OpenSol / docs ← Home Docs

OpenSol docs

OpenSol is Solana intelligence in plain English. Point it at a wallet, a token mint or a transaction and it reads the public chain, weighs the signals and explains what it found with a transparent 0–100 risk score.

It profiles how wallets trade, checks launches for bundles and serial creators, spots Pump.fun and StonkFun market makers, traces money hop by hop to swap services and exchanges, and follows funds into privacy pools and back out again, up to a certain extent.

  • No keys
  • No trading
  • No black boxes
  • Public data only
  • Open source · MIT

Quick start

On the web

Wallet connect for Phantom, Solflare and Backpack is coming soon. OpenSol will only read your public address. It will never ask you to sign, approve or send anything.

From the command line

# clone and build (Node 20+)
git clone https://github.com/Unizuka22/opensol-agent
cd opensol-agent
npm install && npm run build
npm link

# optional: your own RPC endpoint
cp .env.example .env
SOLANA_RPC_URL=https://api.mainnet-beta.solana.com

# first scan
opensol token EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v

If SOLANA_RPC_URL is not set, OpenSol falls back to the public Solana mainnet endpoint. Deep traces and market-maker scans make many requests, so a dedicated RPC is recommended for heavy use.

How it works

Every command runs through the same six stages.

  1. Ingest. Pull signatures, parsed transactions, token accounts and balances for the target from Solana RPC.
  2. Decode. Turn raw instructions into events: transfers, swaps, mints, burns, liquidity adds and removals, pool creations. Swaps are decoded for Jupiter, Raydium, Orca, Meteora, Pump.fun, PumpSwap and StonkFun.
  3. Clean. Strip dust, spam airdrops, address-poisoning transfers, rent and wrap/unwrap moves, so only meaningful flows remain.
  4. Enrich. Attach labels, wallet age, first funder and venue to every address and event.
  5. Analyze. Run the analyzers: profiles, bundles, creator history, market makers, hop traces and privacy exits.
  6. Explain. Turn each finding into a sentence, add its points to the score and print the report.

Commands

CommandWhat it does
token <mint>Authorities, supply, program, holder concentration, bundle detection, creator history and liquidity.
wallet <address>Balance, activity, trade history, PnL, hold times, wallet profile and first funder.
tx <signature>Status, fee, programs touched, swaps, SOL and token transfers, in plain English.
mm <mint>Detects whether a Pump.fun or StonkFun market maker is in play and how much of the volume it drives.
trace <address> [hops] [out]Follows money hop by hop, through privacy pools where possible, and flags swap services and exchanges. Default: 3 hops, incoming.
labelsLists every service OpenSol recognises.
label <address> <name>Teach OpenSol a wallet you have identified. Your labels are flagged in every report.

Flags

--format jsonStructured output for piping into other tools.
--format markdownHuman-readable report.
--out report.mdWrite the report to a file.
--rpc <url>Override the RPC endpoint for one run.

Wallet profiles

A wallet scan rebuilds the wallet's trading history from decoded swaps. Buys and sells of each token are matched first-in, first-out into positions, which gives hold time, realised PnL in SOL (fees included) and win rate for every trade.

ProfileHow it is detected
Paper handsMedian hold under 10 minutes and at least 60% of positions closed within 10 minutes, over 10+ positions.
Diamond handsMedian hold over 7 days, holding through a drawdown of 50% or more from entry.
SniperBought within the first 3 slots after pool creation on 5+ launches.
Fresh walletFirst transaction under 7 days ago, or funded less than 24 hours before its first trade.
Copy traderBuys the same tokens 1–3 slots after the same leader wallet on 5+ occasions.
InsiderReceived tokens from the creator, or bought in the launch block with funding linked to the creator.
Bot / market maker45+ of the last 50 transactions inside an hour, a high failure rate, or same-minute buy and sell round trips.

The scan also reports the first funder of the wallet and, if it sits within two hops of a swap service, exchange or privacy pool, says which one. Each profile is a behaviour signal drawn from public transactions, not a judgement about the person behind the wallet.

