The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Cabal Hunter listing page.
🌐 Available in 9 languages: English · Español · Português · Français · Deutsch · Nederlands · 中文 · 日本語 · 한국어

Stop your AI trading agents getting rugged by coordinated wallet cabals. Drop-in template for Claude Code, Cursor, and ElizaOS.
▶ Try it now: live 3D holder map of any Solana token → — no signup.
Cabal-Hunter is a free on-chain Solana token safety scanner and rug checker. It detects coordinated wallet cabals, same-block bundle buys, serial-launcher deployers and same-block coordinated selling on any Solana mint (pump.fun, PumpSwap, Raydium, Orca, Meteora) — and answers the one question that matters before you ape: are you the exit liquidity? Use it via MCP (Claude, Cursor, ElizaOS), a REST API, or a free interactive 3D holder map.
Your autonomous trading agent is reading rug.check scores, liquidity locks, and contract audits.
None of that catches a cabal.
A handful of wallets take the bottom of a launch, the chart looks clean — contract fine, LP burned, everything green — and then they sell into whoever bought after them. You are the exit liquidity.
This template integrates Cabal-Hunter as a pre-trade safety check, so your agent can see who is holding and who has already positioned to sell before it signs a swap.
A note on what we do and don't claim. This README used to open with "15 fresh wallets funded from the same master wallet, accumulating 25-40% of supply." We went looking for that pattern and could not find it. Tracing 323 pump.fun launches at the bonding curve turned up zero coordinated funding clusters, and showed why: the median launch has about five successful buyers, because on one representative token 1,260 of the curve's 1,266 transactions failed. Launch capture is a sniper race between competing bots, not a quiet cabal. The detection layers below are the ones we can actually evidence — holder concentration, same-block bundles, coordinated selling and deployer history. The pre-launch funding tracer was withdrawn; the full write-up is here.
The classic pump.fun exit-liquidity setup: wallets positioned before the crowd take the bottom of a launch, then dump on the retail (and bots) that pile in after. Cabal-Hunter's headline output is a single Exit-Liquidity Risk verdict — risk_level, one of LOW_SIGNAL | ELEVATED | HIGH that synthesises every signal below into the only thing that matters before you sign a swap: are the insiders positioned to dump on you?
The deployer layer is the one cabals can't dodge: wallets rotate, deployers leave a paper trail. A response of "deployer": {"reputation": "SERIAL_RUGGER", "tokens_launched": 22, "best_peak_usd": 728432, "pump_and_dumps": 2} shows the dev's full track record before the first candle — including whether this "dead" dev has quietly run tokens to six figures and dumped them on holders before. (Honest context: most prolific pump.fun creators have high dead-token rates, so this signal is capped — it flags a token for review but never drives a HIGH verdict on its own.)
FIRST_LAUNCH and UNKNOWN are not the same answer. deployer.verdict of
FIRST_LAUNCH means we walked this creator's history and found no earlier tokens.
UNKNOWN means the history could not be established at all — that is an absence of
evidence, not a clean record, and an agent must not treat it as one. Where a deployer
cannot be resolved the scan says so in words rather than returning a confident silence.
Receipts, not magic. Every wallet cluster carries evidence_txs[] — the raw signatures behind that cluster, checkable on Solscan, and holders carry funding_tx where we resolved one. Holder concentration, deployer history and the honeypot checks are read from chain state, so they carry no transaction of their own: a token can come back HIGH with no clusters at all. Verify what is there rather than trusting a score.
Response in <100ms for a mint traced in the last 8 hours — computed_at (unix seconds) says exactly when that trace ran. Any other mint runs a live on-chain trace and takes 15-20s, so allow a 30s timeout.
Free tier: 5 scans/month with no account, or 250/month with a free key (one email). Then $0.001 per scan — priced at cost (it covers the Helius RPC calls behind each live on-chain trace). Pay by card, in USDC on Solana, or via x402 — same price through every door. $9/month buys unlimited fair-use scans; by card that renews automatically and can be cancelled anytime at cabal-hunter.com/billing.
Add to your MCP config (~/.claude/mcp.json or project .mcp.json):
That's it. Claude will now call check_cabal_risk automatically when you ask it to analyse a Solana token.
Example prompt:
"Before we buy into this token, check if there are any coordinated wallets:
EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v"
Claude calls the tool, pays $0.001 USDC from your connected wallet, and returns the full analysis.
Add to .cursor/mcp.json in your project root:
If you're using ElizaOS with @hugen/plugin-x402-solana, payment is handled automatically. Add to your agent config:
Your agent will call check_cabal_risk(mintAddress) before any swap and abort if cabalScore >= 35 or isControlled === true.
For headless scripts, custom bots, or any language. The first 5 calls/month are free — no key, no signup. A free key (one email) raises that to 250/month. Just call it:
You get the full analysis back immediately, with free_queries_remaining so you always know where you stand. Machine-readable contract: /openapi.json.
