# Introduction

What's MetaSleuth

MetaSleuth is a crypto tracking and investigation platform. It can help monitor market movements, track fund flow of criminal activities, and DYOR to avoid scams.

:detective: **Everyone can become a sleuth in the crypto world and DYOR!**

{% hint style="info" %}
Give it a try -> <https://metasleuth.io>

MetaSleuth resources

* <https://github.com/blocksecteam/metasleuth_resources>
  {% endhint %}

## Features

* Intelligent analysis: MetaSleuth will automatically give you the most valuable interactions based on our Intelligent analysis engine for a given address.
* Cross-chain analysis: MetaSleuth supports cross-chain analysis, e.g., a token transfer from BSC to Ethereum through a bridge. All the cross-chain addresses are shown on one map.
* Sharing of the Analysis: The result can be shared (with others). Other users can further analyze the shared result, creating a collaborative community.
* Enhanced labels: MetaSleuth leverages BlockSec's address labeling system, providing enhanced labels of CEXs, scammer and hacker addresses, and other addresses we collected and verified.
* Customization: Users can customize address labels and add notes to addresses and transactions.

## Supported Chains

[Bitcoin](https://explorer.btc.com/), [Ethereum](https://ethereum.org/en/), [Binance Smart Chain](https://www.bnbchain.org/en), [TRON](https://tron.network/), [Solana](https://solana.com/), [Polygon](https://polygon.technology/), [Mantle](https://www.mantle.xyz/), [Arbitrum](https://arbitrum.io/), [Avalanche](https://www.avax.network/), [Optimism](https://www.optimism.io/), [Base](https://base.org/), [Linea](https://linea.build/)

## Feedback

We value your input and would greatly appreciate any feedback or suggestions you may have. Please feel free to contact us through the social media channels listed below.

* Telegram: <https://t.me/MetaSleuthTeam>
* Twitter: <https://twitter.com/MetaSleuth>
* Email: <ms_support@blocksec.com>

## Tutorials

* [How to use MetaSleuth to analyze a phishing attack](https://blocksecteam.medium.com/metasleuth-how-to-use-metasleuth-to-analyze-a-phishing-attack-b525caac14c5)
* [Crypto Tracking: Starting with a Transaction](/user-manual/tutorials/crypto-tracking-starting-with-a-transaction)
* [Advanced Analysis: Lightweight Fund Tracking](/user-manual/tutorials/advanced-analysis-lightweight-fund-tracking)

## Multiple-Language

* [中文简体手册](https://docs.metasleuth.io/zh_cn)
* [中文繁体手册](https://docs.metasleuth.io/zh_tw)
* [Metasleuth ユーザーマニュアル](https://docs.metasleuth.io/ja)
* [Metasleuth Benutzerhandbuch](https://docs.metasleuth.io/de)
* [Manuel d'utilisation de Metasleuth](https://docs.metasleuth.io/fr)
* [Руководство пользователя Metasleuth](https://docs.metasleuth.io/ru)


# Media Kit

### Transparent Background

PNG

<figure><img src="/files/dYpcKuQYTaiyUy31NG9h" alt=""><figcaption></figcaption></figure>

SVG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FkZ08apa13D5M1x6NrRoy%2F20230809Metasleuth%E6%9B%B4%E6%96%B0-02.svg?alt=media&#x26;token=b68fd89c-284c-4706-aab7-541f07dd2843" alt="" width="563"><figcaption></figcaption></figure>

### White Logo & Transparent Background

PNG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FcPFQy3hjYkRR2m1zzjUL%2FBlocksec%E4%BA%A7%E5%93%81logo%20-19.png?alt=media&#x26;token=61b3a0a0-612b-481c-80dd-279eb1c4a6c2" alt=""><figcaption></figcaption></figure>

SVG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FGaDvv1Lix9gLUidbNRbB%2FMetaSleuth3.svg?alt=media&#x26;token=ace19830-4f2b-46e1-9c7a-9726e7aa455b" alt=""><figcaption></figcaption></figure>


# Getting Started

:tada: Welcome to the MetaSleuth User Manual! :tada:

MetaSleuth is a comprehensive platform designed to track and investigate on-chain assets, catering to diverse analysis needs. To facilitate a quick start with this tool, we have included four key topics in the "Getting Started" section:

1. [Start by a Simple Search](/user-manual/getting-started/start-by-a-simple-search): Quickly find specific addresses or transactions using the search function to access relevant data and insights.
2. [Start by a Shared Chart](/user-manual/getting-started/start-by-a-shared-chart): Collaborate and build upon existing visualizations by exploring shared charts created by other users.
3. [What are Nodes?](/user-manual/getting-started/what-are-nodes) Understand the concept of nodes, which represent entities such as addresses or contracts within the blockchain network.
4. [What are Edges?](/user-manual/getting-started/what-are-edges) Learn about edges, which illustrate the relationships and transactions between nodes, providing context to the data you analyze.


# Start by a Simple Search

On-chain investigations serve various purposes. You might be a law enforcement officer tracing illicit funds, a compliance officer assessing a user's financial risk, or an investor checking for potential issues with a project. You may also need to investigate a fraudulent transaction to track where your money went. In any case, the analysis always starts with an address or a transaction.

## Open MetaSleuth

Using MetaSleuth requires no preparation. Simply visit our website at metasleuth.io. You don’t even need to register or log in; you’ll find the analysis entry point right away—just a simple input box.

<figure><img src="/files/VpIHD1pVSyuFd6pQWoYT" alt=""><figcaption></figcaption></figure>

You can enter an address, transaction hash, or ENS domain name. If you're unsure what to search for, click the search box to see popular addresses and choose one to start.

## Search for an Address

If you enter an address, wait about 1 second for a dropdown box to appear, showing all the chains where the address has been active. Click on the chain you want to analyze to view the fund flows associated with that address.

<figure><img src="/files/bDJortIzshc5ONxA2AM9" alt=""><figcaption></figcaption></figure>

For example, if you search for `0x0629b1048298ae9deff0f4100a31967fb3f98962` and select Arbitrum, you can view the fund flow of the Radiant Capital Exploiter on that chain. Note that not all fund transfers will appear on the canvas for readability. To explore what information you can access via the Analyze feature, visit the [Analyze](/user-manual/trace-funds-ways-to-retrieve-transfer-data/analyze)

<figure><img src="/files/xupCNpUCa3sFQYPhnR3J" alt=""><figcaption></figcaption></figure>

## Search for a Transaction

If you enter a transaction hash, the dropdown will typically show only one result (assuming the hash is correct). Clicking on it will reveal all the fund flows associated with that transaction. For example, try entering `0x7856552db409fe51e17339ab1e0e1ce9c85d68bf0f4de4c110fc4e372ea02fb1`, which is an attack transaction from the Radiant Capital hack event.

<figure><img src="/files/iWb5HFbNWdt4FRriwtPV" alt=""><figcaption></figcaption></figure>

When you enter a transaction, MetaSleuth will display all asset transfers that occurred within that transaction. In this case, the attacker drained several pools from the project, so you will see funds coming from multiple addresses into the attacker's address.

<figure><img src="/files/liwn6y7sss4j2glusYy4" alt=""><figcaption></figcaption></figure>


# Start by a Shared Chart

Sometimes, you may receive a MetaSleuth analysis result shared by someone else, such as [this link](https://metasleuth.io/result/arbitrum/0x0629b1048298ae9deff0f4100a31967fb3f98962?source=b1ec1bc4-9b0a-4109-a3e8-288cbe035485). In MetaSleuth, these links are referred to as Shared links. They allow users to view and edit the canvas associated with the shared analysis.

## View a Shared Canvas

A shared canvas is essentially a snapshot of the analysis results provided by the sharer. When you open a shared link, you see the state of the entire canvas as it was when the link was created. You can click on the edges and nodes to view details, as well as check the sharer's notes. However, keep in mind that this is just one analysis result and does not represent the complete picture.

Clicking on an address node will display details such as the address label, associated tags, risk score, asset balance, and on-chain interactions. It's important to note that the asset transfers shown are only those selected by the sharer to be displayed on the canvas. To view a more comprehensive set of asset transfers, you will need to unlock the canvas for re-analysis.

<figure><img src="/files/hTfo0OAsvJwLHbbUVNjg" alt=""><figcaption></figcaption></figure>

Clicking on the edge will show you the asset transfer between the two nodes. Similarly, only the content selected by the sharer will be displayed here.

<figure><img src="/files/FB36eE5yXQaM4Vlloo7d" alt=""><figcaption></figcaption></figure>

## Edit the Canvas

If you find the shared content valuable and want to continue your analysis, you can unlock the canvas for editing and then save it. Your edits will not sync back to the original sharer.

Unlocking is straightforward—just click on the "Start Editing" button in the top left corner.

<figure><img src="/files/znVVE2bguL9Nv1UsF2Iv" alt=""><figcaption></figcaption></figure>

Generally, the unlocking process is smooth, but sometimes you may encounter a prompt asking if you want to keep some of the sharer's private tags. If you're an experienced MetaSleuth user, you might want to consider which tags are valuable to retain. If you're a beginner, just select "Import"!

For more information about Private Labels, you can visit the Save and Share - [Make Your Work More Readable](/user-manual/save-and-share/make-your-work-more-readble) section.

<figure><img src="/files/LA8Xl64eL0rYAELVQS1C" alt=""><figcaption></figcaption></figure>


# What are Nodes?

The fund flow in MetaSleuth consists of nodes and edges, where the "nodes" represent addresses on the blockchain, also referred to as wallets or accounts.

There are two types of nodes on the MetaSleuth canvas:

1. **Standard Address Nodes:** These are displayed as rounded rectangles.
2. **Resolvable Bridge Nodes:** These are represented as octagons.

## Address Nodes

Address nodes on the canvas typically have two states.

* **Reading State:** The default state of the node, shown on the left, which provides only readable information.
* **Analyzing State:** The state that appears on the right when you hover your mouse over the node, offering various analysis functions.

<figure><img src="/files/U2xk855plrtZmq5qu4VI" alt=""><figcaption></figcaption></figure>

In addition to the two basic states mentioned above, you may also see various useful icons on the nodes (as shown in the image below). We will introduce these icons one by one.

<figure><img src="/files/kUoFXTR6ULDMt1HHCk2a" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ebV1Ee6SuvAVBNQUngzG" alt=""><figcaption></figcaption></figure>

<table data-full-width="true"><thead><tr><th>Icons and Labels</th><th>Meaning</th><th>Actionable</th></tr></thead><tbody><tr><td><img src="/files/QrnVBEDTsbXx7mHaoVIc" alt="" data-size="original"></td><td>Blockchain</td><td>No</td></tr><tr><td><img src="/files/HRCaLLc5nUL5DrNZ8zCU" alt="" data-size="original"></td><td><p>Entity logo</p><p>When an address is associated with an entity that has a logo, the entity's logo will be displayed on the node. This helps to visually identify the organization or project linked to that address.</p></td><td>No</td></tr><tr><td><img src="/files/0x1wmCdX1x7HPGGOiv1r" alt="" data-size="original"></td><td>Address Info</td><td>No</td></tr><tr><td><img src="/files/HPJsoq3SQTNMji3cX3uP" alt="" data-size="original"></td><td><p>Address label</p><p>Address labels are displayed in the following order: user private labels > BlockSec labels. If neither is available, no label will be shown.</p></td><td>No but user can use <img src="/files/wFMPpW9xwA770dFHtuLe" alt=""> to edit</td></tr><tr><td><img src="/files/2cNwTlcoYnlHER4zoQ0D" alt="" data-size="original"></td><td><p>Common tool links</p><p>These links allow you to quickly jump to the details page for the current address on the respective platform. Clicking on them will provide you with more information about the address's activities and status.</p></td><td>No</td></tr><tr><td><img src="/files/ox3s8yHUnWjHAXSHhNdZ" alt="" data-size="original"></td><td><p>Incomplete Data Indicator</p><p>This indicates that the data for the current address is incomplete. Analysts requiring full data integrity should take note and may need to use additional methods to obtain complete information.</p></td><td>No</td></tr><tr><td><img src="/files/x69TXWVp6rDaUmt19fGb" alt="" data-size="original"></td><td><p>Risk Indicator</p><p>This indicates that the address is associated with risky behavior, and users should be cautious when interacting with it. Specific risk details can be found in the address panel.</p></td><td>No</td></tr><tr><td><img src="/files/EJX0sduEqEdbD0nnjxXT" alt="" data-size="original"></td><td>Analyze Button</td><td>Yes. Clicking the Analyze button initiates a detailed analysis of the current address.</td></tr><tr><td><img src="/files/4koJpipFfeRuKjY0NwAq" alt="" data-size="original"></td><td>Analysis Completed</td><td>No. Completion of the analysis indicates that the basic analysis is finished. Users can still perform additional analyses, such as Advanced Analyze or Load More to access further data.</td></tr><tr><td><img src="/files/fu1nMV3MCrwTL38OPtdx" alt="" data-size="original"></td><td>Advanced Analyze Button</td><td>Yes. Clicking the Advanced Analyze button enables you to perform a detailed analysis of the current address, allowing you to specify parameters such as token type, time frame, and amount.</td></tr><tr><td><img src="/files/wFMPpW9xwA770dFHtuLe" alt="" data-size="original"></td><td>Private Label (Edit Address Label)</td><td>Yes. Users can add or modify a label for an address, which will be stored as a private label in their user data.</td></tr><tr><td><img src="/files/DC6bdXlAM5VQsdncDCxs" alt="" data-size="original"></td><td>Delete Address Node</td><td>Yes</td></tr><tr><td><img src="/files/kd0qciJjufPdgMvkAjes" alt="" data-size="original"></td><td>Unidirectional Analysis</td><td>Yes. Click the button on the left side of the node to analyze the source of funds, and click the button on the right side to analyze the destination of funds.</td></tr></tbody></table>

## Bridge Node

When MetaSleuth identifies that an asset transfer likely involves cross-chain activity, it links that transfer to a bridge node. The specifics of the interaction address, including the chain, address, and label, are omitted, and instead, a bridge logo and name are used to represent it.

<figure><img src="/files/I0GjZeBRMIJSipB4lHFE" alt=""><figcaption></figcaption></figure>

Clicking on a bridge node allows you to view the specific interactions, including detailed asset transfers, transactions, and the bridge address involved. You'll also see a **Track** button; clicking this will enable MetaSleuth to automatically analyze the cross-chain destination of the funds.

<figure><img src="/files/NF9uBTWVsrzWf4yiot0G" alt=""><figcaption></figcaption></figure>


# What are Edges?

In MetaSleuth, edges represent the relationships between the connected nodes (addresses). Currently, there are three types of relationships displayed:

* **Standard Asset Transfer:** The most common relationship type, indicating the flow of assets between two addresses.
* **Contract Creation Relationship:** Represents the relationship between a contract creator and the created contract, labeled as '*Contract Creation*'.
* **Cross-Chain Asset Transfer:** This relationship indicates fund interactions between a standard address node and a cross-chain bridge node, typically suggesting that the funds have been transferred across chains. Users can further explore the source and destination of the funds using the InterChain Tracer feature.

In the example provided below, we can simultaneously observe these three types of relationships.

<figure><img src="/files/Z4kHOJznmVa6VqJ4Ywsk" alt=""><figcaption></figcaption></figure>

Next, let's examine the information contained in a standard asset transfer edge.

In the example below, the edge from the node **Euler Finance Exploiter 2 (0xb66cd)** to **KyberSwap Exploiter (0x50275e)** indicates that **Euler Finance Exploiter 2** sent **0.110 Ether** to **KyberSwap Exploiter**.

<figure><img src="/files/hreDKMcCy25edLMQHrkC" alt=""><figcaption></figcaption></figure>

Please note that MetaSleuth consolidates asset transfers of the same direction and type between two addresses into a single edge. Therefore, an edge does not represent a single transaction.

To see more details about an edge, click on it to open the [Edge panel](/user-manual/canvas-and-panels/edge-panel), then select `Detail` to view all transaction information.

<figure><img src="/files/sNRIa2jAQAk2hwS2IWkN" alt=""><figcaption></figcaption></figure>

In the transaction list, you can see that the Euler Finance Exploiter 2 has made two transactions, transferring a total of 0.111 Ether to the KyberSwap Exploiter.

### Edge Colors

Edges are typically gray by default, but to help distinguish different asset transfers, MetaSleuth uses the primary color of the major tokens' icons from each chain as the edge color. This aids users in better understanding the asset flows.

Users can modify edge colors in two ways:

* Change the Color of a Single Edge: Click the canvas icon on the edge. ![](/files/fexUTsEIhXp7Twx3gsq6)
* Change Color for All Edges of a Token: To modify the color of all edges representing a specific token, go to the Token Filters panel in the top left corner. Click the color circle next to the token you wish to change. After selecting your desired color, all edges associated with that asset will update to the new color.\
  ![](/files/8D4vTGgCkAYUIpub0gwT)

### Edge Labels

<figure><img src="/files/Kn0s33AOFno2UeX5psNi" alt=""><figcaption></figcaption></figure>

Edge labels consist of three parts:

1. **Index**: All edges are sorted by the displayed time, with a smaller index indicating an earlier occurrence.
2. **Time**: The earliest timestamp of all transactions included in the edge (the time of the earliest transaction).
3. **Transfer Amount**: The total amount of asset transfers represented by the edge (for the selected transactions displayed on the canvas), along with the token symbol.


# Canvas and Panels

In MetaSleuth, the **Canvas** serves as the central workspace where users can visualize and analyze blockchain data. **Panels** are additional sections that provide detailed information and tools related to the items displayed on the Canvas. We organize it into four sections:

1. [Canvas](/user-manual/canvas-and-panels/canvas): The Canvas is the central workspace for visualizing and analyzing blockchain data, enabling interactive manipulation of nodes and edges.
2. [Address Panel](/user-manual/canvas-and-panels/address-panel): The Address Panel shows detailed information about specific addresses, including transaction history and token holdings.
3. [Edge Panel](/user-manual/canvas-and-panels/edge-panel): The Edge Panel displays the connections between nodes, highlighting transaction flows and relationships.
4. [InterChain Tracker Panel](/user-manual/canvas-and-panels/interchain-tracker-panel): The InterChain Tracker Panel monitors cross-chain transactions, allowing users to trace asset movement between different blockchain networks.


# Canvas

The Canvas in MetaSleuth is your primary workspace for visualizing and analyzing blockchain data. It includes several key features:

1. [Toolbox Overview](/user-manual/canvas-and-panels/canvas/toolbox-overview): Access a variety of tools designed to enhance your analysis and streamline your workflow.
2. [Better Layout](/user-manual/canvas-and-panels/canvas/better-layout): Enjoy an organized interface that allows for efficient arrangement of visual elements, making your data easier to interpret.
3. [Customize Your Canvas](/user-manual/canvas-and-panels/canvas/customize-your-canvas): Tailor the Canvas to fit your needs by adjusting layouts, colors, and other visual settings to improve your analysis experience.
4. [Keyboard Shortcuts](/user-manual/canvas-and-panels/canvas/keyboard-shortcuts): Utilize keyboard shortcuts to navigate and operate more efficiently within the Canvas, saving you time during your investigations.


# Toolbox Overview

The Investigation Toolbox primarily provides filtering and editing capabilities for the data on the canvas. It consists of the following six key functionalities.

**`Address Filter`** lists all the analyzed addresses, including those displayed on the canvas and those not displayed on the canvas. Users can search for specific addresses in the filter and adjust their visualization status.

<figure><img src="/files/zlVQ0g1SJUsH4VpQOyQv" alt="" width="563"><figcaption></figcaption></figure>

**`Token Filter`** lists all the analyzed tokens. If all transfers related to a token are displayed on the canvas, it will be represented as selected (checkbox checked); conversely, if none of the transfers related to a token are displayed on the canvas, it will be represented as unselected (checkbox unchecked). It's important to note that if only some transfers related to a token are displayed on the canvas, it will be represented as partially selected (checkbox indeterminate).

<figure><img src="/files/HB3aNqysJAsg9VdaVgE8" alt="" width="563"><figcaption></figcaption></figure>

**`Add Address/Tx`** allows users to add specific addresses or transactions (intra-asset transfers) to the canvas. For more information, you can refer to the [Add Address/Tx](/user-manual/trace-funds-ways-to-retrieve-transfer-data/add-address-tx) section.

**`Add Memo`** allows users to add text annotations on the canvas. It enables users to provide additional context, notes, or explanations related to specific addresses & transactions on the canvas. For more information on how to use this feature, please refer to the [Memo](/user-manual/save-and-share/make-your-work-more-readble/memo) section.

**`Custom Watermark`** allows users to add their own branding or identification to their analysis results. It enables users to customize the watermark displayed on the canvas, adding their logo, name, or any other desired information. For more information on how to use this feature, please refer to the [Custom Watermark](/user-manual/save-and-share/make-your-work-more-readble/custom-watermark) section.

**`Search in Canvas`** allows users to perform searches within the canvas content based on criteria such as blockchain, address, transaction, label, or edge number. It enables users to quickly locate specific elements or connections within the visualization. By entering relevant keywords or criteria in the search bar, users can filter and focus on specific information of interest within the canvas.

<figure><img src="/files/UMtpZtfOovVWAuANjyy4" alt="" width="563"><figcaption></figcaption></figure>


# Better Layout

Tracking and analyzing on-chain assets often revolve around fund flows, making the layout of the canvas crucial. It not only affects the efficiency of analysis but also impacts the presentation of the analysis results. MetaSleuth has specifically provided a layout adjustment toolbar, which offers the following functionalities:

![](/files/08BjqMoKl49TJPI0TFUw)**`Manual Layout`** allows users to manually adjust the position and alignment of nodes on the canvas. Users can drag and reposition nodes to create a customized layout that suits their analysis needs.

![](/files/4QU3WVUqWFIBFx1W9LyC)**`Automatic Layout`** automatically arranges the nodes and edges on the canvas in an optimized layout, enhancing the visual clarity and organization of the fund flow diagram.

![](/files/9yAjV0KYWNZNxvb3iAuG)**`Adjust Spacing`** allows users to globally adjust the spacing between nodes, creating a more compact or expanded layout.

![](/files/I9dgrl0gX8SRSoqN8jgg)**`Undo and Redo`** enable users to manage and revert changes made to the canvas during the analysis process. Please note that there is a limitation on the number of steps allowed for Undo and Redo, which is set to a maximum of three steps.

![](/files/jAz0ARTImY0qSWqsr04H)**`Center the Graph`** allows you to align and center the entire canvas, bringing it into view and restoring overall control. This functionality is particularly useful when you want to refocus and have a complete view of the graph without any elements being cut off or hidden.

![](/files/QErBYHGuG4ZHr8scusuf)**`Full Screen`** allows you to immerse yourself fully in your analysis and investigation. Give it a try!


# Customize Your Canvas

The Appearance Editing Toolbox provides the functionality to edit the appearance of nodes, edges, and memos. When you open a canvas, it will initially display a node shape editor by default. You can minimize it into a canvas chart and freely drag it around, allowing yourself more space for analysis.

<figure><img src="/files/zggkDlmSoveSdG6m7nEZ" alt="" width="563"><figcaption></figcaption></figure>

Clicking on an address node will open the shape editor related to that node, allowing you to edit its shape, text color, and node color.

<figure><img src="/files/rwwWKzaEKkDPKHZ8Szom" alt="" width="375"><figcaption></figcaption></figure>

You can perform batch editing on addresses by holding down Ctrl (Command) and clicking on nodes to select multiple ones.

<figure><img src="/files/Pc2kwTz8GvEbo5ZXi9uJ" alt="" width="269"><figcaption></figcaption></figure>

Additionally, you can select any edge on the canvas to edit it, adjusting the width and color.

<figure><img src="/files/bBeaMogQ0uFNUff0nyYN" alt="" width="563"><figcaption></figcaption></figure>

By selecting a memo, you can edit the font size, color, formatting, and background color of its text.

<figure><img src="/files/Y6wKnFCfM1b5gsrduBaL" alt="" width="563"><figcaption></figcaption></figure>


# Keyboard Shortcuts

* `Ctrl` / `Cmd` + `Z`: Undo
* `Ctrl` / `Cmd` + Shift + Z: Redo
* `Ctrl` / `Cmd` + F: Search
* `Ctrl` / `Cmd` + `Click`: Multi-Select nodes
* `Ctrl` / `Cmd` + `Drag`: Multi-Select nodes


# Address Panel

When you click on an address node, an address panel will expand from the left side of the canvas. In this panel, you can see the following information:

**`Name Tag`**: If an address has a public name tag supported by BlockSec or a private name tag assigned by a user, it will be displayed. For example, the "Poloniex Exchange Exploiter" in the image below.

