# Stablecoin Scanner (remote · stablescan.achivx.com)

Stablecoin risk for agents: freezes, OFAC, exposure, allowances, transfers, graph. 7 chains.

- Trust score: 68/100 (medium)
- Change this week: +5
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-08

## Components

- remote · `stablescan.achivx.com`: 68/100 (this document), [markdown](https://verifymcp.io/servers/com-achivx-stablescan/stablescan.md), [page](https://verifymcp.io/servers/com-achivx-stablescan/stablescan)

## Channel facts

- Endpoint: `https://stablescan.achivx.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.4.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-08.

- **Endpoint Security**: 74/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 59/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 5405 tokens (~675/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 8 days we've observed: 0 tool removals, 7 breaking changes, 0 auth/transport breaks, 0 additions.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Stablecoin Scanner MCP server?

Stablecoin Scanner is a hosted endpoint at https://stablescan.achivx.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-achivx-stablescan 'https://stablescan.achivx.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-achivx-stablescan": {
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-achivx-stablescan": {
      "type": "http",
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-achivx-stablescan]
url = "https://stablescan.achivx.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-achivx-stablescan": {
      "type": "remote",
      "url": "https://stablescan.achivx.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-achivx-stablescan --url 'https://stablescan.achivx.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-achivx-stablescan:
    url: "https://stablescan.achivx.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-achivx-stablescan": {
      "Transport": "http",
      "Url": "https://stablescan.achivx.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-achivx-stablescan -t streamable-http -u 'https://stablescan.achivx.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-achivx-stablescan": {
      "type": "http",
      "url": "https://stablescan.achivx.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-08 (score 68, +4)

- [security regression] Stability: 0.13 → fail
- [security improvement] Authorization: unverified → partial
- [security] Tool “get_address_approvals” rewrote its description, which is the text the model reads
- [security] Tool “get_address_compliance” rewrote its description, which is the text the model reads
- [security] Tool “get_address_exposure” rewrote its description, which is the text the model reads
- [security] Tool “get_address_risk” rewrote its description, which is the text the model reads
- [security] Tool “get_recent_transactions” rewrote its description, which is the text the model reads
- [security] Tool “get_sanctions_status” rewrote its description, which is the text the model reads
- [security] Tool “get_sync_status” rewrote its description, which is the text the model reads
- [security] Tool “get_wallet_graph_walk” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 391 → 675
- [functional] Server version: 1.3.0 → 1.4.0

### 2026-10-03 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-01 (score 63, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-30 (score 62)

First indexed and scored.

## MCP tools (8)

### `get_address_approvals` (~643 tokens)

Open ERC-20 and Permit2 allowances one address has granted on one chain, one row per spender and token with the raw value, unlimited/oversized/old flags, spender_class and a band (critical|high|low|expired|none): unlimited to a flagged or unknown spender is the main drain vector, a known service spender (DEX router, Permit2) is normal, an expired Permit2 sub-allowance reads 'expired'. Use it when the question is what a wallet has approved and who could pull its stablecoins. Not for a risk tier — the band is informational and never moves get_address_risk. Not for issuer freezes: get_address_compliance. Not for taint: get_address_exposure. address is the allowance owner (the granter), never the spender. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. A heuristic band over decoded on-chain Approval facts, not an AML or legal determination.

Input parameters:

- `address` (string, required): The address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

### `get_address_compliance` (~779 tokens)

Issuer freeze/seize facts for one address on one chain, plus the OFAC SDN flag: freeze[] (one row per freeze-capable stablecoin, status frozen|seized|clear|unknown, with frozen_usd6 = the balance locked now where it was read), not_freezable[] (stablecoins whose issuer cannot freeze on this chain, e.g. the Binance-Peg wrappers on BNB Chain — enforcement is off-chain), frozen_elsewhere[] (the same address bytes under a standing freeze on another indexed chain; EVM and Tron share them, Solana never) and freeze_proposals[] (issuer multisig proposals naming the address, USDT on Ethereum and Tron: executed ones, pending only where the operator publishes them). Use it when the question is whether an issuer or OFAC acted on this address, or how much is frozen. Not for a risk tier: get_address_risk. Not for taint distance: get_address_exposure. Not for when the OFAC list was refreshed: get_sanctions_status. Decoded on-chain issuer acts with provenance, no heuristics. 'unknown' means no act names the address and that pair's freeze history is not fully backfilled yet — absence of evidence is not 'not frozen'; an empty frozen_elsewhere[] or freeze_proposals[] means none in what is indexed, not clean everywhere. Each chain is its own issuer act: pass chain to ask Ethereum or Tron about the same bytes, chains_with_data says where. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Not an identity, AML or legal determination.

