Screen crypto addresses against OFAC sanctions, ransomware attribution, and on-chain activity. Single or bulk. Zero cost, no API key. Ransomware IR & sanctions compliance.
Ghost Worker (optional CORS proxy):not configured
QueryLocal · you supply
Screens against three sources: (1) OFAC SDN list of sanctioned digital-currency addresses (mirror 0xB10C/ofac-sanctioned-digital-currency-addresses, refreshed hourly), (2) Ransomwhere (bulk export of ~25k crowdsourced ransomware payment records), (3) chain-specific block explorer for balance & activity. All free, keyless. OFAC + Ransomwhere are bulk-downloaded on first Analyze and cached in memory; per-address checks are local (no network per address). Only block-explorer calls hit the network per address. A clean result means "no hits in these sources" — not "safe to interact with." Unlisted-but-sanctioned addresses exist. Unattributed-but-malicious wallets exist.
Screening datasetsSourced · GitHub + Ransomwhere
Not loaded — first Analyze will fetch both.
ResultSourced · OFAC + Ransomwhere + explorer
ExportBriefing / handoff
GHOST — Grounded Handling Of Sourced Threat-intel · DEFEND ALWAYS
OFAC list is authoritative for sanctioned addresses; absence from the list is not evidence of legitimacy — sanctioned actors also use unlisted wallets. Ransomwhere is crowdsourced and incomplete. Block-explorer data shows current on-chain state, not wallet clustering, mixer proximity, or attribution beyond what the public ledger records. Paying a ransom may violate laws beyond OFAC (state law, DFARS, sector regulations); this tool reports what it sees, not what to do. Privacy-coin addresses (Monero, Zcash shielded) are out of scope by design of those coins.