Etherscan just shipped a tool that turns blockchain forensics from a dark art into something closer to a Google search. The new Etherscan Flow agent skill, part of the company’s Build with AI suite, lets AI agents and coding assistants trace, verify, and visualize onchain money flows across more than 60 EVM-compatible chains.
It got a real-world stress test almost immediately. Security researchers used Flow to map out exactly how the RedSonic Vault exploit unfolded around September 5, 2026, when an attacker used a flash loan to drain approximately 9.25 ETH, worth roughly $23,000, in a single transaction.
How Etherscan Flow actually works
Think of Flow as a translation layer between raw blockchain data and human understanding. The tool queries Etherscan’s live API data and generates what the company calls a “Flow Case” file, a structured output that can be imported into etherscan.io/flow for visual examination.
The practical upshot: instead of manually hopping between block explorers, contract calls, and wallet addresses to piece together what happened in a complex transaction, Flow does the legwork. It traces transactions and addresses, profiles entities like DAOs or protocols, and can even import documents to verify them against onchain records.
Released in late August 2026, the tool is designed to plug directly into AI agent workflows. That means developers building investigation tools, compliance bots, or security monitors can integrate Flow’s capabilities without rebuilding Etherscan’s entire data pipeline from scratch.
The RedSonic Vault exploit: a case study in real time
The attack exploited a flaw in RedSonic’s permissionless registerErc20() function. In plain terms, the vault let anyone register new token types as collateral, and the attacker found a way to register stETH in a manner that allowed the same collateral to be counted twice.
With double-counted collateral, the attacker could borrow more than they should have been able to, then repay the flash loan and walk away with the difference. The entire sequence played out in a single transaction, hash 0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a.
Security researchers used Etherscan Flow to trace the attacker’s wallet (0x70f2333d21Ed7E7D105F6578227A9A747687982C) and the vault contract (0x4315990d9eeaffdfafd49958b4851f203fa1126f), mapping out each step of the exploit in a format that could be reviewed and shared.
Why better tooling matters for DeFi security
Tools like Etherscan Flow don’t prevent exploits. They can’t patch a buggy smart contract or stop an attacker mid-transaction. What they do is dramatically lower the barrier to understanding what happened after the fact.
On-chain analytics firms like Chainalysis and Elliptic have built large businesses around transaction tracing, but their tools are primarily aimed at institutions and law enforcement. Etherscan Flow, by embedding tracing capabilities directly into developer workflows and AI agent frameworks, potentially democratizes access to this kind of analysis.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

58 minutes ago
20









English (US) ·