Start here
sui-mcp is a read-only MCP server for investigating activity on Sui. It gives an AI assistant tools to trace funds, attribute wallets, read who controls a token or a package, and decode transactions. It holds no keys and never submits a transaction; see Security model.
The npm package is sui-analytics-mcp, MIT licensed. It runs over stdio in any
MCP client, needs no account or API key, reads public Sui endpoints and
defaults to mainnet.
Current release: 1.26.0 (2026-10-01).
Common tasks
Section titled “Common tasks”- Install the server: Install. For investigations, load
the
forensicsprofile as that page shows. - Investigate a hack or exploit: the Cetus exploit example, then the forensics skill, which sets the order to work in.
- Check who controls a token: the
KONG rug pull example, or the
who_controls_this_tokeneveryday prompt. - Check who controls a protocol: the Typus authority example and Packages and upgrade authority.
- Find out what happened to lost funds: the
what_happened_to_my_fundseveryday prompt, and the drainer kit example. - Check a wallet or a suspect address: the
drainer kit example, or the
who_is_this_walleteveryday prompt. - Test whether wallets share an operator: the claim farm example and Shared funders.
- Trace where funds went: the Cetus exploit example and Fund flows.
- Read a result’s warnings:
How an investigation runs
lists the marks tools put on their own answers, such as
truncated,completeandpartial. How to read results explains the ones specific to coins, transactions, fund flows and packages. - Read Move packages or build unsigned transactions: load the
developerprofile (Tool profiles). - Look up a tool’s parameters: the tool reference.
Every worked investigation is listed under Examples.