AI agent for security engineers
On-Chain Activity Monitoring Agent
Early, verified notice of unusual on-chain activity with a suggested response
What it does
Unusual activity on a live contract, like a sudden drain of funds or an admin function being called, is often noticed too late. On a schedule and on key events, this agent reads the contract's events and balances and compares them with normal patterns and your alert rules, such as a large withdrawal, a pause or use of the owner key. When something crosses a rule, it checks the transaction details, the addresses involved and related activity to judge whether it is normal business or a real concern. Known addresses, such as the treasury, are checked against your list. For a confirmed concern it drafts an alert with the transactions and a suggested response, such as pausing. If it cannot tell, it raises a lower-priority notice. You approve any on-chain response.
How it works
Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.
Read the steps as a list
- Scheduled or event-triggered check
- Read recent events and balances
- Compare activity with normal patterns and alert rules
- Does any event cross an alert rule?If not: log the period as normal and wait for the next check. Back to step 2.
- Pull transaction details and check addresses against the known list
- Does the activity look like a real concern rather than normal business?If not: log it as expected or raise a low-priority notice. Back to step 5.
- Draft an alert with the transactions and a suggested response
- Developer approves any on-chain responseThe agent waits here for your OK.
- Monitoring log and any alerts
How it decides
It alerts only when activity crosses a rule and the transaction detail confirms a real concern, recognizing known safe addresses.
- Alert only on a crossed rule confirmed by detail
- Recognize known safe addresses
- Raise a low-priority notice when unsure
Make it yours
Every agent is a starting point. You choose these settings for your own situation.
- Alert rules and thresholds
- Known safe addresses
- Check frequency
- Suggested responses
What keeps you in control
It always asks you first
- Any on-chain response such as pausing
Hard limits
- Never sends an on-chain transaction without approval
- Read-only monitoring by default
It stops when
- Done: activity checked and alerts raised
- Stop: the node or indexer is unreachable
Set it up
We guide you through the set-up, step by step
Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.
- One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
- The agent then walks you through connecting your own data, one source at a time
- A downloadable copy with the flow chart, the rules and the full guide