Once the free tier is used up, calls are $0.001 USDC via x402 — your agent just pays, no billing setup:
Step 1 — Request analysis (get payment instructions):
Response (HTTP 402):
Step 2 — Pay & resubmit:
Response (HTTP 200):
Fastest — no clone needed: npx cabal-hunter-mcp — the same stdio server, published to npm (cabal-hunter-mcp · npm). Or run it from this repo:
Prefer to run the connector yourself instead of hitting the hosted /mcp
endpoint? This repo ships a thin stdio MCP server that exposes
check_cabal_risk(mintAddress) and proxies to the Cabal-Hunter API (free tier
works with no key; paid scans use x402 at call time):
Then point any MCP client at the local command:
See exactly what the analysis found. Every real holder is a faceted crystal sized by its share of supply; wallets in the same cluster are joined by light beams, and the liquidity pool and locked supply sit apart in a wireframe vault because they cannot be sold. Drag to rotate, hover for the wallet, click through to Solscan:
Free to view, in 9 languages. Share this URL when you catch a rug. Every crystal is clickable and links to Solscan for deep-dive research.
Same detection engine, wherever your stack lives:
npx cabal-hunter-mcp — standalone MCP server for Claude · Cursor · VS Code · any MCP client: cabal-hunter-mcp · npmnpm i elizaos-plugin-cabal-hunter — plugin-cabal-hunter · npmFirst 5 scans every month are free — no signup, no API key. A free key (one email) raises that to 250/month.
After that, pick whatever matches how hard your bot works (priced at cost — it covers the Helius RPC behind each live on-chain trace):
| Plan | Price | What you get |
|---|---|---|
| Unlimited ⭐ | $9 USDC / month | Scan all you want — fair use: 50,000/mo, more than any bot needs |
| Pay as you go | $0.001 USDC / scan | Only what you use — prepaid or per-call, no commitment |
Prepaid keys: send USDC once → POST /api/buy-key with the tx signature → use header X-API-Key on every scan. Or pay per-call via x402 (X-Payment-Signature header). No credit card, no account, no lock-in.
Does it pay for itself? Work it out with your own numbers rather than ours: the Unlimited tier is $9 a month, so it pays for itself the first time it keeps you out of a position bigger than $9 that goes to zero. Whether that happens once a month or once a week depends on what you trade and how often — we are not going to invent an average for you.
Payment is native on Solana — no credit card, no account, no subscription lock-in.
Drop a live safety badge into your own bot's dashboard — two lines of HTML, and every token shows its verdict as it trades:
It renders the 0–100 score, the plain-English verdict, and the active flags (bundled launch, coordinated selling, whale concentration, serial-launcher deployer, honeypot). Add data-refresh="120" to re-scan live as you trade, and data-api-key="..." once you're past your free scans. Works anywhere — React, plain HTML, any site.
| Endpoint | Description | Auth |
|---|---|---|
POST /api/scan-cabal | Full cabal analysis | $0.001 USDC |
GET /api/scan-cabal?mintAddress= | GET version | $0.001 USDC |
GET /map?mint= | Interactive 3D holder map | Free |
GET /api/cex-funding?mint= | Per-exchange funding breakdown (which CEXes funded holders, % each) | Free |
GET /api/trade-analysis?mint= | Cohort PnL (Team/Snipers/Insiders) + wash-trading score + exit-liquidity price impact, one call | Free |
POST /api/watch | Register an emergency dump webhook for a mint (push on dump/rug start) | Free |
GET /api/info | Pricing, endpoints | Free |
GET /health | Uptime check | Free |
POST /mcp | MCP tool endpoint | $0.001 USDC per call |
Instead of polling, let your bot subscribe to a token it holds — we push the moment a coordinated dump or liquidity drain starts:
Your endpoint receives:
computed_at always says when it
ran; fresh=1 forces a new oneWhat is a Solana cabal? A group of wallets — often funded from the same source and buying in the same block — that quietly accumulate a large share of a token's supply before retail, then dump simultaneously into everyone who buys after launch.
How do I check if a Solana token is a rug?
Scan the mint with Cabal-Hunter (MCP, REST API, or the free 3D holder map). It traces holder funding back one hop to shared sources, detects same-block bundle buys, flags serial-launcher deployers and same-block coordinated selling, and returns an Exit-Liquidity Risk verdict — risk_level: LOW_SIGNAL, ELEVATED or HIGH.
Is it free? Yes — 5 scans/month with no signup or API key, and 250/month with a free key (one email). Beyond that it's $0.001 USDC per scan — which just covers the Helius RPC cost of the live trace — paid natively on Solana.
Is there a way to use it without writing code? Yes — @TheCabalHunter_Bot on Telegram. Paste a mint, get the same scan as a card, and ask it to watch a token you hold so it messages you when a dump starts. Scored tokens are posted to @CabalHunterAlerts.
Can AI trading agents use it?
Yes — that's the whole point. The MCP server (api.cabal-hunter.com/mcp) lets Claude, Cursor and ElizaOS agents call check_cabal_risk(mintAddress) automatically before any swap, and a REST API covers any other language.
MIT — fork it, build on it, integrate it. If you build something with this, share it.
Built by Cabal Hunter · Powered by Helius · Contact: api.cabal-hunter.com/api/info