**`Compliance Risk Score`**: The compliance risk of an address is evaluated based on the tag information associated with the address and its interaction with other addresses. It is assessed on a scale of five levels: No Risk, Low Risk, Medium Risk, High Risk, and Critical Risk.

**`Address Labels`**: The labels associated with an address are provided by the BlockSec AML team. For example, in the given example, the address carries the label "Attacker." Other common labels include CEX, DEX, Sanctioned, Compromised, and more. These labels are used to identify specific characteristics or risk factors associated with the address, aiding in compliance and risk assessment.

**`Balance`**: The balance of the native token held by the current address on the blockchain, along with its corresponding value in US dollars.

<figure><img src="/files/f4f2vPPzbC3PuluuNQUe" alt=""><figcaption></figcaption></figure>

**`Related Address`**: These are the addresses that have interacted with the target address, compiled based on the acquired transaction data. In addition to the addresses themselves, you can also view the risk score of each address, the direction of fund flow, and the types of assets involved in the flow.

**`Transfers`**: These are all the fund transfers related to the target address that have been obtained.

**`Load More`**: This feature allows users to request more transactions for the current address. For detailed instructions on how to access additional transaction data using this feature, please refer to the "[Load More](/user-manual/trace-funds-ways-to-retrieve-transfer-data/load-more)" section.

**`Address Panel Filter`**: When there is a large amount of interaction in an address, a filtering tool may be needed to narrow down the scope of the investigation.

<figure><img src="/files/JEwyYquB29S6nI13CD1V" alt="" width="401"><figcaption><p>Address Panel Filter</p></figcaption></figure>


# Edge Panel

When clicking on any edge on the canvas, an edge list panel will expand.

<figure><img src="/files/1UezlhHxnbuK0CvBC5eV" alt=""><figcaption></figcaption></figure>

In this panel, you can view all asset transfers between two addresses (based on the currently available data). Each edge is uniquely identified by (from, to, asset). To view specific transfer data, you need to click on "Detail" to enter the Transaction List Panel. For example, clicking on (Poloniex 4, Poloniex Exchange Exploiter, Ether) in the above example would allow you to view all transaction details on the canvas involving the transfer of Ether from Poloniex 4 to Poloniex Exchange Exploiter, as shown below.

<figure><img src="/files/wpgyd3dR4yx7utPrX9kb" alt=""><figcaption></figcaption></figure>


# InterChain Tracker Panel

When tracing funds, the appearance of a cross-chain bridge node on the canvas indicates cross-chain transfers. To explore further, simply click on this bridge node or the connecting edge to open the InterChain Tracer Panel.

The illustration below shows an example of the InterChain Tracer Panel. Here, the ExactlyProtocol Exploiter is depicted using the Across bridge to transfer Ether from the Optimism network to the Ethereum blockchain.

<figure><img src="/files/e3Kf7T0v0FOSDfdzmRmY" alt=""><figcaption><p>The InterChain Tracker Panel</p></figcaption></figure>

Within the InterChain Tracker Panel, each entry represents a cross-chain transaction, providing key details such as the source and destination transactions, as well as the assets transferred. If cross-chain relationships have not yet been traced, information will only be available on either the source or destination side.

Are you wondering how to discover transactions on the respective chain? Which chains and addresses are involved in sending or receiving? By clicking "Track," users can utilize MetaSleuth's automated cross-chain tracking capabilities. Once the analysis is complete, cross-chain asset transfers on the other side will be displayed in the panel and automatically highlighted on the canvas.

If you encounter any unsupported, inaccurate, or failed cross-chain resolutions, we encourage you to provide feedback by selecting the "Report Bug" option located in the bottom right corner of the panel. Your input is invaluable in helping to enhance the tracking experience!


# Trace Funds (Ways to Retrieve Transfer Data)

In MetaSleuth, users can utilize the following features to efficiently and effectively trace funds:

1. [Analyze](/user-manual/trace-funds-ways-to-retrieve-transfer-data/analyze): Examine transaction details and patterns to gain insights into fund flows.
2. [Expand In / Out](/user-manual/trace-funds-ways-to-retrieve-transfer-data/expand-in-out): View incoming and outgoing transactions to understand the movement of assets.
3. [Load More](/user-manual/trace-funds-ways-to-retrieve-transfer-data/load-more)**:** Retrieve additional transaction data to ensure a comprehensive overview.
4. [Advanced Analysis](/user-manual/trace-funds-ways-to-retrieve-transfer-data/advanced-analysis): Utilize advanced tools for deeper insights into complex transactions.
5. [Add Address/Tx](/user-manual/trace-funds-ways-to-retrieve-transfer-data/add-address-tx): Easily incorporate specific addresses or transactions for targeted analysis.
6. [InterChain Traker (Trace across Blockchains Automatically)](/user-manual/trace-funds-ways-to-retrieve-transfer-data/interchain-traker-trace-across-blockchains-automatically): Track funds across different blockchain networks for a holistic view of asset flows.
7. [Data Explorer](/user-manual/trace-funds-ways-to-retrieve-transfer-data/data-explorer): View, filter and select transfer data.


# Analyze

## Analyze (Intelligent Analysis)

The default analysis feature of MetaSleuth. In addition to retrieving basic asset transfer data, **Analyze** incorporates intelligent techniques to facilitate the user's analysis process. Therefore, we also refer to it as "Intelligent Analysis."

You can access the Analyze feature in two main ways: through the search box on the homepage or by selecting an address node on the canvas.

<figure><img src="/files/38zVB3ySw0SFSQsqyVgn" alt=""><figcaption></figcaption></figure>

### Analyzing a Transaction

When analyzing a transaction, MetaSleuth displays all the asset transfers that occur within the transaction on the canvas.

The currently supported chains for transaction analysis include Bitcoin, Ethereum, BSC, TRON[^1], Solana, Polygon, Mantle, Arbitrum, Avalanche, Optimism, Base, and Linea.

### Analyzing an Address

Analyzing addresses involves a more complex algorithm. When analyzing an address, MetaSleuth applies intelligent search and filtering techniques to enhance the efficiency of data retrieval and presentation.

<figure><img src="/files/sBWbg8rIGIOloHZv4bDZ" alt=""><figcaption></figcaption></figure>

#### 🙋‍♂️ What data does Analyze retrieve for an address?

* Recent asset transfers: Analyze retrieves information about the most recent asset transfers associated with the address (small amounts will be filtered out). If a transfer is identified as a cross-chain transfer, you can utilize the "InterChain Tracker" to locate the bridged assets. For more details, please refer to the [InterChain Tracker Panel](/user-manual/canvas-and-panels/interchain-tracker-panel) section.
* Critical paths: Analyze also provides information about reachable paths within two hops between the address and centralized exchanges or mixers. Currently, this feature is only supported for Ethereum.

{% hint style="info" %}
For addresses with high transaction volumes, you may encounter the ⚠️ prompt on the address node, indicating that MetaSleuth has not retrieved all transfer data. In such cases, you can consider the following options if you want more data:

1. Utilize [Advanced Analysis](/user-manual/trace-funds-ways-to-retrieve-transfer-data/advanced-analysis) to retrieve additional data.
2. Import data through [Add Address/Tx](/user-manual/trace-funds-ways-to-retrieve-transfer-data/add-address-tx) to ensure comprehensive analysis.
   {% endhint %}

#### 🙋‍♀️ What data does Analyze prioritize displaying?

Not all retrieved data is displayed on the canvas. There are certain data types that we prioritize for display:

* Interactions with high-risk addresses.
* Interactions with centralized exchanges, mixers, and cross-chain bridges.
* The earliest and latest interactions.
* Interactions with known entities.
* Contract creation relationships.

{% hint style="info" %}
How to display the unshown interactions?

To view the unshown interactions, navigate to the address panel where you can find all the interactions listed. Additionally, there are several handy tools available to filter the interactions based on criteria such as direction, token, datetime, and more.
{% endhint %}

[^1]: Tron transaction analyzing currently only returns transfers involving Native/TRC20/TRC721 tokens.


# Expand In / Out

Looking for specific direction tracking? Use Expand, the single-direction version of Analyze.

<figure><img src="/files/7W46CCNRJQ5hcCauiHJA" alt=""><figcaption></figcaption></figure>


# Load More

The Load More feature provides you with complete control over selecting the data to display on the canvas. It retrieves asset transfers for a target address but does not automatically paint them. You can carefully select the ones you want to show by examining the name tag, risk information, interaction direction, and other details in the Address Panel.

<figure><img src="/files/feN73pbzIDcAcLvkO7IA" alt=""><figcaption></figcaption></figure>


# Advanced Analysis

As the name suggests, Advanced Analyze is an enhanced version of the Analyze feature. With Advanced Analyze, you have the ability to specify the exact direction, token, and date range for your analysis. By utilizing this feature, you can retrieve the desired interaction data exactly as you expect it to be.

<figure><img src="/files/EDvb7T1dJNDFiXx6KcuU" alt=""><figcaption></figcaption></figure>


# Add Address/Tx

Investigations can be complex and have multiple entry points. For example, if you want to investigate a case involving four separate addresses, you can add them to the canvas using this feature.

When you add addresses, they will be placed on the canvas without any immediate analysis, allowing you to perform analyze, expand, or load more operations later. On the other hand, when you add transactions, MetaSleuth will retrieve the inner asset transfers of those transactions and display them all on the canvas.

<figure><img src="/files/jLEeTaLQgHkKqDXuG4QJ" alt=""><figcaption></figcaption></figure>


# InterChain Traker (Trace across Blockchains Automatically)

To facilitate the process of tracking funds for users, MetaSleuth has a built-in InterChain Tracker. The InterChain Tracker automatically identifies potential cross-chain asset transfers when users analyze addresses. It also provides a one-click tracking feature to trace the cross-chain asset transfers on the other side. For more information on how to use it, you can visit the [InterChain Tracker Panel](/user-manual/canvas-and-panels/interchain-tracker-panel).

Currently, MS supports automatic parsing of cross-chain bridges such as Across, Multichain, cBridge, Hop, PolyNetwork, Stargate, Synapse, WormHole, Optimism Gateway, Polygon Pos Bridge, Avalanche Bridge (partial support), and RenBridge (partial support).

For further information on bridges and cross-chain transfers, please visit <https://ethereum.org/en/bridges/>.


# Data Explorer

View, filter and select transfer data.

To improve how we collect and present data, we limit the number of records shown by features like Analyze. Usually, we display only the most recent few hundred transfer records. While these limits can make tracking and analysis harder, we have introduced the ***Data Explorer*** feature to help.

<figure><img src="/files/SP4QdMNPAadeUyrufBqs" alt="" width="375"><figcaption></figcaption></figure>

In the address panel, we now show the number of transfers we have retrieved and the total number of transfers available. This helps you understand the data retrieval status for each address and make better decisions about what to do next.

<figure><img src="/files/Wv6kKCM1LoZ0sDzhWMvb" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Keep in mind that due to our algorithms, the total transfer count might differ from what you see in other sources. Also, our "dust transfer" filter may reduce the final number of transfers you see.
{% endhint %}

If you can't find all the data you need for a specific address using other features, you can use the Data Explorer. This feature allows you to access more complete data. In Data Explorer, transfer data is listed in reverse chronological order, and you can navigate through pages to see more. You can also use filters to get more specific results for larger datasets.

<figure><img src="/files/iKOuvvnQpiuBpui5hgOL" alt=""><figcaption></figcaption></figure>

When you find the transfer you are interested in, you can click the <img src="/files/LpzrqLDT0vSJGFcu94sF" alt="" data-size="line"> icon to add that transfer to the canvas. You can also select multiple transfers to add them all at once.


# Monitor Fund Movements

MetaSleuth Address Monitoring is designed to provide real-time tracking of fund inflows and outflows at specific addresses. We strive for comprehensive monitoring coverage and high availability through the following optimizations:

* **Multi-Chain Support**: We support major blockchains including Bitcoin, Ethereum, BSC, Tron, Solana, Arbitrum, Polygon, Optimism, and Avalanche, allowing users to monitor activities across multiple chains.
* **Multi-Asset Monitoring**: We cover the majority of asset types on these chains, enabling users to track a variety of digital assets they care about.
* **Flexible Rule Configuration**: Users can set precise monitoring rules to track asset transfers, minimizing unnecessary notifications and distractions.
* **Easy Management**: Users can easily create, pause, resume, and delete monitoring rules, allowing for flexible management of their monitoring targets.
* **Timely Notifications**: To ensure users are promptly informed of asset transfers, we offer an email notification service, ensuring no important updates are missed.

#### Address Asset Monitoring

For EVM-compatible chains, this service supports monitoring native tokens and assets that comply with mainstream token protocols (e.g., ERC-20, ERC-721, BEP-20) for any address. For the Bitcoin chain, it supports monitoring BTC transfers. For the Tron chain, it supports monitoring TRX and TRC-20 tokens. For the Solana chain, it supports monitoring native tokens and any specified SPL tokens.

#### Monitoring Rule Configuration

To achieve precise asset transfer monitoring, users can configure rules based on token type, direction, and amount:

* **Token Specification**: Users can specify tokens down to the protocol level (e.g., native, ERC-20, ERC-721, BEP-20) and specific tokens (e.g., designated USDC contract address).
* **Direction Options**: Monitoring can be set for incoming (IN), outgoing (OUT), or both (ALL) transfers.
* **Amount Range**: Users can specify a range for the amount of tokens to monitor. The minimum value for fungible tokens is set at 0.001, with no upper limit.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeKNZZUCBvNx9YI185Bi0qQQtdhJK9qpm6-CEFasJ9WE9NXthBvGc5mzbtcBIDgYO_MOyNNXPJTv8Zsg71AoA1qM8KxvuG_m6EBe_6w5bWem37SG-A2FUCm1cuonZiWCctFyTIPAffnyL-OBCxecWrFpTRM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>This setup monitors the hot wallet address of the NO-KYC exchange FixedFloat on Ethereum. The assets monitored are Ether, USDT, and USDC. The direction is set to <strong>ALL</strong>, tracking both incoming and outgoing transactions. The amount thresholds are <strong>1 ETH or more</strong> for Ether, and <strong>1500 or more</strong> for USDT and USDC.</p></figcaption></figure>

#### Monitoring Rule Management

Configured monitoring rules can be viewed in the Dashboard. The displayed information includes monitoring targets, operational status, creation time, restart time (if paused), and the number of events that met the criteria during monitoring. Users can perform actions on monitoring tasks, including pausing, restarting, editing, and deleting.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcpJn4EYbWlpLcB02JOnK9t9Km-tCsseskK4Nx4X1dzoaL3QKTYZilCJ8Q8CSw6PLU_K9w83X0dKyVDLZHB2h2_ET68c-nfUWYHyrkmd5hx3P7BTVKD8TxNPtGoQy7HiTPgZlfS8WKvb6SwRBPtKSax8QGM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Running Tasks After Initial Creation</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeddjv70rTS5KkTdL9CacxeheL1RZTXPotaX1Fx-nbbwxNqlJAG1j6DjK4PMrEH5ciRfMGqnFxKBcj6_2tKTpRsOyIiQeRqkBcAfA5tY5p7fcwoW2QWF3Q7JANwRhlNOivrKsrnLEfhE1D-owUjSXpFW4IR?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Paused Tasks</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd6aaHHK84gGg4m8GvcNyTkmd6_X2IQ_1MrVWbsc9NB5uiZlKPqu0sL5DwgZ-p-uKoSJBST3hPpDt9qlzeoQEJ4sYxWWwpj-UHPS3cfj66D4lKthEIm4kU4Evsa7P-xTMoL_jxaHJ6ceY3ZvYynqvWAo5VK?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Resumed Tasks</p></figcaption></figure>

#### Monitoring Event Notification

In the Dashboard, users can view all events related to a monitoring task. An event typically represents an asset transfer and includes information such as the transaction time, transaction hash, direction of transfer, counterpart, asset, and amount. If users have configured their email and enabled notifications, they will receive email alerts for these events.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcpJn4EYbWlpLcB02JOnK9t9Km-tCsseskK4Nx4X1dzoaL3QKTYZilCJ8Q8CSw6PLU_K9w83X0dKyVDLZHB2h2_ET68c-nfUWYHyrkmd5hx3P7BTVKD8TxNPtGoQy7HiTPgZlfS8WKvb6SwRBPtKSax8QGM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Users can enable notifications when creating a monitoring task or by toggling the Notif switch in the task management panel.</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc6LBNn3eblJykmE3Zxdh0WlEU716M8aq22uNBf8nWqtRN4dGCiCsmnmAOEWnVUlSme747WryZSWLN0YDaw6rpSmchTZn4NNlvwymW2JJhLkgM5BvhNyYZaTvMOoSG4uG7GD0-zyCbjZ3mxdu2EDsy-f5eN?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Triggered Events After Monitoring Configuration for FixedFloat Hot Wallet Address</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd-6FOQ8I5PR2kxnc7tuX0czExccZerSLX0M1SVEN76JuDcf53t8VZFeUC4vho6WDE9SOY54Yh6xga14mfIeoVMoY5JRD6_mmSSu1yn340vUVlyhDg16Nv8ANbFLvcjvspBSe6zjVhwF2BzyWSw1qNDo50?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>Email Notification for a Triggered Event</p></figcaption></figure>


# Save and Share

In MetaSleuth, the "Save and Share" feature enhances your workflow by allowing you to:

* [Save Your Work](/user-manual/save-and-share/save-your-work): Securely store your analysis and visualizations for future reference.
* [Collaborate with Your Team:](/user-manual/collaborate-with-others) Easily share your findings with team members or stakeholders to foster collaboration and discussion.
* [Export Data](/user-manual/save-and-share/export-data): Export your data and insights in various formats, making it convenient to present your work.
* [Make Your Work More Readable](/user-manual/save-and-share/make-your-work-more-readble): Organize and format your outputs to improve clarity and presentation, ensuring your analysis is easily understandable.
* [Share Your Findings](/user-manual/save-and-share/share-your-findings): Effortlessly share your results with others to facilitate discussions and decision-making.


# Save Your Work

MetaSleuth provides a built-in saving feature that allows you to save your current investigation progress. This ensures that you can come back to it later.\
Also, you can simply click on "Untitled" and modify the chart's name. This makes it easier for you to manage your data and share insights with others.

<figure><img src="/files/drQuS1K1tpYhRwVs4V6N" alt=""><figcaption></figcaption></figure>


# Export Data

You can export the relevant data, such as transaction details, asset transfers, or analysis results, in a suitable format. MetaSleuth supports various export options, including CSV and PNG, depending on your needs.

<figure><img src="/files/AMMYQHcGAUfYD53umr0T" alt=""><figcaption></figcaption></figure>


# Make Your Work more Readble

To enhance the clarity and presentation of your analyses, MetaSleuth offers several features:

* [Memo:](/user-manual/save-and-share/make-your-work-more-readble/memo) Add notes to your visualizations to provide context or explanations for specific data points, making it easier to remember key insights.
* [Labels:](/user-manual/save-and-share/make-your-work-more-readble/labels) Use labels to identify and categorize different elements within your workspace, allowing for quick recognition and organization of your data.
* [Custom Watermark](/user-manual/save-and-share/make-your-work-more-readble/custom-watermark): Personalize your visualizations with a custom watermark, which adds a professional touch and helps maintain ownership of your work.


# Memo

Once you have conducted your analysis and gathered relevant information, it is essential to compile your findings in a comprehensive manner. MetaSleuth has some great features to help you compile your findings effectively.

\
When you come across words that can enhance understanding of the charts and the underlying story, simply utilize the Memo feature.

<figure><img src="/files/4AyRZIaDCyxfW4XjlTIG" alt=""><figcaption></figcaption></figure>


# Labels

During the analysis process, you can add private labels to addresses and transactions to record your own understanding of the specific address or transaction. These private labels serve as personal notes or annotations.

In contrast to private labels, MetaSleuth also provides default public labels supported by the BlockSec Address Label Library. These public labels offer standardized and publicly recognized tags for addresses, helping you gain additional insights or information about specific addresses or transactions.

<figure><img src="/files/cpNtH6pHs1npO3jRtFII" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="/files/vSj1lDSdRszqKGaLhkEs" alt=""><figcaption></figcaption></figure>

##


# Custom Watermark

You have the option to upload your watermark and place it anywhere on the canvas. Additionally, you can attach a hyperlink to your watermark, allowing it to direct viewers to your website.

<figure><img src="/files/6QTLXW3LH60Fc49arieG" alt=""><figcaption></figcaption></figure>


# Share Your Findings

After organizing the fund flow, utilizing memos to note details, and even adding your personal watermark, it's time to share your findings with others. You might want to share it with the media to open-source your findings or with other investigators to further the investigation.

MetaSleuth facilitates this through the 'Share Chart' feature, allowing you to easily share your analysis with others to explore the current canvas content, delve into details, and even continue editing it.

<figure><img src="/files/wEICNtHfmhlL68UtyF2f" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
What can others do with my shared link?

When you share a link generated by MetaSleuth, it captures a snapshot of the current canvas content and associates it with that specific URL. Those who have access to the shared link can view the snapshot and explore all the details on the canvas. If others choose to edit the snapshot, it creates a separate copy that can be modified, saved, and shared independently from the original snapshot.
{% endhint %}


# Collaborate with Your Team

Users can join a team to collaborate, sharing data such as labels, saved charts, shared links, and monitors within that team. Each user is restricted to being a member of just one team.

## Create your team

To start collaborating, create a team first. All teams need a subscription.

Click 'Create a New Team', set up your team information, and select a plan to begin.

<figure><img src="/files/yslgAoHis2olMtLdhzoz" alt=""><figcaption><p>Create Your Team</p></figcaption></figure>

## Add team members

Team admin can invite other MetaSleuth users to join Your Team from the 'My Team' section in the Team settings.

Each team member can have one of the following roles:

* :eyes: Viewer: Can view data in the Team Workspace, including labels, charts, and monitoring data.
* :writing\_hand: Editor: In addition to the above, can create, edit, and delete team data, use Team Plan features for investigation.
* :gear: Admin: In addition to the above, can manage the team and its members. The Admin role is exclusive to the team creator.

The team admin can manage team members on the team settings page, where they can invite or remove team members and modify their roles.

## Team data

### Collaborate in workspace

Data created by users within the team context is automatically saved in the team workspace, accessible to all team members. Within this shared workspace, team members can collaborate, viewing and editing data according to their role-specific permissions.

<figure><img src="/files/T30oES3WsQdrY2XCbwLD" alt=""><figcaption><p>Team Workspace</p></figcaption></figure>

### Share personal data with team

After joining a team, users can share data from their personal accounts with the team. Users can share their address labels, saved charts, shared links and monitors with the team for collaboration.

Sharing data with the team is equivalent to duplicating a copy of the data within the team. Changes made to the data in personal and team contexts do not impact each other.

<figure><img src="/files/FksxyDve6uryUIjep6VZ" alt=""><figcaption><p>Share label to team</p></figcaption></figure>

## Switching contexts

As a team member, you can switch between personal and Team contexts. Labels and charts created in the team context are owned by the team, not you personally.

<figure><img src="/files/PCO22pA7cYKgUWWL3ejd" alt="" width="375"><figcaption><p>Users can switch between Personal and Team context</p></figcaption></figure>

\
Individual and team subscriptions are distinct. Switching contexts alters your permissions and credit usage. In the individual context, you access personal plan features and spend personal plan credits. In the team context, you utilize team plan features and credits.

## Advanced Permission

**Advanced Permission** gives teams more control over access management by enabling custom roles and fine-grained permission settings. With this feature, Admins can create roles with specific permissions and assign them to team members—ensuring each person has access to exactly what they need, and nothing more.

This feature is designed for teams with complex collaboration needs, offering flexibility beyond the default role-based access.

> **Availability**: Advanced Permission is available exclusively for the **Team Ultra Plan**.

### Enabling / Disabling Advanced Permission

Only **Admins** can enable or disable Advanced Permission.

To enable:

1. Go to **Settings → My Team**.
2. Toggle on **Advanced Permission**.

Once enabled:

* All default roles and permissions will be **disabled**.
* The Admin must **manually create roles** and **assign them** to each member.
* Members without a role assignment will have **no access** until assigned.

To disable:

* Toggle off the feature in the same location.
* Default roles and permission settings will be restored.

### Creating a Role

Admins can define roles to manage access to various features within the team workspace.

To create a role:

1. Go to the **Role List** section.
2. For each role, configure permissions for the following features:

**Labels**

* **Viewable**: Can only view all labels in the team workspace.
* **Editable**: In addition to the above, can also add、edit、delete labels.
  * **All data**: Can edit all labels, no matter who created.
  * **Data related to member himself**: Can edit labels created by himself.

