wallet Rotation Was Real</h2>
<p>In February we theorized that operator wallets are disposable. The data now confirms it:</p>
<ul>
<li><p><strong>Primary operator</strong> <code>0xb2de52d8…</code> — last activity 2026-02-14, <strong>3 days before we published</strong>. Dead ever since.</p>
</li>
<li><p><strong>Active operator</strong> <code>0x03309000…</code> — was active on all three chains in February. Today: AVAX depleted (last TX 2026-04-15), ETH depleted (last TX 2026-03-04), POL near-zero (last TX<br />2026-02-25)</p>
</li>
<li><p><strong>Top operator</strong> <code>0x0808469a…</code> — received another 1,794 AVAX late Feb to early March, then quiet. 80 AVAX remains</p>
</li>
<li><p><strong>Lisu deployer</strong> <code>0x64424853…</code> — dormant since 2025-12-23</p>
</li>
</ul>
<p>The 854 fresh destinations the Master Funder has been seeding since Feb 17 are <strong>exactly the replacements</strong>. The operator population turns over on a roughly 2-3 month cycle.</p>
<blockquote>
<p><strong>Implication for AML teams:</strong> address blacklists decay. A list of operator addresses from February is 30–50% stale by April. Detection has to operate at the <strong>fund-flow and behavioral<br />level</strong>, not the static-address level — which is exactly the design of ChainAnalyzer's <a href="https://chain-analyzer.com/news/follow-mode">Follow Mode</a> and graph-clustering detectors.</p>
</blockquote>
<hr />
<h2>5. The Mass-Poisoning Funder Paid Off</h2>
<p>Perhaps the single most striking data point: the Polygon mass-poisoning funder at <code>0xa081aa46…</code> spent just <strong>$12.55</strong> to poison 6,874 addresses in January.</p>
<p>Today, that address holds <strong>23,435 POL (~$24K)</strong>. Active, last TX 2026-04-20 00:14 UTC.</p>
<p>From <strong>\(12.55 to \)24,000+</strong> — <em>a 1,870× return on capital in 3 months</em>, before even counting any funds it has already moved downstream.</p>
<p>That's the entire economic argument for why this attack class is not going away without active defense.</p>
<hr />
<h2>6. The Deployer Hasn't Shipped New Contracts — It Doesn't Need To</h2>
<p><code>0x4226dd7419b1431f512d82a2c9e5fa1597fb1077</code> was the main fake-token deployer responsible for <strong>39 Unicode-impersonation contracts</strong>. We checked whether it has deployed new contracts since Feb 17.</p>
<p><strong>Zero new deployments. 200 other transactions.</strong></p>
<p>The existing 39 contracts are still being used to mint and transfer fake tokens. The deployer is operational but not creating — meaning typical "contract creation detection" signals <strong>miss<br />this operator entirely</strong> during the period it's most active.</p>
<hr />
<h2>What This Changes</h2>
<h3>For victims and potential victims</h3>
<p>The network exposing itself to public investigation did not cause it to shut down. Every protective behavior we recommended in February still applies, with <strong>more urgency</strong>:</p>
<ul>
<li><p>Never copy addresses from TX history</p>
</li>
<li><p>Compare character-by-character</p>
</li>
<li><p>Treat unsolicited tokens as a targeting signal</p>
</li>
<li><p>Screen destinations before sending</p>
</li>
</ul>
<p>ChainAnalyzer does this free at <a href="https://chain-analyzer.com">chain-analyzer.com</a>. The <a href="https://chain-analyzer.com/news/mcp-server-launched">MCP server</a> lets AI agents do it automatically before signing.</p>
<h3>For exchanges</h3>
<p>Two addresses — <code>0x9f8c163c…</code> and <code>0x3bce63c6…</code> — have together funded wallets seeding thousands of poisoning operators. Our review strongly suggests these are <strong>exchange or OTC hot wallets</strong>. If they are yours, your withdrawal-side AML controls have a blind spot specific to address-poisoning actors. We would welcome a <a href="https://chain-analyzer.com/contact_us">conversation</a>.</p>
<h3>For AML teams and regulators</h3>
<p>Address-based blacklists decay within 2–3 months for this attack class because of deliberate wallet rotation. Effective detection has to operate at the <strong>fund-flow and graph level</strong>.</p>
