Skip to main content
POST
Scan Raw EVM Transaction for Security Risks

Authorizations

x-api-key
string
header
required

Path Parameters

fromAddress
string
required

EVM address that signed the transaction

Query Parameters

chain
enum<string>

Chain slug (eth, bsc, pol, opt, arb, base). Optional: the body chain id is used when absent; the query wins when both are given.

Available options:
eth,
bsc,
pol,
opt,
arb,
base
refreshCache
boolean
default:false

Force refresh cached risk data

Body

application/json
tx
object
required

Transaction details

chain

Chain id (1 Ethereum, 56 BSC, 137 Polygon, 10 Optimism, 42161 Arbitrum, 8453 Base) as a number or a decimal / 0x hex string, or a chain slug. Required unless the chain query is given (the query wins). Testnet ids are rejected.

Example:

1

block
integer

Block of a mined transaction. Honoured only when tx.raw is a 66-character transaction hash; raw transaction bytes are always simulated as pending.

Example:

12345678

domain
string

dApp origin (e.g. app.uniswap.org). Scored and returned as the informational top-level domainRisk; it does not change the descriptor on this route.

Response

Transaction risk analysis completed successfully

simulation
array

Transaction simulation results with risk analysis including partyRisk, counterpartyRisk, assetRisk, and functionRisk (if risky 4-byte signature detected)

block
integer | null

Block number of a mined transaction; null for a pending simulation (always present).

timestamp
string<date-time>

Timestamp of the scan

chain
string

Chain identifier

Example:

"eth"

domainRisk
object | null

Risk of the domain sent in the request (riskLevel, description, message); absent when no domain was sent. Informational on this route.

public_key_id
string

Id of the key that signed descriptor.

descriptor
string

Hex-encoded, signed summary of the verdict for hardware-wallet (Ledger) display. API consumers can ignore it.