#### Saved Charts

* **No Permission**: No access to saved charts.
* **Viewable**: Can only view all saved charts in the team workspace.
* **Editable**: In addition to the above, can also add、edit、delete saved charts.
  * **All data**: Can edit all saved charts, no matter who created.
  * **Data related to member himself**: Can edit saved charts created by himself.

#### Shared Links

* **No Permission**
* **Viewable**
* **Editable**
  * **All data**
  * **Data related to member himself**

**Monitors**

* **Viewable**: Can only view all monitor data in the team workspace.
* **Editable**: In addition to the above, can also add、edit、delete monitor data.
  * **All data**: Can edit all monitors, no matter who created.
  * **Data related to member himself**: Can edit monitor data created by himself.

Investigations

* **Allowed**: The member can access or use all basic and advanced investigation features.
* **No Permission**: The member cannot access investigation features at all.

{% hint style="info" %}
Each team can create up to **10 custom roles**.
{% endhint %}

### Assigning Roles to Members

Once roles are created:

1. Go to **My Team**.
2. Assign a role to each member.

* Each member can be assigned **multiple roles**.
* Permissions from multiple roles will be **merged**, and the member will receive the **highest permission level** available across all assigned roles.
* Role changes take **effect immediately**.


# Account and Data Management

In MetaSleuth, effective account and data management is essential for a personalized experience. This section includes:

* [Account Settings: ](/user-manual/account-and-data-management/account-settings)Manage your account details, including password changes and security options to ensure your account remains secure.
* [Preference Settings:](/user-manual/account-and-data-management/preference-settings) Customize your user experience by adjusting settings such as notification preferences, display options, and language choices.
* [User Data: ](/user-manual/account-and-data-management/user-data)Access and manage your data, including viewing your activity history and exporting relevant information for your records.


# Account Settings

To access the account settings page, click the `User avatar icon` on the top right corner, then `Account Settings`.

<figure><img src="/files/90fz8y2KzIMUt5AmdIdn" alt=""><figcaption></figcaption></figure>

In account settings, users can:

* Update username (alias)
* Reset password
* Turn on/off 2FA verification
* Set up 2FA authentication


# Preference Settings

To access the preference settings page, click the `User avatar icon` on the top right corner, then `Preference`.

## Chart Settings

The settings in the chart settings will affect how the canvas is displayed globally.

### Amount Display Format

This setting primarily applies to the display of token amounts within the canvas.

* The Standard Format (e.g., 1,099,999.99 Ether) is the default display format.
* The Abbreviated Format (e.g., 1.099M Ether) can shorten the displayed text, making the layout within the canvas more compact in certain situations.

<figure><img src="/files/DBlhJn8ZuX3NuBp42WDJ" alt=""><figcaption></figcaption></figure>

### Automatically Hide Suspicious Token Transfers

When you turn on this setting, the fund flow will deselect (not display in canvas) those edges which contain suspicious token transfers by default.

{% hint style="warning" %}
For suspicious tokens: We assess token reputation through analysis of on-chain activity and relevant information. If you discover any inaccuracies, please contact us to report them.
{% endhint %}

## Watermark

You can customize your watermark and manage the display of the MetaSleuth watermark here.

### Custom Watermark

You can upload a logo or image to create a custom watermark that represents them or their organization. You can also add a URL link to the uploaded watermark, which allows others to visit the link when clicked. After uploading, you can add this custom watermark to their charts to identify your work. This feature is available to subscribers of the **Pro Plan and higher**.

<figure><img src="/files/eAHgQXs7kuFxKpUf385a" alt=""><figcaption><p>Upload your custom watermark</p></figcaption></figure>

<figure><img src="/files/dIJu4HYZW9G8hY68x0W7" alt=""><figcaption><p>Add custom watermark to your chart</p></figcaption></figure>

### Remove MetaSleuth Watermark

Subscribers to the Pro Plan or above have the option to remove the MetaSleuth Watermark from their Canvas. By turning on the switch, the watermark can be removed globally.

<figure><img src="/files/Yp1kb2bro8heJPKzbZtH" alt=""><figcaption><p>Canvas with MetaSleuth watermark</p></figcaption></figure>

<figure><img src="/files/yZy5n8EpYf2trT33kczR" alt=""><figcaption><p>Canvas without MetaSleuth watermark</p></figcaption></figure>


# User Data

To access the user data management page, click the `User avatar icon` on the top right corner.

## Private Labels

This section includes the private name tag of addresses and private notes of transactions. All private labels are displayed in a table list format, where users can search, edit, and export labels.

<figure><img src="/files/FI2QPaqyhLxz6Qun4yJG" alt=""><figcaption><p>Private labels</p></figcaption></figure>

## Saved Charts

In this section, users can access all saved charts, and options to search, delete, and edit are available.

<figure><img src="/files/OK4oveGjMhwHKCaxemjk" alt=""><figcaption><p>Saved Charts</p></figcaption></figure>

## Shared Links

In this section, users can access all shared links, with options to delete, edit expiration time, and edit information. Please note that shared links are snapshots of charts, and edits cannot update the content of a shared link.

<figure><img src="/files/ziXGHAU7HBl8M2x3244n" alt=""><figcaption><p>Shared Links</p></figcaption></figure>


# Plans, Billings and Payments

MetaSleuth offers a range of plans for user selection. For specific plan details, please refer to: <https://metasleuth.io/plans>.

We also provide two payment options: Card and Crypto. Users can manage their subscribed plans and billing information below:

1. [Change Your Plan](/user-manual/plans-billings-and-payments/change-your-plan): Quickly adjust your subscription plan to fit your needs, whether upgrading or downgrading.
2. [Update Your Payment Method and Billing Information](/user-manual/plans-billings-and-payments/update-your-payment-method-and-billing-information): Easily update your payment details to ensure uninterrupted service and avoid payment issues.


# Change Your Plan

## Upgrade plan

You can upgrade your plan at any time by visiting the [Pricing page](https://metasleuth.io/plans), selecting your desired plan, and clicking "Upgrade."

When upgrading to a higher plan mid-billing cycle:

* You will be charged immediately for the new plan.
* The amount due will be prorated based on the remaining time in your current billing cycle.
* The new plan takes effect immediately, and the billing cycle remains the same.

If you switch to a longer billing interval:

* You will be charged immediately for the new plan.
* The amount due will be reduced by a prorated amount based on the time remaining in your previous billing period for your current plan.
* The new plan takes effect immediately, and the billing cycle changes right away.

## Downgrade plan

Currently, MetaSleuth does not provide the option to downgrade while an active subscription plan is in effect. If you need to downgrade, we kindly ask that you cancel your current subscription first and then resubscribe after the current billing cycle.

{% hint style="info" %}
Please note that in MetaSleuth, changing the billing interval from a longer duration to a shorter one is considered a downgrade.
{% endhint %}

## Cancel subscription

Your MetaSleuth subscription, whether monthly or annually, will renew automatically until you cancel it.

You can cancel anytime by clicking `User avatar icon` -> `Subscription` -> `Manage Billing`.

On the Stripe page, click ***`Cancel subscription`*** to unsubscribe. After you cancel, you’ll still have access to all the paid features until the end of your billing cycle.


# Update Your Payment Method and Billing Information

## Switch payment method between card and crypto

To switch between the Card and Crypto payment methods, you will need to resubscribe after the current billing cycle ends.

## Update card payment method

MetaSleuth uses Stripe to process card payments and subscriptions, so we don't collect or store your card information.

To update your payment method, click the `User avatar icon` -> `Subscription` -> `Manage Billing`. From there, you can change the payment method on the Stripe hosted page.

## Update billing information

Same as the payment method, click the `User avatar icon` -> `Subscription` -> `Manage Billing` to update billing information.

You can change the name, email, address, phone number and tax infomation here.


# Team Plan & Billing

MetaSleuth offers three different Team Plans for you to choose from, which you can explore at: <https://metasleuth.io/plans>.

Please note that team Plan subscriptions do not accept crypto payments.

## Understand the team plans

Team Plans in MetaSleuth are based on seats, which represent the number of individuals who can join your organization. For example, if you have 10 seats and 6 are occupied, you can add 4 more individuals.

### Charge by seat

MetaSleuth charges for all seats on your account, regardless of whether they are being used. For instance, if you have 5 seats and 4 active users, you will be billed for all 5 seats, even if one seat is unfilled.

## Manage your seats

Team admins can increase or decrease the number of seats by clicking on "Update Seats" in the billing section of the Team settings. Please note that the total number of seats cannot be less than the number of occupied seats.

## Upgrade or add seats

If you add seats or upgrade your team plan, the additional costs will be applied immediately to your current billing period.

## Downloade or remove seats

When you remove seats or downgrade your plan, these changes will take effect in your next billing cycle.

Feel free to reach out us at <ms_support@blocksec.com> if you have any questions or need further assistance!


# Tutorials

[Crypto Tracking: Starting with a Transaction](/user-manual/tutorials/crypto-tracking-starting-with-a-transaction)

[Advanced Analysis: Lightweight Fund Tracking](/user-manual/tutorials/advanced-analysis-lightweight-fund-tracking)


# Crypto Tracking: Starting with a Transaction

In this tutorial, we will guide you through the basic functionalities of MetaSleuth by tracing the stolen funds in a phishing transaction. Together, we will explore how to use MetaSleuth to analyze transactions, track specific funds, and monitor untransferred funds.

**Video/Content:** [MetaSleuth Tutorial - Use MetaSleuth to track the stolen funds in a phishing transaction](https://www.youtube.com/watch?v=Ad6sJpiG7Xg)

We have identified a phishing transaction on the Ethereum network with the hash 0x2893fcabb8ed99e9c27a0a442783cf943318b1f6268f9a54a557e8d00ec11f69. Now, let's delve into our analysis.

## Input target, press 'Enter'

To begin, navigate to <https://metasleuth.io/>. Choose Ethereum as the network, and enter the transaction you wish to analyze. Press Enter. Now, await the data returned by MetaSleuth.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FKwJ2Vbz6fTQa9FJ5ieeY%2Fimage.png?alt=media\&token=d7cc498e-a8e9-4b66-a589-17f3b74ecdd2)

## Main functional components

Once the transaction analysis is complete, you will be directed to the MetaSleuth analysis page, where you can see all the asset transfers that took place in the transaction. If the analysis target is an address, the displayed information will be more complex. We will cover address analysis in a separate tutorial.

In addition to the central asset transfer graph, the page includes various other functional components. Here is a simplified diagram, and you are encouraged to explore their specific usage during the analysis process.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FjoRZbk0SPBPy7nfXbUbU%2Fimage.png?alt=media\&token=82d6723b-3eb7-475e-baaa-a44aa7fdb431)

## Track the funds

The transaction we are focusing on involves only one asset transfer: Address 0xbcd131, which is the victim, transferred 2586 MATIC to Fake\_Phishing180627.

To continue tracking the destination of the stolen MATIC tokens, it's straightforward. Simply select the Fake\_Phishing180627 address node and click on the ***"+"*** button on the right side of the node.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FnDwint1byMsaKVcSBhr8%2Fimage.png?alt=media\&token=392d7ca2-f200-4819-b7eb-6148b2553326)

This feature is called ***Expand outgoing*** and allows you to trace the assets sent from this address. In most cases, this feature provides the desired data. However, for addresses with a high transaction volume, you may need to utilize advanced features such as ***Advanced Analyze*** and ***Load More*** to obtain the required data.

After clicking the ***"+"*** button, we can see numerous outgoing Ether transfers from Fake\_Phishing180627. But what about the MATIC we want to track?

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2Fb8P7ZIXKwyRAJDgSUP3i%2Fimage.png?alt=media\&token=c4603dc2-2b92-4c73-9a36-c3cfb4d8f926)

## Filter the canvas

MetaSleuth does not display all the data it retrieves on the canvas to ensure a clean and readable representation of the overall fund flow. However, MetaSleuth provides various tools to help users locate the desired data and add it to the canvas. In this case, we can utilize the ***Token Filter*** to add all the MATIC asset transfers obtained by MetaSleuth to the canvas.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FLUKJS5RQ9ZmPTNBnkb3Z%2Fimage.png?alt=media\&token=b1937bcd-4956-41eb-ba02-87ac67b82475)

After confirming, we can see an additional MATIC transfer on the canvas, originating from Fake\_Phishing180627 and going to Uniswap V3: MATIC. This is exactly the stolen funds we are tracking.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FS4u6ZEbSlx0mSpKpikwG%2Fimage.png?alt=media\&token=55f6d2b2-4715-4e2f-99bf-a674fa1520e1)

When it comes to assets sent to decentralized exchanges (DEX) like Uniswap, our focus is not on the MATIC tokens transferred out from the address Uniswap V3: MATIC, but rather on the assets obtained by Fake\_Phishing180627 through the swap action on Uniswap.

So, what assets did Fake\_Phishing180627 receive through this swap? Let's investigate this swap transaction to find out.

## Add specific data

First, we need to determine the transaction to which the MATIC transfer from Fake\_Phishing180627 to Uniswap V3: MATIC belongs. Click on the asset transfer edge on the canvas, and in the ***Edge List*** that appears below, click on ***Details*** to access the ***Transaction List***. Find the transaction hash for this transfer and copy it.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FfWWg5g159uM4ZiPplRtE%2Fimage.png?alt=media\&token=4dd10b0d-eb35-43d5-ba6f-f691427679cf)

Then, we can add this transaction to the canvas using the ***Add Address / Tx*** functionality located in the top left corner of the canvas. This will allow us to explore the asset transfers that took place within this transaction and gain a clearer understanding of its contents.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FT6bQAwNzGcaTcMTq7LhC%2Fimage.png?alt=media\&token=09b3d743-3b3d-4c01-88d1-96f69ca6c4e1)

After adding it, all the asset transfers within this transaction will be visible on the canvas. It becomes clear that Fake\_Phishing180627 swapped MATIC for 0.944 Ether through Uniswap. This 0.944 Ether is the asset we need to track further.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2F68qtOzlhfl7hsL2Lubk4%2Fimage.png?alt=media\&token=f54ee047-fa41-4ee0-8e42-e301544a46fd)

## Track specific funds

Among the various Ether transfers originating from Fake\_Phishing180627, which ones should we track?

By clicking on Fake\_Phishing180627, you can observe the asset transfers associated with this address in the left-hand address panel. You might have noticed that there is more data available here compared to what is displayed on the canvas (as mentioned earlier, MetaSleuth emphasizes simplicity and readability in the fund flow diagram and does not show all data by default).

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FXr95VjIMZk9Te5yEDzBr%2Fimage.png?alt=media\&token=4f4c50e6-d556-4017-8d6d-fff391c67315)

The transaction where Fake\_Phishing180627 swapped MATIC for Ether occurred on 2023-06-18 at 14:57:11. Therefore, our primary focus should be on Ether token transfers that occurred after this specific time. To filter the data, we can utilize the filter function.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FzpkEX8bNISfmeXRpAO3p%2Fimage.png?alt=media\&token=664e759b-3c31-4ab1-a448-e2feb2f2d680)

Within the filtered results, it is evident that approximately 6 minutes after the swap action, 1.4 Ether was transferred from the address Fake\_Phishing180627 to the address 0x8bae70. This transfer likely contains the funds we are seeking to trace.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FuuGCFJDk1nDnNOld3lR0%2Fimage.png?alt=media\&token=31231f62-5f53-4378-bcf4-823c5cfd32ee)

We can mark and display them on the canvas, continuing to track the assets of 0x8bae70. By doing so, we can observe that the funds eventually settle in the address 0x8de345

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FlsbIk1lwjQSu603v5soD%2Fimage.png?alt=media\&token=b8a5cf40-2b05-4323-af83-c247798a9107)

## Monitor untransferred funds

To stay informed about the funds that have not been transferred yet, we can actively monitor them. By enabling monitoring, you will receive email notifications whenever relevant asset transfers occur. To explore additional monitoring features, please visit the MetaSleuth Monitor Dashboard at: <https://metasleuth.io/monitor>.

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2Fd8HdSs3VWy0SiaM1ThU8%2Fimage.png?alt=media\&token=7409cfb8-9ee1-496a-a092-4f736ac5f827)

## Summary

Although this was a brief exploration, we hope that MetaSleuth has provided you with a convenient and smooth tracking and investigation experience. We will release more instructional material in the future and welcome your suggestions. Join our Telegram group at <https://t.me/MetaSleuthTeam>.

.


# Advanced Analysis: Lightweight Fund Tracking

In this tutorial, we will describe the fund-tracking functionality of MetaSleuth. During the investigation, we usually want to track the **outgoing** funds from an address. MetaSleuth facilitates this process by supporting tracking fund flow from one direction.

**Video/Content:** [MetaSleuth Tutorial: Use MetaSleuth’s advanced analysis for lightweight fund tracking](https://www.youtube.com/watch?v=EH7x7BTumIQ)

In the following, we show a real example of tracking the phishing victim to demonstrate this functionality. The address tracked is *ryanwould.eth (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)*.

### What is Fund Tracking and Why Metasleuth

From its inception, MetaSleuth aimed to provide analysts with more convenient visual analysis capabilities. After immersing in the on-chain sleuth group and Web3 community, we discovered that one of the most common tasks is tracking outgoing funds from a specific address within a defined time range.

For instance, this involves tracking stolen funds from a victim's address to recover the funds, monitoring the targets of smart money for better investments, and tracking suspicious transactions for anti-money laundering (AML) purposes.

However, the fund flow from these active addresses can be extremely complex, involving multiple tokens, diverse targets, and spanning long periods. This situation does bring troubles for on-chain sleuths who must spend time extracting relevant information for their analysis.

To solve this problem, MetaSleuth has provided the most lightweight/ best user experience/ fastest solution plan among all the assistant tools.

## Tracking Details

When investigating a phishing case, the information we have is as follows.

* *ryanwould.eth (*&#x30;xc6D330E5B7Deb31824B837Aa77771178bD8e6713) has suffered considerable losses in phishing. And furious on-chain sleuth tasked with finding out where stolen funds are going and uncovering hidden phishing groups.
* Known Clues
  * Victim：*ryanwould.eth* (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)
  * Time: around 2023.02.25-2023.02.27
  * Loss Assets: unknown token, unknown amount
  * Network: Ethereum

### Step 1: Select the address

Visit [metasleuth.io](https://metasleuth.io/), select the corresponding blockchain network (the default is Ethereum), and enter the origin address of the funds, i.e., ryanwould.eth.

Metasleuth will resolve the corresponding address based on the ENS name. Then, on the search box's right side, use Metasleuth's core function, `Advanced Analyze`.

<figure><img src="/files/8SQFVHpqri6YeYWxhhnv" alt=""><figcaption><p>Entry point of Metasleuth.io</p></figcaption></figure>

### Step 2: Select the direction

After entering the Advanced Analyze Settings panel, we can choose the funds' direction and the time range. In this task, we only focus on the outflow of funds (out) and the time period around the fishing occurred (2023-02-25->2023-02-28). After completing the configuration settings, we click apply and press Enter to enter the canvas.

<figure><img src="/files/bNOJPbiEj4JLXeA74e5C" alt=""><figcaption><p>Advanced analyze setting</p></figcaption></figure>

### Step 3: Generate the first fund flow graph

That's great! Metasleuth.io quickly generates a visual graph of all outgoing fund flows between February 25, 2023, and February 28, 2023. Thanks to this function, we save a lot of data sifting time.

Moreover, leveraging the address label maintained by MetaSleuth, we can readily identify that within this brief timeframe, only two unusual fund flows were detected, both directed toward the address "Fake\_Phishing11227". These anomalous transactions involved 1,842 USDC and 519,351 DATA tokens, as depicted in the graph.

<figure><img src="/files/GVFSrjwGFT7Y7VeYItlC" alt=""><figcaption><p>The initial fund flow</p></figcaption></figure>

### Step 4: Filter interested tokens

For better display, we open the token configuration item, remove other default tokens, leaving only the stolen tokens (USDC, DATA), and then confirm our changes.

<figure><img src="/files/JpdBajelCCjf6pro8dQa" alt=""><figcaption><p>Token filter</p></figcaption></figure>

### Step 5: Extend the fund flow of interested address

The fund flow becomes extremely concise and clear. To trace the fund outgoing, we further extended the second hop of the fund transfer. In the second hop of the fund transfer relationship, we found that the phishing address "Fake\_Phishing11227" transferred the stolen funds to Airswap and exchanged tokens through Airswap.

<figure><img src="/files/TFLEFHZp8qx0pRpR9MMp" alt=""><figcaption><p>The filtered fund flow</p></figcaption></figure>

### Step 6: Process the token swap operation

Due to our token filtering configuration, we only focused on DATA and USDC, which obscured the process of token swapping. To address this, we added ETH to the token configuration and added the swap transaction (0x23f4ed07e2937c3f8f345e44ce489b8f83d2b6fdbf0697f6711ff4c7f2a55162) again. With this update, we now have a complete view of the token-swapping process. The phishing actor exchanged USDC and DATA tokens through AirSwap and obtained 14.58 ETH. At this stage (2022-02-27 22:30), solely focusing on USDC and DATA would no longer be meaningful. We need to trace the path of the acquired ETH to uncover additional phishing addresses.

<figure><img src="/files/sqmDzhMj7zjk03OW9d0T" alt=""><figcaption><p>Add transaction</p></figcaption></figure>

<figure><img src="/files/P7JM9dHnQ9n0ziikggb1" alt=""><figcaption><p>The complete fund flow</p></figcaption></figure>

### Step 7: Further filter with time range

Therefore, we continued with the Advanced Analysis of the phishing address "Fake\_Phishing11227". Similarly, we only focus on the outgoing funds, and the time range between February 27, 2023, and February 28, 2023. We proceed by clicking the "Analyze" button to proceed with the analysis.

<figure><img src="/files/5QbTgDNudl4fiGu5zhQl" alt=""><figcaption><p>Further analyze button</p></figcaption></figure>

### Step 8: Stop the investigation when finding interested recipients

We have obtained the fund destinations from "Fake\_Phishing11227" within the specified time range. It appears that there are numerous receiving addresses involved, indicating a process of distributing the illicitly obtained funds.

Among all the recipients, the addresses *"offtherip.eth"*, "Fake\_Phishing76579", and "Fake\_Phishing7064" received the majority of the distributed funds, amounting to 10.36 ETH, 8.36 ETH, and 1.85 ETH, respectively.

Based on this distribution ratio, we regard *offtherip.eth* as the most suspicious entity in this investigation and attract attention.

<figure><img src="/files/TEO7yaKuPFFGro8JYfGk" alt=""><figcaption><p>Final trace result</p></figcaption></figure>

With obtaining the unusual address "offtherip.eth", further steps may require utilizing non-blockchain techniques, such as social engineering analysis. However, in this analysis focused on on-chain fund transfers, metasleuth.io has provided a plethora of convenient technical assistance, enabling the entire analysis to be completed in less than 10 minutes.

### Conclusion

In this tutorial, we show an example of using MetaSleuth to track a phishing victim's fund flow. The summary of the analysis is as follows.

* Victim: *ryanwould.eth* (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)
* Time: 2023-02-27 22:00
* Loss Assets: 1,842 USDC, 519,351 DATA
* Network: Ethereum
* Funds Target：
  * First Hop: Fake\_Phishing 11227
  * Second Hop:
    * *offtherip.eth*
    * Fake\_Phishing76579
    * Fake\_Phishing7064
* Analysis Time consumed: <10 min


# Introduction

Introduction to BlockSec AML API

The BlockSec AML API Service offers two main sets of APIs, providing services for [**address label queries**](/blocksec-aml-api/address-label-api) and [**risk score queries**](/blocksec-aml-api/wallet-screening-api), respectively.

## API Overview

### Address Label APIs

<table><thead><tr><th width="133">Method</th><th>API</th></tr></thead><tbody><tr><td><code>GET</code></td><td><a href="/pages/UHzHmBv9FSeyIn16P9lr#get-supported-chains">Get Supported Chains</a></td></tr><tr><td><code>POST</code></td><td><a href="/pages/UHzHmBv9FSeyIn16P9lr#get-address-labels">Get Address Labels</a> (in <a href="/pages/UHzHmBv9FSeyIn16P9lr#get-address-labels-in-batch">Batch</a>)</td></tr><tr><td><code>POST</code></td><td><a href="/pages/UHzHmBv9FSeyIn16P9lr#get-entity-info">Get Entity Info</a></td></tr></tbody></table>

### Risk Score APIs

<table><thead><tr><th width="132">Method</th><th>API</th></tr></thead><tbody><tr><td><code>GET</code></td><td><a href="/pages/1k4XyJNHEsxQDLas403U#get-supported-chains">Get Supported Chains</a></td></tr><tr><td><code>GET</code></td><td><a href="/pages/1k4XyJNHEsxQDLas403U#get-risk-indicators">Get Risk Indicators</a></td></tr><tr><td><code>POST</code></td><td><a href="/pages/1k4XyJNHEsxQDLas403U#get-address-compliance-risk">Get Address Risk Score</a></td></tr></tbody></table>

## Rate Limits

The rate limit for each API request is five requests per second, and each subscription plan limits the number of addresses that can be **queried daily**. See our[ subscription page](https://metasleuth.io/plans#apis) for more details.