<p>ChainAnalyzer's detector suite is explicitly designed around this:</p>
<ul>
<li><p><strong>P2 ADDRESS_POISONING</strong> for Unicode impersonation signatures</p>
</li>
<li><p><strong>W9 / W10 bridge detectors</strong> for cross-chain laundering</p>
</li>
<li><p><strong>Follow Mode</strong> for automatic BFS graph exploration</p>
</li>
<li><p><strong>Exchange DB</strong> with 60+ known CEX hot wallets</p>
</li>
</ul>
<h3>For Japan-market crypto operators</h3>
<p>The <strong>176M yen of JPYC</strong> observed in this network in February — and the continued operator expansion since — continues to indicate that <strong>Japanese retail users are specifically in the<br />crosshairs</strong>.</p>
<p><a href="https://chain-analyzer.com/news/jpyc-aml-support">ChainAnalyzer's JPYC AML coverage</a> was built for exactly this. If your product uses JPYC for B2B settlement, creator payouts, or EC payment<br />acceptance, <strong>pre-transfer screening is no longer optional</strong>.</p>
<hr />
<h2>Takeaways</h2>
<ul>
<li><p>The $5.3M network is now <strong>materially larger</strong> than when we published the February report. The investigation publicity did not deter it; <strong>it accelerated</strong></p>
</li>
<li><p>854 new operator wallets funded by the single Master Funder in 60 days. Operator population rotates on a 2-3 month cycle</p>
</li>
<li><p>The Ethereum collector processed \(16.8M USDT from 1,450 senders; the Polygon collector processed \)1.2M USDC from 1,100 senders. <strong>Real victims, real money, active every day</strong></p>
</li>
<li><p>Two "whale co-conspirators" are almost certainly exchange / OTC hot wallets. <strong>The laundering stack starts at a compliance gap inside those exchanges</strong></p>
</li>
<li><p>The fake-token deployer has not shipped new contracts in two months. The existing 39 contracts suffice. <strong>Contract-creation-based detection misses this</strong></p>
</li>
<li><p>For retail Web3, the defense is pre-transfer address screening. For AI agents, the defense is automatic screening via the ChainAnalyzer MCP server at <strong>$0.008 per check</strong></p>
</li>
</ul>
<p>We'll follow up again in 2-3 months. In the meantime, every new operator the Master Funder seeds between now and then will be tagged and propagated to <strong>ScamDB</strong> and the ChainAnalyzer detector suite automatically via Follow Mode.</p>
<hr />
<h2>Try It Yourself</h2>
<p>Any of the addresses above can be scanned free at <a href="https://chain-analyzer.com">chain-analyzer.com</a>. Or programmatically:</p>
<ul>
<li><p><strong>REST API</strong> → <a href="https://chain-analyzer.com/docs/api">/docs/api</a></p>
</li>
<li><p><strong>x402 pay-per-request</strong> → <a href="https://chain-analyzer.com/docs/x402">/docs/x402</a> (\(0.008–\)0.05 per call, no signup)</p>
</li>
<li><p><strong>MCP server</strong> → <code>npx chainanalyzer-mcp</code> (<a href="https://chain-analyzer.com/news/mcp-server-launched">Claude Desktop / Claude Code / ChatGPT / Gemini compatible</a>)</p>
</li>
</ul>
<p>If you find new operator wallets the Master Funder has seeded, <a href="https://chain-analyzer.com/scamdb">report them to ScamDB</a>.</p>
<hr />
<p><em>Originally published at</em> <a href="https://chain-analyzer.com/news/address-poisoning-network-followup"><em>chain-analyzer.com/news/address-poisoning-network-followup</em></a><em>.</em><br /><em>Prior investigation:</em> <a href="https://chain-analyzer.com/news/address-poisoning-network"><em>The $5.3M Address Poisoning Network</em></a> <em>(February 2026).</em><br /><em>ENS:</em> <a href="https://app.ens.domains/chainanalyzer.eth"><em>chainanalyzer.eth</em></a> <em>·</em> <a href="https://blog.chain-analyzer.com"><em>Engineering blog</em></a></p>
]]></content:encoded></item><item><title><![CDATA[Drained for $7.95: How a Solana Phishing Scam Built a Multi-Chain AML Platform]]></title><description><![CDATA[The Drain
Date: 2026-02-09, 14:28 UTCLoss: 0.093668917 SOL (~$7.95)Vector: A "First-Come-First-Served" airdrop link, posted in the Orynth Discord, by an account wearing the ORY admin badge.
