Two ways an EVM address lies to you. Both are cheap to check and expensive to miss.
You are about to send value to a string of 40 hex characters. Nothing about that string tells you whether it is a treasury wallet, a sanctioned entity, or a copy of a legitimate address with two characters changed.
An attacker generates an address whose first and last few characters match one you have paid before, then sends your wallet a zero-value transfer from it. Your transaction history now contains that lookalike. The next time you copy "the address I used last time" from history, you may copy theirs. The funds go to the attacker and the transaction is valid, final and irreversible.
It works because humans and agents both match on the ends of a string. A real example of the shape:
legitimate 0xA2b36c0B392a6bef0Bf73f95EF00c46E004b6B0b
lookalike 0xA2b36c0b7f19D3a4Ee81 ... f73f95EF00c46E004b6B0b
^^^^^^^ same prefix same suffix
The defence is mechanical, not vigilance: compare the whole address, and check it against a list of known-bad addresses for a near-match rather than an exact one. An exact-match-only blocklist never catches this, because the poisoned address is not itself on any list.
Financial institutions are expected to screen counterparties. An autonomous agent moving USDC has no compliance department and, until recently, no cheap way to do it either. The US Treasury publishes the answer for free — the list of digital-currency addresses designated by OFAC — and it currently carries 120 EVM addresses.
That list is authoritative, public domain and small enough to hold in memory. There is no reason to be transacting with an address on it.
reasons[] array and, for every match, the list it came from.$0.02 of USDC on Base, over x402, with no account and no API key:
curl -X POST https://sentinel.pentest.i.ng/v1/screen \
-H 'Content-Type: application/json' \
-d '{"address":"0x0330070FD38Ec3bB94F58FA55D40368271E9e54A","chain":"base"}'
| Field | Meaning |
|---|---|
verdict | PAY_OK, CAUTION or DO_NOT_PAY |
risk_score | 0-100, additive, every point explained |
sanctions_match | exact hit on the OFAC SDN list |
lookalike_of_known_bad | near-match / poisoning pattern |
onchain | balance, nonce, contract or wallet, code size |
Before a payout run, the batch tier screens 25 addresses for $0.10 and returns a
blocked[] list.
The whole OFAC EVM list is public here, no payment and no key — use it however you like, including to build your own screening:
curl https://sentinel.pentest.i.ng/sanctions.txt # one address per line curl https://sentinel.pentest.i.ng/v1/sanctions # JSON, with sources
There is also an Atom feed of addresses as they enter the label index, and a delta endpoint for what changed in the last N days. The index currently holds 3,302 labelled addresses, rebuilt daily.
Signal aggregation over public data, not legal or compliance advice, and not a guarantee. A clear verdict means nothing in the public lists matched and nothing anomalous showed on-chain — not that the counterparty is trustworthy. Absence of evidence is not evidence of absence, and no screening tool should be sold as if it were.