Changelog
The current release is 1.26.0. Each release below links to its full entry in CHANGELOG.md, which lists what was added, changed and fixed, and to its GitHub release.
Published versions are on npm as sui-analytics-mcp. To check that an installed tarball was built by the project’s CI, see Verifying a release.
1.26.0 (2026-10-01)
Section titled “1.26.0 (2026-10-01)”Historical prices keep working when DefiLlama cannot answer, and several long-standing gaps close. Keyless CoinGecko and GeckoTerminal fallbacks price recent dates, with exact coin identity. classify_deposit_address answers for a chosen period, and deposit roles show in the flow, identity and label tools. Historical staking on busy addresses finishes through resumable continuations. Memecoin launchpads, Vice, Blast.fun and DeepBook Predict are known protocols. Long tool descriptions are shorter, list_nfts pages are smaller, and ten known limits are documented with what to do instead.
1.25.0 (2026-09-30)
Section titled “1.25.0 (2026-09-30)”Investigations cost a model less context, and reads that stopped early now reach the end. The longest tool descriptions are shorter, tool answers drop JSON indentation, and get_validators summarises by default. Tools that read a transaction’s balance changes, and query_events, query_transactions and aggregate_events, no longer stop at a short or empty page, and a read that fails is named instead of treated as complete. USD over long windows is priced near each transaction’s time, and a new docs page explains how every USD figure is estimated and why totals may not be exact. get_staking_summary answers for a past date, continuations keep their network, and was_i_scammed becomes what_happened_to_my_funds.
1.24.0 (2026-09-29)
Section titled “1.24.0 (2026-09-29)”Everyday questions get guided answers, and answers are checked against the chain itself. Four prompts walk a non-investigator through “was I scammed”, “who is this wallet” and who controls a token or a protocol, answering in plain words with a How-sure line and never a safety verdict or financial advice. Capability audits now read wrapped, shared, frozen and object-held caps by who can still use them, and find mint authority the publish transaction did not show. Two new gates back this: every framework fact the capability rules rely on is checked against the vendored Sui framework source, and verify:live compares answers on random subjects from every era with the same facts read from the chain another way.
1.23.0 (2026-09-27)
Section titled “1.23.0 (2026-09-27)”What a wallet holds beyond plain coins now has a value. Staked SUI, liquid-staking coins, CLMM and AMM liquidity, lending positions and receipts carry a USD figure with its method and evidence tier, and NFTs carry an estimate. The wallet, flow, loss and attack tools count those values, so a drain of staked SUI or liquidity positions reads as the collector’s gain, not the victim’s. Each reader was checked against the protocol’s own figures: reward amounts, issuer rates, position views and on-chain removals matched exactly.
1.22.1 (2026-09-27)
Section titled “1.22.1 (2026-09-27)”analyze_attack_tx failed on a programmable system transaction.
1.22.0 (2026-09-27)
Section titled “1.22.0 (2026-09-27)”Investigations now ask how an exploit worked, not only where its funds went. Across Typus, Nemo, Cetus, Scallop, Aftermath Perpetuals, BlueMove, Haedal, Full Sail and AlphaFi, the tools found the flaw in the Move code with the decompiler switched off, including two incidents no public source gave an address for. An audit checked every detection rule against incidents it was not written from and against ordinary mainnet traffic. Rules keyed to one incident’s names or thresholds were replaced with rules on data flow, state and value, and a scoring harness keeps detectors honest on transactions their authors never saw. The case library grows from 8 to 19 incidents.
1.21.0 (2026-09-26)
Section titled “1.21.0 (2026-09-26)”Seven blind investigations of real Sui incidents ran through the server using only its tools: an address-poisoning loss, a wallet drainer campaign and its NFT thefts, a token rug, an airdrop claim farm, a vault key compromise and an exploit cash-out. Their answers were graded against the published reports and the chain, and each incident is now a case file replayed on every npm run verify:live. The fixes below come from those investigations and from two code reviews of the fixes.
1.20.0 (2026-09-25)
Section titled “1.20.0 (2026-09-25)”Every tool now has a live check against real mainnet data. Before this release 24 of the 76 tools had one. verify:live replays the Cetus and Nemo exploits and checks each answer against a raw chain read taken in the same run, and a generated pass sends malformed input to every argument of every tool. The checks found the defects below, and each fix has a regression test.
1.19.1 (2026-09-25)
Section titled “1.19.1 (2026-09-25)”disassemble_module showed the latest version’s bytecode for every version.
1.19.0 (2026-09-25)
Section titled “1.19.0 (2026-09-25)”Two public incidents were replayed end to end through the server: the Cetus exploit of 22 May 2025 and the Nemo exploit of 7 September 2025. Both runs, together with an audit of address balances and of the tool surface, found reads that were cut short without saying so, lists that started at the wrong end, and traces that stopped or went the wrong way. Every such defect below was reproduced on mainnet before it was fixed and checked again after.
