Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Stablecoin Scanner

REMOTE · STABLESCAN.ACHIVX.COM · SCANNED OCT 8

Stablecoin risk for agents: freezes, OFAC, exposure, allowances, transfers, graph. 7 chains.

+5 this week 68 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security74
Transport & Reachability100
Schema Quality & AI Usability59
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 5405 tokens (~675/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability check failed: schema churn in the 8 days we've observed: 0 tool removals, 7 breaking changes, 0 auth/transport breaks, 0 additions. See how to fix → Fail
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Stablecoin Scanner MCP server?

Stablecoin Scanner is a hosted endpoint at https://stablescan.achivx.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · stablescan.achivx.com

# add to Claude Code
claude mcp add --transport http com-achivx-stablescan 'https://stablescan.achivx.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-achivx-stablescan": {
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-achivx-stablescan": {
      "type": "http",
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-achivx-stablescan]
url = "https://stablescan.achivx.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-achivx-stablescan": {
      "type": "remote",
      "url": "https://stablescan.achivx.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-achivx-stablescan --url 'https://stablescan.achivx.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-achivx-stablescan:
    url: "https://stablescan.achivx.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-achivx-stablescan": {
      "Transport": "http",
      "Url": "https://stablescan.achivx.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-achivx-stablescan -t streamable-http -u 'https://stablescan.achivx.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-achivx-stablescan": {
      "type": "http",
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 8 Oct 26 +4
    • Stability: 0.13 → fail ▼ security
    • Authorization: unverified → partial ▲ security
    • Tool “get_address_approvals” rewrote its description, which is the text the model reads security
    • Tool “get_address_compliance” rewrote its description, which is the text the model reads security
    • Tool “get_address_exposure” rewrote its description, which is the text the model reads security
    • Tool “get_address_risk” rewrote its description, which is the text the model reads security
    • Tool “get_recent_transactions” rewrote its description, which is the text the model reads security
    • Tool “get_sanctions_status” rewrote its description, which is the text the model reads security
    • Tool “get_sync_status” rewrote its description, which is the text the model reads security
    • Tool “get_wallet_graph_walk” rewrote its description, which is the text the model reads security
    • Schema quality: 391 → 675 ▼ functional
    • Server version: 1.3.0 → 1.4.0 functional
  • 3 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Oct 26 +1
    • Stability: unverified → 0.03 ▲ functional
  • 30 Sept 26 62

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 8 Oct 2026 · Probed https://stablescan.achivx.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=achivx.com CN=YE1,O=Let's Encrypt,C=US 5 Oct 2026 3 Jan 2027 ECDSA 256 ECDSA-SHA384 6f4d99cd1a1008421537b3dee71b390536e
SANs: *.achivx.com, achivx.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of stablescan.achivx.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
achivx.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://stablescan.achivx.com/mcp Verified 200
http (plaintext) http://stablescan.achivx.com/mcp HTTPS enforced 301 https://stablescan.achivx.com/mcp
MCP tools · 8 exposed · ~5,405 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
get_address_approvals ~643

Open ERC-20 and Permit2 allowances one address has granted on one chain, one row per spender and token with the raw value, unlimited/oversized/old flags, spender_class and a band (critical|high|low|expired|none): unlimited to a flagged or unknown spender is the main drain vector, a known service spender (DEX router, Permit2) is normal, an expired Permit2 sub-allowance reads 'expired'. Use it when the question is what a wallet has approved and who could pull its stablecoins. Not for a risk tier — the band is informational and never moves get_address_risk. Not for issuer freezes: get_address_compliance. Not for taint: get_address_exposure. address is the allowance owner (the granter), never the spender. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. A heuristic band over decoded on-chain Approval facts, not an AML or legal determination.

NameTypeReqDescription
addressstringyesThe address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

No output schema declared.

No examples provided.

get_address_compliance ~779

Issuer freeze/seize facts for one address on one chain, plus the OFAC SDN flag: freeze[] (one row per freeze-capable stablecoin, status frozen|seized|clear|unknown, with frozen_usd6 = the balance locked now where it was read), not_freezable[] (stablecoins whose issuer cannot freeze on this chain, e.g. the Binance-Peg wrappers on BNB Chain — enforcement is off-chain), frozen_elsewhere[] (the same address bytes under a standing freeze on another indexed chain; EVM and Tron share them, Solana never) and freeze_proposals[] (issuer multisig proposals naming the address, USDT on Ethereum and Tron: executed ones, pending only where the operator publishes them). Use it when the question is whether an issuer or OFAC acted on this address, or how much is frozen. Not for a risk tier: get_address_risk. Not for taint distance: get_address_exposure. Not for when the OFAC list was refreshed: get_sanctions_status. Decoded on-chain issuer acts with provenance, no heuristics. 'unknown' means no act names the address and that pair's freeze history is not fully backfilled yet — absence of evidence is not 'not frozen'; an empty frozen_elsewhere[] or freeze_proposals[] means none in what is indexed, not clean everywhere. Each chain is its own issuer act: pass chain to ask Ethereum or Tron about the same bytes, chains_with_data says where. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Not an identity, AML or legal determination.