That last ]]></description><link>https://blog.chain-analyzer.com/drained-for-795-origin-story</link><guid isPermaLink="true">https://blog.chain-analyzer.com/drained-for-795-origin-story</guid><category><![CDATA[Web3]]></category><category><![CDATA[Security]]></category><category><![CDATA[aml]]></category><category><![CDATA[defi]]></category><category><![CDATA[Solana]]></category><dc:creator><![CDATA[Kenzo ARAI]]></dc:creator><pubDate>Sat, 25 Apr 2026 19:36:18 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69e516de13e74eec5835238e/5ef0a8c0-c313-4580-8192-efa48a223114.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>The Drain</h2>
<p><strong>Date:</strong> 2026-02-09, 14:28 UTC<br /><strong>Loss:</strong> 0.093668917 SOL (~$7.95)<br /><strong>Vector:</strong> A "First-Come-First-Served" airdrop link, posted in the Orynth Discord, by an account wearing the <strong>ORY admin badge</strong>.</p>
<p>That last detail is the whole story.</p>
<p>I'd been in that Discord for months. Active member. Followed the project. So when the post landed in <code>#FCFS</code> — admin badge, friendly tone, link to <code>solland.cc</code> redirecting to <code>hibit.app</code> — I did what any conditioned crypto user does: connect wallet, sign, claim.</p>
<p>The "claim" was a <code>System Program Transfer</code> disguised as an airdrop call. My SOL went straight to:</p>
<pre><code class="language-plaintext">7kMpieh2THdaC5eUvxFJDL3TdsQWVQCwdhsEjLj1eL26                                                                                                                                                    
</code></pre>
<p><a href="https://solscan.io/tx/3jnHUZ5TucK5uVFNKJJzaPSf1LfEJhPG9sWomw6he3dj9s46F7ZAj1EAFwRpe4YFSp1yrwujoZA8MdRb4tcDQaJE">Solscan TX →</a></p>
<p>The amount didn't matter. What mattered was the realization sitting in my chest as I watched the TX confirm:</p>
<p><strong>I fell for it because the badge was real.</strong></p>
<p>If the compromise vector I just experienced — <em>authority-based trust</em> — could catch someone who'd been in this space for years, then it could catch literally anyone.</p>
<hr />
<h2>48 Hours Later</h2>
<p>I didn't post a warning thread on Twitter and move on. I traced the wallet.</p>
<p>What I found was not an opportunist.</p>
<ul>
<li><p><strong>Funded via</strong> <a href="https://fixedfloat.com"><strong>FixedFloat</strong></a> (KYC-free instant exchange)</p>
</li>
<li><p><strong>Laundered via Jupiter</strong> (SOL → USDT swap)</p>
</li>
<li><p><strong>Withdrawn back through FixedFloat</strong> to break the chain</p>
</li>
<li><p><strong>$3,700+ stolen across the previous two weeks</strong> — 3,640 USDT + 0.67 SOL</p>
</li>
<li><p><strong>Dozens of victims</strong> matching exactly the same TX shape as mine</p>
</li>
</ul>
<p>This was a pipeline. Industrialized. Repeatable. And nobody in retail crypto had a tool that would have flagged any of it before signing.</p>
<p>That's the moment the real problem clicked into focus:</p>
<blockquote>
<p>The problem wasn't "I made a mistake." The problem was that <strong>no tool existed that would have caught this before I signed.</strong></p>
</blockquote>
<hr />
<h2>ScamDB Entry #1</h2>
<p>Before I wrote a single line of UI code, I created a JSON file: <code>scamdb.json</code>.</p>