## Read More

[Authentication](/blocksec-aml-api/introduction/authentication)

[Response Format](/blocksec-aml-api/introduction/response-format)


# Authentication

Our API is authenticated using the API key. To ensure the security of your data, **please do not share your API key with anyone.**

### How to get the API Key?

To generate an API key, begin by [registering for a BlockSec account](https://account.blocksec.com/signup?referer=https%3A%2F%2Fmetasleuth.io). Once registered, access the [APIs](https://metasleuth.io/settings?type=apis) panel in the ***Settings*** section to quickly get your API key.

{% hint style="info" %}
If you subscribed to the customized API service through our sales channel, please get in touch with your designated service contact to acquire the API key.
{% endhint %}

<figure><img src="/files/csG8D76ObGwe0y9WM1M8" alt=""><figcaption></figcaption></figure>

### How to use the API Key

Include the "**API-KEY**" header in the HTTP Request Headers for each API request, and provide your API key as the value. See the following example.

{% code overflow="wrap" %}

```sh
curl -L \
  -X POST \
  -H 'Content-Type: application/json' \
  -H 'API-KEY:$API_KEY' \
  'https://aml.blocksec.com/address-label/api/v3/labels' \
  -d '{"chain_id":1,"address":"0x00d7e7409bfe09a736d3e993de9b87d0baa314d5"}'
```

{% endcode %}


# Response Format

When your HTTPS request is successful, you will see the following four main fields in each response.

<table><thead><tr><th width="135">Field</th><th width="90">Type</th><th>Description</th></tr></thead><tbody><tr><td>request_id</td><td>String</td><td>The unique id for the current request. If you have any questions or concerns regarding the results of this request, please send us the request ID for review.</td></tr><tr><td>code</td><td>Integer</td><td>The request's status code. A code of 200000 indicates a successful request, while other codes indicate errors. The table below provides a comprehensive list of codes and their meanings.</td></tr><tr><td>message</td><td>String</td><td>Information regarding the code.</td></tr><tr><td>data</td><td>-</td><td>Detailed results. This field is different according to each request. Please refer to the doc of each endpoint to get the details.</td></tr></tbody></table>

<table><thead><tr><th width="137">Code</th><th>Description</th></tr></thead><tbody><tr><td>200000</td><td>Success</td></tr><tr><td>400001</td><td>Unauthorized operation</td></tr><tr><td>400002</td><td>Request rate is too high. Please try again later.</td></tr><tr><td>400004</td><td>Invalid params</td></tr><tr><td>400005</td><td>User does not exist</td></tr><tr><td>400006</td><td>Server busy</td></tr><tr><td>400007</td><td>Invalid API key</td></tr><tr><td>400008</td><td>Invalid auth format</td></tr><tr><td>400009</td><td>The API key is expired</td></tr><tr><td>400010</td><td>404 not found!</td></tr><tr><td>400011</td><td>Invalid address. Please ensure that you have provided the correct chain and address.</td></tr><tr><td>400012</td><td>Daily request limit exceeded. Please try again tomorrow.</td></tr><tr><td>400013</td><td>Invalid params. Unsupported chain name</td></tr><tr><td>500000</td><td>Internal error</td></tr></tbody></table>


# Address Label API

The Address Label API enables users to fetch address labels and comprehensively understand an address from various perspectives. [It currently supports more than 25](#supported-networks) different blockchains, including Solana, Bitcoin, Tron, Ethereum, BSC and other EVM-compatible chains.

## Address Label

When using our API to look up an address, **we will return three types of labels to describe the address**.

### Entity

We use ***Entity*** to describe an address's owner or controller. If it's an EoA address, this means the entity that controls this EoA address (with the private key). For a smart contract, the entity can refer to their deployers (projects).

{% hint style="info" %}
**An address may have more than one entity.**

Assigning an entity to an address is primarily to establish a connection between a cryptocurrency address and a known organization or individual. However, there are cases where an address can be associated with multiple entities. In these cases, we will assign the **Main Entity and Complementary Entities.**

For instance, consider Alameda's deposit address on Binance. We can state that Binance exercises control over the private key of this address or that Alameda utilizes it. In such situations, **we designate Binance as the primary entity for this address while considering Alameda as a secondary or complementary entity**.
{% endhint %}

#### Entity Category

Most entities are organizations or services, while only a few represent individuals. Most entities are categorized into the following categories, which can help you understand their nature.

<table><thead><tr><th width="172">Category</th><th width="92">Code</th><th>Description</th></tr></thead><tbody><tr><td>ASSET MANAGEMENT</td><td>3001</td><td>Financial institutions that specialize in managing and investing assets on behalf of clients.</td></tr><tr><td>BRIDGE</td><td>3002</td><td>Protocols that facilitate the movement of assets and data between different blockchain networks.</td></tr><tr><td>CHILD ABUSE MATERIAL</td><td>3003</td><td>Forums and websites that facilitate the buying, selling, and distribution of child abuse material.</td></tr><tr><td>CLOUD MINING</td><td>3004</td><td>Services that allow individuals to rent processing power from remote data centers to mine cryptocurrency without managing physical hardware.</td></tr><tr><td>DAPP</td><td>3005</td><td>A decentralized application (dApp) is an application developed on a decentralized network, integrating a smart contract and a user interface. When a dApp does not fit into specific categories such as DEFI, it is placed under this general category. However, it may be categorized under newly added categories in the future.</td></tr><tr><td>DARK MARKET</td><td>3006</td><td>Illicit websites on the dark web that facilitate the buying and selling of illegal goods and services, including drugs, weapons, counterfeit currency, and stolen data.</td></tr><tr><td>DEFI</td><td>3007</td><td>DeFi apps, which are decentralized finance applications, provide peer-to-peer financial services on public blockchains. When a DeFi dApp does not fall into specific categories like DEX (Decentralized Exchange), it is placed under this general category. However, it may be categorized under newly added categories in the future.</td></tr><tr><td>DEX</td><td>3008</td><td>Peer-to-peer marketplaces where transactions occur directly between crypto traders.</td></tr><tr><td>DEX AGGREGATOR</td><td>3009</td><td>A platform that sources liquidity from various decentralized exchanges to provide optimal trade execution in terms of price and slippage</td></tr><tr><td>ECOMMERCE</td><td>3010</td><td>E-commerce platforms that support cryptocurrencies.</td></tr><tr><td>EXCHANGE</td><td>3011</td><td>Centralized platforms that enable individuals to buy, sell, and trade various cryptocurrencies.</td></tr><tr><td>FAUCET</td><td>3012</td><td>An app or a website that distributes small amounts of cryptocurrencies as a reward for completing easy tasks.</td></tr><tr><td>GAMBLING</td><td>3013</td><td>Online platforms that allow users to gamble using cryptocurrencies.</td></tr><tr><td>INFRASTRUCTURE</td><td>3014</td><td>Basic services or programs deployed on the blockchain, such as the ENS (Ethereum Name Service) service and Solana system programs.</td></tr><tr><td>NFT MARKETPLACE</td><td>3015</td><td>Platforms that facilitate the buying, selling, and creation of Non-Fungible Tokens (NFTs).</td></tr><tr><td>MINING POOL</td><td>3016</td><td>A mining pool is when individual crypto miners join together and pool their resources in order to improve their chances of obtaining a block reward.</td></tr><tr><td>MIXER</td><td>3017</td><td>A service that blends the cryptocurrencies of many users together to obfuscate the origins and owners of the funds.</td></tr><tr><td>PAYMENT PROCESSOR</td><td>3018</td><td>A service that processes payments in digital currencies and allows merchants to accept cryptocurrency payments.</td></tr><tr><td>RANSOMWARE</td><td>3019</td><td>Criminal gangs conducting extortion through ransomware.</td></tr><tr><td>WALLET</td><td>3020</td><td>Softwares or hardwares that enable users to store and use cryptocurrency.</td></tr><tr><td>OTC DESK</td><td>3021</td><td>Service providers offering OTC intermediary platforms, e.g., Binance, Coinbase.</td></tr><tr><td>GOVERNMENT</td><td>3022</td><td>Government institutions.</td></tr><tr><td>STAKING</td><td>3023</td><td>Staking-related projects.</td></tr><tr><td>STABLE COIN</td><td>3024</td><td>Stablecoin-related projects, including collateralized and algorithmic stablecoins.</td></tr><tr><td>LENDING</td><td>3025</td><td>Lending platforms.</td></tr><tr><td>YIELD FARMING</td><td>3026</td><td>Yield farming projects.</td></tr><tr><td>YIELD AGGREGATOR</td><td>3027</td><td>Yield aggregators.</td></tr><tr><td>DERIVATIVES</td><td>3028</td><td>Derivative trading platforms.</td></tr><tr><td>SERVICES</td><td>3029</td><td>One-stop DeFi service platforms offering LaunchPad, Staking, Swap, and other services.</td></tr><tr><td>LAUNCHPAD</td><td>3030</td><td>ICO platforms.</td></tr><tr><td>INDEXES</td><td>3031</td><td>Projects similar to traditional finance index funds.</td></tr><tr><td>PRIVACY</td><td>3032</td><td>Protocols that hide transaction information.</td></tr><tr><td>SYNTHETICS</td><td>3033</td><td>Synthetic asset-related projects.</td></tr><tr><td>INSURANCE</td><td>3034</td><td>Insurance-related projects.</td></tr><tr><td>SOCIALFI</td><td>3035</td><td>On-chain social networking.</td></tr><tr><td>GAMING</td><td>3036</td><td>Gaming-related projects.</td></tr><tr><td>ORACLE</td><td>3037</td><td>Projects connecting on-chain and off-chain data.</td></tr><tr><td>TRADING</td><td>3038</td><td>Projects that perform trading or help users trade (trading platforms).</td></tr><tr><td>UTILITY TOOL</td><td>3039</td><td>Practical blockchain tools for token management, distribution, etc.</td></tr><tr><td>NFT</td><td>3040</td><td>NFT projects.</td></tr><tr><td>DAO</td><td>3041</td><td>DAO organizations.</td></tr><tr><td>SCAM</td><td>3042</td><td>Scam-related groups.</td></tr><tr><td>LIQUIDITY MANAGER</td><td>3043</td><td>Liquidity management projects.</td></tr><tr><td>Options</td><td>3044</td><td>Options-related projects.</td></tr><tr><td>RWA</td><td>3045</td><td>Real-world asset-related projects.</td></tr><tr><td>RESERVE CURRENCY</td><td>3046</td><td>Reserve currency-related projects.</td></tr><tr><td>INDIVIDUAL</td><td>3047</td><td>Individual related accounts.</td></tr><tr><td>CELEBRITY</td><td>3048</td><td>Celebrities, etc.</td></tr><tr><td>TERRORIST</td><td>3049</td><td>Entities that use violence or threats to intimidate populations or governments for political or ideological aims.</td></tr></tbody></table>

### Attribute

We use ***Attribute*** to describe the behavior or action associated with a specific address or entity. All attributes are listed in the table below.

<table><thead><tr><th width="163">Attribute</th><th width="92">Code</th><th>Description</th></tr></thead><tbody><tr><td>ATTACKER</td><td>4001</td><td>Addresses involved in attack events, such as contract exploits, private key hacks, or extortions.</td></tr><tr><td>BLOCKED</td><td>4002</td><td>Addresses that have been blocked by critical contracts, primarily USDT and USDC.</td></tr><tr><td>COLD WALLET</td><td>4004</td><td>A cold wallet refers to a type of cryptocurrency wallet that is stored offline and is not connected to the internet.</td></tr><tr><td>DARKWEB BUSINESS</td><td>4006</td><td>Addresses involved in dark web businesses, encompassing activities such as drugs, weapons, abuse, and other illicit practices.</td></tr><tr><td>DEPOSIT ADDRESS</td><td>4007</td><td>The deposit address here refers to the address used by the centralized platform to receive user deposits, and typically, each user is assigned their own unique deposit address.</td></tr><tr><td>HOT WALLET</td><td>4009</td><td>A hot wallet is a type of cryptocurrency wallet that is connected to the internet and is actively used for transactions and day-to-day cryptocurrency management.</td></tr><tr><td>LAUNDERING</td><td>4011</td><td>The addresses and entities associated with this attribute are believed to engage in money laundering activities.</td></tr><tr><td>MIXING</td><td>4012</td><td>This label is attributed to services or addresses (primarily contracts) that are believed to possess the capability to obfuscate fund flows.</td></tr><tr><td>NO KYC</td><td>4013</td><td>The VASP (Virtual Asset Service Provider) associated with the address does not have a KYC (Know Your Customer) procedure in place.</td></tr><tr><td>RETURN FUNDS</td><td>4014</td><td>Address utilized for executing an attack or exploit, followed by the subsequent return of funds. This individual could be a white hat hacker or someone who reached a settlement with the project team.</td></tr><tr><td>SANCTIONED</td><td>4015</td><td>The cryptocurrency address associated with individuals or organizations subject to sanctions.</td></tr><tr><td>SCAM</td><td>4016</td><td>The addresses associated with individuals or organizations involved in fraudulent activities, including phishing, honeypots, Ponzi schemes, and more.</td></tr><tr><td>SUSPICIOUS</td><td>4017</td><td>Addresses showing unusual patterns that may indicate illegal activities or money laundering attempts.However, it is not currently possible to determine what type of illegal activity this is.</td></tr><tr><td>EXPLOIT</td><td>4018</td><td>Address involved in one or more attacks.</td></tr><tr><td>WHITE HAT</td><td>4019</td><td>The 'White Hat' attribute designates an address associated with individuals or entities known for ethical practices in cybersecurity, typically engaging in activities that aid in identifying and resolving security vulnerabilities lawfully and constructively.</td></tr></tbody></table>

### Name Tag

A name is utilized to describe a cryptocurrency address with human-readable information. Assigning names usually considers the entity associated with the address and its specific attributes, such as Binance Hot Wallet 1 or Vitalik 2.

## Supported Networks

The Address Label API supports 25 different chains, which are listed in the chart below. We also provide an [APIs](/blocksec-aml-api/address-label-api/apis#get-supported-chains) that allows you to retrieve a list of all supported chains, enabling you to stay informed about any newly added chains.

{% hint style="info" %}
When making an API request, please use the **Chain ID** to specify the desired chain.
{% endhint %}

| Network Name             | Short Name    | Chain ID   |
| ------------------------ | ------------- | ---------- |
| Solana                   | SOLANA        | -3         |
| Tron                     | TRX           | -2         |
| Bitcoin Mainnet          | BTC           | -1         |
| Ethereum Mainnet         | ETH           | 1          |
| Optimism Mainnet         | OPTIMISM      | 10         |
| Cronos Mainnet           | CRONOS        | 25         |
| BNB Smart Chain Mainnet  | BSC           | 56         |
| Gnosis                   | GNOSIS        | 100        |
| Polygon Mainnet          | POLYGON       | 137        |
| BitTorrent Chain Mainnet | BITTORRENT    | 199        |
| Fantom                   | FANTOM        | 250        |
| Boba Network             | BOBA          | 288        |
| zkSync Era Mainnet       | ZKSYNC ERA    | 324        |
| CLV Parachain            | CLV           | 1024       |
| Polygon zkEvm            | POLYGON ZKEVM | 1101       |
| WEMIX3.0 Mainnet         | WEMIX         | 1111       |
| Moonbeam                 | MOONBEAM      | 1284       |
| Moonriver                | MOONRIVER     | 1285       |
| Base                     | BASE          | 8453       |
| Arbitrum One             | ARBITRUM      | 42161      |
| Celo Mainnet             | CELO          | 42220      |
| Avalanche C-Chain        | AVALANCHE     | 43114      |
| Linea                    | LINEA         | 59144      |
| Blast Mainnet            | BLAST         | 81457      |
| Aurora Mainnet           | AURORA        | 1313161554 |

## Subscription

{% hint style="success" %}
Subscribe to [our plan](https://metasleuth.io/plans#apis) to use this API in your service to help meet the compliance requirements and secure users' assets.
{% endhint %}


# APIs

## Subscription

{% hint style="success" %}
Subscribe to [our plan](https://metasleuth.io/plans#apis) to use this API in your service to help meet the compliance requirements and save users' assets.
{% endhint %}

## Get Supported Chains

## Get a list of supported chains

> Retrieve a list of all blockchains supported by the address label APIs

```json
{"openapi":"3.1.1","info":{"title":"address label api","version":"3.1"},"servers":[{"url":"https://aml.blocksec.com/address-label/api/v3"}],"security":[{"apiKey":[]}],"components":{"securitySchemes":{"apiKey":{"type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"response.ApiResponse":{"type":"object","properties":{"code":{"description":"Error code, 200000 means no error","allOf":[{"$ref":"#/components/schemas/err.BizCode"}]},"message":{"description":"Prompt message","type":"string"},"request_id":{"description":"The unique ID of the request","type":"string"}}},"err.BizCode":{"type":"integer","enum":[200000,400000,400001,400002,400003,400004,400005,400006,400007,400008,400009,400010,400011,400012,400013,400014,400015,400016,500000]},"chain.ChainResponse":{"type":"object","properties":{"chain_id":{"type":"integer"},"chain_name":{"type":"string"}}}}},"paths":{"/chain-list":{"get":{"description":"Retrieve a list of all blockchains supported by the address label APIs","tags":["chains"],"summary":"Get a list of supported chains","responses":{"200":{"description":"OK","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/chain.ChainResponse"}}}}]}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"object"}}}]}}}}}}}}}
```

## Get Address Labels

## Get the label of a single address.

> Retrieve detailed label information of a specific address on a particular chain.

```json
{"openapi":"3.1.1","info":{"title":"address label api","version":"3.1"},"servers":[{"url":"https://aml.blocksec.com/address-label/api/v3"}],"security":[{"apiKey":[]}],"components":{"securitySchemes":{"apiKey":{"type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"response.ApiResponse":{"type":"object","properties":{"code":{"description":"Error code, 200000 means no error","allOf":[{"$ref":"#/components/schemas/err.BizCode"}]},"message":{"description":"Prompt message","type":"string"},"request_id":{"description":"The unique ID of the request","type":"string"}}},"err.BizCode":{"type":"integer","enum":[200000,400000,400001,400002,400003,400004,400005,400006,400007,400008,400009,400010,400011,400012,400013,400014,400015,400016,500000]},"common.AddressResponse":{"description":"Detailed address information including chain and entity details","type":"object","properties":{"address":{"description":"Blockchain address","type":"string"},"attributes":{"description":"Address attributes","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"chain_id":{"description":"Chain ID","type":"integer"},"comp_entity":{"description":"Complementary entity name","type":"string"},"comp_entity_info":{"description":"Complementary entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"main_entity":{"description":"Main entity name","type":"string"},"main_entity_info":{"description":"Main entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"name_tag":{"description":"Custom name tag","type":"string"}}},"common.AttributeInfo":{"description":"Attribute information with name, code and details","type":"object","properties":{"code":{"description":"Attribute code","type":"integer"},"comp_info":{"description":"Additional attribute details","type":"array","items":{"type":"string"}},"name":{"description":"Attribute name","type":"string"}}},"common.EntityResponse":{"description":"Entity information including name, categories, attributes and description","type":"object","properties":{"attributes":{"description":"Attributes of the entity","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"categories":{"description":"Categories of the entity","type":"array","items":{"$ref":"#/components/schemas/common.CategoryInfo"}},"description":{"description":"Detailed description of the entity","allOf":[{"$ref":"#/components/schemas/model.Description"}]},"entity":{"description":"Entity name","type":"string"}}},"common.CategoryInfo":{"description":"Category information with name and code","type":"object","properties":{"code":{"description":"Category code","type":"integer"},"name":{"description":"Category name","type":"string"}}},"model.Description":{"type":"object","properties":{"discord":{"type":"string"},"telegram":{"type":"string"},"twitter":{"type":"string"},"website":{"type":"string"}}},"address.labelByAddressReq":{"type":"object","required":["address","chain_id"],"properties":{"address":{"type":"string"},"chain_id":{"type":"integer"}}}}},"paths":{"/labels":{"post":{"description":"Retrieve detailed label information of a specific address on a particular chain.","tags":["address"],"summary":"Get the label of a single address.","responses":{"200":{"description":"OK","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"$ref":"#/components/schemas/common.AddressResponse"}}}]}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/response.ApiResponse"}}}}},"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/address.labelByAddressReq"}}},"description":"Request body with chain and address","required":true}}}}}
```

## Get Address Labels in Batch

## Get the labels of multiple addresses on the same chain in batch

> Retrieve detailed label information of a list of addresses on a particular chain.

```json
{"openapi":"3.1.1","info":{"title":"address label api","version":"3.1"},"servers":[{"url":"https://aml.blocksec.com/address-label/api/v3"}],"security":[{"apiKey":[]}],"components":{"securitySchemes":{"apiKey":{"type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"response.ApiResponse":{"type":"object","properties":{"code":{"description":"Error code, 200000 means no error","allOf":[{"$ref":"#/components/schemas/err.BizCode"}]},"message":{"description":"Prompt message","type":"string"},"request_id":{"description":"The unique ID of the request","type":"string"}}},"err.BizCode":{"type":"integer","enum":[200000,400000,400001,400002,400003,400004,400005,400006,400007,400008,400009,400010,400011,400012,400013,400014,400015,400016,500000]},"common.AddressResponse":{"description":"Detailed address information including chain and entity details","type":"object","properties":{"address":{"description":"Blockchain address","type":"string"},"attributes":{"description":"Address attributes","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"chain_id":{"description":"Chain ID","type":"integer"},"comp_entity":{"description":"Complementary entity name","type":"string"},"comp_entity_info":{"description":"Complementary entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"main_entity":{"description":"Main entity name","type":"string"},"main_entity_info":{"description":"Main entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"name_tag":{"description":"Custom name tag","type":"string"}}},"common.AttributeInfo":{"description":"Attribute information with name, code and details","type":"object","properties":{"code":{"description":"Attribute code","type":"integer"},"comp_info":{"description":"Additional attribute details","type":"array","items":{"type":"string"}},"name":{"description":"Attribute name","type":"string"}}},"common.EntityResponse":{"description":"Entity information including name, categories, attributes and description","type":"object","properties":{"attributes":{"description":"Attributes of the entity","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"categories":{"description":"Categories of the entity","type":"array","items":{"$ref":"#/components/schemas/common.CategoryInfo"}},"description":{"description":"Detailed description of the entity","allOf":[{"$ref":"#/components/schemas/model.Description"}]},"entity":{"description":"Entity name","type":"string"}}},"common.CategoryInfo":{"description":"Category information with name and code","type":"object","properties":{"code":{"description":"Category code","type":"integer"},"name":{"description":"Category name","type":"string"}}},"model.Description":{"type":"object","properties":{"discord":{"type":"string"},"telegram":{"type":"string"},"twitter":{"type":"string"},"website":{"type":"string"}}},"address.labelByAddressesReq":{"type":"object","required":["addresses","chain_id"],"properties":{"addresses":{"type":"array","items":{"type":"string"}},"chain_id":{"type":"integer"}}}}},"paths":{"/batch-labels":{"post":{"description":"Retrieve detailed label information of a list of addresses on a particular chain.","tags":["address"],"summary":"Get the labels of multiple addresses on the same chain in batch","responses":{"200":{"description":"OK","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/common.AddressResponse"}}}}]}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/response.ApiResponse"}}}}},"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/address.labelByAddressesReq"}}},"description":"Request body with chain and addresses","required":true}}}}}
```

