What these examples are good for
Use these addresses below to:- Confirm your integration works (request/response structure, latency, pagination, error handling)
- Validate risk outcomes (flags, severity, labels, and explainability fields)
- Test decisioning logic (block, warn, allow, review)
- Prototype dashboards (monitoring views, alert feeds, triage workflows)
Notes
- These examples are provided for testing and development only.
- Address risk is contextual and time-sensitive. Results may change as new on-chain activity occurs.
- If you’d like a broader sample set (including “clean,” borderline, and mixed-risk examples), reach out and we can provide a curated testing bundle.
Sanctioned Addresses
These addresses are on sanctions lists and will returnis_sanctioned: true from the /addresses/sanctioned/{address} endpoint.
Hacker Addresses
These addresses are associated with known hacks and exploits. They return high-risk scores with tags likehack, stealing_attack, and blacklist_doubt.
DPRK (North Korea) Linked
These addresses are associated with North Korean cyber operations and return thedprk tag.
Address Poisoning
These addresses are involved in address poisoning attacks. The/addresses/{address}/poisoning endpoint will return poisoning_detected: true for attackers.
Phishing Addresses
These addresses are associated with phishing campaigns and return thephishing_activities tag.
Mixers
These addresses are associated with mixing services and return tags likeassociated_mixer and sanctioned.