<p>The first entry was <code>7kMpieh2TH…j1eL26</code>, with:</p>
<ul>
<li><p>the two phishing domains</p>
</li>
<li><p>the laundering path</p>
</li>
<li><p>the asset profile</p>
</li>
<li><p>the entry vector (compromised admin)</p>
</li>
</ul>
<p>That entry still lives in the production <a href="https://chain-analyzer.com/scamdb">ScamDB</a> today — alongside 100+ curated entries, OFAC SDN, Chainabuse, CryptoScamDB, GoPlus, and community reports. Every scan ChainAnalyzer runs checks against this set first.</p>
<p>The \(7.95 was the most valuable \)7.95 I've ever spent.</p>
<hr />
<h2>TokenForge → ChainAnalyzer</h2>
<p>The first ship — <strong>TokenForge</strong>, February 2026 — was Solana-only. 14 detection rules. One-click scan of any mint or wallet. No login. Free.</p>
<p>Two weeks in, a friend asked me to scan an Avalanche address. I didn't have EVM support yet. He showed me what he was seeing: fake Cyrillic <code>UЅDT</code> tokens being spammed at legitimate wallets,<br />looking pixel-identical to real USDT in every wallet UI.</p>
<p>I added Avalanche. Then Ethereum. Then Polygon. Bitcoin later. Then I pointed the scanner at his Avalanche address.</p>
<p>It flagged <strong>CRITICAL</strong> with 20 detections. I turned on <strong>Follow Mode</strong> — a graph BFS feature I'd just shipped — and let it crawl the transaction graph.</p>
<p>Fourteen wallets became fifty. Fifty became two hundred and sixty-four.</p>
<p><strong>Together they moved $5.3M across three chains.</strong> Every one of them funded by a single upstream wallet I started calling <strong>Master Funder</strong>.</p>
<p>That was the moment I realized what I was building wasn't a "consumer scam scanner." It was an <strong>AML-grade investigation platform for the retail Web3 era</strong>.</p>
<blockquote>
<p><a href="https://chain-analyzer.com/news/address-poisoning-network-followup">Two months later, the network is still growing → 854 new operator wallets, $16.8M USDT collected.</a></p>
</blockquote>
<hr />
<h2>What Changed</h2>
<table>
<thead>
<tr>
<th></th>
<th>TokenForge (2026-02)</th>
<th>ChainAnalyzer (2026-04)</th>
</tr>
</thead>
<tbody><tr>
<td>Chains</td>
<td>Solana only</td>
<td>BTC, ETH, POL, AVAX, SOL</td>
</tr>
<tr>
<td>Detection rules</td>
<td>14</td>
<td>76+</td>
</tr>
<tr>
<td>OSINT</td>
<td>ScamDB</td>
<td>ScamDB + OFAC + Chainabuse + GoPlus + Reddit</td>
</tr>
<tr>
<td>ML</td>
<td>—</td>
<td>3-model ensemble (Isolation Forest + AutoEncoder + GraphSAGE)</td>
</tr>
<tr>
<td>Audience</td>
<td>Retail Solana traders</td>
<td>Exchanges, compliance, law enforcement</td>
</tr>
<tr>
<td>Interfaces</td>
<td>Web UI</td>
<td>Web UI + REST API + MCP + x402 + PDF reports</td>
</tr>
</tbody></table>
<p>What didn't change: <strong>every feature is still exercised against the kind of attack that cost me $7.95.</strong></p>
<hr />
<h2>Five Lessons I Wish Someone Had Told Me</h2>
<ol>
<li><p><strong>Admin badges mean nothing.</strong> Treat any post in your favorite project's server the same way you'd treat a cold DM.</p>
</li>
<li><p><strong>"Connect wallet" is not a safe operation.</strong> Read what you're signing. If you can't read it, don't sign.</p>
</li>
<li><p><strong>Address-first verification.</strong> Before sending anything, scan the destination. Three seconds.</p>
