aggregate_events |
Rank senders or event types by event count, or by a summed event field, across a window in one call instead of paging query_events. |
Incident investigation |
forensics |
analyze_attack_tx |
Investigate one exploit transaction. |
Incident investigation |
forensics |
analyze_multisig |
Read which of a multisig wallet’s committee keys sign and which never have, across its recent sent transactions rather than one. |
Incident investigation |
forensics |
analyze_package |
Scan a Move package’s API, struct shapes and heuristic risks: freeze/denylist, mint and admin authority, fund handling, randomness and hot-potato types. |
Packages |
forensics, developer |
analyze_token |
Get a comprehensive analysis of a Sui token in one call: metadata, current price, 24h change, total supply, and top 5 holders. |
Recommended starting points |
core (default) |
build_staking |
Build an unsigned transaction to stake or unstake SUI. |
Transaction building |
developer |
build_timeline |
Reconstruct an incident across up to 10 wallets or objects as one decoded timeline, deduplicated and ordered by checkpoint. |
Incident investigation |
forensics |
build_transfer |
Build an unsigned transaction to transfer a coin (SUI or any coin type) from one address to another. |
Transaction building |
developer |
build_wallet_edges |
Find possible shared operators when a fund trace reaches fresh wallets. |
Incident investigation |
forensics |
check_activity |
Stateless one-shot check for new activity on a Sui address or object since a known checkpoint, timestamp, cursor or version. |
Advanced |
forensics |
check_coin_restrictions |
Read issuer freezes and whole-coin pauses from regulated coins’ on-chain deny lists. |
Incident investigation |
forensics |
classify_deposit_address |
Classify exchange deposit behaviour over a chosen window. |
Incident investigation |
forensics |
compare_oracle_price |
Compare the Pyth oracle price against the price DeepBook actually traded at, over a time window. |
DeepBook |
forensics |
decode_ptb |
Decode a PTB without executing: pre-sign base64 BCS bytes BEFORE approving a wallet prompt, or an executed digest. |
Advanced |
developer |
decompile_module |
Decompile Move module(s) from a Sui package into readable source code. |
Packages |
developer |
deepbook_orderbook |
Live order book depth for a DeepBook v3 pool: bids, asks, spread, mid price and resting-liquidity imbalance. |
DeepBook |
market |
deepbook_trades |
Recent fills for a DeepBook v3 pool, with the maker and taker balance manager IDs behind each trade. |
DeepBook |
market |
delete_finding |
Remove a finding by id, for retracting something that turned out to be wrong. |
Incident investigation |
forensics |
diff_package_upgrade |
Compare two Move package versions for upgrade changes or backdoors. |
Packages |
developer |
disassemble_module |
Read Move bytecode assembly for a package ID or MVR name, without an external binary. |
Packages |
forensics, developer |
enable_tools |
Turn on more Sui tool profiles for this session. |
Profile switching |
always on |
export_case |
Render a case’s findings as a Markdown report, ready to paste into a ticket, post-mortem or writeup. |
Incident investigation |
forensics |
find_flow_path |
Find value paths from one address to another. |
Incident investigation |
forensics |
find_funding_source |
Follow a wallet’s first funding transaction and sender, then each funder’s own funding. |
Incident investigation |
forensics |
find_funding_sources |
Trace funding for many addresses together, cheaper than repeated find_funding_source calls. |
Incident investigation |
forensics |
find_pools |
Find liquidity pools for a token pair across Cetus, DeepBook v2/v3, Turbos and BlueMove v1. |
DeFi |
core (default) |
find_shared_multisig |
Given several addresses you already suspect are related, find any multisig wallet they jointly control, even one that never appeared in your trace. |
Incident investigation |
forensics |
get_address_fanout |
Measure how many distinct addresses an address transacts with, in BOTH directions, over its most recent activity. |
Incident investigation |
forensics |
get_balance |
Read one coin’s liquid balance for a Sui address or object, now or at a past time/checkpoint; the default coin is SUI. |
Coins and tokens |
core (default) |
get_chain_info |
Get current Sui network info: chain ID, epoch, checkpoint height, timestamp, and reference gas price. |
Chain and network |
core (default) |
get_checkpoint |
Get a Sui checkpoint by sequence number, digest or timestamp, or the latest if none is given. |
Chain and network |
developer |
get_coin_info |
Get on-chain metadata for a token/coin given its exact coin type string (e.g. ‘0x2::sui::SUI’). |
Coins and tokens |
market |
get_defi_positions |
Find and value a wallet’s staked SUI with rewards, issuer-rate liquid-staking coins, CLMM/AMM liquidity, lending and balances inside owned objects. |
DeFi |
core (default) |
get_move_function |
Get a specific Move function signature from a Sui package. |
Packages |
forensics, developer |
get_nft_sales |
NFT marketplace sales over a recent window, with volume and per-marketplace totals. |
NFTs |
forensics |
get_object |
Get a Sui object by its ID. |
Objects |
core (default) |
get_package |
Get a Sui Move package by its ID. |
Packages |
forensics, developer |
get_package_dependency_graph |
Get the dependency graph of a Sui Move package from its linkage table. |
Packages |
developer |
get_pool_stats |
Get stats for a DeFi liquidity pool on Sui given its object ID. |
DeFi |
market |
get_staking_summary |
Get directly held StakedSui positions and principal, now or at as_of. |
Staking |