1.18.0 (2026-09-21)
Section titled “1.18.0 (2026-09-21)”get_transaction reports what a transaction touched.
1.17.0 (2026-09-15)
Section titled “1.17.0 (2026-09-15)”identify_address reports address aliases.
1.16.0 (2026-09-14)
Section titled “1.16.0 (2026-09-14)”watch_addresses and poll_watch.
1.15.0 (2026-09-11)
Section titled “1.15.0 (2026-09-11)”Address-poisoning detection.
1.14.1 (2026-09-10)
Section titled “1.14.1 (2026-09-10)”Four cases where a tool reported something it could not determine as something it had. Found by sweeping for the pattern rather than by any single failure.
1.14.0 (2026-09-10)
Section titled “1.14.0 (2026-09-10)”Investigations can now say who controls a wallet, who wrote the code, why a transaction failed, and whether the asset they followed is the real one.
1.13.0 (2026-09-10)
Section titled “1.13.0 (2026-09-10)”Multisig wallets are now legible: who is on the committee, which of them actually sign, and who signed a given transaction.
1.12.1 (2026-09-04)
Section titled “1.12.1 (2026-09-04)”A rarely-used wallet was reported as automated.
1.12.0 (2026-09-04)
Section titled “1.12.0 (2026-09-04)”Clustering found more of what it was looking for, and timing analysis turned out to be a bot detector.
1.11.0 (2026-09-04)
Section titled “1.11.0 (2026-09-04)”One new tool (61 → 62): reading many transactions in a single call.
1.10.1 (2026-09-04)
Section titled “1.10.1 (2026-09-04)”Package analysis was unreachable from an investigation, in two different ways. Reported from a real run that fell back to hand-written GraphQL as a result.
1.10.0 (2026-09-04)
Section titled “1.10.0 (2026-09-04)”A minor rather than a patch release: alongside the fixes there is new capability — historical SuiNS name recovery, address classification in every investigation flow — and shipping that under a patch bump would leave it unread.
1.9.0 (2026-09-04)
Section titled “1.9.0 (2026-09-04)”One new tool (60 → 61) and a round of correctness work on fund tracing.
1.8.0 (2026-09-03)
Section titled “1.8.0 (2026-09-03)”Inbound bridge transfers now resolve to their origin.
1.7.0 (2026-09-03)
Section titled “1.7.0 (2026-09-03)”One new tool (59 → 60) and the identity change that makes cross-chain work possible at all.
1.6.0 (2026-08-09)
Section titled “1.6.0 (2026-08-09)”Four new tools and richer output from find_funding_sources (53 → 59 tools).
1.5.1 (2026-08-09)
Section titled “1.5.1 (2026-08-09)”All fixes, no new tools. Every item is 1.5.0 changing how fan-out is measured without the surface around it following: the description, the comments, the cache schema and the embedded summary were all still answering the 1.4.x question.
1.5.0 (2026-08-08)
Section titled “1.5.0 (2026-08-08)”Minor rather than patch: fan-out numbers change meaningfully, so a figure from 1.4.x and one from 1.5.0 are not comparable.
1.4.1 (2026-08-07)
Section titled “1.4.1 (2026-08-07)”Setting SUI_STORE_PATH to a path whose parent directory did not exist disabled persistence with only a line on stderr — the store looked configured but silently kept nothing.
1.4.0 (2026-08-07)
Section titled “1.4.0 (2026-08-07)”Minimum Node is now 22.13.
1.3.0 (2026-08-07)
Section titled “1.3.0 (2026-08-07)”Everything here came out of a real investigation — ranking AlphaLend wallets by flow and attributing their funding — where the walls hit were specific enough to fix.
1.2.0 (2026-08-07)
Section titled “1.2.0 (2026-08-07)”Minor, and it changes default behaviour: the server now starts with 17 tools instead of all 50. Nothing is removed — enable_tools turns the rest on mid-session, and SUI_TOOLS=all restores the previous startup surface.
1.1.1 (2026-08-07)
Section titled “1.1.1 (2026-08-07)”Patch: both changes harden decompile_module against hostile input. No tool signatures or output shapes change, except that a truncated all_modules run now says so explicitly.
1.1.0 (2026-08-07)
Section titled “1.1.0 (2026-08-07)”Minor rather than patch: protocol_type can now return categories that did not exist in 1.0.0 (oracle, bridge, yield, farm, and unknown for runtime-resolved packages), and decoded output changes for packages the registry previously missed — a DeepBook call that rendered as a truncated address in 1.0.0 now renders as a named action.
1.0.0 (2026-08-07)
Section titled “1.0.0 (2026-08-07)”First release published to npm and the MCP Registry.
0.1.0 (2026-02-14)
Section titled “0.1.0 (2026-02-14)”Initial public release.