Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.
BlockSec — Verification Record
VERDICT: VERIFIED.
BlockSec is the parent company of MetaSleuth (already in SatoshiShield blocklist since v1.0 baseline) and operates two additional product lines from the blocksec.com domain: Phalcon (enterprise security and compliance suite, including Phalcon Compliance — the enterprise surveillance product) and MetaSuites (developer-side blockchain analysis tooling). The v1.5.0 blocklist covers metasleuth.io but does not cover blocksec.com, leaving the enterprise surveillance surface unprotected.
Block scope
| Domain | Recommendation |
|---|---|
blocksec.com |
BLOCK (root + wildcard) |
docs.blocksec.com |
Covered by wildcard |
Path-based products: blocksec.com/phalcon/compliance, blocksec.com/phalcon, etc. |
Blocked by root domain entry |
Existing entry updates (recommended)
The existing MetaSleuth rows in domains.csv (*.metasleuth.io, metasleuth.io) should be updated in the same v1.6.0 PR to reflect the parent organization:
- Organization field:
MetaSleuth→BlockSecorBlockSec (operator of MetaSleuth) - Source URL stays at
https://metasleuth.io/ - date_verified:
2026-05-04→2026-05-29 - Notes field: append "Operated by BlockSec; see also blocksec.com entries."
This matches the precedent set by Lukka/Coinfirm in v1.5.0 (parent organization in the org field with predecessor noted).
Step 1 — WHOIS lookup — RUN LOCALLY
whois blocksec.com
Expected findings to document: - Registrant organization (likely BlockSec or a privacy-redacted variant; possibly Chinese registrar given founder origin) - Registration date (founded 2021, so domain likely registered 2021) - Nameservers - Lock status
Step 2 — SSL Certificate — RUN LOCALLY
echo | openssl s_client -connect blocksec.com:443 -servername blocksec.com 2>/dev/null | openssl x509 -text -noout | grep -E "Subject:|DNS:"
echo | openssl s_client -connect docs.blocksec.com:443 -servername docs.blocksec.com 2>/dev/null | openssl x509 -text -noout | grep -E "Subject:|DNS:"
Or browser: visit each URL and inspect cert via padlock > Certificate.
Expected: - Organization (O) field should identify BlockSec - Subject Alternative Names should enumerate additional active subdomains (likely app, api, docs, blog)
Step 3 — SecurityTrails / Passive DNS — RUN LOCALLY (or browser)
Visit in browser: - https://crt.sh/?q=blocksec.com (full certificate transparency log) - https://securitytrails.com/domain/blocksec.com (DNS history)
Expected findings to document:
- All active subdomains (the wildcard will cover them all, but enumeration confirms product surface)
- Likely candidates beyond docs: app, api, phalcon, blog, dashboard
- IP history showing infrastructure consistency
Step 4 — Behavioral Evidence — COMPLETE (vendor documentation route)
BlockSec is a self-documented surveillance vendor with extensive product documentation. Vendor-documentation route per Contributor Guide v1.4 §4.4 applies. Evidence:
Corporate self-description from blocksec.com/about-us:
"BlockSec is a top blockchain security firm. It blends research and industry solutions. This way, it provides complete security and compliance for the ecosystem... BlockSec was founded to address blockchain's evolving security and regulatory challenges. We combine advanced security research with real-world experience in cyber defense and financial compliance. Since 2021, we've built a strong security system. This includes auditing, real-time defense, and fund tracing."
Product line confirmed from docs.blocksec.com:
- Phalcon family: Phalcon Explorer, Phalcon Compliance, Phalcon Block, Security Incident List
- MetaSleuth: crypto tracking and investigation platform (already in v1.0 blocklist at metasleuth.io)
- MetaSuites: developer tooling including Fund Flow Graph, Transaction Insights, Transaction Simulation API
Phalcon Compliance surveillance function (from blocksec.com/phalcon/compliance):
"Use Phalcon Compliance to monitor on-chain activities in real time." "Phalcon Compliance speeds up investigations, and turns complex blockchain data into clear, defensible insights." "KYT + KYA screens addresses and monitors transactions in real time. It uses verifiable blockchain data and entity intelligence across the crypto ecosystem." "MetaSleuth traces funds and maps transaction networks with investigation tools. It reveals hidden links between entities and activities."
Customer pattern (from blocksec.com/customers):
Partners include Compound Finance, PancakeSwap, Radiant, Cobo, Goplus, Tokenlon, Forta (security intel network), and others. Cobo specifically quoted: "BlockSec is a critical partner for Cobo. Their Phalcon platform is groundbreaking and marks a huge step forward in DeFi security."
Product launch milestone (from blocksec.com/newsroom):
"BlockSec launches the world's first 'Compliance+Security' one-stop management platform" — April 24, 2025
Corporate identity: - Founded 2021 - Founders: academic security researchers (extensive peer-reviewed publications in blockchain security venues) - Origin: China (Zhejiang University connection per public research records); operations also in US - Self-description: "full-stack blockchain security and compliance provider" - Funding: not publicly disclosed; backed by tier-1 crypto VCs per industry reporting
Step 5 — Privacy Harm Assessment
BlockSec operates two distinct surveillance surfaces from blocksec.com:
-
Phalcon Compliance API: enterprise-grade KYT (Know Your Transaction) and KYA (Know Your Address) screening. The API logs querying IP addresses against the Bitcoin addresses being screened, identical to the standard Tier 1 surveillance pattern (Chainalysis Reactor, TRM Forensics, Elliptic Navigator). Customers including major DeFi platforms, exchanges, and asset managers integrate Phalcon Compliance into their compliance backends.