NameTypeReqDescription
addressstringyesThe address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

No output schema declared.

No examples provided.

get_address_exposure ~727

Taint exposure of one address on one chain: a bounded backward walk over the value graph to the nearest OFAC-sanctioned or hack/drainer/mixer root, answered as a class (sanctioned|direct|indirect|negligible|unknown|none), the nearest hop and a value-proportional haircut fraction. Use it to explain how closely an address is tied to a sanctioned or hack root and by how much value. Not for one go/no-go tier — get_address_risk already includes this walk. Not for the counterparties themselves or a chosen depth, token or window: get_wallet_graph_walk. Not for issuer freezes: get_address_compliance. 'unknown' means the walk did not complete — OFAC list unloaded, time_budget, frontier_cap, Solana coverage pending or partial, short history, or no hack/drainer/mixer label loaded for this chain — never a false 'none'; incomplete_reasons names which (time_budget may complete at a quieter moment, frontier_cap repeats). Depth is fixed at 3 hops and the walk never crosses chains: ask again with chain set for each network in chains_with_data. A verdict is reused for up to 60 s (10 s after a time_budget cut). Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. A heuristic signal, not an AML or legal determination.

NameTypeReqDescription
addressstringyesThe address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

No output schema declared.

No examples provided.

get_address_risk ~753

Unified risk tier for one address on one chain — unknown|none|low|medium|high|severe — from decoded facts (OFAC listing, issuer freeze/seize on this chain, exposure to a sanctioned or hack root) and attributed labels with provenance (labels alone cap at medium; a lone-source accusation adds no tier). Use it for one go/no-go read before accepting or sending funds. Not for freeze proposals, frozen balances or a freeze on another chain (frozen_elsewhere): get_address_compliance. Not for taint hops or the haircut: get_address_exposure. Not for open allowances: get_address_approvals. 'unknown' means the check did not finish, never 'checked clean'; evidence and incomplete_reasons name the cause (e.g. time_budget: the exposure walk was cut, a quieter moment may complete it). The freeze input is this chain's per-token status alone: frozen/seized argues for high, and an 'unknown' status or a pair whose freeze history is not backfilled turns a would-be 'none' into 'unknown' — so a Solana tier, where every freeze pair is unknown, is never 'none'. The exposure walk behind the tier is fixed at 3 hops; pick depth and window with get_wallet_graph_walk. A verdict is reused for up to 60 s (10 s after a time_budget cut). Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Not an identity, AML or legal determination.

NameTypeReqDescription
addressstringyesThe address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

No output schema declared.

No examples provided.

get_recent_transactions ~608

Recent stablecoin transfers on one chain, newest first, filterable by payer and/or recipient, cursor-paginated. Use it for the latest transfers of an address or of the whole chain, with a tx_hash to cite. Not for who an address settles with over time: get_wallet_graph_walk. Not for how fresh the feed is: get_sync_status. Not for any verdict about an address: get_address_risk. Answer: items[], each row tx_hash, log_index, block_number, block_time (RFC 3339), payer, recipient, amount {amount (minor units, string), decimals, token (symbol)}, token (the contract address), finality, and usd_amount where priced. The chain is the one asked for — rows do not repeat it. payer and recipient narrow together; omit both for the chain-wide feed; pass next_cursor back unchanged as cursor for older rows, and a page without it is the last. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Plain on-chain Transfer facts, no scoring.

NameTypeReqDescription
chaininteger|string|null–Chain of the feed, in any of four spellings: the id (8453 Base — default, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 728126428 Tron, -1 Solana), the same id as a string, the network slug…
cursorstring–Pagination cursor from a previous response
limitnull|integer–Max rows, 1..200 (default 25). A value outside that range is refused, as REST refuses it
payerstring–Filter by payer address: 0x… (EVM), T… (Tron) or base58 (Solana)
recipientstring–Filter by recipient address: 0x… (EVM), T… (Tron) or base58 (Solana)

No output schema declared.

