HexScan
Verification PAYMENT-READYpayment-ready until 2026-08-20
Smart contract risk triage API. Send a contract address, get a composite risk score (0-100) with honeypot detection, tax analysis, source verification, and heuristic findings. Not an audit.
Pay from $0.10 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.
first settlement 2026-07-24 · $0.80 all-time · settled via coinbase
ASSESSMENT
updated 3h agoEvidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.
reliability 100%
- uptime 24h
- 100%
- uptime 7d
- 100%
- uptime 30d
- 100%
- uptime 90d
- 100%
- response p95
- 1200ms
- avg response
- 789ms
- total checks
- 2,068
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.10 (p75 in Verification)
- price (min)
- $0.10
- category percentile (min)
- p75 in Verification
- endpoints / prices
- 1 / 1
- model
- flat
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- 21d
- registrar
- Cloudflare, Inc.
- hosting
- custom
- domain created
- 2026-07-21
Identity facts, not a risk score.
traction $0.80 30d · 1 buyers · top buyer 100%
- volume 30d
- $0.80
- buyers 30d
- 1
- settlements 30d
- 8
- first settlement
- 2026-07-24
- last settlement
- 2026-07-27
- top buyer share
- 100% of 30d volume
- trend 7d vs 30d
- 0.00x the 30d daily rate
- networks
- eip155:8453
- volume all-time
- $0.80
- settlements all-time
- 8
- median settlement 30d
- $0.10
- max settlement 30d
- $0.10
- settled via
- coinbase ($0.80, 8 tx)
Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.
Top buyer share is a concentration signal, not part of the ranking score.
WHAT IT DOES
ai-derivedScans smart contracts for risk signals
- category
- smart-contract-risk
AI-generated summary. The measured data is never altered by it.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| GET | /scan | $0.10 | Base | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to GET /scan returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i 'https://hexscan.xyz/scan'
// 402 response (captured by monitor) · 1 payload · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x841Ef35b7b7ee4C820BFF040369a8Ade4741b45d",
"amount": "100000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://hexscan.xyz/scan",
"mimeType": "application/json",
"description": "Smart contract risk triage - honeypot detection, tax analysis, source verification. Not an audit."
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"chain": "ethereum",
"address": "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"riskLevel": "MINIMAL",
"riskScore": 5,
"tokenName": "USD Coin"
}
}
}
}
},
"x402Version": 2
}
] OVER TIME
All charts use the 90d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/hexscan/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-07-21 · last up 2026-08-13
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (18) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/hexscan.svg" alt="HexScan listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/hexscan.svg?data=uptime" alt="HexScan uptime on x402-list" height="28"> </a>