Token checks

Authorities and supply

Reads the mint account for mint and freeze authority, supply, decimals, token program and Token-2022 extensions.

Holder concentration

Builds the holder list from the mint's token accounts, then removes pool vaults, burn addresses and program-owned accounts so only real holders count. Reports the top holder, top 10 share and how many top holders share a funder.

Bundle detection

Looks at every buyer in the launch slot and the next few slots and clusters them. Wallets join a bundle when they share a funder within two hops, share a fee payer, were funded in the same fan-out transaction, or bought near-identical amounts in the same slot. The report shows how many wallets are in the bundle, how much supply they took and where their SOL came from.

Creator history

Identifies the creator from the token's create instruction, lists every other token that wallet launched, and checks how each one ended: creator sold most of the supply within the first hour, liquidity pulled, or still trading. The creator's own funding is traced too.

Liquidity

Finds the token's pools, reads depth on each side and checks whether LP tokens are burned, locked or held by a wallet that can pull them.

Market makers

mm <mint> tells you when a market maker is in play and who is really moving the chart. The venue is identified from the programs the token trades on: Pump.fun bonding curve and PumpSwap pools for Pump.fun, and StonkFun's own pools for StonkFun.

What OpenSol looks for

  1. Wallet fleets. Many fresh wallets funded in one burst, often a single transaction splitting equal SOL to 10–50 addresses.
  2. Wash patterns. Buys and sells of near-identical size from the fleet within seconds, leaving each wallet close to flat.
  3. Machine timing. Trades at regular intervals with very low variance, uniform sizes and repeated round trips.
  4. Known operators. Fee wallets and funders of known market-making and volume services, matched against labels.
  5. Volume share. The share of recent volume the cluster drives.

A market maker is reported as in play when its cluster drives 30% or more of the last hour's volume. The report names the venue, the number of wallets, their shared funder and the volume share, for example: Pump.fun market maker in play · 41% of last-hour volume · 18 wallets.

Hop tracing

trace walks the money backwards, hop by hop, up to five hops. Add out to follow where it went instead.

  1. Read the wallet's earliest and latest transfers. The earliest usually show who funded it.
  2. Rank counterparties by value moved in SOL, USDC and USDT and follow the largest to the next hop.
  3. Flag every hop that lands on a labeled swap service, bridge, exchange or privacy pool, even if it isn't followed.
  4. Mark wallets doing 100+ transactions an hour as busy hubs and stop there.
  5. When a path enters a privacy pool, hand it to the privacy tracer and continue from the likely exits.
  6. Print every flagged path and the full hop tree.

Services flagged

Instant swaps

Husher · HoudiniSwap · ChangeNOW · SimpleSwap · Changelly · SideShift · FixedFloat · StealthEX · Exolix · LetsExchange

Bridges & aggregators

Relay · RocketX

Low-KYC exchanges

MEXC

Exchanges

Binance · Coinbase · Kraken · OKX · Bybit · Bitget · KuCoin · Gate.io · HTX

Privacy on Solana

Mask · Privacy Cash · Umbra · Solflare Private Send · Nullmask · Vanish · encrypt.trade · Zero · ShadowWire · Confidential Balances

Privacy off Solana

Railgun

Privacy pools

Privacy pools break the direct link between a deposit and a withdrawal. OpenSol can't see inside them, but it can follow money in and pick the trail back up on the other side, up to a certain extent.

Following money in

Deposits are recognised from the pool's program and vault addresses. The trail is marked with the pool, amount, token and time.

Picking it back up

Every withdrawal from the same pool after the deposit is a candidate exit. Candidates are ranked by:

AmountWithdrawal matches the deposit once the pool's fee is taken off, or several withdrawals add up to it.
TimingHow soon after the deposit it happened, and whether it fits the depositor's usual active hours.
Gas fundingWho paid to fund the fresh withdrawal wallet, traced back toward the depositor.
ConvergenceWithdrawals that end up at the same exchange deposit, wallet or token as the depositor's known wallets.
BehaviourSame swap routes, same tokens bought, same trade sizes and timing as the depositor.

