Skip to main content
In March 2022, the Lazarus Group drained $625M from Ronin Bridge in a single attack. The deposit address was already flagged—but no one checked. Don’t make the same mistake. This guide shows you how to screen every deposit and withdrawal in real-time, across 13 chains, with one API.

Why Wallet Screening Matters

Compliance

Stay ahead of OFAC and AML requirements—sanctions lists update daily

Risk Management

Stop bad actors at the door, not after they’ve moved funds

User Protection

Catch address poisoning before your users lose millions
Why exchanges choose Webacy:
  • One integration, 13 chains — ETH, SOL, BTC, and 10 more. No vendor sprawl.
  • Sub-500ms responses — Screen in real-time without blocking transactions
  • Sanctions + fraud in one call — Compliance and security, unified
  • Address poisoning detection — The threat most providers miss

Prerequisites

Before implementing wallet screening, ensure you have:
  • A Webacy API key (sign up here)
  • Basic familiarity with REST APIs or the Webacy SDK
  • Your application’s deposit/withdrawal flow identified for integration points

Deposit Screening

Every deposit is a potential liability until you verify the source. Screen every incoming deposit address to catch sanctioned entities, mixer activity, and high-risk wallets.

Sanctions Check

The fastest compliance check—verify if an address is on OFAC or other sanctions lists.
Try it now: Paste 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 into the sanctions endpoint. This is the actual Lazarus Group wallet from Ronin Bridge—instant hit.

Full Risk Analysis

For addresses that pass sanctions screening, perform a comprehensive risk analysis.
Response fields to use:
Try it now: Test 0x722122dF12D4e14e13Ac3b6895a86e84145b6967—the Tornado Cash Router. You’ll get high risk scores and mixer tags in the response.

Multi-Chain Support

The same endpoints work across all supported chains—just change the chain parameter.

Withdrawal Protection

Your users trust you to protect their funds—even from their own mistakes. Protect users from sending funds to risky destinations, including address poisoning attacks.

Address Poisoning Detection

Address poisoning is a sophisticated attack where scammers create lookalike addresses to trick users into sending funds to the wrong destination.
Real Case: In May 2024, a victim lost $68 million in WBTC by copying a poisoned address from their transaction history. The legitimate and scam addresses looked nearly identical.
The Attack Pattern—Can You Spot the Difference? Both start with 0xd9A1. Both end with 53a91. The victim couldn’t tell them apart—and lost $68 million.
One API call, millions saved: Add this check before every withdrawal. Your users won’t notice the 300ms latency—but they’ll notice when you save them from a $68M mistake.

Withdrawal Destination Check

Screen withdrawal destinations for general risk factors.

Complete Integration Workflow

Here’s how it all fits together.

Implementation Example


Example Addresses for Testing

Use these addresses to test your integration:

OFAC Sanctioned Addresses

Known Hackers

Mixers & Money Laundering

Phishing & Scam Addresses

Address Poisoning

Clean Addresses (for comparison)

For a complete list of test addresses, see Example Addresses.

API Quick Reference

Authentication:

Ready to Ship?

You’ve seen how it works. Now integrate it:
  1. Get your API key — Takes 2 minutes
  2. Test with the example addresses — Verify your integration
  3. Go live — Start screening deposits today

Next Steps

Get Your API Key

Start screening in minutes

API Reference

Every endpoint, every parameter

Install the SDK

TypeScript bindings included

Understanding Risk Tags

Know what you’re looking at