# Crypto Address Sanctions Checker (OFAC / SlowMist / BlockSec) (`gochujang/crypto-address-sanctions-checker`) Actor

On-demand risk lookup for EVM wallet addresses. Returns flags for sanctioned, mixer, money laundering, cybercrime, phishing, darkweb, blacklist, fake KYC, stealing attack. Source: GoPlus Security aggregating SlowMist + BlockSec + OFAC. $0.01 per address.

- **URL**: https://apify.com/gochujang/crypto-address-sanctions-checker.md
- **Developed by:** [Hojun Lee](https://apify.com/gochujang) (community)
- **Categories:** Developer tools, Automation, News
- **Stats:** 7 total users, 0 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $10.00 / 1,000 address checkeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Crypto Address Sanctions Checker

> On-demand risk lookup for EVM wallet addresses. Returns flags for **sanctioned, mixer, money laundering, cybercrime, phishing, darkweb, blacklist, fake KYC, stealing attack** and 10+ other categories. Powered by **GoPlus Security** (aggregates SlowMist + BlockSec + OFAC sanctions data). **$0.01 per address.**

***

### ⚡ Run in 30 seconds

Click **Start**, enter any EVM wallet address, and get back a complete risk profile flagging sanctions (OFAC), mixer usage, cybercrime, phishing, and 10+ other threat categories sourced from GoPlus, SlowMist, and BlockSec. Costs $0.01 per address.

***

### Input Parameters

| Parameter | Type | Default | Description |
|---|---|---|---|
| `addresses` | array | `[]` | List of EVM wallet addresses (0x...) to check. Each is billed individu |
| `address` | string | ``| Single EVM address (used when 'addresses' is empty). |
| `chainId` | integer | `1` | EVM chain ID. 1=Ethereum, 56=BSC, 137=Polygon, 42161=Arbitrum, 10=Opti |
| `telegramBotToken` | string | `—` | Telegram bot token for risk alerts. |
| `telegramChatId` | string |`` | Telegram chat ID to send alerts to (get it from @userinfobot) |

***

### Why this exists

If you run an exchange, lending protocol, or any dApp where users connect wallets, you have **compliance obligations**. OFAC requires you to screen against the SDN list. Major chains like Ethereum + USDC freeze sanctioned addresses on-chain.

Commercial compliance APIs (Chainalysis KYT, TRM Labs, Elliptic) cost **$10K-$100K/year minimum** and gate basic risk checks. This actor uses GoPlus Security's free public API — which aggregates SlowMist, BlockSec, OFAC, and Chainabuse — to return the same yes/no risk signals for **$0.01 per address**.

It's not a replacement for full Chainalysis KYT in regulated environments, but for early-stage products / individual research / triage, this is the fastest free check available.

***

### What you get per address

| Field | Example | Notes |
|---|---|---|
| `address` | `0x098B...2f96` | input address |
| `chain_id` | `1` | |
| `risk_level` | `critical` | clean / warn / high / critical / unknown |
| `flagged_fields` | `["sanctioned", "money_laundering"]` | list of flagged categories |

Plus per-category boolean fields:

| Field | Source flag |
|---|---|
| `sanctioned` | OFAC SDN list match |
| `money_laundering` | known ML wallet (SlowMist, BlockSec) |
| `cybercrime` | involved in cybercrime ops |
| `financial_crime` | broader financial crime category |
| `darkweb_transactions` | has interacted with darkweb mixers/markets |
| `mixer` | known Tornado Cash / similar |
| `phishing_activities` | phishing scam wallet |
| `stealing_attack` | known attack / drainer |
| `blackmail_activities` | ransomware / extortion |
| `blacklist_doubt` | not confirmed but suspicious |
| `fake_kyc` | used in KYC fraud |
| `fake_standard_interface` | malicious contract pretending to be ERC20 |
| `fake_token` | rug-pull token deployer |
| `honeypot_related_address` | involved with honeypot tokens |
| `malicious_mining_activities` | mining-pool fraud |
| `gas_abuse` | gas-token abuse / spam |
| `reinit` | proxy reinit attack |

`"1"` = flagged. `"0"` = clean.

