OceanAltOceanAlt

Coverage · figures computed live

How deep we screen, declared chain by chain.

OceanAlt currently holds 24,042 risk addresses and 858,138 malicious domains, refreshed daily. Public data differs by chain, so screening depth does too — the table below states which steps run on each chain, so you can decide which payments need extra checks.

Risk addresses

24,042

lists 23,104 + team-reviewed high-risk 938 · lists refreshed daily at 04:15

Malicious domains

858,138

covers the payment-URL layer (endpoint screening)

Chains supported

10

6 at full depth; per chain below

Chain by chain: how deep

ChainDepthWhat that means
EthereumFullList matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request. The on-chain USDT freeze list flags even the zero address, so it contains non-risk entries and is not used in verdicts.
PolygonFullList matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request.
ArbitrumFullList matching, issuer freeze list (USDC), address age and activity, one-hop taint; fund flow and deep trace on request.
BaseFullList matching, issuer freeze list (USDC), address age and activity, one-hop taint (transaction history from the public Blockscout API); fund flow and deep trace on request.
OptimismFullList matching, issuer freeze list (USDC), address age and activity, one-hop taint (transaction history from the public Blockscout API); fund flow and deep trace on request.
TRONFullList matching, the Tether freeze list (USDT-TRC20), one-hop taint (USDT received from Tether-frozen addresses), address age, activity and Tronscan public labels; fund flow and deep trace on request (also available as a paid per-call endpoint).
BNB ChainPartialList matching and address activity (on-chain transaction count and balance). There is no free transaction-history API on this chain, so no one-hop taint, fund flow or deep trace; USDT and USDC here are Binance-Peg tokens with no issuer freeze list to query.
AvalanchePartialList matching, issuer freeze list (USDC) and address activity (on-chain transaction count and balance). There is no free transaction-history API on this chain, so no one-hop taint, fund flow or deep trace.
SolanaList matchingVerdicts use list matching, without on-chain behavioural analysis; deep trace on request (follows USDC/USDT inflows upstream, up to 3 hops, parsing at most 12 transactions per address).
BitcoinList matchingVerdicts use list matching, without on-chain behavioural analysis; deep trace on request (follows inflows upstream, up to 3 hops).

Batch screening skips the EVM issuer-freeze lookup and TRON one-hop taint for speed; screen addresses one at a time when you need those steps.

What the list is made of

ransomware11,186Phishing addresses6,208Community scam lists3,182OFAC designations1,755Hacks & exploits708Mixers65

Addresses removed upstream are not deleted; they are marked delisted and kept. “Was this address listed on the day we paid?” is the question compliance actually asks, and deleting the row makes it unanswerable forever.

Reading a verdict, and scope

  • No match is not safety. New addresses and new domains always precede any list. We report “no risk signal found”, never “safe”.
  • Verdicts use one-hop relations only (funds received from a listed or frozen address), as signals. Multi-hop tracing runs on request in the deep trace — up to 3 hops, following the largest few sources per hop — and its result is returned separately without changing the verdict.
  • No identity attribution: verdicts rest on the address and its on-chain behaviour; we neither infer nor collect who is behind it.
  • Contract security auditing is out of scope: contract bugs, oracle and bridge risks need an audit.
  • We do not decide for you. We return a verdict and the evidence; whether the payment moves is your policy's call.