No examples provided.

get_sanctions_status ~180

OFAC SDN list coverage as this scanner holds it: evm_count, solana_count, tron_count and total addresses loaded (the free public 0xB10C list of US-Government public-domain data), updated_at of the last refresh (null until the first ingest) and the source. Use it to date the sanctions input behind a verdict, or to tell a clear OFAC flag from an unloaded list. Not for whether one address is listed: get_address_compliance (the flag) or get_address_risk (the tier). Not for indexer freshness: get_sync_status. No parameters; one answer covers every chain. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools. Verify against the official SDN list before acting on it; not legal advice.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_sync_status ~457

Indexer freshness for one chain: freshness_seconds (the age of the newest indexed transfer; null when it could not be read for this answer), the indexer's head and finalized blocks, its safe block and its lag in blocks (lag_blocks = head_block - last_indexed_block). Use it before trusting how recent an address answer is, or to tell an empty feed from a stalled indexer. Not for how fresh the OFAC list is: get_sanctions_status. Every address verdict already carries freshness_seconds, so call this only for the block numbers or for a chain you have not asked about yet. On Solana (chain -1) safe_block is the finalized slot, and lag_blocks is near 0 by construction and never negative, so it is not a freshness signal there: read freshness_seconds. On the EVM chains and Tron a negative lag_blocks means the node's head went back. chain is the only parameter; omit it for Base. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools.

NameTypeReqDescription
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 728126428 Tron, -1 Solana), the same id as a string, the network slug (base, ether…

No output schema declared.

No examples provided.

get_wallet_graph_walk ~1,258

Bounded walk over the indexed settlement graph of one stablecoin from one wallet on one chain: payer<->recipient hops with value-weighted scores, entity-aware node keys, a stop at known services and sanctioned-node markers. Use it to explain who an address settles with and through which hops. Not for a verdict: get_address_risk. Not for the taint class or haircut: get_address_exposure. Not for a flat list of transfers with tx hashes: get_recent_transactions. token is required and must be a stablecoin enabled on that chain (a refusal names them); hops=0 with stop_on_sanctioned=true is the cheapest check of the subject itself; subjects over the degree gate (~50k edge-rows) return hop 1 only with frontier_truncated=true. Heavy read: under load it answers busy or timeout — retry with backoff, a narrower window or a lower frontier_cap. No auth; 1200 requests/min shared by all tools. An explainability primitive, not a detector verdict, identity/control assertion, AML decision or legal advice. window_from present means the answer was built from that date, the edge-grain horizon, not from the start of the requested window; the default window all, 90d and 1y included (/v1/methodology edge_grain_horizon). When window_from is present, read the graph as covering that span only — do not treat the absence of a counterparty, a path or a sanctioned node as evidence about anything before that date. volume on nodes is the token's raw minor units (divide by 10^decimals); volume_usd6 is the same amount in USD with 6 decimals at peg 1. On Solana (chain -1) the answer carries coverage_status for the subject address only, never for its counterparties: pending — its history is still being filled, so an empty or small answer is not final; partial — filled to a documented bound. The walk shows a finished fill after the next Solana rollup pass (about 10 minutes), and never shows history older than window_from. This read never starts a fill, so pending can also mean none was asked for yet: on…

NameTypeReqDescription
addressstringyesWallet address. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sent (req…
chaininteger|string|null–Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…
frontier_capinteger–Per-hop frontier cap, 1..500 (default 500)
hopsnull|integer–Max graph hops, 0..4 (default 2)
stop_at_attributednull|boolean–Stop expanding known services/facilitators (default true)
stop_on_sanctionednull|boolean–Stop once a sanctioned node is reached (default false)
tokenstringyesToken symbol — REQUIRED, the server does not guess it (e.g. USDT). The asset hub page for a stablecoin names its own token.
windowstring–Time window: 1h|24h|7d|30d|90d|1y|all (default all)

No output schema declared.

No examples provided.

Common questions

What is the Stablecoin Scanner MCP server?

Stablecoin Scanner is an MCP server listed in the public MCP registry as com.achivx/stablescan. Stablecoin risk for agents: freezes, OFAC, exposure, allowances, transfers, graph. 7 chains. This page covers its hosted endpoint (https://stablescan.achivx.com/mcp).

Is the Stablecoin Scanner MCP server safe to use?

Stablecoin Scanner scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Stablecoin Scanner MCP server expose?

Stablecoin Scanner exposes 8 tools: get_address_approvals, get_address_compliance, get_address_exposure, get_address_risk, get_recent_transactions, and 3 more. Their descriptions and schemas cost roughly 5,405 tokens of context every time the server is loaded.

Does the Stablecoin Scanner MCP server require authentication?

No. We connected to Stablecoin Scanner without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Stablecoin Scanner MCP server still maintained?

Stablecoin Scanner is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.