SatoshiShield
Verification record

Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.

BlockSec — Verification Record

VERDICT: VERIFIED.

BlockSec is the parent company of MetaSleuth (already in SatoshiShield blocklist since v1.0 baseline) and operates two additional product lines from the blocksec.com domain: Phalcon (enterprise security and compliance suite, including Phalcon Compliance — the enterprise surveillance product) and MetaSuites (developer-side blockchain analysis tooling). The v1.5.0 blocklist covers metasleuth.io but does not cover blocksec.com, leaving the enterprise surveillance surface unprotected.

Block scope

Domain Recommendation
blocksec.com BLOCK (root + wildcard)
docs.blocksec.com Covered by wildcard
Path-based products: blocksec.com/phalcon/compliance, blocksec.com/phalcon, etc. Blocked by root domain entry

Existing entry updates (recommended)

The existing MetaSleuth rows in domains.csv (*.metasleuth.io, metasleuth.io) should be updated in the same v1.6.0 PR to reflect the parent organization:

  • Organization field: MetaSleuthBlockSec or BlockSec (operator of MetaSleuth)
  • Source URL stays at https://metasleuth.io/
  • date_verified: 2026-05-042026-05-29
  • Notes field: append "Operated by BlockSec; see also blocksec.com entries."

This matches the precedent set by Lukka/Coinfirm in v1.5.0 (parent organization in the org field with predecessor noted).

Step 1 — WHOIS lookup — RUN LOCALLY

whois blocksec.com

Expected findings to document: - Registrant organization (likely BlockSec or a privacy-redacted variant; possibly Chinese registrar given founder origin) - Registration date (founded 2021, so domain likely registered 2021) - Nameservers - Lock status

Step 2 — SSL Certificate — RUN LOCALLY

echo | openssl s_client -connect blocksec.com:443 -servername blocksec.com 2>/dev/null | openssl x509 -text -noout | grep -E "Subject:|DNS:"
echo | openssl s_client -connect docs.blocksec.com:443 -servername docs.blocksec.com 2>/dev/null | openssl x509 -text -noout | grep -E "Subject:|DNS:"

Or browser: visit each URL and inspect cert via padlock > Certificate.

Expected: - Organization (O) field should identify BlockSec - Subject Alternative Names should enumerate additional active subdomains (likely app, api, docs, blog)

Step 3 — SecurityTrails / Passive DNS — RUN LOCALLY (or browser)

Visit in browser: - https://crt.sh/?q=blocksec.com (full certificate transparency log) - https://securitytrails.com/domain/blocksec.com (DNS history)

Expected findings to document: - All active subdomains (the wildcard will cover them all, but enumeration confirms product surface) - Likely candidates beyond docs: app, api, phalcon, blog, dashboard - IP history showing infrastructure consistency

Step 4 — Behavioral Evidence — COMPLETE (vendor documentation route)

BlockSec is a self-documented surveillance vendor with extensive product documentation. Vendor-documentation route per Contributor Guide v1.4 §4.4 applies. Evidence:

Corporate self-description from blocksec.com/about-us:

"BlockSec is a top blockchain security firm. It blends research and industry solutions. This way, it provides complete security and compliance for the ecosystem... BlockSec was founded to address blockchain's evolving security and regulatory challenges. We combine advanced security research with real-world experience in cyber defense and financial compliance. Since 2021, we've built a strong security system. This includes auditing, real-time defense, and fund tracing."

Product line confirmed from docs.blocksec.com: - Phalcon family: Phalcon Explorer, Phalcon Compliance, Phalcon Block, Security Incident List - MetaSleuth: crypto tracking and investigation platform (already in v1.0 blocklist at metasleuth.io) - MetaSuites: developer tooling including Fund Flow Graph, Transaction Insights, Transaction Simulation API

Phalcon Compliance surveillance function (from blocksec.com/phalcon/compliance):

"Use Phalcon Compliance to monitor on-chain activities in real time." "Phalcon Compliance speeds up investigations, and turns complex blockchain data into clear, defensible insights." "KYT + KYA screens addresses and monitors transactions in real time. It uses verifiable blockchain data and entity intelligence across the crypto ecosystem." "MetaSleuth traces funds and maps transaction networks with investigation tools. It reveals hidden links between entities and activities."

Customer pattern (from blocksec.com/customers):

Partners include Compound Finance, PancakeSwap, Radiant, Cobo, Goplus, Tokenlon, Forta (security intel network), and others. Cobo specifically quoted: "BlockSec is a critical partner for Cobo. Their Phalcon platform is groundbreaking and marks a huge step forward in DeFi security."

Product launch milestone (from blocksec.com/newsroom):

"BlockSec launches the world's first 'Compliance+Security' one-stop management platform" — April 24, 2025

Corporate identity: - Founded 2021 - Founders: academic security researchers (extensive peer-reviewed publications in blockchain security venues) - Origin: China (Zhejiang University connection per public research records); operations also in US - Self-description: "full-stack blockchain security and compliance provider" - Funding: not publicly disclosed; backed by tier-1 crypto VCs per industry reporting

Step 5 — Privacy Harm Assessment

BlockSec operates two distinct surveillance surfaces from blocksec.com:

  1. Phalcon Compliance API: enterprise-grade KYT (Know Your Transaction) and KYA (Know Your Address) screening. The API logs querying IP addresses against the Bitcoin addresses being screened, identical to the standard Tier 1 surveillance pattern (Chainalysis Reactor, TRM Forensics, Elliptic Navigator). Customers including major DeFi platforms, exchanges, and asset managers integrate Phalcon Compliance into their compliance backends.