</li>
<li><p><strong>FCFS airdrops are always scams.</strong> Real projects don't panic people into signing instantly.</p>
</li>
<li><p><strong>Post-mortem immediately.</strong> When you lose money, trace it on-chain before you spiral. The understanding is more valuable than the money you lost.</p>
</li>
</ol>
<hr />
<h2>Where We Are Today</h2>
<p>ChainAnalyzer now:</p>
<ul>
<li><p>Scans across <strong>five chains</strong>: BTC, ETH, POL, AVAX, SOL</p>
</li>
<li><p>Runs on Azure Japan East, FISC-aligned hosting</p>
</li>
<li><p>Ships an <a href="https://chain-analyzer.com/news/mcp-server-launched">MCP server</a> on <a href="https://www.npmjs.com/package/chainanalyzer-mcp">npm</a> and the <a href="https://registry.modelcontextprotocol.io">official MCP<br />Registry</a>, callable from Claude Desktop, Claude Code, ChatGPT, Gemini, Cursor</p>
</li>
<li><p>Supports pay-per-request via <a href="https://chain-analyzer.com/docs/x402">x402 USDC on Base or Solana mainnet</a> — \(0.003 to \)0.05 per call, no API key</p>
</li>
<li><p>Ships a <a href="https://chain-analyzer.com/news/jpyc-aml-support">JPYC-specific compliance suite</a> for Japanese stablecoin operators</p>
</li>
<li><p>Was accepted into the Japan FSA FinTech Proof-of-Concept Hub (2026-03)</p>
</li>
<li><p>Earned a <strong>AAA score</strong> on <a href="https://glama.ai/mcp/servers/rascal-3/chainanalyzer-mcp">Glama MCP Directory</a> and is listed on<br /><a href="https://github.com/punkpeye/awesome-mcp-servers">awesome-mcp-servers</a></p>
</li>
</ul>
<p>All from a $7.95 drain two months ago.</p>
<hr />
<h2>What's Next</h2>
<p>Two things pull me forward.</p>
<p><strong>1. The \(5.3M network is still growing.</strong><br />Since our February report, the Master Funder has disbursed another 49,441 AVAX (~\)1.24M) to 854 new destination addresses. The ETH collector has received $16.8M USDT from 1,450 senders in two months. These aren't numbers — they're 1,450 real people whose TX history got polluted hoping they'd copy-paste the wrong address. (<a href="https://chain-analyzer.com/news/address-poisoning-network-followup">Read the follow-up →</a>)</p>
<p><strong>2. AI agents are about to do this at scale.</strong><br />With MCP + x402, any autonomous agent can screen any address before signing — <em>autonomously</em>, in a single tool call. The exact attack vector I fell for — copy-paste from history,<br />trust-by-badge, panic-driven UX — becomes structurally impossible if the agent runs <code>check_address_risk</code> first.</p>
<p>ChainAnalyzer is one of the first AML platforms wired into both protocols.</p>
<hr />
<h2>Try It</h2>
<ul>
<li><p>Scan an address for free → <a href="https://chain-analyzer.com">chain-analyzer.com</a></p>
</li>
<li><p>Public ScamDB (no API key) → <a href="https://chain-analyzer.com/scamdb">/scamdb</a></p>
</li>
<li><p>MCP server → <code>npx chainanalyzer-mcp</code></p>
</li>
<li><p>REST API → <a href="https://chain-analyzer.com/docs/api">/docs/api</a></p>
</li>
<li><p>x402 endpoints → <a href="https://chain-analyzer.com/docs/x402">/docs/x402</a></p>
</li>
</ul>
<p>If you've been drained, <a href="https://chain-analyzer.com/contact_us">reach out</a>. Send me the TX. I'll add the drainer to ScamDB. The next person who tries to send to that address will get a <strong>CRITICAL</strong> flag.</p>