Each candidate gets a confidence of low, medium or high with its reasons listed, and the trace continues from the strongest ones.

Where the trail fades

  • Fixed-size deposits and large, busy pools make many withdrawals look alike, so confidence drops.
  • Confidential Balances hide amounts but not addresses, so links come from the address graph instead.
  • Pools on other chains such as Railgun are linked through bridge deposits and withdrawals on Solana, matched by amount and timing.

Noise filtering

Explorers show everything. OpenSol drops what doesn't matter before it analyzes anything:

  • Dust: SOL and token transfers too small to matter.
  • Address poisoning: tiny or zero transfers from lookalike addresses that copy the start and end of a real counterparty.
  • Spam airdrops of unknown tokens nobody asked for.
  • Failed transactions, rent deposits and refunds, account creation and wSOL wrap and unwrap.
  • Transfers between a wallet's own token accounts.

Reports state how many transfers were skipped, so nothing disappears silently.

Labels

Labels turn addresses into names. Built-in labels cover exchange hot wallets, swap-service payout wallets, bridge depositories and solvers, privacy pool programs and vaults, DEX programs and market-making services. Every built-in label comes from a public, citable source such as official docs, labeled datasets or published investigations.

Some services create a fresh deposit address for every order. When you identify one, add it with label <address> <name> and it will be flagged in every report you run.

Risk scoring

Every score starts at 5 and only rises for observable signals. Every point comes with its reason.

Token signals

SignalPointsWhy it matters
Active mint authority+30More supply may be created by the authority.
Bundled launch+25A linked cluster bought a large share of supply at launch.
Active freeze authority+20Token accounts may be frozen by the authority.
Serial creator+20The creator dumped or abandoned earlier launches.
Top-10 concentration+15Top 10 real holders own 40% or more of supply.
Bundle funded via swap or bridge+10The bundle's SOL came through an instant swap, bridge or privacy pool.
Market maker in play+10A cluster drives 30% or more of recent volume.
Unknown token program+5Owner is not SPL Token or Token-2022.

Wallet signals

SignalPointsWhy it matters
Bot-like activity+25Very high activity, or high activity plus failed transactions.
High failed-tx rate+25A large share of recent transactions failed.
Privacy pool exit+20Funded by a likely privacy-pool withdrawal (medium or high confidence).
Funded via swap service+15An instant swap or low-KYC exchange sits within two hops of the first funder.
High recent activity+12More active than a casual wallet; not suspicious alone.
Sniper pattern+12Repeated first-slot buys on new launches.
Elevated failed-tx rate+10Some recent failures observed.
Fresh wallet+5Little history before its first trades.
low < 35medium 35–69high ≥ 70

Architecture

command
  → config / RPC setup
  → fetchers             src/solana/    token · wallet · transaction · programs
  → decoders                            swaps · pools · launches · privacy pools
  → noise filter                        dust · poisoning · spam · rent
  → enrichment                          labels · wallet age · first funder
  → analyzers            src/analyzers/ tokenRisk · walletProfile · tradeHistory
                                        bundles · creatorHistory · marketMaker
                                        hopTrace · privacyExit · liquidity
  → explanation layer    src/agent/     deterministic, plain English
  → report               src/reports/   markdown · json

Every analyzer is deterministic and documented. Unknown data stays unknown instead of being guessed.

Safety

OpenSol does not:

  • Buy, sell, swap or trade
  • Sign transactions
  • Ask for or store private keys
  • Give financial, legal or investment advice
  • Claim to prove fraud, manipulation or intent

OpenSol produces heuristic reports from public Solana data. Profiles, clusters, market-maker flags and privacy exits are leads with stated confidence, not proof. Public data can be incomplete or delayed depending on the RPC endpoint. Verify every finding independently.

Source, issues and contributions: github.com/Unizuka22/opensol-agent