core (default) |
get_token_prices |
Get USD prices for Sui coins by full coin type, current by default or at a past moment when at is set. |
Coins and tokens |
core (default) |
get_top_holders |
Scan objects of a given type and return top holders. |
NFTs |
forensics |
get_transaction |
Read one Sui transaction’s sender, status, gas, balance changes, decoded actions and event fields; no hand-written GraphQL is needed to read event values. |
Transactions and events |
core (default) |
get_transaction_history |
Read a wallet’s decoded protocols, actions and coin flows; prefer this to query_transactions for exploring activity. |
Recommended starting points |
core (default) |
get_transactions |
Read 1-50 transaction digests in one call instead of repeated get_transaction calls. |
Transactions and events |
core (default) |
get_upgrade_history |
Read upgrade governance across a package lineage: each version’s ID, transaction, time, publisher, signing scheme and UpgradeCap holder then. |
Incident investigation |
forensics |
get_validators |
List current Sui validators, or return detailed info for one address (credentials, staking stats, network addresses). |
Staking |
market |
get_wallet_overview |
Overview of a Sui wallet: every coin balance, SuiNS name, staked SUI and kiosk counts, and recent transactions. |
Recommended starting points |
core (default) |
identify_address |
Classify a Sui address as wallet, package, validator or object before choosing other tools. |
Recommended starting points |
core (default) |
list_dynamic_fields |
List dynamic fields of a Sui object. |
Objects |
developer |
list_findings |
List recorded findings, or every case with its finding count. |
Incident investigation |
forensics |
list_nft_collections |
Summary of the NFT collections a wallet holds: every kiosk plus directly owned objects, one row per collection type with its count. |
NFTs |
core (default) |
list_nfts |
List NFTs owned by a wallet, including kiosk-stored NFTs. |
NFTs |
core (default) |
list_owned_objects |
List raw objects owned by a Sui address with optional type filter and pagination. |
Objects |
core (default) |
manage_labels |
Manage chain-qualified address labels for investigation and trace sinks. |
Incident investigation |
forensics |
mvr_get_package_info |
Get the full Move Registry record for a single package name. |
Move Registry (MVR) |
developer |
mvr_resolve |
Resolve one or more Move Registry (MVR) names to their on-chain package IDs. |
Move Registry (MVR) |
developer |
mvr_resolve_struct |
Resolve fully-qualified Move struct names (e.g. ‘@suins/core::config::Config’) to their canonical type tag using the type’s defining-package address. |
Move Registry (MVR) |
developer |
mvr_reverse_resolve |
Reverse-lookup MVR names from one or more package addresses. |
Move Registry (MVR) |
developer |
mvr_search |
Browse or search the Move Registry for packages. |
Move Registry (MVR) |
developer |
poll_watch |
Return what has happened to watched addresses since the last poll, and nothing else. |
Advanced |
forensics |
query_events |
Query events by type, sender, emitting module or time/checkpoint range. |
Transactions and events |
forensics |
query_transactions |
Query raw transactions by sender, affected address or object, Move function, or time/checkpoint range. |
Transactions and events |
core (default) |
resolve_bridge_transfer |
Resolve bridge transfers from a Sui digest using cross-chain message identities rather than guesses from amounts and timing. |
Incident investigation |
forensics |
resolve_name |
Resolve a SuiNS name (.sui domain) to an address, or reverse-lookup an address to its SuiNS name. |
Names |
core (default) |
resolve_protocol_packages |
Find which package IDs of a protocol are actually emitting events right now, so a query targets something live. |
Incident investigation |
forensics |
sample_control_addresses |
Draw a random control group from the same population as a cohort you are testing: other addresses that used the same protocol over the same window. |
Incident investigation |
forensics |
save_finding |
Record a conclusion against a named case, so an investigation survives the session it happened in. |
Incident investigation |
forensics |
screen_address |
Screen direct and indirect exposure to labelled malicious, sanctioned, exchange, bridge and mixer accounts, by default two hops in both directions. |
Incident investigation |
forensics |
search_token |
Find a Sui coin type by name or symbol for get_balance, get_coin_info or get_token_prices. |
Coins and tokens |
market |
simulate_transaction |
Dry-run a Sui transaction without signing, sending, or spending anything. |
Transaction building |
developer |
summarize_address_flows |
Summarize an address’s coin and object inflows, outflows, counterparties, gas sponsorship and bridge exits over a window. |
Incident investigation |
forensics |
summarize_incident_losses |
Total an attacker’s take across exploit digests or a sender’s window, grouped by drained pool or vault. |
Incident investigation |
forensics |
trace_flow_graph |
Trace every branch of funds forward or backward from a transaction or a time-bounded address, rather than the single branch trace_funds follows. |
Incident investigation |
forensics |
trace_funds |
Follow a fund-flow path from a transaction. |
Incident investigation |
forensics |
trace_object_history |
Trace an object’s versions, producing transactions, times and ownership transitions, including transfers, sharing, freezing and party transfers. |
Incident investigation |
forensics |
watch_addresses |
Add, remove or list addresses watched for new activity during an investigation. |
Advanced |
forensics |