<p>That's the whole point.</p>
<blockquote>
<p><em>One person's \(7.95 lesson becomes another person's saved \)50,000.</em></p>
</blockquote>
<hr />
<p><em>Originally published at</em> <a href="https://chain-analyzer.com/news/origin-drainer-story"><em>chain-analyzer.com/news/origin-drainer-story</em></a><em>.</em><br /><em>ENS:</em> <a href="https://app.ens.domains/chainanalyzer.eth"><em>chainanalyzer.eth</em></a> <em>·</em> <a href="https://blog.chain-analyzer.com"><em>Engineering blog</em></a></p>
]]></content:encoded></item><item><title><![CDATA[Shipping x402 USDC Payments to Base + Solana Mainnet for an MCP Server]]></title><description><![CDATA[Last week, ChainAnalyzer (a multi-chain blockchain AML platform) crossedthree milestones in five days:

✅ Merged into awesome-mcp-servers

✅ Earned a AAA score on Glama MCP Directory

✅ Switched x402 ]]></description><link>https://blog.chain-analyzer.com/x402-usdc-mcp-server-mainnet</link><guid isPermaLink="true">https://blog.chain-analyzer.com/x402-usdc-mcp-server-mainnet</guid><category><![CDATA[mcp]]></category><category><![CDATA[Web3]]></category><category><![CDATA[ai agents]]></category><category><![CDATA[Blockchain]]></category><category><![CDATA[x402]]></category><dc:creator><![CDATA[Kenzo ARAI]]></dc:creator><pubDate>Sat, 25 Apr 2026 12:12:44 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69e516de13e74eec5835238e/bd69f637-6bd7-4f78-b4e3-ddbb549b4f69.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Last week, ChainAnalyzer (a multi-chain blockchain AML platform) crossed<br />three milestones in five days:</p>
<ul>
<li><p>✅ Merged into <a href="https://github.com/punkpeye/awesome-mcp-servers">awesome-mcp-servers</a></p>
</li>
<li><p>✅ Earned a <strong>AAA score</strong> on <a href="https://glama.ai/mcp/servers/rascal-3/chainanalyzer-mcp">Glama MCP Directory</a></p>
</li>
<li><p>✅ Switched x402 from testnet to <strong>Base + Solana mainnet</strong> via the<br />Coinbase CDP Facilitator</p>
</li>
</ul>
<p>This post is a brain-dump of how each piece fits together for anyone building an MCP server with native crypto micropayments.</p>
<hr />
<h2>What is x402?</h2>
<p>x402 is an HTTP 402 micropayment protocol from Coinbase. The flow:</p>
<ol>
<li><p>Client calls a paid endpoint without payment headers</p>
</li>
<li><p>Server returns <code>HTTP 402 Payment Required</code> with a JSON body listing<br />accepted networks, prices, and recipient addresses</p>
</li>
<li><p>Client signs a USDC transfer matching one of the requirements</p>
</li>
<li><p>Client retries with <code>X-PAYMENT: &lt;signed payload&gt;</code> header</p>
</li>
<li><p>Server verifies via the <em>facilitator</em> and returns 200 with the result</p>
</li>
</ol>
<p>This makes per-request billing trivial for AI agents — no API key<br />provisioning, no subscription forms.</p>
<h2>What is MCP?</h2>
<p><a href="https://modelcontextprotocol.io">Model Context Protocol</a> is Anthropic's<br />standard for letting LLMs call tools. Any MCP-compatible client (Claude<br />Desktop, Claude Code, ChatGPT, Cursor, Cline, Windsurf) can use any MCP<br />server through a single config file.</p>
<h2>Combining the two</h2>