Input parameters:

- `address` (string, required): The address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

### `get_address_exposure` (~727 tokens)

Taint exposure of one address on one chain: a bounded backward walk over the value graph to the nearest OFAC-sanctioned or hack/drainer/mixer root, answered as a class (sanctioned|direct|indirect|negligible|unknown|none), the nearest hop and a value-proportional haircut fraction. Use it to explain how closely an address is tied to a sanctioned or hack root and by how much value. Not for one go/no-go tier — get_address_risk already includes this walk. Not for the counterparties themselves or a chosen depth, token or window: get_wallet_graph_walk. Not for issuer freezes: get_address_compliance. 'unknown' means the walk did not complete — OFAC list unloaded, time_budget, frontier_cap, Solana coverage pending or partial, short history, or no hack/drainer/mixer label loaded for this chain — never a false 'none'; incomplete_reasons names which (time_budget may complete at a quieter moment, frontier_cap repeats). Depth is fixed at 3 hops and the walk never crosses chains: ask again with chain set for each network in chains_with_data. A verdict is reused for up to 60 s (10 s after a time_budget cut). Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. A heuristic signal, not an AML or legal determination.

Input parameters:

- `address` (string, required): The address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

### `get_address_risk` (~753 tokens)

Unified risk tier for one address on one chain — unknown|none|low|medium|high|severe — from decoded facts (OFAC listing, issuer freeze/seize on this chain, exposure to a sanctioned or hack root) and attributed labels with provenance (labels alone cap at medium; a lone-source accusation adds no tier). Use it for one go/no-go read before accepting or sending funds. Not for freeze proposals, frozen balances or a freeze on another chain (frozen_elsewhere): get_address_compliance. Not for taint hops or the haircut: get_address_exposure. Not for open allowances: get_address_approvals. 'unknown' means the check did not finish, never 'checked clean'; evidence and incomplete_reasons name the cause (e.g. time_budget: the exposure walk was cut, a quieter moment may complete it). The freeze input is this chain's per-token status alone: frozen/seized argues for high, and an 'unknown' status or a pair whose freeze history is not backfilled turns a would-be 'none' into 'unknown' — so a Solana tier, where every freeze pair is unknown, is never 'none'. The exposure walk behind the tier is fixed at 3 hops; pick depth and window with get_wallet_graph_walk. A verdict is reused for up to 60 s (10 s after a time_budget cut). Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Not an identity, AML or legal determination.

Input parameters:

- `address` (string, required): The address to check. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sen…
- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…

### `get_recent_transactions` (~608 tokens)

Recent stablecoin transfers on one chain, newest first, filterable by payer and/or recipient, cursor-paginated. Use it for the latest transfers of an address or of the whole chain, with a tx_hash to cite. Not for who an address settles with over time: get_wallet_graph_walk. Not for how fresh the feed is: get_sync_status. Not for any verdict about an address: get_address_risk. Answer: items[], each row tx_hash, log_index, block_number, block_time (RFC 3339), payer, recipient, amount {amount (minor units, string), decimals, token (symbol)}, token (the contract address), finality, and usd_amount where priced. The chain is the one asked for — rows do not repeat it. payer and recipient narrow together; omit both for the chain-wide feed; pass next_cursor back unchanged as cursor for older rows, and a page without it is the last. Heavy read: under load it answers busy or timeout — retry with backoff. No auth; 1200 requests/min shared by all tools. Plain on-chain Transfer facts, no scoring.

Input parameters:

- `chain` (integer|string|null): Chain of the feed, in any of four spellings: the id (8453 Base — default, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 728126428 Tron, -1 Solana), the same id as a string, the network slug…
- `cursor` (string): Pagination cursor from a previous response
- `limit` (null|integer): Max rows, 1..200 (default 25). A value outside that range is refused, as REST refuses it
- `payer` (string): Filter by payer address: 0x… (EVM), T… (Tron) or base58 (Solana)
- `recipient` (string): Filter by recipient address: 0x… (EVM), T… (Tron) or base58 (Solana)

### `get_sanctions_status` (~180 tokens)

OFAC SDN list coverage as this scanner holds it: evm_count, solana_count, tron_count and total addresses loaded (the free public 0xB10C list of US-Government public-domain data), updated_at of the last refresh (null until the first ingest) and the source. Use it to date the sanctions input behind a verdict, or to tell a clear OFAC flag from an unloaded list. Not for whether one address is listed: get_address_compliance (the flag) or get_address_risk (the tier). Not for indexer freshness: get_sync_status. No parameters; one answer covers every chain. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools. Verify against the official SDN list before acting on it; not legal advice.