  2. MetaSuites Transaction Simulation API: developer-tooling endpoint that processes transaction queries. Each call to the simulation API logs the querying IP against the transactions being simulated.

The v1.5.0 blocklist's coverage of metasleuth.io protects against the consumer-facing investigation product but leaves the enterprise compliance API and developer-tooling API unblocked. A Bitcoin user whose ISP, employer's network, or device-level apps make queries to blocksec.com endpoints (e.g., a DeFi wallet integrated with Phalcon Block real-time hack detection) will have those queries logged.

DNS-layer blocking of blocksec.com and its wildcard subdomains prevents the entire BlockSec surveillance surface from being reachable from the protected network.

Step 6 — Inclusion Criteria — MEETS MULTIPLE

Applying the six SatoshiShield inclusion criteria from the white paper:

  • [x] Blockchain Analytics firm — BlockSec self-describes as a "full-stack blockchain security and compliance provider" with both surveillance (Phalcon Compliance) and investigation (MetaSleuth) products.
  • [x] Address Screening API — Phalcon Compliance is an explicit KYT/KYA API for compliance use.
  • [x] IP-Logging Infrastructure — canonical IP-logging pattern across both Phalcon Compliance and MetaSuites APIs.
  • [x] KYC/AML Intelligence — Phalcon Compliance is positioned as the "Compliance" half of BlockSec's "Compliance+Security one-stop management platform" launched April 2025.
  • [x] Deanonymization-adjacent — MetaSleuth (already blocked) operates from a path that the wildcard would cover, and Phalcon's entity attribution similarly produces deanonymization output.
  • [ ] Wallet Telemetry — BlockSec is a B2B vendor; no consumer wallet integration documented.

Five of six criteria met. The case for inclusion is structurally identical to the existing MetaSleuth case; BlockSec is the parent vehicle running the enterprise version of the same surveillance function.

Step 7 — Functional Impact Test — RUN LOCALLY

Procedure: 1. Add *.blocksec.com and blocksec.com to your Pi-hole instances (the test resolver at and the test resolver at ) as temporary blocks 2. Test with Sparrow Wallet → Bitcoin Knots RPC (should still work) 3. Test with Electrum → public Electrum server (should still work) 4. Test with BlueWallet (mobile) (should still work) 5. Test with browser visits to mempool.space and blockstream.info (should still work) 6. Negative test: visit blocksec.com directly (should fail — connection refused)

Expected outcome: no impact on Bitcoin wallet functionality. BlockSec is a B2B blockchain security/compliance vendor not integrated into consumer Bitcoin wallets. DeFi platforms that have integrated Phalcon Block real-time defense may show errors if accessed from the protected network — this is by design and acceptable per SatoshiShield's mission.

domains.csv entries (2 new rows)

*.blocksec.com,BlockSec,Blockchain Analytics,1,Parent organization of MetaSleuth (already blocked). Operates Phalcon Compliance enterprise KYT/KYA API and MetaSuites developer tooling. Logs querying IP addresses against Bitcoin address screening queries.,https://blocksec.com/phalcon/compliance,2026-05-29,Founded 2021. Operates Phalcon product family (Phalcon Explorer Compliance and Block) plus MetaSuites. April 2025 launched 'Compliance+Security one-stop management platform'.
blocksec.com,BlockSec,Blockchain Analytics,1,Root domain of BlockSec parent organization for MetaSleuth Phalcon and MetaSuites surveillance products.,https://blocksec.com/,2026-05-29,Parent of MetaSleuth.

For each of the two existing MetaSleuth rows, change MetaSleuthBlockSec in the organization field, update date_verified to 2026-05-29, and append to notes: Operated by BlockSec; see also blocksec.com entries.

regex.txt pattern to add

(\.|^)blocksec\.com$

Pattern observations

BlockSec/MetaSleuth is a clean example of the "consumer-tool blocked but enterprise-tool unblocked" coverage gap pattern. Other Tier 1 firms in the v1.5.0 blocklist should be audited for the same pattern — specifically, any firm where the consumer-facing product is blocked but the enterprise compliance product runs from a different domain. Candidates to check in a future Phase 4 cycle: AnChain.AI (consumer vs government subsidiary domain split), Inca Digital (federal subsidiary), and others.

Verification status

Step Status Outcome
1. WHOIS ⨯ Pending local Commands documented above
2. SSL certificate ⨯ Pending local Commands documented above
3. SecurityTrails ⨯ Pending local/browser URLs documented above
4. Behavioral evidence ✓ Complete Vendor self-documentation across multiple product pages
5. Privacy harm ✓ Complete IP logging against Bitcoin address queries on Phalcon Compliance and MetaSuites APIs
6. Inclusion criteria ✓ Complete MEETS 5 of 6 CRITERIA — INCLUDE
7. Functional impact test ⨯ Pending local Procedure documented above

Final verdict (pending Steps 1-3 and Step 7 local execution): BlockSec is the parent organization of MetaSleuth and operates additional surveillance products (Phalcon Compliance, MetaSuites) from blocksec.com. The existing MetaSleuth block covers only a fraction of the surveillance surface. INCLUDE BlockSec parent domain in SatoshiShield v1.6.0.