<p>Our <code>chainanalyzer-mcp</code> package wraps six tools:</p>
<table>
<thead>
<tr>
<th>Tool</th>
<th>Price (USDC)</th>
</tr>
</thead>
<tbody><tr>
<td><code>check_address_risk</code></td>
<td>$0.008</td>
</tr>
<tr>
<td><code>sanctions_check</code></td>
<td>$0.003</td>
</tr>
<tr>
<td><code>trace_transaction</code></td>
<td>$0.015</td>
</tr>
<tr>
<td><code>detect_coinjoin</code></td>
<td>$0.01</td>
</tr>
<tr>
<td><code>cluster_wallet</code></td>
<td>$0.02</td>
</tr>
<tr>
<td><code>batch_screening</code></td>
<td>$0.05</td>
</tr>
</tbody></table>
<p>Install:</p>
<pre><code class="language-bash">npx -y chainanalyzer-mcp
</code></pre>
<p>Or add to <code>claude_desktop_config.json</code>:</p>
<pre><code class="language-json">{
  "mcpServers": {
    "chainanalyzer": {
      "command": "npx",
      "args": ["-y", "chainanalyzer-mcp"],
      "env": {
        "X402_WALLET_PRIVATE_KEY": "0x..."
      }
    }
  }
}
</code></pre>
<p>The <code>X402_WALLET_PRIVATE_KEY</code> is your <em>spender</em> wallet — the agent uses<br />it to sign USDC transfers. If you'd rather pay by subscription, set <code>CHAINANALYZER_API_KEY=tfk_...</code> instead.</p>
<hr />
<h2>Server-side: x402 on FastAPI</h2>
<p>We use a custom middleware (intentionally — we wanted full control over<br />the Bazaar metadata + bilingual error responses). The core verification flow:</p>
<pre><code class="language-python">async def _verify_payment(payment: str, config: dict) -&gt; bool:
    auth_token = _generate_cdp_jwt(
        method="POST",
        host="api.cdp.coinbase.com",
        path="/platform/v2/x402/verify",
    )
    headers = {"Content-Type": "application/json"}
    if auth_token:
        headers["Authorization"] = f"Bearer {auth_token}"

    async with httpx.AsyncClient() as client:
        resp = await client.post(
            f"{FACILITATOR_URL}/verify",
            headers=headers,
            json={"payment": payment, "requirements": {...}},
        )
        return resp.json().get("valid", False)
</code></pre>
<p>The CDP facilitator wants an Ed25519 JWT signed with the API key from<br />the <a href="https://portal.cdp.coinbase.com">CDP portal</a>. The portal hands you<br />a base64-encoded private key — sign with <code>cryptography</code> + <code>PyJWT</code>:</p>
<pre><code class="language-python">import base64, time, uuid, jwt
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey

def _generate_cdp_jwt(method, host, path):
    seed = base64.b64decode(CDP_API_KEY_SECRET)[:32]
    sk = Ed25519PrivateKey.from_private_bytes(seed)
    now = int(time.time())
    return jwt.encode(
        {
            "iss": "cdp",
            "sub": CDP_API_KEY_ID,
            "nbf": now,
            "exp": now + 120,
            "uri": f"{method.upper()} {host}{path}",
        },
        sk,
        algorithm="EdDSA",
        headers={"kid": CDP_API_KEY_ID, "nonce": uuid.uuid4().hex},
    )
</code></pre>
<p>That's all. Mainnet billing is now live.</p>
<hr />
<h2>Bazaar / Agentic.Market auto-discovery</h2>
<p>Coinbase's Bazaar crawler picks up x402 services automatically if your 402 response and <code>/services.json</code> manifest carry the right metadata:</p>
<pre><code class="language-python">ROUTE_CONFIG = {
    "GET /api/v1/x402/address/*/risk-score": {
