OpenSol docs
OpenSol is Solana intelligence in plain English. Point it at a wallet, a token mint or a transaction and it reads the public chain, weighs the signals and explains what it found with a transparent 0–100 risk score.
It profiles how wallets trade, checks launches for bundles and serial creators, spots Pump.fun and StonkFun market makers, traces money hop by hop to swap services and exchanges, and follows funds into privacy pools and back out again, up to a certain extent.
- No keys
- No trading
- No black boxes
- Public data only
- Open source · MIT
Quick start
On the web
Wallet connect for Phantom, Solflare and Backpack is coming soon. OpenSol will only read your public address. It will never ask you to sign, approve or send anything.
From the command line
# clone and build (Node 20+) git clone https://github.com/Unizuka22/opensol-agent cd opensol-agent npm install && npm run build npm link # optional: your own RPC endpoint cp .env.example .env SOLANA_RPC_URL=https://api.mainnet-beta.solana.com # first scan opensol token EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
If SOLANA_RPC_URL is not set, OpenSol falls back to the public Solana mainnet endpoint. Deep traces and market-maker scans make many requests, so a dedicated RPC is recommended for heavy use.
How it works
Every command runs through the same six stages.
- Ingest. Pull signatures, parsed transactions, token accounts and balances for the target from Solana RPC.
- Decode. Turn raw instructions into events: transfers, swaps, mints, burns, liquidity adds and removals, pool creations. Swaps are decoded for Jupiter, Raydium, Orca, Meteora, Pump.fun, PumpSwap and StonkFun.
- Clean. Strip dust, spam airdrops, address-poisoning transfers, rent and wrap/unwrap moves, so only meaningful flows remain.
- Enrich. Attach labels, wallet age, first funder and venue to every address and event.
- Analyze. Run the analyzers: profiles, bundles, creator history, market makers, hop traces and privacy exits.
- Explain. Turn each finding into a sentence, add its points to the score and print the report.
Commands
| Command | What it does |
|---|---|
token <mint> | Authorities, supply, program, holder concentration, bundle detection, creator history and liquidity. |
wallet <address> | Balance, activity, trade history, PnL, hold times, wallet profile and first funder. |
tx <signature> | Status, fee, programs touched, swaps, SOL and token transfers, in plain English. |
mm <mint> | Detects whether a Pump.fun or StonkFun market maker is in play and how much of the volume it drives. |
trace <address> [hops] [out] | Follows money hop by hop, through privacy pools where possible, and flags swap services and exchanges. Default: 3 hops, incoming. |
labels | Lists every service OpenSol recognises. |
label <address> <name> | Teach OpenSol a wallet you have identified. Your labels are flagged in every report. |
Flags
--format json | Structured output for piping into other tools. |
--format markdown | Human-readable report. |
--out report.md | Write the report to a file. |
--rpc <url> | Override the RPC endpoint for one run. |
Wallet profiles
A wallet scan rebuilds the wallet's trading history from decoded swaps. Buys and sells of each token are matched first-in, first-out into positions, which gives hold time, realised PnL in SOL (fees included) and win rate for every trade.
| Profile | How it is detected |
|---|---|
| Paper hands | Median hold under 10 minutes and at least 60% of positions closed within 10 minutes, over 10+ positions. |
| Diamond hands | Median hold over 7 days, holding through a drawdown of 50% or more from entry. |
| Sniper | Bought within the first 3 slots after pool creation on 5+ launches. |
| Fresh wallet | First transaction under 7 days ago, or funded less than 24 hours before its first trade. |
| Copy trader | Buys the same tokens 1–3 slots after the same leader wallet on 5+ occasions. |
| Insider | Received tokens from the creator, or bought in the launch block with funding linked to the creator. |
| Bot / market maker | 45+ of the last 50 transactions inside an hour, a high failure rate, or same-minute buy and sell round trips. |
The scan also reports the first funder of the wallet and, if it sits within two hops of a swap service, exchange or privacy pool, says which one. Each profile is a behaviour signal drawn from public transactions, not a judgement about the person behind the wallet.
