Data Sources, Attribution and Licensing Statement
OceanAlt's screening relies on government and sanctions notices, stablecoin-issuer public information, malicious-domain/phishing databases, academic datasets, public blockchain data and data reviewed by the OceanAlt team. We publish our main sources, licences and boundaries so you know where a result comes from and which data may or may not be redistributed. The table below is generated from the internal source ledger.
1. Rights principles
Third-party data remains its owner's; OceanAlt's use does not imply the owner's approval or endorsement; sources carry different licences; seeing a result in the OceanAlt API does not entitle you to download or redistribute that source's full dataset; where this page conflicts with a source licence, the source licence prevails; for unclear licences OceanAlt restricts use and keeps confirming, and never reads “not forbidden” as “commercial redistribution allowed”.
2. Source and licence ledger (generated)
OFAC SDN digital-currency addresses (auto-compiled by 0xB10C) · owner: US Treasury OFAC · compilation: 0xB10C · use: Sanctioned addresses (18 chains) · licence/rights: MIT (the compilation); the underlying data is US government public information · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/0xB10C/ofac-sanctioned-digital-currency-addresses — MIT permits commercial use; the OFAC list itself is public government information.
UK OFSI consolidated sanctions list · owner: HM Treasury / OFSI · use: Sanctioned addresses (UK) · licence/rights: Open Government Licence v3.0 · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://www.gov.uk/government/publications/financial-sanctions-consolidated-list-of-targets — OGL v3 permits commercial use with attribution.
Israel NBCTF seizure-order addresses (official originals) · owner: Israel Ministry of Defense NBCTF (original seizure and forfeiture orders) · use: Terror-financing addresses (incl. TRON/USDT) · licence/rights: Facts published by a government (the addresses), attributed to NBCTF; extracted and verified by us from the originals · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-16 · https://nbctf.mod.gov.il/en/Minister%20Sanctions/PropertyPerceptions/Pages/Blockchain.aspx — Primary path since 2026-09-16: 76 official originals (72 scanned PDFs + 4 Excel annexes) downloaded by hand from the official page (it is behind a bot challenge, which we do not bypass), extracted with scripts/nbctf-extract.mjs; all 548 addresses passed their own checksum before ingestion, and OCR reads that a checksum could not prove are excluded. Addresses only — the names, ID numbers, phone numbers and emails in those annexes are never extracted, stored or published. The data file (site/data/nbctf-official.json) traces every address back to an order, page or spreadsheet cell.
Israel NBCTF addresses (OpenSanctions compilation, gap filler) · owner: Israel Ministry of Defense NBCTF · machine-readable compilation: OpenSanctions · use: The portion of those addresses we could not read verbatim from the originals · licence/rights: The original notices are public government facts; this path is the OpenSanctions compilation (CC BY-NC 4.0, non-commercial) · tier: YELLOW · usable/citable; commercial redistribution boundary pending · attribution: yes · status: integrated · last reviewed: 2026-09-16 · https://nbctf.mod.gov.il/ — Demoted to a gap filler on 2026-09-16: 548 addresses are now verified from the official originals, while 179 appear only in this compilation — 102 of them match OCR-garbled fragments in the scanned originals (so the originals do contain them), and 76 appear nowhere in this batch of orders (possibly older orders no longer listed). The non-commercial licence does not match our commercial use; whether to keep this path is the founder's call (docs/nbctf-source.md). We ingest addresses only, never personal data, and do not redistribute the compilation.
Ransomwhere ransomware payment addresses · owner: Jack Cable (the Ransomwhere project) · Zenodo DOI 10.5281/zenodo.6512122 · use: Historical ransomware-associated addresses · licence/rights: Not stated (the site declares all report content public; no SPDX licence) · tier: YELLOW · usable/citable; commercial redistribution boundary pending · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://ransomwhe.re/ — Used with attribution and DOI citation per academic-dataset convention; a licence enquiry is drafted. Hits are labelled as historical associations, not current activity.
MyEtherWallet ethereum-lists darklist · owner: MyEtherWallet · use: Community scam/phishing addresses · licence/rights: MIT · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/MyEtherWallet/ethereum-lists — MIT permits commercial use.
ScamSniffer scam-database · owner: ScamSniffer · use: Phishing domains + scam addresses · licence/rights: GPL-3.0 · tier: YELLOW · usable/citable; commercial redistribution boundary pending · attribution: yes · status: integrated · last reviewed: 2026-09-13 · https://github.com/scamsniffer/scam-database — Queried server-side only; never bundled into the SDK or offered for download. Whether GPL copyleft reaches a network service over factual data, and whether the EU database right applies, was assessed three times as low risk; on 2026-09-13 the operator decided to continue on that basis without external counsel, with a reversible plan in place: every domain carries a source tag (sourceRef=scamsniffer, 347,451 entries) so the source can be disabled precisely at any time without touching others. Remains YELLOW and never in a distributable package.
