BnbchainCAUTION
A MCP server for BNB Chain that supports BSC, opBNB, Greenfield, and other popular EVM-compatible networks.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful toolkit for interacting with BNB Chain and other EVM-compatible networks through natural language processing and AI assistance.
Description
BNBChain MCP is a Model Context Protocol implementation that enables seamless interaction with blockchain networks through AI-powered interfaces. It provides a comprehensive set of tools and resources for blockchain development, smart contract interaction, and network management.
Core Modules
The project is organized into several core modules:
- Blocks: Query and manage blockchain blocks
- Contracts: Interact with smart contracts
- Network: Network information and management
- NFT: NFT (ERC721/ERC1155) operations
- Tokens: Token (ERC20) operations
- Transactions: Transaction management
- Wallet: Wallet operations and management
- Common: Shared utilities and types
- Greenfield: Support file management operations on Greenfield network including, uploading, downloading, and managing files and buckets
- Additional features coming soon (Greenfield, Swap, Bridge, etc.)
- Agents (ERC-8004): Register and resolve on-chain AI agent identities (ERC-8004 Trustless Agents) on BSC and BSC Testnet
Important Notes
We do not recommend deploying this MCP Server on the public internet. (1) The SSE endpoint has no authentication—anyone who can reach it can use the server. (2) There is no centralized service that custodies private keys or funds; keys and signing are the responsibility of the client. If you still need to deploy it publicly, add an authentication layer in front (e.g. API keys, JWT, or a reverse proxy with auth), or deploy a keyless version that only exposes read-only or non-sensitive tools.
Credentials: Pre
86985b0e6d87OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env PRIVATE_KEY=${PRIVATE_KEY} -- npx -y @bnb-chain/[email protected]{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@bnb-chain/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"PRIVATE_KEY": "${PRIVATE_KEY}"
}
}
}
}Exposed tools (45)
30 read · 13 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
approve_token_spending | read | |
confirm_transfer | write | Execute a pending transfer or payment that was returned as a preview. Pass the confirmToken from the preview response and your privateKey. The token expires after 5 minutes. |
create_erc20_token | write | Create a new ERC20 token |
estimate_gas | read | Estimate the gas cost for a transaction |
get_address_from_private_key | read | Get the EVM address derived from a private key |
get_block_by_hash | read | Get block metadata by hash. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data). |
get_block_by_number | read | Get block metadata by number. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data). |
get_chain_info | read | Get chain information for a specific network |
get_erc1155_token_metadata | read | Get the metadata for an ERC1155 token (multi-token standard used for both fungible and non-fungible tokens). The metadata typically points to JSON metadata about the token. |
get_erc20_balance | read | Get ERC20 token balance for an address |
get_erc20_token_info | read | Get ERC20 token information |
get_erc8004_agent | read | Get agent info from the ERC-8004 Identity Registry: owner address and tokenURI (metadata URI). |
get_erc8004_agent_wallet | read | Get the verified payment wallet address for an ERC-8004 agent (for x402 / agent payments). Set on-chain via setAgentWallet; defaults to owner on registration. |
get_latest_block | read | Get the latest block metadata. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data). |
get_native_balance | read | Get native token balance for an address |
get_nft_info | read | Get detailed information about a specific NFT (ERC721 token), including collection name, symbol, token URI, and current owner if available. |
get_supported_networks | read | Get list of supported networks |
get_transaction | write | Get detailed information about a specific transaction by its hash. Includes sender, recipient, value, data, and more. |
gnfd_create_bucket | write | Create a new bucket in Greenfield storage |
gnfd_create_file | write | Upload a file to a Greenfield bucket |
gnfd_create_folder | write | Create a folder in a Greenfield bucket |
gnfd_create_payment_account | write | Create a new payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