### `get_sync_status` (~457 tokens)

Indexer freshness for one chain: freshness_seconds (the age of the newest indexed transfer; null when it could not be read for this answer), the indexer's head and finalized blocks, its safe block and its lag in blocks (lag_blocks = head_block - last_indexed_block). Use it before trusting how recent an address answer is, or to tell an empty feed from a stalled indexer. Not for how fresh the OFAC list is: get_sanctions_status. Every address verdict already carries freshness_seconds, so call this only for the block numbers or for a chain you have not asked about yet. On Solana (chain -1) safe_block is the finalized slot, and lag_blocks is near 0 by construction and never negative, so it is not a freshness signal there: read freshness_seconds. On the EVM chains and Tron a negative lag_blocks means the node's head went back. chain is the only parameter; omit it for Base. Light read, never waits for a slot. No auth; 1200 requests/min shared by all tools.

Input parameters:

- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 728126428 Tron, -1 Solana), the same id as a string, the network slug (base, ether…

### `get_wallet_graph_walk` (~1258 tokens)

Bounded walk over the indexed settlement graph of one stablecoin from one wallet on one chain: payer<->recipient hops with value-weighted scores, entity-aware node keys, a stop at known services and sanctioned-node markers. Use it to explain who an address settles with and through which hops. Not for a verdict: get_address_risk. Not for the taint class or haircut: get_address_exposure. Not for a flat list of transfers with tx hashes: get_recent_transactions. token is required and must be a stablecoin enabled on that chain (a refusal names them); hops=0 with stop_on_sanctioned=true is the cheapest check of the subject itself; subjects over the degree gate (~50k edge-rows) return hop 1 only with frontier_truncated=true. Heavy read: under load it answers busy or timeout — retry with backoff, a narrower window or a lower frontier_cap. No auth; 1200 requests/min shared by all tools. An explainability primitive, not a detector verdict, identity/control assertion, AML decision or legal advice. window_from present means the answer was built from that date, the edge-grain horizon, not from the start of the requested window; the default window all, 90d and 1y included (/v1/methodology edge_grain_horizon). When window_from is present, read the graph as covering that span only — do not treat the absence of a counterparty, a path or a sanctioned node as evidence about anything before that date. volume on nodes is the token's raw minor units (divide by 10^decimals); volume_usd6 is the same amount in USD with 6 decimals at peg 1. On Solana (chain -1) the answer carries coverage_status for the subject address only, never for its counterparties: pending — its history is still being filled, so an empty or small answer is not final; partial — filled to a documented bound. The walk shows a finished fill after the next Solana rollup pass (about 10 minutes), and never shows history older than window_from. This read never starts a fill, so pending can also mean none was asked for yet: on…

Input parameters:

- `address` (string, required): Wallet address. The address in its network's own spelling: 0x… for EVM chains, T… for Tron, base58 for Solana. The answer writes it in the spelling of chain_id (address) and echoes what you sent (req…
- `chain` (integer|string|null): Chain, in any of four spellings: the id (8453 Base — default for 0x addresses; a T… address defaults to Tron and a base58 one to Solana, 1 Ethereum, 10 Optimism, 42161 Arbitrum, 56 BNB Chain, 7281264…
- `frontier_cap` (integer): Per-hop frontier cap, 1..500 (default 500)
- `hops` (null|integer): Max graph hops, 0..4 (default 2)
- `stop_at_attributed` (null|boolean): Stop expanding known services/facilitators (default true)
- `stop_on_sanctioned` (null|boolean): Stop once a sanctioned node is reached (default false)
- `token` (string, required): Token symbol — REQUIRED, the server does not guess it (e.g. USDT). The asset hub page for a stablecoin names its own token.
- `window` (string): Time window: 1h|24h|7d|30d|90d|1y|all (default all)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-achivx-stablescan/stablescan#diagnostics

## Score history

- 2026-10-08: 68
- 2026-10-04: 64
- 2026-10-03: 64
- 2026-10-02: 63
- 2026-10-01: 63
- 2026-09-30: 62

## Common questions

### What is the Stablecoin Scanner MCP server?

Stablecoin Scanner is an MCP server listed in the public MCP registry as com.achivx/stablescan. Stablecoin risk for agents: freezes, OFAC, exposure, allowances, transfers, graph. 7 chains. This page covers its hosted endpoint (https://stablescan.achivx.com/mcp).

### Is the Stablecoin Scanner MCP server safe to use?

Stablecoin Scanner scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Stablecoin Scanner MCP server expose?

Stablecoin Scanner exposes 8 tools: get_address_approvals, get_address_compliance, get_address_exposure, get_address_risk, get_recent_transactions, and 3 more. Their descriptions and schemas cost roughly 5,405 tokens of context every time the server is loaded.

### Does the Stablecoin Scanner MCP server require authentication?

No. We connected to Stablecoin Scanner without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Stablecoin Scanner MCP server still maintained?

Stablecoin Scanner is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://stablescan.achivx.com/mcp
- Website: https://stablescan.achivx.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-achivx-stablescan/stablescan.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-achivx-stablescan/stablescan.json
- HTML version of this page: https://verifymcp.io/servers/com-achivx-stablescan/stablescan
