2026-09-20
NewImprovementFixSecurityMuch of this week is about the product being honest about what it knows. A vendor that answered with nothing is now a result rather than a gap, movements that settle through a contract are gathered rather than silently missing and a case now opens on a header that states the position before you scroll.
- NewSecond platform-supplied attribution source — a second attribution vendor now labels addresses as a platform-supplied source alongside the existing one, at no cost to your organisation. It adds Ronin, Chiliz, Litecoin, Blast, Scroll and XRP; the existing source alone still covers Arbitrum and Zcash. Before this the new source produced no address labels at all, so nothing from it reached the case map. One platform call now serves every organisation rather than each organisation's screen billing separately.
- NewGrade follows who paid — output from a platform-supplied credential is graded a lead, which informs an officer but cannot back a disposition, while an organisation using its own purchased key for the same vendor gets evidence grade. Your organisation's own explicit grade setting still overrides both.
- NewCautious VASP identification — where the existing source publishes a closed list of entity types and can positively assert that an entity is not a VASP, the new source's tags are an open set, so an unrecognised tag resolves to unknown rather than to no.
- NewCase header rebuilt as a dossier — every case tab now opens on the case name, a one-line summary of the subject, total exposure, the top counterparty with its risk tone, the number of transfers and that counterparty's share of the position, a status strip with state, service-level deadline, risk and priority, an exposure verdict bar scoped to a single vendor so money is never counted twice and blocks for assignee, subject, recommendation and created date. Where exposure data is unavailable the summary falls back to the first line of the AI rationale, then to a plain state note.
- NewToday dashboard summary — the dashboard now greets you with a one-line summary of how many alerts are waiting for review, how many cases are due today against their service-level deadline and how many cases are active, with each clause dropping out at zero and an all-caught-up line when there is nothing to do.
- NewBrowser tab identity — each area of the product carries its own tab icon for cases, alerts, chat, settings and the brand mark on the dashboard, adapting to a light or dark tab bar. While alerts are waiting for review the dashboard tab carries an amber dot, which clears when the queue does.
- ImprovedYour own key is no longer a one-way door — connecting your own key for a vendor used to supersede the platform-supplied row permanently. That is now reversible from settings, and the settings screen shows whose key is paying rather than only whether a provider may be connected.
- ImprovedThree screening states on the node sheet — the node sheet now distinguishes never screened, screened with no claim and screened with a claim, rather than folding the first two together.
- ImprovedProcessing state as one banner — a case's processing state reads as a single banner, running, failed with a re-run action or queued, rather than three stacked notices.
- ImprovedExposure verdict is a link — the exposure verdict bar on the case header is a keyboard-activatable link into the map's Exposure view.
- ImprovedAlerts for review shows only unclaimed work — the list includes only cases that are both untriaged and unassigned, so nothing a colleague has already picked up appears.
- ImprovedVendor alert identifiers on review rows — alert-review rows for a single-alert case carry the vendor's own alert identifier rather than the internal case number.
- ImprovedCases board scrolling — the board has one scrollbar rather than several, sticky column headers and equal-height columns, so a collapsed column's header stays put.
- ImprovedCase tabs open at the top — switching a case tab scrolls the tab strip to the top of the viewport.
- ImprovedLocked priority explains itself — the read-only priority chip carries a tooltip saying why it is locked, which is that the case is not assigned to you.
- ImprovedAlert severity as text tone — alert rows signal severity through the text tone rather than a soft background fill.
- ImprovedConsistent settings lists — the issued-assets list, the members list and the add-token dialog now match the rest of settings.
- ImprovedConsistent sheet headers — wallet-detail and map-node sheet headers now match the transfer and alert sheet headers.
- ImprovedAmounts line up — amounts on all six transfer lists share a reserved column width, so trailing amounts align down a list instead of shifting with each value.
- ImprovedAnalysis headings at document weight — headings inside the AI analysis and recommendation cards render at document weight rather than the compact chat scale.
- ImprovedKeyboard-reachable badge hints — the service-level deadline, AI-assessed severity and AI-recommended kind badges, which carried a mouse-only tooltip, now have a hint reachable from the keyboard.
- FixedAn empty screen is now a result — a vendor that answered successfully with nothing used to read as never having been screened, so the case map kept offering Screen rather than Re-screen and each press spent vendor quota to get the same nothing back. All four screening vendors were affected. An empty answer is now recorded as a result.
- FixedContract-driven movements were missing from evidence — address history gathered only transfers signed directly by a key-holder, and token movements. Native currency an address received from or sent through a contract, a decentralised-exchange withdrawal, a multisig disbursement, an unstake or a mixer payout, was never gathered, so the record looked complete and was not. Those movements now appear in a case's movement evidence. Mixers and most decentralised finance settle this way, so the movements an investigation most cares about were the ones most under-represented.
- FixedAbsorbed failures recorded as failed — an inner contract call that fails but whose failure is absorbed by its caller leaves the outer transfer reporting success; those transfers are now recorded as failed.
- FixedCluster-derived cases can be screened — a case created from one provider's polled cross-chain cluster analysis carried a cluster marker rather than a chain, which no screening vendor declares, so every such case was permanently unscreenable while its own history and balances resolved normally. The screening step now resolves the subject's real chain the way the history and balance steps always have.
- FixedBalance provider restored, and three chains lost coverage with it — the balance provider has been swapped back to the previous one on cost grounds. Polygon balances are gained; Bitcoin, Tron and Dogecoin now have no balance provider, as only the removed provider served them. This is a deliberate decision. A Bitcoin, Tron or Dogecoin subject re-investigated after this release receives a no-provider result, and the case page still renders the older holdings figure gathered before the change.
- SecurityAPI information disclosure — error responses no longer disclose details of the API's own schema, on any request path.
- SecurityAPI resource exhaustion — the amount of work a single request can ask of the API is now bounded.