Token checks
Authorities and supply
Reads the mint account for mint and freeze authority, supply, decimals, token program and Token-2022 extensions.
Holder concentration
Builds the holder list from the mint's token accounts, then removes pool vaults, burn addresses and program-owned accounts so only real holders count. Reports the top holder, top 10 share and how many top holders share a funder.
Bundle detection
Looks at every buyer in the launch slot and the next few slots and clusters them. Wallets join a bundle when they share a funder within two hops, share a fee payer, were funded in the same fan-out transaction, or bought near-identical amounts in the same slot. The report shows how many wallets are in the bundle, how much supply they took and where their SOL came from.
Creator history
Identifies the creator from the token's create instruction, lists every other token that wallet launched, and checks how each one ended: creator sold most of the supply within the first hour, liquidity pulled, or still trading. The creator's own funding is traced too.
Liquidity
Finds the token's pools, reads depth on each side and checks whether LP tokens are burned, locked or held by a wallet that can pull them.
Market makers
mm <mint> tells you when a market maker is in play and who is really moving the chart. The venue is identified from the programs the token trades on: Pump.fun bonding curve and PumpSwap pools for Pump.fun, and StonkFun's own pools for StonkFun.
What OpenSol looks for
- Wallet fleets. Many fresh wallets funded in one burst, often a single transaction splitting equal SOL to 10–50 addresses.
- Wash patterns. Buys and sells of near-identical size from the fleet within seconds, leaving each wallet close to flat.
- Machine timing. Trades at regular intervals with very low variance, uniform sizes and repeated round trips.
- Known operators. Fee wallets and funders of known market-making and volume services, matched against labels.
- Volume share. The share of recent volume the cluster drives.
A market maker is reported as in play when its cluster drives 30% or more of the last hour's volume. The report names the venue, the number of wallets, their shared funder and the volume share, for example: Pump.fun market maker in play · 41% of last-hour volume · 18 wallets.
Hop tracing
trace walks the money backwards, hop by hop, up to five hops. Add out to follow where it went instead.
- Read the wallet's earliest and latest transfers. The earliest usually show who funded it.
- Rank counterparties by value moved in SOL, USDC and USDT and follow the largest to the next hop.
- Flag every hop that lands on a labeled swap service, bridge, exchange or privacy pool, even if it isn't followed.
- Mark wallets doing 100+ transactions an hour as busy hubs and stop there.
- When a path enters a privacy pool, hand it to the privacy tracer and continue from the likely exits.
- Print every flagged path and the full hop tree.
Services flagged
Instant swaps
Husher · HoudiniSwap · ChangeNOW · SimpleSwap · Changelly · SideShift · FixedFloat · StealthEX · Exolix · LetsExchange
Bridges & aggregators
Relay · RocketX
Low-KYC exchanges
MEXC
Exchanges
Binance · Coinbase · Kraken · OKX · Bybit · Bitget · KuCoin · Gate.io · HTX
Privacy on Solana
Mask · Privacy Cash · Umbra · Solflare Private Send · Nullmask · Vanish · encrypt.trade · Zero · ShadowWire · Confidential Balances
Privacy off Solana
Railgun
Privacy pools
Privacy pools break the direct link between a deposit and a withdrawal. OpenSol can't see inside them, but it can follow money in and pick the trail back up on the other side, up to a certain extent.
Following money in
Deposits are recognised from the pool's program and vault addresses. The trail is marked with the pool, amount, token and time.
Picking it back up
Every withdrawal from the same pool after the deposit is a candidate exit. Candidates are ranked by:
| Amount | Withdrawal matches the deposit once the pool's fee is taken off, or several withdrawals add up to it. |
| Timing | How soon after the deposit it happened, and whether it fits the depositor's usual active hours. |
| Gas funding | Who paid to fund the fresh withdrawal wallet, traced back toward the depositor. |
| Convergence | Withdrawals that end up at the same exchange deposit, wallet or token as the depositor's known wallets. |
| Behaviour | Same swap routes, same tokens bought, same trade sizes and timing as the depositor. |
Each candidate gets a confidence of low, medium or high with its reasons listed, and the trace continues from the strongest ones.