        "price": "$0.008",
        "description": "AML risk score (5 chains, 76+ detectors)",
        "bazaar": {
            "discoverable": True,
            "category": "data",
            "tags": ["aml", "compliance", "risk-score", "blockchain"],
        },
    },
    # ... 5 more routes
}
</code></pre>
<p>Then expose <code>services.json</code>:</p>
<pre><code class="language-python">@router.get("/services.json")
async def x402_services_manifest():
    return {
        "id": "chainanalyzer",
        "name": "ChainAnalyzer AML API",
        "category": "data",
        "x402Version": 2,
        "networks": ["base", "solana"],
        "endpoints": [...],
    }
</code></pre>
<p>Bazaar requests this manifest with an empty body, validates the 402<br />response shape, and indexes the service. End users then find your API<br />on agentic.market without you submitting anything by hand.</p>
<hr />
<h2>Discoverability checklist</h2>
<p>If you're building an MCP server that wants to be findable by agents<br /><em>and</em> humans, here's what we did (most of it transferable to any service):</p>
<ol>
<li><p><code>/llms.txt</code> <strong>+</strong> <code>/llms-full.txt</code> — the <a href="https://llmstxt.org">llmstxt.org</a><br />convention. AI crawlers (Claude, GPT, Mistral, Perplexity) pick this<br />up to summarize your product.</p>
</li>
<li><p><code>/.well-known/ai-plugin.json</code> — older but ChatGPT custom GPTs<br />still read it.</p>
</li>
<li><p><code>robots.txt</code> — explicit <code>Allow:</code> for <code>GPTBot</code>, <code>ClaudeBot</code>,<br /><code>PerplexityBot</code>, <code>Google-Extended</code>, <code>Applebot-Extended</code>. Don't rely<br />on <code>User-agent: *</code>.</p>
</li>
<li><p><strong>JSON-LD</strong> <code>Service</code> <strong>/</strong> <code>SoftwareApplication</code> schema on key pages —<br />AI Overview / Bing Copilot read these.</p>
</li>
<li><p><strong>IndexNow API</strong> — pings Bing/Yandex/Naver/Seznam in one HTTP call.<br />Google ignores it but the cascade picks up.</p>
</li>
<li><p><strong>awesome-* GitHub lists</strong> — submit a PR. Surprisingly high CTR.</p>
</li>
<li><p><strong>Glama MCP Directory</strong> — submit your MCP server, then add a<br /><code>Dockerfile</code> to score AAA on security/license/quality.</p>
</li>
<li><p><strong>MCP Registry</strong> — official registry at registry.modelcontextprotocol.io.<br />Submit <code>mcp.json</code> via PR.</p>
</li>
</ol>
<hr />
<h2>What's next</h2>
<p>We're investigating Stripe's <a href="https://docs.stripe.com/payments/machine/mpp">Machine Payments Protocol</a><br />as a parallel rail (cards via Shared Payment Token + Tempo crypto), so<br />customers without a crypto wallet can still pay per request.</p>
<p>If you're shipping an MCP server and want to compare notes — drop a<br />comment or hit me on <a href="https://www.linkedin.com/posts/kenzo-arai-d_mcp-server-launched-call-chainanalyzer-share-7451274705354907648-dmF7?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAACH0GxIBTlmp61nI3EaRcOYEmeekwneTQ4g">LinkedIn</a>.</p>
<hr />
<p><em>Originally posted at</em> <a href="https://chain-analyzer.com/news/mcp-server-launched"><em>chain-analyzer.com</em></a><em>.</em></p>
]]></content:encoded></item></channel></rss>