Coverage · figures computed live
How deep we screen, declared chain by chain.
OceanAlt currently holds 24,042 risk addresses and 858,138 malicious domains, refreshed daily. Public data differs by chain, so screening depth does too — the table below states which steps run on each chain, so you can decide which payments need extra checks.
24,042
858,138
10
Chain by chain: how deep
| Chain | Depth | What that means |
|---|---|---|
| Ethereum | List matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request. The on-chain USDT freeze list flags even the zero address, so it contains non-risk entries and is not used in verdicts. | |
| Polygon | List matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request. | |
| Arbitrum | List matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request. | |
| Base | List matching, issuer freeze list (USDC), address age and activity, one-hop taint (transaction history from the public Blockscout API); fund flow and deep trace on request. | |
| Optimism | List matching, issuer freeze list (USDC), address age and activity, one-hop taint (transaction history from the public Blockscout API); fund flow and deep trace on request. | |
| TRON | List matching, the Tether freeze list (USDT-TRC20), one-hop taint (USDT received from Tether-frozen addresses), address age, activity and Tronscan public labels; fund flow and deep trace on request (also available as a paid per-call endpoint). | |
| BNB Chain | List matching and address activity (on-chain transaction count and balance). There is no free transaction-history API on this chain, so no one-hop taint, fund flow or deep trace; USDT and USDC here are Binance-Peg tokens with no issuer freeze list to query. | |
| Avalanche | List matching, issuer freeze list (USDC) and address activity (on-chain transaction count and balance). There is no free transaction-history API on this chain, so no one-hop taint, fund flow or deep trace. | |
| Solana | Verdicts use list matching, without on-chain behavioural analysis; deep trace on request (follows USDC/USDT inflows upstream, up to 3 hops, parsing at most 12 transactions per address). | |
| Bitcoin | Verdicts use list matching, without on-chain behavioural analysis; deep trace on request (follows inflows upstream, up to 3 hops). |
What the list is made of
ransomware11,186Phishing addresses6,208Community scam lists3,182OFAC designations1,755Hacks & exploits708Mixers65
Addresses removed upstream are not deleted; they are marked delisted and kept. “Was this address listed on the day we paid?” is the question compliance actually asks, and deleting the row makes it unanswerable forever.
Reading a verdict, and scope
- No match is not safety. New addresses and new domains always precede any list. We report “no risk signal found”, never “safe”.
- Verdicts use one-hop relations only (funds received from a listed or frozen address), as signals. Multi-hop tracing runs on request in the deep trace — up to 3 hops, following the largest few sources per hop — and its result is returned separately without changing the verdict.
- No identity attribution: verdicts rest on the address and its on-chain behaviour; we neither infer nor collect who is behind it.
- Contract security auditing is out of scope: contract bugs, oracle and bridge risks need an audit.
- We do not decide for you. We return a verdict and the evidence; whether the payment moves is your policy's call.

