Watchlist follows the addresses that matter to an active case and tells you the moment their funds move. You add a subject, and while the page is open a live feed streams fund-movement alerts — money coming in, money going out, and anything that lands on an address you flagged as an off-ramp.
Why it exists
During an incident the useful signal is not “was this address involved” — it’s “where are the funds now”. Watchlist narrows the firehose of on-chain activity down to the specific subjects in your case and alerts only on value movement, so you can react to a drain or a cash-out attempt as it happens rather than reconstructing it afterward.
Who uses it
- Incident responder — watches a compromised or attacker address during a live drain and reacts as funds move toward an off-ramp.
- Forensics analyst — keeps case subjects under watch and records each movement as it lands.
How to open it
- Sidebar → Monitoring → Watchlist.
- Direct URL —
/watchlist.
Live alerting runs only while the page is open. The feed pauses when no one is watching and resumes on your next visit — it is not a background monitor.
The layout
- Live fund-movement alerts (left) — a real-time feed with a connection indicator. Each alert names the subject, the direction, the counterparty, and the amount.
- Watched subjects (right) — every address you are tracking, with an Add to watchlist button and a control to stop watching one.
Adding a subject
- Click Add to watchlist.
- Enter the subject address and pick its network.
- Choose a direction — inbound, outbound, or both.
- Optionally set a minimum amount so small transfers don’t alert.
- Optionally list off-ramp addresses — destinations (an exchange deposit address, a mixer) that should raise a distinct alert when the subject’s funds reach them.
- Save. Alerts for that subject start streaming immediately.
Limits
- Alerts cover fund movement, not contract-internal state.
- Because alerting is page-open only, close-and-reopen gaps are expected; Watchlist is a live triage surface, not a durable audit log.
Related pages
- Sentinel — network-level event and mempool monitoring.
- Entity Labels — attach private names to the addresses that appear in your alerts.