## Get Address Labels Across Multiple Chains in Batch

## Get address labels across multiple chains

> Retrieve address labels for multiple addresses across specified blockchain networks

```json
{"openapi":"3.1.1","info":{"title":"address label api","version":"3.1"},"servers":[{"url":"https://aml.blocksec.com/address-label/api/v3"}],"security":[{"apiKey":[]}],"components":{"securitySchemes":{"apiKey":{"type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"response.ApiResponse":{"type":"object","properties":{"code":{"description":"Error code, 200000 means no error","allOf":[{"$ref":"#/components/schemas/err.BizCode"}]},"message":{"description":"Prompt message","type":"string"},"request_id":{"description":"The unique ID of the request","type":"string"}}},"err.BizCode":{"type":"integer","enum":[200000,400000,400001,400002,400003,400004,400005,400006,400007,400008,400009,400010,400011,400012,400013,400014,400015,400016,500000]},"common.BatchAddressesResponse":{"description":"Response containing multiple addresses for a specific chain","type":"object","properties":{"addresses":{"description":"List of addresses","type":"array","items":{"$ref":"#/components/schemas/common.AddressResponse"}},"chain_id":{"description":"Chain ID","type":"integer"}}},"common.AddressResponse":{"description":"Detailed address information including chain and entity details","type":"object","properties":{"address":{"description":"Blockchain address","type":"string"},"attributes":{"description":"Address attributes","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"chain_id":{"description":"Chain ID","type":"integer"},"comp_entity":{"description":"Complementary entity name","type":"string"},"comp_entity_info":{"description":"Complementary entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"main_entity":{"description":"Main entity name","type":"string"},"main_entity_info":{"description":"Main entity detailed information","allOf":[{"$ref":"#/components/schemas/common.EntityResponse"}]},"name_tag":{"description":"Custom name tag","type":"string"}}},"common.AttributeInfo":{"description":"Attribute information with name, code and details","type":"object","properties":{"code":{"description":"Attribute code","type":"integer"},"comp_info":{"description":"Additional attribute details","type":"array","items":{"type":"string"}},"name":{"description":"Attribute name","type":"string"}}},"common.EntityResponse":{"description":"Entity information including name, categories, attributes and description","type":"object","properties":{"attributes":{"description":"Attributes of the entity","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"categories":{"description":"Categories of the entity","type":"array","items":{"$ref":"#/components/schemas/common.CategoryInfo"}},"description":{"description":"Detailed description of the entity","allOf":[{"$ref":"#/components/schemas/model.Description"}]},"entity":{"description":"Entity name","type":"string"}}},"common.CategoryInfo":{"description":"Category information with name and code","type":"object","properties":{"code":{"description":"Category code","type":"integer"},"name":{"description":"Category name","type":"string"}}},"model.Description":{"type":"object","properties":{"discord":{"type":"string"},"telegram":{"type":"string"},"twitter":{"type":"string"},"website":{"type":"string"}}},"address.labelByChainsAddressesReq":{"type":"object","required":["addresses","chains"],"properties":{"addresses":{"type":"array","items":{"type":"string"}},"chains":{"type":"array","items":{"type":"integer"}}}}}},"paths":{"/multi-chains-labels":{"post":{"description":"Retrieve address labels for multiple addresses across specified blockchain networks","tags":["address"],"summary":"Get address labels across multiple chains","responses":{"200":{"description":"Successfully returned address labels","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/common.BatchAddressesResponse"}}}}]}}}},"400":{"description":"Invalid request parameters","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"object"}}}]}}}},"500":{"description":"Internal server error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"object"}}}]}}}}},"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/address.labelByChainsAddressesReq"}}},"description":"Multi-chain address label request","required":true}}}}}
```

{% hint style="info" %}
The quota consumed is calculated as follows:

**Quota = Number of Addresses × Number of Chains.**

For example, querying 3 addresses on 2 chains consumes a total of 6 quotas (3 × 2 = 6).
{% endhint %}

## Get Entity Info

## Get entity information by entity name

> Retrieve detailed information based on the provided entity name, supporting suffix matching

```json
{"openapi":"3.1.1","info":{"title":"address label api","version":"3.1"},"servers":[{"url":"https://aml.blocksec.com/address-label/api/v3"}],"security":[{"apiKey":[]}],"components":{"securitySchemes":{"apiKey":{"type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"response.ApiResponse":{"type":"object","properties":{"code":{"description":"Error code, 200000 means no error","allOf":[{"$ref":"#/components/schemas/err.BizCode"}]},"message":{"description":"Prompt message","type":"string"},"request_id":{"description":"The unique ID of the request","type":"string"}}},"err.BizCode":{"type":"integer","enum":[200000,400000,400001,400002,400003,400004,400005,400006,400007,400008,400009,400010,400011,400012,400013,400014,400015,400016,500000]},"common.EntityResponse":{"description":"Entity information including name, categories, attributes and description","type":"object","properties":{"attributes":{"description":"Attributes of the entity","type":"array","items":{"$ref":"#/components/schemas/common.AttributeInfo"}},"categories":{"description":"Categories of the entity","type":"array","items":{"$ref":"#/components/schemas/common.CategoryInfo"}},"description":{"description":"Detailed description of the entity","allOf":[{"$ref":"#/components/schemas/model.Description"}]},"entity":{"description":"Entity name","type":"string"}}},"common.AttributeInfo":{"description":"Attribute information with name, code and details","type":"object","properties":{"code":{"description":"Attribute code","type":"integer"},"comp_info":{"description":"Additional attribute details","type":"array","items":{"type":"string"}},"name":{"description":"Attribute name","type":"string"}}},"common.CategoryInfo":{"description":"Category information with name and code","type":"object","properties":{"code":{"description":"Category code","type":"integer"},"name":{"description":"Category name","type":"string"}}},"model.Description":{"type":"object","properties":{"discord":{"type":"string"},"telegram":{"type":"string"},"twitter":{"type":"string"},"website":{"type":"string"}}},"entity.requestByEntity":{"type":"object","required":["entity"],"properties":{"entity":{"type":"string"}}}}},"paths":{"/entity":{"post":{"description":"Retrieve detailed information based on the provided entity name, supporting suffix matching","tags":["entity"],"summary":"Get entity information by entity name","responses":{"200":{"description":"OK","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"$ref":"#/components/schemas/common.EntityResponse"}}}]}}}},"400":{"description":"Parameter error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"string"}}}]}}}},"500":{"description":"Internal service error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/response.ApiResponse"},{"type":"object","properties":{"data":{"type":"string"}}}]}}}}},"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/entity.requestByEntity"}}},"description":"Entity query request","required":true}}}}}
```


# Risk Score API

The **Risk Score API** evaluates the risk level associated with a given address. When an address is assessed as high-risk, the API also returns detailed insights explaining the key factors contributing to that risk.

Please note that this API analyzes only the target address and its **one-hop** related addresses. For a comprehensive crypto-compliance solution—such as a fully featured **Know-Your-Address (KYA)** API—refer to the [**BlockSec Phalcon Compliance App**](https://blocksec.com/phalcon/compliance), which offers a free trial account.

## How is risk assessed?

When assessing the risk of an address, we take into account several key factors, including its type, attributes, associated entities, and on-chain interactions. The address type indicates whether it is an **EOA (Externally Owned Account)** or a **CA (Contract Account)**. The concepts of *attributes* and *entities* are [explored in detail in this document](/blocksec-aml-api/address-label-api#whats-an-address-label). On-chain interactions refer to the specific blockchain transactions and activities in which the address has participated.

Among the information involved in the assessment, certain factors influence the assessment strategy, while others serve as critical risk indicators that significantly affect the assessment results. The following are the leading risk indicators used in our methodology, which can also be obtained through [APIs](/blocksec-aml-api/wallet-screening-api/apis#get-risk-indicators) requests to stay informed about any changes in risk indicators.

<table><thead><tr><th width="180">Risk Indicator</th><th width="86">Code</th><th>Description</th></tr></thead><tbody><tr><td>NO KYC</td><td>5020</td><td>The VASP (Virtual Asset Service Provider) associated with the address does not have a KYC (Know Your Customer) procedure in place.</td></tr><tr><td>BLOCKED</td><td>5018</td><td>The address has been blacklisted by critical contracts, primarily USDT and USDC.</td></tr><tr><td>SUSPICIOUS</td><td>5017</td><td>Address with suspicious activities.</td></tr><tr><td>COMPROMISED</td><td>5013</td><td>This address is deemed at risk, either due to being an externally owned account (EOA) with a weak key or a contract that is susceptible to exploitation.</td></tr><tr><td>GAMBLING</td><td>5016</td><td>The entity associated with this address is a gambling platform.</td></tr><tr><td>MIXING</td><td>5008</td><td>The address, primarily a contract, or associated service is believed to possess the capability to obfuscate fund flows.</td></tr><tr><td>LAUNDERING</td><td>5034</td><td>The addresses and entities associated with this label are believed to engage in money laundering activities.</td></tr><tr><td>CHILD ABUSE MATERIAL</td><td>5002</td><td>The entity associated with this address has been identified as forums and websites that facilitate the buying, selling, and distribution of child abuse material.</td></tr><tr><td>MIXER</td><td>5003</td><td>The entity associated with this address has been classified as a mixer.</td></tr><tr><td>DARKWEB BUSINESS</td><td>5001</td><td>This address has been involved in illicit businesses within the dark web.</td></tr><tr><td>DARK MARKET</td><td>5010</td><td>The entity associated with this address is a dark web marketplace.</td></tr><tr><td>ATTACKER</td><td>5012</td><td>This address is involved in a cyber attack.</td></tr><tr><td>RANSOMWARE</td><td>5009</td><td>The entity affiliated with this address is a ransomware group.</td></tr><tr><td>SCAM</td><td>5005</td><td>This address is engaged in fraudulent activities.</td></tr><tr><td>SANCTIONED</td><td>5006</td><td>The entity associated with this address has been sanctioned.</td></tr><tr><td>EXPLOIT</td><td>5040</td><td>The attacker or the attacker's contract or the attacker transfers funds and other addresses related to the attacker.</td></tr><tr><td>TERRORIST</td><td>5043</td><td>Entities that use violence or threats to intimidate populations or governments for political or ideological aims.</td></tr></tbody></table>

### Interpreting the risk score

Based on the risk assessment algorithm mentioned earlier, we classify an address's compliance risk into five levels, represented by **scores ranging from 1 to 5**. A higher score indicates a higher compliance risk associated with that address.

For addresses with a score of **4 or higher**, it is advisable to refrain from interacting with them. For addresses with a score of 3, it is recommended to carefully consider the accompanying indicators to determine whether it is appropriate to engage with them.

### Individual risk vs. Interaction risk

Based on how we identify risks, we categorize them into Individual and interaction risk&#x73;**. Individual risk primarily stems from the attributes and behavior of the address itself, while interaction risk arises from the address's involvement in risky on-chain transactions.**

By default, we consider Individual and interaction risks to provide the final result. However, due to the temporary lack of support for interaction risk in some networks (refer to the [Supported Networks ](#supported-networks)section) and the longer calculation time required for interaction risk, we offer the option to specify whether to include the calculation of interaction risk when requesting compliance risk for an address.

## Supported networks

<table><thead><tr><th width="207">Network Name</th><th width="172">Short Name</th><th width="117">Chain ID</th><th>Support for interaction risk</th></tr></thead><tbody><tr><td>Solana</td><td>SOLANA</td><td>-3</td><td><code>True</code></td></tr><tr><td>Tron</td><td>TRX</td><td>-2</td><td><code>True</code></td></tr><tr><td>Bitcoin Mainnet</td><td>BTC</td><td>-1</td><td><code>True</code></td></tr><tr><td>Ethereum Mainnet</td><td>ETH</td><td>1</td><td><code>True</code></td></tr><tr><td>Optimism Mainnet</td><td>OPTIMISM</td><td>10</td><td><code>True</code></td></tr><tr><td>Cronos Mainnet</td><td>CRONOS</td><td>25</td><td><code>False</code></td></tr><tr><td>BNB Smart Chain Mainnet</td><td>BSC</td><td>56</td><td><code>True</code></td></tr><tr><td>Gnosis</td><td>GNOSIS</td><td>100</td><td><code>False</code></td></tr><tr><td>Polygon Mainnet</td><td>POLYGON</td><td>137</td><td><code>True</code></td></tr><tr><td>BitTorrent Chain Mainnet</td><td>BITTORRENT</td><td>199</td><td><code>False</code></td></tr><tr><td>Fantom</td><td>FANTOM</td><td>250</td><td><code>False</code></td></tr><tr><td>Boba Network</td><td>BOBA</td><td>288</td><td><code>False</code></td></tr><tr><td>zkSync Era Mainnet</td><td>ZKSYNC ERA</td><td>324</td><td><code>False</code></td></tr><tr><td>CLV Parachain</td><td>CLV</td><td>1024</td><td><code>False</code></td></tr><tr><td>Polygon zkEvm</td><td>POLYGON ZKEVM</td><td>1101</td><td><code>False</code></td></tr><tr><td>WEMIX3.0 Mainnet</td><td>WEMIX</td><td>1111</td><td><code>False</code></td></tr><tr><td>Moonbeam</td><td>MOONBEAM</td><td>1284</td><td><code>False</code></td></tr><tr><td>Mantle</td><td>MANTLE</td><td>5000</td><td><code>True</code></td></tr><tr><td>Moonriver</td><td>MOONRIVER</td><td>1285</td><td><code>False</code></td></tr><tr><td>Base</td><td>BASE</td><td>8453</td><td><code>True</code></td></tr><tr><td>Arbitrum One</td><td>ARBITRUM</td><td>42161</td><td><code>True</code></td></tr><tr><td>Celo Mainnet</td><td>CELO</td><td>42220</td><td><code>False</code></td></tr><tr><td>Avalanche C-Chain</td><td>AVALANCHE</td><td>43114</td><td><code>True</code></td></tr><tr><td>Linea</td><td>LINEA</td><td>59144</td><td><code>True</code></td></tr><tr><td>Blast Mainnet</td><td>BLAST</td><td>81457</td><td><code>False</code></td></tr><tr><td>Aurora Mainnet</td><td>AURORA</td><td>1313161554</td><td><code>False</code></td></tr></tbody></table>

{% hint style="info" %}
**What does 'Support for interaction risk' mean?**

When evaluating risks, we distinguish between [Individual and Interaction risks](#individual-risk-vs.-interaction-risk) based on their origins. It is worth noting that calculating interaction risk may require additional resources that may not be readily available in specific networks. If a network supports Interaction risk, querying an address on that blockchain will yield a more thorough evaluation result.
{% endhint %}

## Subscription

{% hint style="success" %}
Subscribe to [our plan](https://metasleuth.io/plans#apis) to use this API in your service to help meet the compliance requirements and secure users' assets.
{% endhint %}


# APIs

## Subscription

{% hint style="success" %}
Subscribe to [our plan](https://metasleuth.io/plans#apis) to use this API in your service to help meet the compliance requirements and save users' assets.
{% endhint %}

## Get Supported Chains

## GET /chain-list

> Get the list of supported chains.

```json
{"openapi":"3.0.0","info":{"title":"Compliance API powered by BlockSec Address Label database and risk assessment","version":"3.0"},"servers":[{"url":"https://aml.blocksec.com/address-compliance/api/v3","description":"Get label and related information of addresses."}],"security":[{"APIKey":[]}],"components":{"securitySchemes":{"APIKey":{"description":"Add your api key in header (API-KEY) for authentication","type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"ApiResponse":{"type":"object","properties":{"request_id":{"type":"string","description":"The unique ID of the request."},"code":{"type":"integer","description":"Error code, 200000 means no error."},"message":{"type":"string","description":"Prompt message."},"data":{"nullable":true,"description":"Response data."}}}}},"paths":{"/chain-list":{"get":{"summary":"Get the list of supported chains.","parameters":[{"in":"header","name":"API-KEY","schema":{"type":"string"},"required":true}],"responses":{"200":{"description":"A successful resquest","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"type":"object","properties":{"request_id":{"type":"string"},"code":{"type":"integer"},"message":{"type":"string"},"data":{"type":"array","items":{"type":"object","properties":{"chain_id":{"type":"integer","description":"Unique identifier for the chain. In accordance with the chain IDs listed in the 'Supported Networks' section."},"chain_name":{"type":"string","description":"The short name of the chain. In accordance with the short names listed in the 'Supported Networks' section."},"support_interaction_risk":{"type":"boolean","description":"Indicates whether the current API supports calculating interaction risk for this chain."}}}}}}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiResponse"}}}}}}}}}
```

## Get Risk Indicators

## GET /risk-items

> Retrieve a comprehensive list of all risk indicators.

```json
{"openapi":"3.0.0","info":{"title":"Compliance API powered by BlockSec Address Label database and risk assessment","version":"3.0"},"servers":[{"url":"https://aml.blocksec.com/address-compliance/api/v3","description":"Get label and related information of addresses."}],"security":[{"APIKey":[]}],"components":{"securitySchemes":{"APIKey":{"description":"Add your api key in header (API-KEY) for authentication","type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"ApiResponse":{"type":"object","properties":{"request_id":{"type":"string","description":"The unique ID of the request."},"code":{"type":"integer","description":"Error code, 200000 means no error."},"message":{"type":"string","description":"Prompt message."},"data":{"nullable":true,"description":"Response data."}}}}},"paths":{"/risk-items":{"get":{"summary":"Retrieve a comprehensive list of all risk indicators.","parameters":[{"in":"header","name":"API-KEY","schema":{"type":"string"},"required":true}],"responses":{"200":{"description":"A successful resquest","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"type":"object","properties":{"request_id":{"type":"string"},"code":{"type":"integer"},"message":{"type":"string"},"data":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string","description":"Indicator string."},"code":{"type":"string","description":"Indicator code."}}}}}}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiResponse"}}}}}}}}}
```

## Get Address Risk Score

## POST /risk-score

> Retrieve the address's risk score and all associated risk indicators.

```json
{"openapi":"3.0.0","info":{"title":"Compliance API powered by BlockSec Address Label database and risk assessment","version":"3.0"},"servers":[{"url":"https://aml.blocksec.com/address-compliance/api/v3","description":"Get label and related information of addresses."}],"security":[{"APIKey":[]}],"components":{"securitySchemes":{"APIKey":{"description":"Add your api key in header (API-KEY) for authentication","type":"apiKey","name":"API-KEY","in":"header"}},"headers":{"Access-Control-Allow-Origin":{"description":"Origin allowed by the API CORS policy.","schema":{"type":"string"}},"Access-Control-Expose-Headers":{"description":"Response headers exposed to browser JavaScript clients.","schema":{"type":"string"}},"Strict-Transport-Security":{"description":"Instructs browsers to access the API only over HTTPS.","schema":{"type":"string"}},"X-Content-Type-Options":{"description":"Prevents browsers from MIME-sniffing the response content type.","schema":{"type":"string"}},"X-Frame-Options":{"description":"Controls whether the response can be embedded in a frame.","schema":{"type":"string"}},"X-RateLimit-Cost":{"description":"Points charged by this response.","schema":{"type":"integer"}},"X-RateLimit-Limit":{"description":"Daily point limit for the API key.","schema":{"type":"integer"}},"X-RateLimit-Remaining":{"description":"Remaining points after this response.","schema":{"type":"integer"}},"X-RateLimit-Reset":{"description":"Next UTC 00:00 reset time as a Unix timestamp.","schema":{"type":"integer","format":"int64"}},"X-RateLimit-Used":{"description":"Used points after this response.","schema":{"type":"integer"}}},"schemas":{"ApiResponse":{"type":"object","properties":{"request_id":{"type":"string","description":"The unique ID of the request."},"code":{"type":"integer","description":"Error code, 200000 means no error."},"message":{"type":"string","description":"Prompt message."},"data":{"nullable":true,"description":"Response data."}}}}},"paths":{"/risk-score":{"post":{"summary":"Retrieve the address's risk score and all associated risk indicators.","parameters":[{"in":"header","name":"API-KEY","schema":{"type":"string"},"required":true}],"requestBody":{"content":{"application/json":{"schema":{"type":"object","properties":{"chain_id":{"type":"integer","description":"Chain ID. Please refer to the 'Supported Networks' section for specific IDs."},"address":{"type":"string","description":"The specific address you want to query. EVM addresses are case-insensitive, while non-EVM addresses are case-sensitive."},"interaction_risk":{"type":"boolean","description":"Whether to calculate the interaction risk of the queried address."}}}}}},"responses":{"200":{"description":"A successful request","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"type":"object","properties":{"request_id":{"type":"string"},"code":{"type":"integer"},"message":{"type":"string"},"data":{"type":"object","properties":{"chain_id":{"type":"integer","description":"Chain ID."},"address":{"type":"string","description":"The queried address."},"risk_score":{"type":"integer","description":"Risk score."},"risk_indicators":{"type":"array","description":"Relevant risk indicators","items":{"type":"object","properties":{"type":{"type":"string","description":"Individual Risk / Interaction Risk"},"indicator":{"type":"object","properties":{"name":{"type":"string","description":"The indicator string."},"code":{"type":"integer","description":"The indicator code."}}},"source":{"type":"string","description":"The source address to which the risk indicator of type 'Interaction Risk' belongs."},"risk_interactions":{"type":"array","items":{"type":"object","properties":{"block_number":{"type":"integer","description":"The block number where the funds are transferred."},"timestamp":{"type":"string","format":"unix-timestamp","description":"Timestamp of the block number."},"tx_hash":{"type":"string","description":"Transaction hash of transfer."},"from":{"type":"string","description":"The source address (sender) of the transfer."},"to":{"type":"string","description":"The destination address (recipient) of the transfer."},"token_contract":{"type":"string","description":"The token contract address of the transfer. Returns \"-\" string for native token transfers."},"token_symbol":{"type":"string","description":"The token symbol (e.g., Ether, USDT, DAI)."},"amount":{"type":"number","description":"The amount of tokens transferred, scaled by the token's decimals."},"usd_value":{"type":"number","format":"float","description":"The USD value of the transfer at the time of transaction."}}}}}}}}}}}}}},"400":{"description":"Invalid request parameters","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiResponse"}}}},"500":{"description":"Internal Server Error","headers":{"Access-Control-Allow-Origin":{"$ref":"#/components/headers/Access-Control-Allow-Origin"},"Access-Control-Expose-Headers":{"$ref":"#/components/headers/Access-Control-Expose-Headers"},"Strict-Transport-Security":{"$ref":"#/components/headers/Strict-Transport-Security"},"X-Content-Type-Options":{"$ref":"#/components/headers/X-Content-Type-Options"},"X-Frame-Options":{"$ref":"#/components/headers/X-Frame-Options"},"X-RateLimit-Cost":{"$ref":"#/components/headers/X-RateLimit-Cost"},"X-RateLimit-Limit":{"$ref":"#/components/headers/X-RateLimit-Limit"},"X-RateLimit-Remaining":{"$ref":"#/components/headers/X-RateLimit-Remaining"},"X-RateLimit-Reset":{"$ref":"#/components/headers/X-RateLimit-Reset"},"X-RateLimit-Used":{"$ref":"#/components/headers/X-RateLimit-Used"}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiResponse"}}}}}}}}}
```


# 介绍

什么是MetaSleuth

MetaSleuth是一个加密货币跟踪和调查平台。它可以帮助监控市场动态，跟踪犯罪活动的资金流，并通过DYOR（自行研究）来避免骗局。

:detective: **每个人都可以在加密世界中成为侦探并进行DYOR！**

{% hint style="info" %}
体验一下 -> <https://metasleuth.io>
{% endhint %}

{% hint style="info" %}
MetaSleuth资源

* <https://github.com/blocksecteam/metasleuth_resources>
  {% endhint %}

## 功能

* 智能分析：MetaSleuth将基于我们的智能分析引擎为给定地址自动提供最有价值的交互。
* 跨链分析：MetaSleuth支持跨链分析，例如，通过跨链桥从BSC到Ethereum的代币转移。所有的跨链地址都显示在一张图上。
* 分析分享：结果可以与他人分享。其他用户可以进一步分析共享结果，创建一个协作社区。
* 增强标签：MetaSleuth利用BlockSec的地址标记系统，提供了CEXs、诈骗者和黑客地址的增强标签，以及我们收集和验证的其他地址。
* 定制化：用户可以自定义地址标签并为地址和交易添加备注。

## 支持的链

[Bitcoin](https://explorer.btc.com/), [Ethereum](https://ethereum.org/en/), [Binance Smart Chain](https://www.bnbchain.org/en), [TRON](https://tron.network/), [Solana](https://solana.com/), [Polygon](https://polygon.technology/), [Mantle](https://www.mantle.xyz/), [Arbitrum](https://arbitrum.io/), [Cronos](https://cronos.org/), [Moonbeam](https://moonbeam.network/), [Avalanche](https://www.avax.network/), [Optimism](https://www.optimism.io/), [Base](https://base.org/), [Linea](https://linea.build/)

## 反馈

我们重视您的意见，并非常感谢您可能提供的任何反馈或建议。请通过以下列出的社交媒体渠道联系我们。

* Telegram: <https://t.me/MetaSleuthTeam>
* Twitter: <https://twitter.com/MetaSleuth>
* Email: <ms_support@blocksec.com>