Where the trail fades
- Fixed-size deposits and large, busy pools make many withdrawals look alike, so confidence drops.
- Confidential Balances hide amounts but not addresses, so links come from the address graph instead.
- Pools on other chains such as Railgun are linked through bridge deposits and withdrawals on Solana, matched by amount and timing.
Noise filtering
Explorers show everything. OpenSol drops what doesn't matter before it analyzes anything:
- Dust: SOL and token transfers too small to matter.
- Address poisoning: tiny or zero transfers from lookalike addresses that copy the start and end of a real counterparty.
- Spam airdrops of unknown tokens nobody asked for.
- Failed transactions, rent deposits and refunds, account creation and wSOL wrap and unwrap.
- Transfers between a wallet's own token accounts.
Reports state how many transfers were skipped, so nothing disappears silently.
Labels
Labels turn addresses into names. Built-in labels cover exchange hot wallets, swap-service payout wallets, bridge depositories and solvers, privacy pool programs and vaults, DEX programs and market-making services. Every built-in label comes from a public, citable source such as official docs, labeled datasets or published investigations.
Some services create a fresh deposit address for every order. When you identify one, add it with label <address> <name> and it will be flagged in every report you run.
Risk scoring
Every score starts at 5 and only rises for observable signals. Every point comes with its reason.
Token signals
| Signal | Points | Why it matters |
|---|---|---|
| Active mint authority | +30 | More supply may be created by the authority. |
| Bundled launch | +25 | A linked cluster bought a large share of supply at launch. |
| Active freeze authority | +20 | Token accounts may be frozen by the authority. |
| Serial creator | +20 | The creator dumped or abandoned earlier launches. |
| Top-10 concentration | +15 | Top 10 real holders own 40% or more of supply. |
| Bundle funded via swap or bridge | +10 | The bundle's SOL came through an instant swap, bridge or privacy pool. |
| Market maker in play | +10 | A cluster drives 30% or more of recent volume. |
| Unknown token program | +5 | Owner is not SPL Token or Token-2022. |
Wallet signals
| Signal | Points | Why it matters |
|---|---|---|
| Bot-like activity | +25 | Very high activity, or high activity plus failed transactions. |
| High failed-tx rate | +25 | A large share of recent transactions failed. |
| Privacy pool exit | +20 | Funded by a likely privacy-pool withdrawal (medium or high confidence). |
| Funded via swap service | +15 | An instant swap or low-KYC exchange sits within two hops of the first funder. |
| High recent activity | +12 | More active than a casual wallet; not suspicious alone. |
| Sniper pattern | +12 | Repeated first-slot buys on new launches. |
| Elevated failed-tx rate | +10 | Some recent failures observed. |
| Fresh wallet | +5 | Little history before its first trades. |
Architecture
command → config / RPC setup → fetchers src/solana/ token · wallet · transaction · programs → decoders swaps · pools · launches · privacy pools → noise filter dust · poisoning · spam · rent → enrichment labels · wallet age · first funder → analyzers src/analyzers/ tokenRisk · walletProfile · tradeHistory bundles · creatorHistory · marketMaker hopTrace · privacyExit · liquidity → explanation layer src/agent/ deterministic, plain English → report src/reports/ markdown · json
Every analyzer is deterministic and documented. Unknown data stays unknown instead of being guessed.
Safety
OpenSol does not:
- Buy, sell, swap or trade
- Sign transactions
- Ask for or store private keys
- Give financial, legal or investment advice
- Claim to prove fraud, manipulation or intent
OpenSol produces heuristic reports from public Solana data. Profiles, clusters, market-maker flags and privacy exits are leads with stated confidence, not proof. Public data can be incomplete or delayed depending on the RPC endpoint. Verify every finding independently.
Source, issues and contributions: github.com/Unizuka22/opensol-agent