Every free tool response, and every paid MCP and A2A response, carries reasons: [{ code, message }]: zero or more machine-readable codes from the list below. It is empty when nothing is flagged.
Codes
| Code | Kind | Meaning |
|---|---|---|
WALLET_SANCTIONED | Warning | Address matches an entry on the sanctions list. |
DOMAIN_NEWLY_REGISTERED_30D | Warning | Domain was registered fewer than 30 days ago. |
HOSTNAME_PHISHING_LISTED | Warning | Hostname, or a parent domain of it, is on the phishing blocklist. |
HOSTNAME_LOOKALIKE | Warning | Hostname is a probable lookalike/typosquat of a known brand domain. |
WALLET_NO_HISTORY | Warning | No on-chain transfer history was found for this address on this chain. |
WALLET_AGE_PARTIAL | Incomplete | Internal transfers were not checked in time; the wallet may be older than shown. |
CVE_KNOWN_EXPLOITED_KEV | Warning | CVE is on the known exploited vulnerabilities catalog. |
IOC_FOUND_IN_THREAT_FEED | Warning | Indicator has at least one matching record in the threat indicator feed. |
WALLET_DELEGATED | Informational | Address currently has an EIP-7702 delegation on this chain: its code points to a delegate contract. |
How codes affect status
- Warning codes make
status"flagged". - Informational codes report a fact and never change
statuson their own. - Incomplete codes mean a check did not complete: they make
status"unknown", never"flagged". A warning code alongside one still flags. - With no warning or incomplete code,
statusis"unknown"if any source needed for the answer timed out, errored or was skipped, and"no_flags"otherwise. A check that did not complete is never reported as"no_flags".
Stability
- Codes are permanent: once shipped, a code is never removed or renamed. New codes are only added.
- A response's
messagecan be more specific than the meaning above (for example, it may include a count). Match oncode, never onmessage.
Test inputs
Fixed test inputs, free for every caller, are listed on Test your integration. They return WALLET_SANCTIONED, DOMAIN_NEWLY_REGISTERED_30D, HOSTNAME_PHISHING_LISTED, WALLET_NO_HISTORY, CVE_KNOWN_EXPLOITED_KEV, IOC_FOUND_IN_THREAT_FEED and WALLET_DELEGATED without a live lookup. No test input returns HOSTNAME_LOOKALIKE or WALLET_AGE_PARTIAL.