## 教程

* [如何使用MetaSleuth分析钓鱼攻击](https://blocksecteam.medium.com/metasleuth-how-to-use-metasleuth-to-analyze-a-phishing-attack-b525caac14c5)
* [加密货币追踪：从一笔交易开始](/zh_cn/yong-hu-shou-ce/tutorials/crypto-tracking-starting-with-a-transaction)
* [高级分析：轻量级资金追踪](/zh_cn/yong-hu-shou-ce/tutorials/advanced-analysis-lightweight-fund-tracking)

## 多语言

* [中文简体手册](https://docs.metasleuth.io/zh_cn)
* [中文繁体手册](https://docs.metasleuth.io/zh_tw)
* [Metasleuth ユーザーマニュアル](https://docs.metasleuth.io/ja)
* [Metasleuth Benutzerhandbuch](https://docs.metasleuth.io/de)
* [Manuel d'utilisation de Metasleuth](https://docs.metasleuth.io/fr)
* [Руководство пользователя Metasleuth](https://docs.metasleuth.io/ru)


# 媒体工具包

### 透明背景

PNG

<figure><img src="/files/ybyikUMEMS3zVG5w5r07" alt=""><figcaption></figcaption></figure>

SVG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FkZ08apa13D5M1x6NrRoy%2F20230809Metasleuth%E6%9B%B4%E6%96%B0-02.svg?alt=media&#x26;token=b68fd89c-284c-4706-aab7-541f07dd2843" alt="" width="563"><figcaption></figcaption></figure>

### 白色徽标和透明背景

PNG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FcPFQy3hjYkRR2m1zzjUL%2FBlocksec%E4%BA%A7%E5%93%81logo%20-19.png?alt=media&#x26;token=61b3a0a0-612b-481c-80dd-279eb1c4a6c2" alt=""><figcaption></figcaption></figure>

SVG

<figure><img src="https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FGaDvv1Lix9gLUidbNRbB%2FMetaSleuth3.svg?alt=media&#x26;token=ace19830-4f2b-46e1-9c7a-9726e7aa455b" alt=""><figcaption></figcaption></figure>


# 入门

🎉 欢迎阅读MetaSleuth用户手册！ 🎉

MetaSleuth是一个全面的平台，旨在跟踪和调查链上资产，以满足各种分析需求。为了帮助您快速上手使用本工具，我们在“开始使用”部分包括了四个关键主题：

1. [通过简单搜索开始](/zh_cn/yong-hu-shou-ce/getting-started/start-by-a-simple-search)：使用搜索功能快速找到特定地址或交易，以访问相关数据和见解。
2. [通过共享图表开始](/zh_cn/yong-hu-shou-ce/getting-started/start-by-a-shared-chart)：通过探索其他用户创建的共享图表进行协作和构建现有可视化。
3. [什么是节点？](/zh_cn/yong-hu-shou-ce/getting-started/what-are-nodes) 了解节点的概念，节点代表区块链网络中的实体，如地址或合约。
4. [什么是边？](/zh_cn/yong-hu-shou-ce/getting-started/what-are-edges) 学习边，它们展示节点之间的关系和交易，为您分析的数据提供上下文。


# 从简单搜索开始

链上调查有着多种目的。你可能是追踪非法资金的执法人员，或是评估用户财务风险的合规官员，或者是检查项目潜在问题的投资者。你也可能需要调查一笔欺诈交易以追踪你的资金流向。在任何情况下，分析总是从一个地址或交易开始。

## 打开 MetaSleuth

使用 MetaSleuth 无需任何准备。只需访问我们的网站，metasleuth.io。您甚至不需要注册或登录；您将立即找到分析的切入点，只需一个简单的输入框。

<figure><img src="/files/T19BmpiGZxSVOEqGQncA" alt=""><figcaption></figcaption></figure>

您可以输入一个地址、交易哈希或 ENS 域名。如果您不确定要搜索什么，可以点击搜索框查看热门地址并选择一个开始。

## 搜索一个地址

如果您输入一个地址，等待大约 1 秒会出现一个下拉框，显示该地址活跃的所有链。点击您想分析的链即可查看与该地址相关的资金流动。

<figure><img src="/files/rvMLEiIRsSjOWsXdbJSE" alt=""><figcaption></figcaption></figure>

例如，如果您搜索 `0x0629b1048298ae9deff0f4100a31967fb3f98962` 并选择 Arbitrum，您可以查看 Radiant Capital 攻击者在该链上的资金流动。注意，并不是所有的资金转移都会显示在画布上以保持可读性。要探索通过 Analyze 功能可以获取哪些信息，请访问 [追踪资金 - 分析](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/analyze)。

<figure><img src="/files/YMGZ494J59aslAsSImnt" alt=""><figcaption></figcaption></figure>

## 搜索一笔交易

如果您输入一个交易哈希，通常下拉框只会显示一个结果（假设哈希是正确的）。点击它将展示与该交易相关的所有资金流动。例如，试着输入 `0x7856552db409fe51e17339ab1e0e1ce9c85d68bf0f4de4c110fc4e372ea02fb1`，这是 Radiant Capital 攻击事件的一笔攻击交易。

<figure><img src="/files/iqJnCRRnUCxKbhTGAbwd" alt=""><figcaption></figcaption></figure>

当您输入一笔交易时，MetaSleuth 会显示该交易中发生的所有资产转移。在这种情况下，攻击者从项目中抽取了若干池的资金，因此您会看到多个地址的资金流入攻击者的地址。

<figure><img src="/files/PmBAyAWWgZKcHY5pS87P" alt=""><figcaption></figcaption></figure>


# 从共享图表开始

有时，您可能会收到其他人共享的MetaSleuth分析结果，例如[这个链接](https://metasleuth.io/result/arbitrum/0x0629b1048298ae9deff0f4100a31967fb3f98962?source=b1ec1bc4-9b0a-4109-a3e8-288cbe035485)。在MetaSleuth中，这些链接称为共享链接。它们允许用户查看和编辑与共享分析相关的画布。

## 查看共享画布

共享画布本质上是分享者提供的分析结果的快照。打开共享链接时，您会看到创建链接时整个画布的状态。您可以单击边和节点查看详细信息，并查看分享者的笔记。但请务必记住，这只是一个分析结果，不能代表完整的全貌。

单击地址节点将显示地址标签、关联标签、风险评分、资产余额和链上交互等详细信息。需要注意的是，显示的资产转移仅限于分享者选择在画布上显示的部分。要查看更全面的资产转移，您需要解锁画布以进行重新分析。

<figure><img src="/files/ZUfFRZHOkggFPOtRKWA3" alt=""><figcaption></figcaption></figure>

单击边将显示两个节点之间的资产转移。同样，这里仅显示分享者选择的内容。

<figure><img src="/files/iEz3f9LobzNx2rH5Cy9o" alt=""><figcaption></figcaption></figure>

## 编辑画布

如果您发现共享内容有价值并希望继续分析，可以解锁画布进行编辑，然后保存。您的编辑不会同步回原始分享者。

解锁很简单——只需点击左上角的“开始编辑”按钮。

<figure><img src="/files/XFPhea9y6gn1jf62nlpi" alt=""><figcaption></figcaption></figure>

通常，解锁过程很顺利，但有时您可能会遇到提示，询问是否要保留一些分享者的私有标签。如果您是经验丰富的MetaSleuth用户，您可能需要考虑哪些标签有价值。如果您是初学者，只需选择“导入”即可！

有关私有标签的更多信息，您可以访问保存和共享- [让你的工作更易读](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble) 部分。

<figure><img src="/files/MLmb96fFyC384M4mZk2N" alt=""><figcaption></figcaption></figure>


# 什么是节点？

MetaSleuth中的资金流动由节点和边组成，其中“节点”代表区块链上的地址，也称为钱包或账户。

在MetaSleuth画布上有两种类型的节点：

1. **标准地址节点：** 这些节点显示为圆角矩形。
2. **可解析的跨链桥节点：** 这些节点显示为八边形。

## 地址节点

画布上的地址节点通常有两种状态。

* **阅读状态：** 节点的默认状态，显示在左侧，仅提供可读信息。
* **分析状态：** 当您将鼠标悬停在节点上时，出现在右侧的状态，提供各种分析功能。

<figure><img src="/files/aYFu454LGAQ28CNijQLf" alt=""><figcaption></figcaption></figure>

除了上述的两个基本状态之外，您还可能会在节点上看到各种有用的图标（如下面的图片所示）。我们将逐一介绍这些图标。

<figure><img src="/files/Mh3julCnN0nmMkWLMAIc" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/hJkxP8FzW00dAz1Ab5cD" alt=""><figcaption></figcaption></figure>

<table data-full-width="true"><thead><tr><th>图标和标签</th><th>含义</th><th>可操作性</th></tr></thead><tbody><tr><td><img src="/files/n1TmFbEFEIg4T0H2hyUr" alt="" data-size="original"></td><td>区块链</td><td>否</td></tr><tr><td><img src="/files/KvSctOqzuRXwFBlQk2tM" alt="" data-size="original"></td><td><p>实体标志</p><p>当一个地址与具有标志的实体相关联时，该实体的标志将显示在节点上。这有助于直观地识别与该地址相关联的组织或项目。</p></td><td>否</td></tr><tr><td><img src="/files/wW12IT4UUM8p81zEK7xe" alt="" data-size="original"></td><td>地址信息</td><td>否</td></tr><tr><td><img src="/files/NdA3G8rd6WzTjMSaNfp3" alt="" data-size="original"></td><td><p>地址标签</p><p>地址标签按以下顺序显示：用户私人标签 > BlockSec标签。如果两者都不可用，则不显示标签。</p></td><td>否，但用户可以使用 <img src="/files/TwRfMP7aU2xVEVuJU2CH" alt=""> 进行编辑</td></tr><tr><td><img src="/files/Nry1lyWK5PcGLxVfD7VV" alt="" data-size="original"></td><td><p>常用工具链接</p><p>这些链接允许您快速跳转到各自平台上的当前地址详情页面。点击它们将为您提供有关地址活动和状态的更多信息。</p></td><td>否</td></tr><tr><td><img src="/files/7ccsqv4jDBntwFWKjkix" alt="" data-size="original"></td><td><p>不完整数据指示器</p><p>这表示当前地址的数据不完整。需要数据完整性的分析师应注意，并可能需要使用其他方法获得完整信息。</p></td><td>否</td></tr><tr><td><img src="/files/UqmsouGpWOHEJYRDUfja" alt="" data-size="original"></td><td><p>风险指示器</p><p>这表明该地址与风险行为相关联，用户在与其交互时应谨慎。具体风险详情可以在地址面板中找到。</p></td><td>否</td></tr><tr><td><img src="/files/7GggsWKeoogowry3rS1K" alt="" data-size="original"></td><td>分析按钮</td><td>是。点击分析按钮可以启动对当前地址的详细分析。</td></tr><tr><td><img src="/files/GltHpukZrjwZCO0pslNU" alt="" data-size="original"></td><td>分析完成</td><td>否。分析完成表示基本分析已经完成。用户仍然可以执行额外的分析，例如高级分析或加载更多以访问更多数据。</td></tr><tr><td><img src="/files/3HB8m7IrvKxsjKZESsrM" alt="" data-size="original"></td><td>高级分析按钮</td><td>是。点击高级分析按钮可以对当前地址执行详细分析，允许您指定参数，例如令牌类型、时间范围和金额。</td></tr><tr><td><img src="/files/TwRfMP7aU2xVEVuJU2CH" alt="" data-size="original"></td><td>私人标签（编辑地址标签）</td><td>是。用户可以为地址添加或修改标签，该标签将在其用户数据中存储为私人标签。</td></tr><tr><td><img src="/files/gW552EfpGRwW32ZCX9SV" alt="" data-size="original"></td><td>删除地址节点</td><td>是</td></tr><tr><td><img src="/files/w6oC888G0wssca2I9N5l" alt="" data-size="original"></td><td>单向分析</td><td>是。点击节点左侧的按钮以分析资金来源，点击右侧的按钮以分析资金去向。</td></tr></tbody></table>

## 跨链桥节点

当MetaSleuth识别出资产转移可能涉及跨链活动时，它会将该转移链接到一个跨链桥节点。交互地址的具体信息，包括链、地址和标签，会被省略，而是用一个跨链桥标志和名称来表示。

<figure><img src="/files/Q0O05gj79IjrsL240nW6" alt=""><figcaption></figcaption></figure>

点击跨链桥节点可以查看具体的交互，包括详细的资产转移、交易和涉及的跨链桥地址。您还会看到一个**跟踪**按钮；点击它，MetaSleuth将自动分析资金的跨链去向。

<figure><img src="/files/pHASbQj6m79l8i4t4xUn" alt=""><figcaption></figcaption></figure>


# 什么是边？

在MetaSleuth中，边表示连接节点（地址）之间的关系。目前，显示有三种类型的关系：

* **标准资产转移：** 最常见的关系类型，表示两个地址之间的资产流动。
* **合约创建关系：** 表示合约创建者与已创建合约之间的关系，标记为"*Contract Creation*"。
* **跨链资产转移：** 此关系表示标准地址节点与跨链桥节点之间的资金交互，通常表明资金已跨链转移。用户可以使用InterChain Tracer功能进一步探索资金的来源和去向。

在下面提供的示例中，我们可以同时观察到这三种关系类型。

<figure><img src="/files/uOeIYfJsU5hZbGMh8rN7" alt=""><figcaption></figcaption></figure>

接下来，让我们检查标准资产转移边中包含的信息。

在下面的示例中，从节点**Euler Finance Exploiter 2 (0xb66cd)到KyberSwap Exploiter (0x50275e)的边表示Euler Finance Exploiter 2**向**KyberSwap Exploiter**发送了**0.110 Ether**。

<figure><img src="/files/uZ812mp5keh7VjZIyq9c" alt=""><figcaption></figcaption></figure>

请注意，MetaSleuth将两个地址之间相同方向和类型的资产转移合并为单个边。因此，一个边并不代表单一交易。

要查看关于边的更多详情，请点击边打开[边面板](/zh_cn/yong-hu-shou-ce/canvas-and-panels/edge-panel)，然后选择`Detail`查看所有交易信息。

<figure><img src="/files/MtWmibPnrfenQXdjewWN" alt=""><figcaption></figcaption></figure>

在交易列表中，可以看到Euler Finance Exploiter 2进行了两笔交易，总共向KyberSwap Exploiter转移了0.111 Ether。

### 边的颜色

边通常默认为灰色，但为了帮助区分不同的资产转移，MetaSleuth使用每个链上的主要代币图标的主色作为边的颜色。这有助于用户更好地理解资产流动。

用户可以通过两种方式修改边的颜色：

* 更改单个边的颜色：点击边上的画布图标。![](/files/xKxrwHRj6xBObvHgIPlJ)
* 更改所有代表特定代币的边的颜色：要修改所有代表特定代币的边的颜色，请转到左上角的Token Filters面板。点击您想更改颜色的代币旁边的颜色圈。选择所需颜色后，所有与该资产相关的边将更新为新颜色。\
  ![](/files/t5qasQBRisHtoMaUlz4n)

### 边的标签

<figure><img src="/files/JVjsGyGh5nw77YlpLhsP" alt=""><figcaption></figcaption></figure>

边的标签由三部分组成：

1. **索引：** 所有边按照显示的时间排序，索引越小表示发生时间越早。
2. **时间：** 边中包含的所有交易的最早时间戳（最早交易的时间）。
3. **转移金额：** 由边表示的资产转移总金额（对画布上显示的选定交易），以及代币符号。


# 画布和面板

在MetaSleuth中，**画布**是用户可视化和分析区块链数据的中央工作区。**面板**是提供与画布上显示的项目相关的详细信息和工具的附加部分。我们将其组织为四个部分：

1. [画布](/zh_cn/yong-hu-shou-ce/canvas-and-panels/canvas): 画布是可视化和分析区块链数据的中央工作区，支持节点和边的互动操作。
2. [地址面板](/zh_cn/yong-hu-shou-ce/canvas-and-panels/address-panel): 地址面板显示特定地址的详细信息，包括交易历史和代币持有量。
3. [边面板](/zh_cn/yong-hu-shou-ce/canvas-and-panels/edge-panel): 边面板显示节点之间的连接，突出显示交易流和关系。
4. [跨链追踪面板](/zh_cn/yong-hu-shou-ce/canvas-and-panels/interchain-tracker-panel): 跨链追踪面板监控跨链交易，让用户能够跟踪不同区块链网络之间的资产流动。


# 画布

MetaSleuth中的画布是您可视化和分析区块链数据的主要工作区。它包括几个关键功能：

1. [工具箱概览](/zh_cn/yong-hu-shou-ce/canvas-and-panels/canvas/toolbox-overview)：访问各种工具，旨在增强您的分析并简化您的工作流程。
2. [更好的布局](/zh_cn/yong-hu-shou-ce/canvas-and-panels/canvas/better-layout)：享受一个有组织的界面，允许有效安排视觉元素，使您的数据更易于解释。
3. [自定义您的画布](/zh_cn/yong-hu-shou-ce/canvas-and-panels/canvas/customize-your-canvas)：通过调整布局、颜色和其他视觉设置来定制画布，以改善您的分析体验。
4. [键盘快捷键](/zh_cn/yong-hu-shou-ce/canvas-and-panels/canvas/keyboard-shortcuts)：利用键盘快捷键在画布中更高效地导航和操作，为您的调查节省时间。


# 工具箱概览

调查工具箱主要为画布上的数据提供过滤和编辑功能。其包含以下六个关键功能。

**`地址过滤器`** 列出了所有已分析的地址，包括画布上显示的和未显示的地址。用户可以在过滤器中搜索特定地址并调整其可视化状态。

<figure><img src="/files/CGLyxUjziZyAdPfYUEi7" alt="" width="563"><figcaption></figcaption></figure>

**`代币过滤器`** 列出了所有已分析的代币。如果与某个代币相关的所有转移都显示在画布上，它将显示为选中状态（复选框已选中）；相反，如果与某个代币相关的转移都未显示在画布上，它将显示为未选中状态（复选框未选中）。需要注意的是，如果只有部分与某个代币相关的转移显示在画布上，它将显示为部分选中状态（复选框不定态）。

<figure><img src="/files/fx4V1S8Agopbk5rYPCIO" alt="" width="563"><figcaption></figcaption></figure>

**`添加地址/交易`** 允许用户将特定地址或交易（资产内部转移）添加到画布中。有关更多信息，请参阅 [添加地址/交易](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/add-address-tx) 部分。

**`添加备注`** 允许用户在画布上添加文本注释。用户可以为画布上的特定地址和交易提供额外的背景信息、备注或解释。有关如何使用此功能的更多信息，请参阅 [备注](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble/memo) 部分。

**`自定义水印`** 允许用户在分析结果中添加自己的品牌或标识。用户可以自定义显示在画布上的水印，添加他们的标志、姓名或任何其他所需信息。有关如何使用此功能的更多信息，请参阅 [自定义水印](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble/custom-watermark) 部分。

**`在画布中搜索`** 允许用户根据区块链、地址、交易、标签或边编号等标准在画布内容中进行搜索。用户可以快速定位可视化中具体的元素或连接。通过在搜索栏输入相关关键字或条件，用户可以过滤并专注于画布中感兴趣的特定信息。

<figure><img src="/files/UrOPdVLYAcbMfP7gbUPd" alt="" width="563"><figcaption></figcaption></figure>


# 更好的布局

对链上资产的跟踪和分析通常围绕资金流动进行，因此画布的布局至关重要。它不仅影响分析的效率，还影响分析结果的呈现。MetaSleuth 专门提供了布局调整工具栏，提供以下功能：

![](/files/kTlpAKCDdDhhxPsALjci)**`手动布局`** 允许用户手动调整画布上节点的位置和对齐。用户可以拖动和重新定位节点，以创建适合其分析需求的自定义布局。

![](/files/hbwegyIDXzzKovzB97FS)**`自动布局`** 自动优化排列画布上的节点和边，增强资金流动图的视觉清晰度和组织性。

![](/files/OLE20xMHBysBqtJxVwjG)**`调整间距`** 允许用户全局调整节点之间的间距，创建更紧凑或更扩展的布局。

![](/files/8Kbb6CwDS7oqmKXEumnp)**`撤销和重做`** 使用户能够管理和恢复分析过程中的画布更改。请注意，撤销和重做步骤的数量有限制，最多允许三步。

![](/files/WPJJcqvpPgwiSTlNdigY)**`居中图形`** 允许您对齐并居中整个画布，使其进入视野并恢复整体控制。此功能特别有用，当您想重新聚焦并完整查看图形，而不希望任何元素被剪断或隐藏时。

![](/files/ikCySJi1qjd6zOYlPotX)**`全屏`** 允许您全身心投入分析和调查。来试试吧！


# 自定义你的画布

外观编辑工具箱提供编辑节点、边和备注外观的功能。当您打开画布时，系统默认会显示一个节点形状编辑器。您可以将其最小化为画布图表，自由拖动，从而获得更多分析空间。

<figure><img src="/files/V4RD572022NCzWzq3i1h" alt="画布截图" width="563"><figcaption></figcaption></figure>

点击一个地址节点将打开与该节点相关的形状编辑器，您可以编辑其形状、文字颜色和节点颜色。

<figure><img src="/files/MCAFp5eQmvEhsShhsBC8" alt="节点编辑器" width="375"><figcaption></figcaption></figure>

您可以通过按住 Shift/Ctrl（Command）键并点击节点来选择多个节点，从而对地址进行批量编辑。

<figure><img src="/files/yRRxU9P8FdBMrp4abtS0" alt="批量编辑" width="269"><figcaption></figcaption></figure>

另外，您可以在画布上选择任一边对其进行编辑，调整线型、宽度和颜色。

<figure><img src="/files/DItBeseWdljl21rzjDYD" alt="边编辑" width="563"><figcaption></figcaption></figure>

通过选择一个备注，您可以编辑其文字的字体大小、颜色、格式和背景颜色。

<figure><img src="/files/o6UpMkx8SOISMnCMAowP" alt="备注编辑" width="563"><figcaption></figcaption></figure>


# 键盘快捷键

* `Ctrl` / `Cmd` + `Z`: 撤销
* `Ctrl` / `Cmd` + Shift + Z: 重做
* `Ctrl` / `Cmd` + F: 搜索
* `Ctrl` / `Cmd` + `Shift` + `Click`: 多选节点
* `Ctrl` / `Cmd` + `Shift` + `Drag`: 多选节点


# 地址面板

当您点击地址节点时，地址面板将从画布左侧展开。在此面板中，您可以看到以下信息：

**`名称标签`**: 如果某个地址具有BlockSec支持的公共名称标签或用户分配的私人名称标签，将会显示出来。例如，下图中的“Poloniex Exchange Exploiter”。

**`合规风险评分`**: 地址的合规风险是基于与该地址相关的标签信息及其与其他地址的互动评估的。评估分为五个等级：无风险、低风险、中风险、高风险和关键风险。

**`地址标签`**: 地址关联的标签由BlockSec反洗钱团队提供。例如，在给定示例中，地址带有“攻击者”标签。其他常见标签包括 CEX、DEX、制裁、受损等。这些标签用于识别与地址相关的特定特征或风险因素，辅助合规和风险评估。

**`余额`**: 当前地址在区块链上持有的原生代币余额，以及其对应的美元价值。

<figure><img src="/files/Jsek0uSpexxX7DI4IVez" alt=""><figcaption></figcaption></figure>

**`相关地址`**: 这些是与目标地址有交互的地址，根据获取的交易数据编制的。除了地址本身，您还可以查看每个地址的风险评分、资金流向以及流动中所涉及的资产类型。

**`转账`**: 这些是与目标地址相关的所有资金转账。

**`加载更多`**: 此功能允许用户请求当前地址的更多交易。关于如何使用此功能获取更多交易数据的详细说明，请参考“[加载更多](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/load-more)”部分。

**`地址面板过滤`**: 当一个地址有大量交互时，可能需要一个过滤工具来缩小调查范围。

<figure><img src="/files/2WGMQA6ngWvRMcdCtV0z" alt="" width="401"><figcaption><p>地址面板过滤</p></figcaption></figure>


# 边面板

当点击画布上的任何边时，会展开一个边列表面板。

<figure><img src="/files/qPdbwUtJkL7Bizky4YcH" alt=""><figcaption></figcaption></figure>

在此面板中，您可以查看两个地址之间的所有资产转移（基于当前可用数据）。每条边由（from, to, asset）唯一标识。要查看具体转移数据，您需要点击“详细信息”进入交易列表面板。例如，点击上述示例中的（Poloniex 4, Poloniex Exchange Exploiter, Ether）将允许您在画布上查看涉及从 Poloniex 4 到 Poloniex Exchange Exploiter 的 Ether 转移的所有交易详情，如下所示。

<figure><img src="/files/STH8To0jNbDLeujmqAEA" alt=""><figcaption></figcaption></figure>


