Reproduce the results
Run the leak scanner yourself with Node and one RPC key. It prints aggregate numbers only.
Everything in the leak study comes from one open-source scanner. You can run it and compare.
Requirements
- Node 20 or later.
- An Alchemy key on a plan that allows wide
eth_getLogsranges. A full mainnet scan costs a few dollars of requests.
Run it
git clone https://github.com/siriusthemaster/ephemeral
cd ephemeral
cp .env.example .env # put your key in .env: ALCHEMY_KEY=...
npm install
npm test # unit tests and an end-to-end scan against a fake node
npm run scan:sepolia # quick smoke test on Sepolia
npm run scan # Ethereum mainnet, full historyThe first run fixes the end block at the latest finalized block, so every later run reads the same range. An interrupted scan resumes from its cache.
Check the fingerprint
Download the same range again from scratch and compare:
npm run scan -- --fresh --to-block 26127110The summary prints a fingerprint. For our published run it is cc961f9b2c0bbd11.
Options
| Option | Default | Meaning |
|---|---|---|
--chain | mainnet | mainnet or sepolia |
--to-block | finalized | Last block to include |
--fresh | off | Delete the cache for this chain and download again |
--sample | all | N stealth addresses spread evenly over time, for a quick look |
--concurrency | 8 | Parallel RPC requests |
Output
out/summary.md and out/summary.json hold counts only: no address, cluster or link. The raw cache stays on your machine and is never uploaded.