-
MetaSuites Transaction Simulation API: developer-tooling endpoint that processes transaction queries. Each call to the simulation API logs the querying IP against the transactions being simulated.
The v1.5.0 blocklist's coverage of metasleuth.io protects against the consumer-facing investigation product but leaves the enterprise compliance API and developer-tooling API unblocked. A Bitcoin user whose ISP, employer's network, or device-level apps make queries to blocksec.com endpoints (e.g., a DeFi wallet integrated with Phalcon Block real-time hack detection) will have those queries logged.
DNS-layer blocking of blocksec.com and its wildcard subdomains prevents the entire BlockSec surveillance surface from being reachable from the protected network.
Step 6 — Inclusion Criteria — MEETS MULTIPLE
Applying the six SatoshiShield inclusion criteria from the white paper:
- [x] Blockchain Analytics firm — BlockSec self-describes as a "full-stack blockchain security and compliance provider" with both surveillance (Phalcon Compliance) and investigation (MetaSleuth) products.
- [x] Address Screening API — Phalcon Compliance is an explicit KYT/KYA API for compliance use.
- [x] IP-Logging Infrastructure — canonical IP-logging pattern across both Phalcon Compliance and MetaSuites APIs.
- [x] KYC/AML Intelligence — Phalcon Compliance is positioned as the "Compliance" half of BlockSec's "Compliance+Security one-stop management platform" launched April 2025.
- [x] Deanonymization-adjacent — MetaSleuth (already blocked) operates from a path that the wildcard would cover, and Phalcon's entity attribution similarly produces deanonymization output.
- [ ] Wallet Telemetry — BlockSec is a B2B vendor; no consumer wallet integration documented.
Five of six criteria met. The case for inclusion is structurally identical to the existing MetaSleuth case; BlockSec is the parent vehicle running the enterprise version of the same surveillance function.
Step 7 — Functional Impact Test — RUN LOCALLY
Procedure:
1. Add *.blocksec.com and blocksec.com to your Pi-hole instances (the test resolver at blocksec.com directly (should fail — connection refused)
Expected outcome: no impact on Bitcoin wallet functionality. BlockSec is a B2B blockchain security/compliance vendor not integrated into consumer Bitcoin wallets. DeFi platforms that have integrated Phalcon Block real-time defense may show errors if accessed from the protected network — this is by design and acceptable per SatoshiShield's mission.
domains.csv entries (2 new rows)
*.blocksec.com,BlockSec,Blockchain Analytics,1,Parent organization of MetaSleuth (already blocked). Operates Phalcon Compliance enterprise KYT/KYA API and MetaSuites developer tooling. Logs querying IP addresses against Bitcoin address screening queries.,https://blocksec.com/phalcon/compliance,2026-05-29,Founded 2021. Operates Phalcon product family (Phalcon Explorer Compliance and Block) plus MetaSuites. April 2025 launched 'Compliance+Security one-stop management platform'.
blocksec.com,BlockSec,Blockchain Analytics,1,Root domain of BlockSec parent organization for MetaSleuth Phalcon and MetaSuites surveillance products.,https://blocksec.com/,2026-05-29,Parent of MetaSleuth.
Existing rows to update (2 updates — recommended in same PR)
For each of the two existing MetaSleuth rows, change MetaSleuth → BlockSec in the organization field, update date_verified to 2026-05-29, and append to notes: Operated by BlockSec; see also blocksec.com entries.
regex.txt pattern to add
(\.|^)blocksec\.com$
Pattern observations
BlockSec/MetaSleuth is a clean example of the "consumer-tool blocked but enterprise-tool unblocked" coverage gap pattern. Other Tier 1 firms in the v1.5.0 blocklist should be audited for the same pattern — specifically, any firm where the consumer-facing product is blocked but the enterprise compliance product runs from a different domain. Candidates to check in a future Phase 4 cycle: AnChain.AI (consumer vs government subsidiary domain split), Inca Digital (federal subsidiary), and others.
Verification status
| Step | Status | Outcome |
|---|---|---|
| 1. WHOIS | ⨯ Pending local | Commands documented above |
| 2. SSL certificate | ⨯ Pending local | Commands documented above |
| 3. SecurityTrails | ⨯ Pending local/browser | URLs documented above |
| 4. Behavioral evidence | ✓ Complete | Vendor self-documentation across multiple product pages |
| 5. Privacy harm | ✓ Complete | IP logging against Bitcoin address queries on Phalcon Compliance and MetaSuites APIs |
| 6. Inclusion criteria | ✓ Complete | MEETS 5 of 6 CRITERIA — INCLUDE |
| 7. Functional impact test | ⨯ Pending local | Procedure documented above |
Final verdict (pending Steps 1-3 and Step 7 local execution): BlockSec is the parent organization of MetaSleuth and operates additional surveillance products (Phalcon Compliance, MetaSuites) from blocksec.com. The existing MetaSleuth block covers only a fraction of the surveillance surface. INCLUDE BlockSec parent domain in SatoshiShield v1.6.0.