# 跨链监测面板

在资金追踪过程中，画布上出现的跨链桥节点表示跨链转移。要进行进一步探索，只需点击该跨链桥节点或连接的边，即可打开跨链追踪面板。

下图展示了跨链追踪面板的一个示例。在这里，ExactlyProtocol攻击者使用跨链桥Across从Optimism网络转移以太币到以太坊区块链。

<figure><img src="/files/bdM8hrfSUcve438xzX2U" alt="跨链追踪面板"><figcaption><p>跨链追踪面板</p></figcaption></figure>

在跨链追踪面板中，每个条目代表一个跨链交易，提供了关键细节，如源交易和目标交易，以及转移的资产。如果跨链关系尚未被追踪，信息将仅在源或目标一侧可用。

您是否好奇如何在各自链上发现交易？涉及哪些链和地址在发送或接收？通过点击“追踪”，用户可以利用MetaSleuth的自动跨链追踪能力。一旦分析完成，另一侧的跨链资产转移将显示在面板中，并自动在画布上高亮显示。

如果您遇到任何不支持、不准确或失败的跨链解决方案，我们鼓励您通过选择面板右下角的“报告错误”选项来提供反馈。您的意见对于提升追踪体验至关重要！


# 追踪资金（检索转账数据的方法）

在MetaSleuth中，用户可以利用以下功能高效追踪资金：

1. [Analyze](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/analyze)：检查交易详情和模式，以获取资金流动的见解。
2. [Expand In/Out](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/expand-in-out)：查看进出交易以了解资产的流动。
3. [Load More](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/load-more)\*\*：\*\*检索更多交易数据以确保全貌。
4. [Advanced Analysis](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/advanced-analysis)：利用高级工具深入了解复杂交易。
5. [Add Address/Tx](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/add-address-tx)：轻松添加特定地址或交易以进行有针对性的分析。
6. [InterChain Tracker](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/interchain-traker-trace-across-blockchains-automatically)：跟踪跨不同区块链网络的资金流动以获得全面的资产流动视图。
7. [Data Explorer](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/data-explorer)：查看、筛选和选择转账数据。


# 分析

## 分析（智能分析）

MetaSleuth的默认分析功能。除了检索基本的资产转移数据之外，**分析**还结合了智能技术来促进用户的分析过程。因此，我们也称之为“智能分析”。

您可以通过两种主要方式访问分析功能：通过主页上的搜索框或通过在画布上选择一个地址节点。

<figure><img src="/files/u6uO5xLvfhX1D3EQr9ul" alt=""><figcaption></figcaption></figure>

### 分析交易

在分析交易时，MetaSleuth会在画布上显示交易中发生的所有资产转移。

当前支持交易分析的链包括Bitcoin, Ethereum, BSC, TRON[^1], Solana, Polygon, Mantle, Arbitrum, Avalanche, Optimism, Base，以及Linea。

### 分析地址

分析地址涉及更复杂的算法。在分析地址时，MetaSleuth应用智能搜索和过滤技术，以提高数据检索和展示的效率。

<figure><img src="/files/g5ipe4UDOTMpd4zWmTqo" alt=""><figcaption></figcaption></figure>

#### 🙋‍♂️ Analyze从地址中检索哪些数据？

* 最近的资产转移：分析会检索与该地址相关联的最新资产转移的信息（小金额将被过滤掉）。如果转移被识别为跨链转移，您可以利用“跨链追踪器”来定位跨链桥资产。更多详细信息，请参阅[跨链追踪器](#interchain-tracker)部分。
* 关键路径：分析还提供关于地址与中心化交易所或混币器之间两次跳跃内可达路径的信息。目前，该功能仅支持Ethereum。

{% hint style="info" %}
对于高交易量的地址，您可能会在地址节点上遇到⚠️提示，这表明MetaSleuth尚未检索到所有的转移数据。在这种情况下，如果您想要更多数据，可以考虑以下选项：

> 1. 利用[Advanced Analyze](/zh_cn/yong-hu-shou-ce/trace-funds-ways-to-retrieve-transfer-data/advanced-analysis)来获取更多数据。
> 2. 通过[批量导入](#add-addresses-transactions)导入数据，以确保全面分析。
>    {% endhint %}

#### 🙋‍♀️ Analyze优先显示哪些数据？

并不是所有检索到的数据都会展示在画布上。我们优先展示某些数据类型：

* 与高风险地址的互动。
* 与中心化交易所、混币器和跨链桥的互动。
* 最早和最新的互动。
* 与已知实体的互动。
* 合约创建关系。

{% hint style="info" %}
如何展示未显示的互动？

> 要查看未显示的互动，请导航到地址面板，您可以在那里找到所有互动的列表。此外，还有几个便捷工具可用于根据方向、代币、日期时间等标准过滤互动。
> {% endhint %}

[^1]: Tron交易分析目前仅返回涉及Native/TRC20/TRC721代币的转移。


# 扩展进/出

寻找特定的方向追踪？使用扩展，这是Analyze的单向版本。

<figure><img src="/files/XrCafKMaNaRe0rVJfDeO" alt=""><figcaption></figcaption></figure>


# 加载更多

加载更多功能让您完全控制在画布上选择要显示的数据。它会检索目标地址的资产转移信息，但不会自动展示它们。您可以通过在地址面板中查看名称标签、风险信息、交互方向和其他详细信息，仔细选择要展示的项目。

<figure><img src="/files/lcUWsngGj9tbD3SraT57" alt=""><figcaption></figcaption></figure>


# 高级分析

顾名思义，高级分析是分析功能的增强版。使用高级分析，您可以指定分析的确切方向、代币和日期范围。通过利用此功能，您可以准确获取所需的交互数据。

<figure><img src="/files/o4EtE6bFYA6wJPYiAV2k" alt="高级分析功能界面"><figcaption></figcaption></figure>


# 添加地址/交易

调查可能很复杂，并且有多个切入点。例如，如果您想调查一个涉及四个独立地址的案件，可以使用此功能将它们添加到画布上。

当您添加地址时，它们将被放置在画布上，暂时不会进行任何分析，您可以稍后进行分析、展开或加载更多操作。另一方面，当您添加交易时，MetaSleuth 将检索这些交易的内部资产转移，并将它们全部显示在画布上。

<figure><img src="/files/zXg5weBmpwjUUA893Elq" alt=""><figcaption></figcaption></figure>


# 跨链追踪（自动跨链追踪）

为了简化用户跟踪资金的过程，MetaSleuth 内置了一个跨链追踪器。跨链追踪器在用户分析地址时自动识别潜在的跨链资产转移。它还提供一键追踪功能，以追踪跨链资产在另一边的转移。有关如何使用的更多信息，您可以访问[跨链追踪器面板](/zh_cn/yong-hu-shou-ce/canvas-and-panels/interchain-tracker-panel)。

目前，MS 支持自动解析跨链桥，如 Across、Multichain、cBridge、Hop、PolyNetwork、Stargate、Synapse、WormHole、Optimism Gateway、Polygon Pos Bridge、Avalanche Bridge（部分支持），以及 RenBridge（部分支持）。

有关跨链桥和跨链转移的更多信息，请访问 <https://ethereum.org/en/bridges/>。


# 数据探查器

***

### description: 查看、筛选和选择转账数据。

## 数据探索器

为了改进我们收集和展示数据的方式，我们通过诸如分析之类的功能限制显示的记录数量。通常，我们仅显示最近几百个转账记录。虽然这些限制可能使跟踪和分析变得更加困难，但我们引入了\_**数据探索器**\_功能来提供帮助。

<figure><img src="/files/0oUVIQN8sS99PKVIOM1C" alt="" width="375"><figcaption></figcaption></figure>

在地址面板中，我们现在显示已检索到的转账数量和可用的转账总数。这有助于您了解每个地址的数据检索状态，并就接下来要做的事情做出更好的决策。

<figure><img src="/files/1b4Z1pJBHaSvZBu8Uucz" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
请记住，由于我们的算法，转账总数可能与您在其他来源看到的不同。此外，我们的“微小转账”过滤器可能会减少您看到的最终转账数量。
{% endhint %}

如果您无法通过其他功能找到特定地址所需的所有数据，可以使用数据探索器。此功能允许您访问更完整的数据。在数据探索器中，转账数据以逆时序排列，您可以通过页面导航查看更多，还可以使用过滤器来获取更大数据集的更具体结果。

<figure><img src="/files/IDE7xoZ9buqovU3O9tqu" alt=""><figcaption></figcaption></figure>

当您找到感兴趣的转账时，可以点击 <img src="/files/ge2eMmei8GudSTMIOnt3" alt="" data-size="line"> 图标将该转账添加到画布。您也可以选择多个转账一次性全部添加。


# 监控资金流动

MetaSleuth 地址监控旨在为特定地址提供实时的资金流入和流出跟踪。我们通过以下优化追求全面的监控覆盖和高可用性：

* **多链支持**: 我们支持主要的区块链，包括Bitcoin、Ethereum、BSC、Tron、Solana、Arbitrum、Polygon、Optimism、Avalanche，让用户可以监控多个链上的活动。
* **多资产监控**: 我们涵盖这些链上的大多数资产类型，使用户可以追踪他们关心的各种数字资产。
* **灵活的规则配置**: 用户可以设置精确的监控规则来跟踪资产转移，最大限度地减少不必要的通知和干扰。
* **简单管理**: 用户可以轻松创建、暂停、恢复和删除监控规则，灵活管理他们的监控目标。
* **及时通知**: 为确保用户及时获得资产转移信息，我们提供电子邮件通知服务，确保不遗漏任何重要更新。

#### 地址资产监控

对于EVM兼容的链，此服务支持监控任何地址的原生代币和符合主流代币协议（例如，ERC-20、ERC-721、BEP-20）的资产。对于Solana链，则支持监控原生代币和任何指定的SPL代币。

#### 监控规则配置

为了精确监控资产转移，用户可以根据代币类型、方向和数量配置规则：

* **代币规格**: 用户可以指定代币到协议层（例如，原生，ERC-20，ERC-721，BEP-20）和具体代币（例如，指定的USDC合约地址）。
* **方向选项**: 监控可以设置为入账（IN），出账（OUT）或全向（ALL）的转移。
* **数量范围**: 用户可以指定监控代币的数量范围。可替代代币的最小值设定为0.001，没有上限。

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeKNZZUCBvNx9YI185Bi0qQQtdhJK9qpm6-CEFasJ9WE9NXthBvGc5mzbtcBIDgYO_MOyNNXPJTv8Zsg71AoA1qM8KxvuG_m6EBe_6w5bWem37SG-A2FUCm1cuonZiWCctFyTIPAffnyL-OBCxecWrFpTRM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>该设置用于监控Ethereum上的NO-KYC交易所FixedFloat的热钱包地址。监控的资产是Ether、USDT和USDC。方向设置为<strong>ALL</strong>，跟踪所有入账和出账交易。数量阈值为<strong>1 ETH或更多</strong>的Ether，以及<strong>1500或更多</strong>的USDT和USDC。</p></figcaption></figure>

#### 监控规则管理

配置的监控规则可在仪表板中查看。显示的信息包括监控目标、运行状态、创建时间、重启时间（如果暂停），以及监控期间符合条件的事件数量。用户可以对监控任务执行操作，包括暂停、重启、编辑和删除。

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcpJn4EYbWlpLcB02JOnK9t9Km-tCsseskK4Nx4X1dzoaL3QKTYZilCJ8Q8CSw6PLU_K9w83X0dKyVDLZHB2h2_ET68c-nfUWYHyrkmd5hx3P7BTVKD8TxNPtGoQy7HiTPgZlfS8WKvb6SwRBPtKSax8QGM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>运行后的任务初始创建</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeddjv70rTS5KkTdL9CacxeheL1RZTXPotaX1Fx-nbbwxNqlJAG1j6DjK4PMrEH5ciRfMGqnFxKBcj6_2tKTpRsOyIiQeRqkBcAfA5tY5p7fcwoW2QWF3Q7JANwRhlNOivrKsrnLEfhE1D-owUjSXpFW4IR?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>已暂停的任务</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd6aaHHK84gGg4m8GvcNyTkmd6_X2IQ_1MrVWbsc9NB5uiZlKPqu0sL5DwgZ-p-uKoSJBST3hPpDt9qlzeoQEJ4sYxWWwpj-UHPS3cfj66D4lKthEIm4kU4Evsa7P-xTMoL_jxaHJ6ceY3ZvYynqvWAo5VK?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>已恢复的任务</p></figcaption></figure>

#### 监控事件通知

在仪表板中，用户可以查看与监控任务相关的所有事件。一个事件通常表示资产转移，并包括交易时间、交易哈希、转移方向、对应方、资产和数量等信息。如果用户已配置电子邮件并启用通知，他们将收到这些事件的电子邮件提醒。

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcpJn4EYbWlpLcB02JOnK9t9Km-tCsseskK4Nx4X1dzoaL3QKTYZilCJ8Q8CSw6PLU_K9w83X0dKyVDLZHB2h2_ET68c-nfUWYHyrkmd5hx3P7BTVKD8TxNPtGoQy7HiTPgZlfS8WKvb6SwRBPtKSax8QGM?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>用户可以在创建监控任务时启用通知，或通过任务管理面板中的Notif开关来切换。</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc6LBNn3eblJykmE3Zxdh0WlEU716M8aq22uNBf8nWqtRN4dGCiCsmnmAOEWnVUlSme747WryZSWLN0YDaw6rpSmchTZn4NNlvwymW2JJhLkgM5BvhNyYZaTvMOoSG4uG7GD0-zyCbjZ3mxdu2EDsy-f5eN?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>监控FixedFloat热钱包地址配置后的触发事件</p></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd-6FOQ8I5PR2kxnc7tuX0czExccZerSLX0M1SVEN76JuDcf53t8VZFeUC4vho6WDE9SOY54Yh6xga14mfIeoVMoY5JRD6_mmSSu1yn340vUVlyhDg16Nv8ANbFLvcjvspBSe6zjVhwF2BzyWSw1qNDo50?key=Jl51vrsB_5mVBZ39nY67pw" alt=""><figcaption><p>触发事件的电子邮件通知</p></figcaption></figure>


# 保存和共享

在MetaSleuth中，“保存和分享”功能通过以下方式增强您的工作流：

* [保存您的工作](/zh_cn/yong-hu-shou-ce/save-and-share/save-your-work)：安全地存储您的分析和可视化，以供将来参考。
* [与他人协作：](https://github.com/blocksecteam/ms_document_cn/blob/main/user-manual/save-and-share/collaborate-with-others.md) 轻松地与团队成员或利益相关者分享您的发现，以促进协作和讨论。
* [导出数据](/zh_cn/yong-hu-shou-ce/save-and-share/export-data)：以各种格式导出您的数据和见解，方便您展示您的工作。
* [让您的工作更易读](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble)：组织和格式化您的输出，以提高清晰度和呈现，确保您的分析易于理解。
* [分享您的发现](/zh_cn/yong-hu-shou-ce/save-and-share/share-your-findings)：轻松分享您的结果，与他人进行讨论和决策。


# 保存你的工作

MetaSleuth 提供了一个内置的保存功能，允许您保存当前的调查进度。这确保您可以稍后继续。\
另外，您只需点击“无标题”，然后修改图表的名称。这使得您更容易管理数据并与他人分享见解。

<figure><img src="/files/LM6B4aUIatnhUMYNlkRn" alt="图表界面"><figcaption></figcaption></figure>


# 与他人协作

用户可以加入团队进行合作，分享如标签、保存的图表、共享链接和监控在团队内。每位用户限于成为一个团队的成员。

## 创建你的团队

要开始合作，首先创建一个团队。所有团队均需订阅。

点击“创建新团队”，设置您的团队信息，并选择一个计划开始。

<figure><img src="/files/MHHhxKPhmanle8BXtnsU" alt=""><figcaption><p>创建您的团队</p></figcaption></figure>

## 添加团队成员

团队管理员可以从团队设置的“我的团队”部分邀请其他MetaSleuth用户加入您的团队。

每个团队成员可以拥有以下角色之一：

* :eyes: 观察者：可以查看团队工作空间中的数据，包括标签、图表和监控数据。在团队中不占用席位。
* :writing\_hand: 编辑者：除了以上内容，还可以创建、编辑和删除团队数据，使用团队计划功能进行调查。
* :gear: 管理员：除了以上内容，还可以管理团队及其成员。管理员角色仅限团队创建者。

团队管理员可以在团队设置页面管理团队成员，邀请或移除团队成员并修改其角色。

## 团队数据

### 在工作区中协作

用户在团队环境中创建的数据会自动保存在团队工作区中，所有团队成员都可以访问。在这个共享的工作区中，团队成员可以根据其角色特定的权限合作查看和编辑数据。

<figure><img src="/files/hIhDGa6xMzC1bX8JgwEK" alt=""><figcaption><p>团队工作区</p></figcaption></figure>

### 与团队共享个人数据

加入团队后，用户可以与团队共享其个人账户中的数据。用户可以与团队共享其地址标签、保存的图表、共享链接和监控进行协作。

与团队共享数据相当于在团队中复制数据的副本。在个人和团队环境中对数据所做的更改不会相互影响。

<figure><img src="/files/cU1NNVukXDjcis02SMGQ" alt=""><figcaption><p>将标签共享给团队</p></figcaption></figure>

## 切换环境

作为团队成员，您可以在个人与团队环境之间切换。在团队环境中创建的标签和图表属于团队，而不是您个人。

<figure><img src="/files/vHVBgLLJsQOaX7tnFQkJ" alt="" width="375"><figcaption><p>用户可以在个人与团队环境间切换</p></figcaption></figure>

\
个人和团队订阅是不同的。切换环境会改变您的权限和信用使用。在个人环境中，您访问个人计划功能并花费个人计划信用。在团队环境中，您利用团队计划的功能和信用。


# 导出数据

您可以以合适的格式导出相关数据，如交易详情、资产转移或分析结果。MetaSleuth 支持各种导出选项，包括 CSV 和 PNG，具体取决于您的需求。

<figure><img src="/files/2Y6GOqIaZfn1JDZeUJU4" alt=""><figcaption></figcaption></figure>


# 让你的工作更易读

为了增强分析的清晰度和展示效果，MetaSleuth 提供了多个功能：

* [备注：](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble/memo) 向您的可视化图表添加备注，为特定数据点提供背景或解释，使得记住关键见解更加容易。
* [标签：](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble/labels) 使用标签来识别和分类工作空间内的不同元素，方便快速识别和组织您的数据。
* [自定义水印](/zh_cn/yong-hu-shou-ce/save-and-share/make-your-work-more-readble/custom-watermark)：个性化您的可视化图表，加上自定义水印，不仅增加专业感，还帮助保持您的工作所有权。


# 备忘录

一旦您完成分析并收集了相关信息，就需要以全面的方式汇总您的发现。MetaSleuth 有一些很好的功能可以帮助您有效地汇总您的发现。

\
当您遇到可以增强对图表和背后故事理解的词语时，只需使用备忘录功能即可。

<figure><img src="/files/7VI2prEueCLQxM835Uqa" alt=""><figcaption></figcaption></figure>


# 标签

在分析过程中，您可以为地址和交易添加私人标签，以记录您对特定地址或交易的理解。这些私人标签充当个人笔记或注释。

与私人标签相反，MetaSleuth 还提供由 BlockSec 地址标签库支持的默认公共标签。这些公共标签为地址提供标准化和公众认可的标签，帮助您获得关于特定地址或交易的更多见解或信息。

<figure><img src="/files/hFJxEQiqrZLCha50RifO" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="/files/bIwEGf2JbXyWk7N6FCqV" alt=""><figcaption></figcaption></figure>

##


# 自定义水印

您可以选择上传自己的水印并将其放置在画布上的任意位置。此外，您可以为水印附加一个超链接，使其能够将观众引导到您的网站。

<figure><img src="/files/HjUF7zZP1U9rZZWgU1Hi" alt="自定义水印的示例"><figcaption></figcaption></figure>


# 分享你的发现

在组织资金流动、利用备忘录记录细节，甚至添加个人水印之后，是时候与他人分享你的发现了。你可能想与媒体分享，以开源你的发现，或者与其他调查人员分享以推进调查。

MetaSleuth 通过“分享图表”功能简化了这一过程，使您能够轻松分享您的分析，让其他人探索当前画布内容、深入细节，甚至继续编辑它。

<figure><img src="/files/ZjVllCBtCHLqo1WxTbzc" alt=""><figcaption></figcaption></figure>

其他人可以用我分享的链接做什么？ > > 当您通过 MetaSleuth 分享链接时，它会捕捉当前画布内容的快照并将其与该特定 URL 相关联。那些拥有访问共享链接的人可以查看快照并探索画布上的所有细节。如果其他人选择编辑快照，它会创建一个单独的副本，可以独立于原始快照进行修改、保存和共享。 其他人可以用我分享的链接做什么？ > > 当您通过 MetaSleuth 分享链接时，它会捕捉当前画布内容的快照并将其与该特定 URL 相关联。那些拥有访问共享链接的人可以查看快照并探索画布上的所有细节。如果其他人选择编辑快照，它会创建一个单独的副本，可以独立于原始快照进行修改、保存和共享。


# 账户和数据管理

在MetaSleuth中，有效的账户和数据管理对于个性化体验至关重要。本节内容包括：

* [账户设置：](/zh_cn/yong-hu-shou-ce/account-and-data-management/account-settings)管理您的账户详细信息，包括更改密码和安全选项，以确保您的账户保持安全。
* [偏好设置：](/zh_cn/yong-hu-shou-ce/account-and-data-management/preference-settings)通过调整设置（如通知偏好、显示选项和语言选择）定制您的用户体验。
* [用户数据：](/zh_cn/yong-hu-shou-ce/account-and-data-management/user-data)访问和管理您的数据，包括查看您的活动历史记录和导出相关信息以供记录。


# 账户设置

要访问帐户设置页面，点击右上角的`用户头像图标`，然后选择`帐户设置`。

<figure><img src="/files/QelApBeEuxVrUbriAPdF" alt=""><figcaption></figcaption></figure>

在帐户设置中，用户可以：

* 更新用户名（别名）
* 重置密码
* 开启/关闭 2FA 验证
* 设置 2FA 身份验证


# 偏好设置

要访问偏好设置页面，请点击右上角的`用户头像图标`，然后选择`偏好设置`。

## 图表设置

图表设置中的设置将影响画布的全局显示方式。

### 数量显示格式

此设置主要适用于画布中代币数量的显示。

* 标准格式（例如，1,099,999.99 Ether）为默认显示格式。
* 缩写格式（例如，1.099M Ether）可以缩短显示文本，使得在特定情况下画布内的布局更加紧凑。

<figure><img src="/files/xJcSOjZWqx0VC03Ce8P4" alt=""><figcaption></figcaption></figure>

### 自动隐藏可疑代币转移

当您打开此设置时，资金流动将默认取消选择（不在画布中显示）包含可疑代币转移的边。

{% hint style="warning" %}
对于可疑代币：我们通过分析链上活动和相关信息来评估代币声誉。如果您发现任何不准确之处，请联系我们进行报告。
{% endhint %}

## 水印

您可以在此处自定义水印并管理MetaSleuth水印的显示。

### 自定义水印

您可以上传徽标或图像来创建代表他们或其组织的自定义水印。您还可以为上传的水印添加URL链接，这样可以让他人在点击时访问链接。上传后，您可以将此自定义水印添加到他们的图表中以识别您的作品。此功能可供**专业计划及以上**的订阅者使用。

<figure><img src="/files/kWuHgrQNwlce5DqdCHba" alt=""><figcaption><p>上传您的自定义水印</p></figcaption></figure>

<figure><img src="/files/dz2rE5BEJVyhpMGbsZeb" alt=""><figcaption><p>将自定义水印添加到图表中</p></figcaption></figure>

### 移除MetaSleuth水印

专业计划及以上订阅者有权选择从他们的画布中移除MetaSleuth水印。通过打开开关，可以在全局范围内移除水印。

<figure><img src="/files/QviqqSGbqJ1KMxaR3Lyr" alt=""><figcaption><p>带有MetaSleuth水印的画布</p></figcaption></figure>

<figure><img src="/files/Kyhfde716axwnr5CnZ5L" alt=""><figcaption><p>没有MetaSleuth水印的画布</p></figcaption></figure>


# 用户数据

要访问用户数据管理页面，请点击右上角的`用户头像图标`。

## 私有标签

本节包括地址的私有名称标签和交易的私有备注。所有私有标签以表格列表格式显示，用户可以搜索、编辑和导出标签。

<figure><img src="/files/VmnyNUEi6lNfahJhmOK1" alt="私有标签"><figcaption><p>私有标签</p></figcaption></figure>