MetaMask eth-phishing-detect · owner: MetaMask (Consensys) · use: Phishing domains · licence/rights: DON'T BE A DICK PUBLIC LICENSE (permissive) · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/MetaMask/eth-phishing-detect — The licence text permits use and redistribution for any purpose (notice retained).
Polkadot.js phishing · owner: Parity / polkadot-js · use: Phishing domains · licence/rights: Apache-2.0 · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/polkadot-js/phishing — Apache-2.0 permits commercial use.
Phishing.Database · owner: Mitchell Krog / Phishing-Database · use: General phishing domains · licence/rights: MIT · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/Phishing-Database/Phishing.Database — MIT permits commercial use. Ingest gate refuses shared-hosting apexes and major exchange/wallet domains to avoid flagging legitimate services.
Forta labelled-datasets · owner: Forta Foundation · use: Hack/exploit contracts, phishing addresses · licence/rights: MIT · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/forta-network/labelled-datasets — MIT permits commercial use.
Stablecoin issuer on-chain freeze lists (read-only calls to the USDT / USDC contracts) · owner: Tether / Circle (public on-chain state) · use: Issuer freeze status · licence/rights: Public on-chain state, read directly from the contract · tier: GREEN · commercial use clearly permitted · attribution: no · status: integrated · last reviewed: 2026-09-12 · https://etherscan.io/token/0xdac17f958d2ee523a2206206994597c13d831ec7 — Read directly from public contract state on-chain; no dataset licence involved. A failed lookup is returned as unknown, never as not-frozen.
eth-labels entity labels (dawsbot) · owner: dawsbot (derived from public block-explorer labels) · use: Neutral entity labels (exchanges, protocols); explanation only, never scored · licence/rights: MIT (the compilation); upstream are public block-explorer labels · tier: YELLOW · usable/citable; commercial redistribution boundary pending · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://github.com/dawsbot/eth-labels — The compilation is MIT, but it derives from block-explorer pages whose terms restrict scraping. Used for explanation only, never attributed to the explorer, never redistributed.
DefiLlama hacks dataset · owner: DefiLlama · use: Public incident archive (event-level, no addresses) · licence/rights: Open API (no key) · tier: GREEN · commercial use clearly permitted · attribution: yes · status: integrated · last reviewed: 2026-09-12 · https://defillama.com/hacks — Open API; each incident links to its original report, and we label whether pre-payment screening could have caught it.
CERT Polska warning list (hole.cert.pl) · owner: CERT Polska / NASK · use: Phishing domains (Polish national CERT) · licence/rights: Not stated · tier: YELLOW · usable/citable; commercial redistribution boundary pending · attribution: yes · status: not integrated · last reviewed: 2026-09-12 · https://hole.cert.pl/ — Not integrated. Commercial-use and redistribution terms are unstated; an enquiry is drafted and we will not integrate without a clear basis.
OpenPhish Community Feed · owner: OpenPhish · use: Phishing URLs · licence/rights: The terms expressly forbid commercial use, including security operations, threat intelligence and product development · tier: RED · must not be used · attribution: no · status: not integrated · last reviewed: 2026-09-12 · https://openphish.com/ — Commercial use prohibited. Not integrated.
Phishing Army · owner: Phishing Army · use: Phishing domains · licence/rights: CC BY-NC 4.0 · tier: RED · must not be used · attribution: no · status: not integrated · last reviewed: 2026-09-12 · https://phishing.army/ — Non-commercial licence. Not integrated.
OpenSanctions bulk data · owner: OpenSanctions · use: Sanctions and PEP entities (bulk) · licence/rights: CC BY-NC 4.0 (commercial use requires a paid licence) · tier: RED · must not be used · attribution: no · status: not integrated · last reviewed: 2026-09-12 · https://www.opensanctions.org/ — Non-commercial licence; not bulk-integrated. Used only as an index of which government lists carry crypto addresses; we fetch from the primary government sources.
3. Tier gate
GREEN: commercial use clearly permitted. YELLOW: internal use or citation permitted, commercial redistribution boundary unclear. RED: non-commercial, prohibited, conflicting or unlicensed.
Ingest and release gates block RED data from any commercial distribution package; a weekly check confirms the SDK and MCP packages contain no address or domain datasets.
4. SDK principles
Unless legal review confirms otherwise: the SDK bundles no GPL, non-commercial or unclear-licence datasets; the SDK contains only call logic; risk data is processed on OceanAlt's servers; API output provides sources and evidence rather than copies of third-party databases.

