sui-mcp
Documentation: sui-mcp.vercel.app
Read-only MCP server for investigating activity on Sui. Trace where funds went, attribute wallets to their funding sources, rank addresses by protocol flow, work out who can actually sign for a multisig treasury, and tell a coordinated cluster from a crowd, then reconstruct it all on a timeline.
It also covers the ordinary things: wallet overviews, DeFi positions, NFTs, prices and Move package analysis. USD totals are provider-based estimates; see How USD values are calculated.
Install
Add this to your MCP client config (Claude Code, Claude Desktop, Cursor, or anything else that speaks MCP over stdio):
{
"mcpServers": {
"sui": {
"command": "npx",
"args": ["-y", "sui-analytics-mcp"]
}
}
}
No account, API key, or config file is required. The server reads public Sui endpoints and defaults to mainnet. Requires Node.js >= 22.13.
For investigative work, start with the forensics tools loaded:
"env": { "SUI_TOOLS": "core,forensics" }
What an investigation looks like
The first two steps on the 22 May 2025 Cetus CLMM exploit, starting from the attacker wallet:
get_transaction_history(0xe28b50cef1d633ea43d3296a3f6b67ff0312a5f1a99f0af753c85b8b5de8ff06, order: "oldest")
→ funded once with 9.98 SUI, one failed transaction, then the first
success: DVMG3B2kocLEnVMDuQzTYRgjwuuFSfciawPvXXheB3x at 10:30:50 UTC
analyze_attack_tx(DVMG3B2kocLEnVMDuQzTYRgjwuuFSfciawPvXXheB3x)
→ attacker gained 10,024,321.28 haSUI and 5,765,124.46 SUI
haSUI/SUI pool price moved -99.9999%
anomalies: outsized-mint (high), shared-state-jump (high), …
Every value can be checked on chain. The full example goes on to total the whole run, find where the proceeds left Sui, and check who funded the wallet.
Documentation
- Start here: common tasks and the page for each
- Examples: real incidents worked through with the tools
- Install: clients, forensics profile, running from source
- Tool profiles:
SUI_TOOLS,enable_toolsand what each profile loads - Configuration: environment variables, price sources, the optional local store
- The forensics skill and its investigation prompts
- Multisig: committees, signers, aliases
- Watching addresses
- Move decompiler
- How to read results: verified coins, fund flows, lookalike addresses, truncated lists and more
- Tool reference and capabilities
Everyday prompts
For people without investigation experience (details):
what_happened_to_my_funds: whether anyone can still move what is left, how the funds left, where they went, and whom to report towho_controls_this_token: who can mint, freeze or upgrade a coinwho_controls_this_protocol: who can upgrade a protocol's code or use its admin capswho_is_this_wallet: what kind of account an address is, its labels, funding and activity
Security
Read-only: no wallet, no keys, and it never submits a transaction. See the security model and SECURITY.md for reporting a vulnerability.