## 已保存的图表

在本节中，用户可以访问所有已保存的图表，并提供搜索、删除和编辑的选项。

<figure><img src="/files/tkDH0roJNgwuUKRUCPns" alt="已保存的图表"><figcaption><p>已保存的图表</p></figcaption></figure>

## 共享链接

在本节中，用户可以访问所有共享链接，并有删除、编辑到期时间和编辑信息的选项。请注意，共享链接是图表的快照，编辑不能更新共享链接的内容。

<figure><img src="/files/cR0omTRc2DONKVPvfqhb" alt="共享链接"><figcaption><p>共享链接</p></figcaption></figure>


# 计划、账单和付款

MetaSleuth 提供一系列供用户选择的计划。有关具体计划的详细信息，请参阅：<https://metasleuth.io/plans>。

我们还提供两种支付方式：银行卡和加密货币。用户可以在下方管理其订阅计划和账单信息：

1. [更改您的计划](/zh_cn/yong-hu-shou-ce/plans-billings-and-payments/change-your-plan)：快速调整您的订阅计划以满足您的需求，无论是升级还是降级。
2. [更新您的支付方式和账单信息](https://github.com/blocksecteam/ms_document_cn/blob/main/user-manual/plans-billings-and-payments/update-your-payment-method-and-billing-infomation.md)：轻松更新您的支付详情，确保不中断服务并避免支付问题。


# 更改你的计划

## 升级计划

您可以随时通过访问[定价页面](https://metasleuth.io/plans)、选择您想要的计划，并点击“升级”来升级您的计划。

在账单周期中途升级到更高的计划时：

* 您将立即被收取新计划的费用。
* 费用将根据当前账单周期剩余时间按比例计算。
* 新计划立即生效，账单周期保持不变。

如果您切换到较长的结算间隔：

* 您将立即为新计划付费。
* 费用将根据当前计划的先前结算周期剩余时间按比例减少金额。
* 新计划立即生效，并且账单周期立即更改。

## 降级计划

目前，MetaSleuth不提供在活跃订阅计划生效期间降级的选项。如果您需要降级，我们诚挚地建议您先取消现有订阅，然后在当前账单周期结束后重新订阅。

{% hint style="info" %}
请注意，在MetaSleuth中，将结算间隔从较长时间更改为较短时间被视为降级。
{% endhint %}

## 取消订阅

您的MetaSleuth订阅，无论是按月订阅还是按年订阅，都会自动续订，直到您取消为止。

您可以随时通过点击`用户头像图标` -> `订阅` -> `管理结算`来取消。

在Stripe页面上，点击 ***`取消订阅`*** 以取消订阅。取消后，您仍可以使用所有付费功能，直到账单周期结束。


# 更新您的付款方式和账单信息

## 在卡片和加密货币之间切换支付方式

要在卡片和加密货币支付方式之间切换，您需要在当前账单周期结束后重新订阅。

## 更新卡片支付方式

MetaSleuth 使用 Stripe 处理卡片支付和订阅，因此我们不会收集或存储您的卡片信息。

要更新您的支付方式，请点击 `用户头像图标` -> `订阅` -> `管理账单`。从那里，您可以在 Stripe 托管页面上更改支付方式。

## 更新账单信息

与支付方式相同，点击 `用户头像图标` -> `订阅` -> `管理账单` 以更新账单信息。

您可以在这里更改姓名、邮箱、地址、电话号码和税务信息。


# 团队计划与账单

MetaSleuth 提供三种不同的团队计划供您选择，您可以在此处查看：<https://metasleuth.io/plans>。

请注意，团队计划订阅不接受加密货币支付。

## 了解团队计划

MetaSleuth 的团队计划是基于成员数量（座位）的，这表示可以加入您组织的人员数量。例如，如果您有 10 个座位且占用了 6 个，则可以再添加 4 人。

### 按座位收费

MetaSleuth 会对您帐户上的所有座位收费，无论是否正在使用。例如，如果您有 5 个座位和 4 个活跃用户，即使一个座位未被占用，您也会为所有 5 个座位付费。

## 管理您的座位

团队管理员可以在团队设置的计费部分点击“更新座位”来增加或减少座位数量。请注意，总座位数不能少于已占用的座位数。

## 升级或添加座位

如果您添加座位或升级团队计划，新增的费用将立即应用到您当前的计费周期。

## 下载或移除座位

当您移除座位或降低计划时，这些变更将在您的下一个计费周期生效。

如有任何问题或需要进一步帮助，请随时通过 <ms_support@blocksec.com> 联系我们！


# 教程

[加密追踪：从一次交易开始](/zh_cn/yong-hu-shou-ce/tutorials/crypto-tracking-starting-with-a-transaction)

[高级分析：轻量级资金追踪](/zh_cn/yong-hu-shou-ce/tutorials/advanced-analysis-lightweight-fund-tracking)


# 加密货币追踪：从一笔交易开始

在本教程中，我们将通过追踪网络钓鱼交易中的被盗资金，指导您使用MetaSleuth的基本功能。我们将一起探索如何使用MetaSleuth分析交易、追踪特定资金及监控未转出资金。

**Video/Content:** [MetaSleuth 教程 - 使用 MetaSleuth 追踪网络钓鱼交易中的被盗资金](https://www.youtube.com/watch?v=Ad6sJpiG7Xg)

我们已在以太坊网络上识别出一笔交易哈希为0x2893fcabb8ed99e9c27a0a442783cf943318b1f6268f9a54a557e8d00ec11f69的网络钓鱼交易。现在，让我们深入分析。

## 输入目标，按“Enter”

首先，导航至 <https://metasleuth.io/>。选择以太坊作为网络，并输入您希望分析的交易。按回车键。现在，等待MetaSleuth返回的数据。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FKwJ2Vbz6fTQa9FJ5ieeY%2Fimage.png?alt=media\&token=d7cc498e-a8e9-4b66-a589-17f3b74ecdd2)

## 主要功能组件

一旦交易分析完成，您将被引导到MetaSleuth分析页面，您可以看到交易中发生的所有资产转移情况。如果分析目标是一个地址，所显示的信息将会更加复杂。我们将在单独的教程中介绍地址分析。

除了中心的资产转移图外，该页面还包括其他各种功能组件。以下是一个简化的图示，鼓励您在分析过程中探索它们的具体用法。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FjoRZbk0SPBPy7nfXbUbU%2Fimage.png?alt=media\&token=82d6723b-3eb7-475e-baaa-a44aa7fdb431)

## 追踪资金

我们关注的交易涉及只有一笔资产转移：地址0xbcd131，即受害者，转移了2586个MATIC到Fake\_Phishing180627。

要继续追踪被盗MATIC代币的去向，操作简单。只需选择Fake\_Phishing180627地址节点，点击节点右侧的 ***"+"*** 按钮。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FnDwint1byMsaKVcSBhr8%2Fimage.png?alt=media\&token=392d7ca2-f200-4819-b7eb-6148b2553326)

此功能被称之为 ***展开输出***，允许您追踪从这个地址发送的资产。在多数情况下，该功能提供了所需数据。然而，对于交易量较大的地址，您可能需要利用高级功能，如 ***高级分析*** 和 ***载入更多*** 来获得所需数据。

在点击 ***"+"*** 按钮后，我们可以看到 Fake\_Phishing180627 发出的多笔以太转账。那么我们想要追踪的 MATIC 呢？

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2Fb8P7ZIXKwyRAJDgSUP3i%2Fimage.png?alt=media\&token=c4603dc2-2b92-4c73-9a36-c3cfb4d8f926)

## 过滤画布

MetaSleuth不在画布上显示其获取的所有数据，以确保整体资金流动的表示干净且清晰。然而，MetaSleuth提供了多种工具，帮助用户找到所需数据并将其添加到画布上。在本例中，我们可以利用 ***代币过滤器***，将MetaSleuth获取的所有MATIC资产转移添加到画布中。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FLUKJS5RQ9ZmPTNBnkb3Z%2Fimage.png?alt=media\&token=b1937bcd-4956-41eb-ba02-87ac67b82475)

确认后，我们可以在画布上看到另外一笔由Fake\_Phishing180627发出的MATIC转移到Uniswap V3: MATIC。这正是我们追踪的被盗资金。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FS4u6ZEbSlx0mSpKpikwG%2Fimage.png?alt=media\&token=55f6d2b2-4715-4e2f-99bf-a674fa1520e1)

当涉及到发送到去中心化交易所（DEX）如Uniswap的资产时，我们的关注点不在于从地址Uniswap V3: MATIC转出的MATIC代币，而是在于Fake\_Phishing180627通过Uniswap的交换操作获得的资产。

那么Fake\_Phishing180627通过此次交换获得了哪些资产？让我们来调查这笔交换交易以找出答案。

## 添加特定数据

首先，我们需要确定MATIC从Fake\_Phishing180627转移到Uniswap V3: MATIC所属的交易。点击画布上的资产转移边缘，并在下面显示的 ***边缘列表*** 中点击 ***详细信息*** 以访问 ***交易列表***。找到该转移的交易哈希并复制它。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FfWWg5g159uM4ZiPplRtE%2Fimage.png?alt=media\&token=4dd10b0d-eb35-43d5-ba6f-f691427679cf)

然后，我们可以使用画布左上角的 ***添加地址/交易*** 功能将此交易添加到画布中。这将允许我们探索该交易中发生的资产转移，并更清晰地了解其内容。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FT6bQAwNzGcaTcMTq7LhC%2Fimage.png?alt=media\&token=09b3d743-3b3d-4c01-88d1-96f69ca6c4e1)

添加后，这笔交易中的所有资产转移将在画布上可见。很明显，Fake\_Phishing180627通过Uniswap将MATIC换成了0.944个以太币。这0.944个以太币是我们需要进一步追踪的资产。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2F68qtOzlhfl7hsL2Lubk4%2Fimage.png?alt=media\&token=f54ee047-fa41-4ee0-8e42-e301544a46fd)

## 追踪特定资金

在Fake\_Phishing180627发出的各种以太转账中，我们应该追踪哪些交易？

点击Fake\_Phishing180627，您可以在左侧地址面板中观察与此地址相关的资产转移。您可能已经注意到，这里可用的数据比画布上显示的更多（如前所述，MetaSleuth注重资金流动图的简洁性和可读性，默认并不显示所有数据）。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FXr95VjIMZk9Te5yEDzBr%2Fimage.png?alt=media\&token=4f4c50e6-d556-4017-8d6d-fff391c67315)

Fake\_Phishing180627 进行 MATIC 换以太交易的时间为 2023-06-18 14:57:11。因此，我们的主要关注点应该是此特定时间之后发生的以太币转账。为了过滤数据，我们可以使用过滤功能。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FzpkEX8bNISfmeXRpAO3p%2Fimage.png?alt=media\&token=664e759b-3c31-4ab1-a448-e2feb2f2d680)

在过滤结果中，很明显，在交换操作大约6分钟后，1.4个以太从Fake\_Phishing180627地址转移到了0x8bae70。这笔转账很可能包含我们要追踪的资金。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FuuGCFJDk1nDnNOld3lR0%2Fimage.png?alt=media\&token=31231f62-5f53-4378-bcf4-823c5cfd32ee)

我们可以在画布上标记并显示它们，继续追踪0x8bae70的资产。通过这样做，我们可以观察到资金最终在地址0x8de345中定居。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2FlsbIk1lwjQSu603v5soD%2Fimage.png?alt=media\&token=b8a5cf40-2b05-4323-af83-c247798a9107)

## 监控未转移资金

为确保您了解尚未转移的资金，我们可以主动监控它们。启用监控后，您将在相关资产转移发生时收到电子邮件通知。要探索更多的监控功能，请访问MetaSleuth监控仪表板：<https://metasleuth.io/monitor>。

![](https://3379259938-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwxbNGlBc5Kji1KaYLlhe%2Fuploads%2Fd8HdSs3VWy0SiaM1ThU8%2Fimage.png?alt=media\&token=7409cfb8-9ee1-496a-a092-4f736ac5f827)

## 总结

虽然这只是一次简短的探索，但我们希望MetaSleuth为您提供了便捷并流畅的追踪和调查体验。我们将在未来发布更多的教学材料，并欢迎您的建议。加入我们的Telegram群组：<https://t.me/MetaSleuthTeam>。


# 高级分析：轻量级资金追踪

在本教程中，我们将描述MetaSleuth的资金追踪功能。在调查过程中，我们通常希望追踪一个地址的**外出**资金。MetaSleuth通过支持从一个方向追踪资金流动来简化这一过程。

**Video/Content:** [MetaSleuth教程：使用MetaSleuth的高级分析进行轻量级资金追踪](https://www.youtube.com/watch?v=EH7x7BTumIQ)

下面，我们展示一个追踪网络钓鱼受害者的真实案例以展示该功能。被追踪的地址是\_ryanwould.eth (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)\_。

### 什么是资金追踪以及为何选择MetaSleuth

自成立以来，MetaSleuth的目标是为分析师提供更方便的可视化分析能力。在专注于链上侦查组和Web3社区后，我们发现最常见的任务之一是追踪指定地址在定义时间范围内的外出资金。

例如，这涉及追踪受害者地址中的被盗资金以便追回资金、监控聪明资金的目标以便更好地投资，以及为了反洗钱（AML）目的追踪可疑交易。

然而，这些活跃地址的资金流动可能极为复杂，涉及多种代币、不同目标，并跨越较长时间。这种情况确实给链上侦探带来了麻烦，他们必须花时间提取分析所需的相关信息。

为解决这一问题，MetaSleuth在所有辅助工具中提供了最轻量化/用户体验最佳/最快速的解决方案。

## 追踪细节

在调查网络钓鱼案件时，我们拥有以下信息。

* *ryanwould.eth (*&#x30;xc6D330E5B7Deb31824B837Aa77771178bD8e6713) 在网络钓鱼中遭受了重大损失。一位愤怒的链上侦探被赋予了寻找被盗资金去向并揭露隐藏的网络钓鱼团伙的任务。
* 已知线索
  * 受害者：*ryanwould.eth* (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)
  * 时间：大约在2023.02.25-2023.02.27
  * 损失资产：未知代币，未知金额
  * 网络：以太坊

### 第一步：选择地址

访问[metasleuth.io](https://metasleuth.io/)，选择相应的区块链网络（默认是以太坊），并输入资金的来源地址，即ryanwould.eth。

MetaSleuth将基于ENS名称解析相应地址。然后，在搜索框的右侧，使用MetaSleuth的核心功能，`高级分析`。

<figure><img src="/files/OoqPlLLCefhgRk2u0XvN" alt=""><figcaption><p>Metasleuth.io的入口点</p></figcaption></figure>

### 第二步：选择方向

进入高级分析设置面板后，我们可以选择资金的方向和时间范围。在这个任务中，我们只关注资金的流出（出）和网络钓鱼发生的时间段（2023-02-25->2023-02-28）。完成配置设置后，我们点击应用并按下Enter进入画布。

<figure><img src="/files/excRCjesAbnVruvFV5i4" alt=""><figcaption><p>高级分析设置</p></figcaption></figure>

### 第三步：生成第一张资金流动图

太好了！Metasleuth.io快速生成了2023年2月25日至2023年2月28日期间所有外出资金流动的可视化图表。多亏了这个功能，我们节省了大量的数据筛选时间。

此外，利用MetaSleuth维护的地址标签，我们可以轻松识别出在这段简短的时间内，只有两个不寻常的资金流动被检测到，均指向地址 "Fake\_Phishing11227"。这些异常交易涉及1,842 USDC和519,351 DATA代币，如图所示。

<figure><img src="/files/KgcJ7mzRo3ThF04rWXCG" alt=""><figcaption><p>初始资金流动</p></figcaption></figure>

### 第四步：筛选感兴趣的代币

为了更好地显示，我们打开代币配置项，移除其他默认代币，仅保留被盗代币（USDC, DATA），然后确认我们的更改。

<figure><img src="/files/8IlXDbBXqkVsK8WSyuiI" alt=""><figcaption><p>代币筛选</p></figcaption></figure>

### 第五步：扩展感兴趣地址的资金流动

资金流动变得非常简洁明了。为追踪资金流出，我们进一步扩展了资金转帐的第二跳。在资金转帐关系的第二跳中，我们发现网络钓鱼地址 "Fake\_Phishing11227" 将被盗资金转移到了Airswap并通过Airswap进行了代币交换。

<figure><img src="/files/5fbk6KF59MuniA4Jwqbm" alt=""><figcaption><p>筛选后的资金流动</p></figcaption></figure>

### 第六步：处理代币交换操作

由于我们的代币筛选配置，我们只关注DATA和USDC，这遮蔽了代币交换过程。为了解决这个问题，我们在代币配置中加入了ETH并重新添加了交换交易(0x23f4ed07e2937c3f8f345e44ce489b8f83d2b6fdbf0697f6711ff4c7f2a55162)。随着这一更新，我们现在对代币交换过程有了一个完整的视图。网络钓鱼行为者通过AirSwap交换了USDC和DATA代币并获得了14.58 ETH。此阶段（2022-02-27 22:30），单纯关注USDC和DATA再无意义。我们需要追踪获得的ETH路径以揭示更多的网络钓鱼地址。

<figure><img src="/files/t9QcDPFifUrOUAohCq2M" alt=""><figcaption><p>添加交易</p></figcaption></figure>

<figure><img src="/files/otuIufdOWduvtSrOaqgr" alt=""><figcaption><p>完整的资金流动</p></figcaption></figure>

### 第七步：进一步使用时间范围筛选

因此，我们继续对网络钓鱼地址 "Fake\_Phishing11227" 进行高级分析。同样，我们只关注外出资金，并选择时间范围在2023年2月27日至2023年2月28日之间。我们继续点击“分析”按钮以进行分析。

<figure><img src="/files/WuEEVoF0AuKaadqUyhaa" alt=""><figcaption><p>进一步分析按钮</p></figcaption></figure>

### 第八步：在发现感兴趣接收者时停止调查

在指定时间范围内，我们已经获取了从 "Fake\_Phishing11227" 发出的资金目标。似乎有许多接收地址参与其中，表示分配非法获取的资金过程。

在所有接收者中，地址\_"offtherip.eth"\_, "Fake\_Phishing76579", 和 "Fake\_Phishing7064" 接收了大部分分配资金，分别是10.36 ETH, 8.36 ETH, 和1.85 ETH。

基于这样的分配比例，我们认为\_offtherip.eth\_ 是此次调查中最为可疑的实体，需要引起关注。

<figure><img src="/files/YXKpjFobgpwkZdXCcClZ" alt=""><figcaption><p>最终追踪结果</p></figcaption></figure>

取得了该异常地址 "offtherip.eth" 后，后续步骤可能需要使用非区块链技术，例如社交工程分析。然而，在此次针对链上资金转移的分析中，metasleuth.io 提供了多种便利的技术协助，让整个分析过程在不到十分钟内就完成。

### 结论

在本教程中，我们展示了如何使用MetaSleuth追踪网络钓鱼受害者的资金流动。分析总结如下。

* 受害者: *ryanwould.eth* (0xc6D330E5B7Deb31824B837Aa77771178bD8e6713)
* 时间: 2023-02-27 22:00
* 损失资产: 1,842 USDC, 519,351 DATA
* 网络: 以太坊
* 资金目标：
  * 第一跳: Fake\_Phishing 11227
  * 第二跳:
    * *offtherip.eth*
    * Fake\_Phishing76579
    * Fake\_Phishing7064
* 分析耗时: <10分钟


# 介绍

BlockSec AML API 介绍

BlockSec AML API 服务提供两套主要的 API，分别为 [**地址标签查询**](/zh_cn/blocksec-fan-xi-qian-api/address-label-api) 和 [**风险评分查询**](/zh_cn/blocksec-fan-xi-qian-api/wallet-screening-api) 提供服务。

## API 概览

### 地址标签 API

<table><thead><tr><th width="133">方法</th><th>API</th></tr></thead><tbody><tr><td><code>GET</code></td><td><a href="/pages/Rg30dXr1l3wH97B0SZX7#get-supported-chains">获取支持的链</a></td></tr><tr><td><code>POST</code></td><td><a href="/pages/Rg30dXr1l3wH97B0SZX7#get-address-labels">获取地址标签</a>（以<a href="/pages/Rg30dXr1l3wH97B0SZX7#get-address-labels-in-batch">批量</a>方式）</td></tr><tr><td><code>POST</code></td><td><a href="/pages/Rg30dXr1l3wH97B0SZX7#get-entity-info">获取实体信息</a></td></tr></tbody></table>

### 风险评分 API

<table><thead><tr><th width="132">方法</th><th>API</th></tr></thead><tbody><tr><td><code>GET</code></td><td><a href="/pages/gCoH5fKTEmBvfSer7uwk#get-supported-chains">获取支持的链</a></td></tr><tr><td><code>GET</code></td><td><a href="/pages/gCoH5fKTEmBvfSer7uwk#get-risk-indicators">获取风险指标</a></td></tr><tr><td><code>POST</code></td><td><a href="/pages/gCoH5fKTEmBvfSer7uwk#get-address-compliance-risk">获取地址风险评分</a></td></tr></tbody></table>

## 速率限制

每个 API 请求的速率限制为每秒五个请求，每个订阅计划限定每日可 **查询的地址** 数量。查看我们的 [订阅页面](https://metasleuth.io/plans#apis) 以获取更多详情。

## 了解更多

[authentication.md](/zh_cn/blocksec-fan-xi-qian-api/introduction/authentication)

[response-format.md](/zh_cn/blocksec-fan-xi-qian-api/introduction/response-format)


# 身份验证

我们的API使用API密钥进行身份验证。为了确保您的数据安全，**请不要与任何人共享您的API密钥。**

### 如何获取API密钥？

要生成API密钥，请先[注册一个BlockSec账户](https://account.blocksec.com/signup?referer=https%3A%2F%2Fmetasleuth.io)。注册成功后，访问\_**设置**\_部分中的[APIs](https://metasleuth.io/settings?type=apis)面板，快速获取您的API密钥。

{% hint style="info" %}
如果您通过我们的销售渠道订阅了定制的API服务，请联系您的指定服务联系人以获取API密钥。
{% endhint %}

<figure><img src="/files/P6idY1svKWqeuLYTxW80" alt=""><figcaption></figcaption></figure>

### 如何使用API密钥

在每个API请求的HTTP请求头中包含"**API-KEY**"头，并将您的API密钥作为值提供。请参见以下示例。

{% code overflow="wrap" %}

```sh
curl -L \
  -X POST \
  -H 'Content-Type: application/json' \
  -H 'API-KEY:$API_KEY' \
  'https://aml.blocksec.com/address-label/api/v3/labels' \
  -d '{"chain_id":1,"address":"0x00d7e7409bfe09a736d3e993de9b87d0baa314d5"}'
```

{% endcode %}


# 响应格式

当您的 HTTPS 请求成功时，您将在每个响应中看到以下四个主要字段。

<table><thead><tr><th width="135">字段</th><th width="90">类型</th><th>描述</th></tr></thead><tbody><tr><td>request_id</td><td>String</td><td>当前请求的唯一 ID。如果您对该请求的结果有任何疑问或担忧，请发送给我们请求 ID 以供审查。</td></tr><tr><td>code</td><td>Integer</td><td>请求的状态码。代码 200000 表示请求成功，而其他代码表示错误。下表提供了代码及其含义的详细列表。</td></tr><tr><td>message</td><td>String</td><td>有关代码的信息。</td></tr><tr><td>data</td><td>-</td><td>详细结果。根据每个请求，此字段有所不同。请参考每个端点的文档以获取详细信息。</td></tr></tbody></table>

<table><thead><tr><th width="137">代码</th><th>描述</th></tr></thead><tbody><tr><td>200000</td><td>成功</td></tr><tr><td>400001</td><td>未经授权的操作</td></tr><tr><td>400002</td><td>请求频率过高。请稍后再试。</td></tr><tr><td>400004</td><td>参数无效</td></tr><tr><td>400005</td><td>用户不存在</td></tr><tr><td>400006</td><td>服务器繁忙</td></tr><tr><td>400007</td><td>无效的 API 密钥</td></tr><tr><td>400008</td><td>无效的认证格式</td></tr><tr><td>400009</td><td>API 密钥已过期</td></tr><tr><td>400010</td><td>404 未找到！</td></tr><tr><td>400011</td><td>地址无效。请确保您提供了正确的链和地址。</td></tr><tr><td>400012</td><td>超过每日请求限制。请明天再试。</td></tr><tr><td>400013</td><td>参数无效。不支持的链名称</td></tr><tr><td>500000</td><td>内部错误</td></tr></tbody></table>




---

[Next Page](/llms-full.txt/1)