***

### Risk level decoded

| Level | Trigger |
|---|---|
| ✅ `clean` | No flags |
| 🟡 `warn` | 1–2 minor flags (e.g. `blacklist_doubt` only) |
| 🔴 `high` | Multiple flags or any phishing/fake-KYC/honeypot |
| ☠️ `critical` | Sanctioned, money laundering, cybercrime, mixer, stealing |

***

### Quick start

#### Check a single address (Ronin bridge hacker / Lazarus Group)

```json
{
  "address": "0x098B716B8Aaf21512996dC57EB0615e2383E2f96",
  "chainId": 1
}
```

#### Batch check multiple addresses

```json
{
  "addresses": [
    "0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
    "0x098B716B8Aaf21512996dC57EB0615e2383E2f96",
    "0x910Cbd523D972eb0a6f4cAe4618aD62622b39DbF"
  ],
  "chainId": 1
}
```

#### With Telegram alert

```json
{
  "address": "0x...",
  "telegramBotToken": "YOUR_BOT_TOKEN",
  "telegramChatId": "YOUR_CHAT_ID"
}
```

***

### Supported chains

| Chain | ID |
|---|---|
| Ethereum | 1 |
| BSC | 56 |
| Polygon | 137 |
| Arbitrum | 42161 |
| Optimism | 10 |
| Base | 8453 |
| Avalanche | 43114 |
| Fantom | 250 |

***

### Pricing

**Pay-Per-Event**: `$0.01 per address checked.`

| Run | Addresses | Cost |
|---|---|---|
| Single address | 1 | $0.01 |
| Batch of 100 | 100 | $1.00 |
| Daily KYT batch of 1000 | 1000 | $10.00 |

vs Chainalysis KYT — minimum $10,000/year baseline. For triage / early product, this is 10-100x cheaper.

***

### Use cases

1. **Pre-onboarding screening** — Reject addresses on OFAC SDN list at signup
2. **Continuous monitoring** — Re-screen connected wallets daily via Apify schedule
3. **Inbound transaction filter** — Check the sender before crediting deposit
4. **Treasury triage** — Check addresses interacting with your DAO multisig
5. **Research** — Investigate hack flows + sanctioned cluster activity
6. **Personal safety** — Verify counterparty wallets before P2P transactions

***

### Disclaimer

This actor is a triage tool, **not** a final compliance system. GoPlus is one of multiple data sources. For regulated production use:

- Combine with at least one other provider (Chainalysis / TRM / Elliptic)
- Maintain your own internal blacklist
- Document your risk decision process

This actor returns data from GoPlus Security's public address\_security endpoint. We are not affiliated with GoPlus.

***

### Related actors (same author)

- [Token Honeypot Detector](https://apify.com/gochujang/token-honeypot-detector) — Pair with this when checking a token's creator wallet
- [Wallet PnL Analyzer](https://apify.com/gochujang/wallet-pnl-analyzer) — Activity history of an address
- [Smart Money Wallet Tracker](https://apify.com/gochujang/smart-money-tracker)
- [DeFi Liquidation Risk Checker](https://apify.com/gochujang/defi-liquidation-risk-checker)

***

### Feedback

A short review helps compliance teams find it: [Leave a review on Apify Store](https://apify.com/gochujang/crypto-address-sanctions-checker#reviews)

# Actor input Schema

## `addresses` (type: `array`):

List of EVM wallet addresses (0x...) to check. Each is billed individually.

## `address` (type: `string`):

Single EVM address (used when 'addresses' is empty).

## `chainId` (type: `integer`):

EVM chain ID. 1=Ethereum, 56=BSC, 137=Polygon, 42161=Arbitrum, 10=Optimism, 8453=Base, 43114=Avalanche, 250=Fantom.

## `telegramBotToken` (type: `string`):

Telegram bot token for risk alerts.

## `telegramChatId` (type: `string`):

Telegram chat ID to send alerts to (get it from @userinfobot)

## Actor input object example

```json
{
  "addresses": [
    "0x098B716B8Aaf21512996dC57EB0615e2383E2f96"
  ],
  "address": "",
  "chainId": 1,
  "telegramChatId": ""
}
```

# Actor output Schema

## `dataset` (type: `string`):

No description

## `summary` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "addresses": [
        "0x098B716B8Aaf21512996dC57EB0615e2383E2f96"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("gochujang/crypto-address-sanctions-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "addresses": ["0x098B716B8Aaf21512996dC57EB0615e2383E2f96"] }

# Run the Actor and wait for it to finish
run = client.actor("gochujang/crypto-address-sanctions-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "addresses": [
    "0x098B716B8Aaf21512996dC57EB0615e2383E2f96"
  ]
}' |
apify call gochujang/crypto-address-sanctions-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=gochujang/crypto-address-sanctions-checker",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/DSfHbJ8TVXngO8li2/builds/rkoAkXlrverZg6wMW/openapi.json