gnfd_delete_bucket | destructive | Delete a bucket |
gnfd_delete_object | destructive | Delete an object from a bucket |
gnfd_deposit_to_payment | read | Deposit funds into a payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
gnfd_download_object | read | Download an object from a bucket |
gnfd_get_account_balance | read | Get the balance for an account |
gnfd_get_all_sps | read | Get a list of all storage providers in the Greenfield network |
gnfd_get_bucket_full_info | read | Get bucket basic information and quota usage |
gnfd_get_bucket_info | read | Get detailed information about a bucket |
gnfd_get_object_info | read | Get detailed information about an object in a bucket |
gnfd_get_payment_account_info | read | Get the info for a payment account |
gnfd_get_payment_accounts | read | Get the payment accounts for a given address |
gnfd_list_buckets | read | List buckets owned by the account with pagination. Returns totalCount and hasMore for paging. |
gnfd_list_objects | read | List objects in a bucket with pagination. Returns totalCount and hasMore for paging. |
gnfd_withdraw_from_payment | read | Withdraw funds from a payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
is_contract | read | Check if an address is a smart contract or an externally owned account (EOA) |
read_contract | read | Read data from a smart contract by calling a view/pure function. Response is truncated if it exceeds maxResponseSize bytes. |
register_erc8004_agent | read | Register an agent on the ERC-8004 Identity Registry. Mints an on-chain agent identity (NFT) and returns the agent ID. Use BSC or BSC Testnet; the agentURI should point to a JSON metadata file (AgentURI format) with name, description, image, and services (e.g. MCP endpoint). |
set_erc8004_agent_uri | write | Update the metadata URI for an existing ERC-8004 agent. Caller must be the owner of the agent NFT. |
transfer_erc1155 | write | Transfer ERC1155 tokens to another address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
transfer_erc20 | write | Transfer ERC20 tokens to an address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
transfer_native_token | write | Transfer native tokens (BNB, ETH, MATIC, etc.) to an address. By default returns a preview and confirmToken—call confirm_transfer with the token to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
transfer_nft | write | Transfer an NFT to an address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
write_contract | write | Write data to a smart contract by calling a state-changing function. By default returns a preview and confirmToken—call confirm_transfer with the token to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
bun.lockb
Logger.info(`Deployed new ERC20 token (${name} - ${symbol}): ${hash}`)"0x608060405234801561000f575f5ffd5b506040516118df3803806118df833981810160405281019061003191906104b7565b828281600390816100429190610746565b5080600490816100529190610746565b5050506100893361006761009160201
gnfd_delete_bucket, gnfd_delete_object
- Imports must use the `@/*` alias (maps to `src/*`). Flag relative `../../` paths beyond one level up.
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, @types/node, typescript
@langchain/core, @langchain/langgraph, @langchain/mcp-adapters, @langchain/openai, @modelcontextprotocol/sdk, dotenv, @types/node, typescript
@bnb-chain/greenfield-js-sdk, @bnb-chain/reed-solomon, @modelcontextprotocol/sdk, cors, dotenv, express, mime, reflect-metadata
Gates applied: no_behavioural_pass.
86985b0e6d87full audit observations/trust-audit/mcp-server/bnb-chain__bnbchain.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 86985b0e6d87 | CAUTION | B | 89 | first audit |
Questions
What is the Bnbchain MCP server?
A MCP server for BNB Chain that supports BSC, opBNB, Greenfield, and other popular EVM-compatible networks.
What tools does Bnbchain expose?
45 in total: 30 read-only, 13 that write, and 2 that can delete or overwrite (gnfd_delete_bucket, gnfd_delete_object). Every one is listed on this page with its risk.
Is Bnbchain safe to connect to an agent?
With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Bnbchain need?
It reads ANTHROPIC_API_KEY, DEEPSEEK_API_KEY, OPENAI_API_KEY and PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Bnbchain run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @bnb-chain/mcp at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (86985b0e6d87), read on 2026-10-07. The repository is watched and re-audited when it changes.