Atlas / MCP servers / bnb-chain / Bnbchain

BnbchainCAUTION

mcp/bnb-chain/bnbchain

A MCP server for BNB Chain that supports BSC, opBNB, Greenfield, and other popular EVM-compatible networks.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
45 30r · 13w · 2d
Transport
sse · stdio
License
MIT
Stars
59
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful toolkit for interacting with BNB Chain and other EVM-compatible networks through natural language processing and AI assistance.

Description

BNBChain MCP is a Model Context Protocol implementation that enables seamless interaction with blockchain networks through AI-powered interfaces. It provides a comprehensive set of tools and resources for blockchain development, smart contract interaction, and network management.

Core Modules

The project is organized into several core modules:

  • Blocks: Query and manage blockchain blocks
  • Contracts: Interact with smart contracts
  • Network: Network information and management
  • NFT: NFT (ERC721/ERC1155) operations
  • Tokens: Token (ERC20) operations
  • Transactions: Transaction management
  • Wallet: Wallet operations and management
  • Common: Shared utilities and types
  • Greenfield: Support file management operations on Greenfield network including, uploading, downloading, and managing files and buckets
  • Additional features coming soon (Greenfield, Swap, Bridge, etc.)
  • Agents (ERC-8004): Register and resolve on-chain AI agent identities (ERC-8004 Trustless Agents) on BSC and BSC Testnet

Important Notes

We do not recommend deploying this MCP Server on the public internet. (1) The SSE endpoint has no authentication—anyone who can reach it can use the server. (2) There is no centralized service that custodies private keys or funds; keys and signing are the responsibility of the client. If you still need to deploy it publicly, add an authentication layer in front (e.g. API keys, JWT, or a reverse proxy with auth), or deploy a keyless version that only exposes read-only or non-sensitive tools.

Credentials: Pre

Read from source at commit 86985b0e6d87OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env PRIVATE_KEY=${PRIVATE_KEY} -- npx -y @bnb-chain/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@bnb-chain/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "PRIVATE_KEY": "${PRIVATE_KEY}"
      }
    }
  }
}
03

Exposed tools (45)

30 read · 13 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
approve_token_spendingread
confirm_transferwriteExecute a pending transfer or payment that was returned as a preview. Pass the confirmToken from the preview response and your privateKey. The token expires after 5 minutes.
create_erc20_tokenwriteCreate a new ERC20 token
estimate_gasreadEstimate the gas cost for a transaction
get_address_from_private_keyreadGet the EVM address derived from a private key
get_block_by_hashreadGet block metadata by hash. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data).
get_block_by_numberreadGet block metadata by number. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data).
get_chain_inforeadGet chain information for a specific network
get_erc1155_token_metadatareadGet the metadata for an ERC1155 token (multi-token standard used for both fungible and non-fungible tokens). The metadata typically points to JSON metadata about the token.
get_erc20_balancereadGet ERC20 token balance for an address
get_erc20_token_inforeadGet ERC20 token information
get_erc8004_agentreadGet agent info from the ERC-8004 Identity Registry: owner address and tokenURI (metadata URI).
get_erc8004_agent_walletreadGet the verified payment wallet address for an ERC-8004 agent (for x402 / agent payments). Set on-chain via setAgentWallet; defaults to owner on registration.
get_latest_blockreadGet the latest block metadata. Returns number, hash, timestamp, gasUsed, transaction count, and optionally transaction hashes (not full tx data).
get_native_balancereadGet native token balance for an address
get_nft_inforeadGet detailed information about a specific NFT (ERC721 token), including collection name, symbol, token URI, and current owner if available.
get_supported_networksreadGet list of supported networks
get_transactionwriteGet detailed information about a specific transaction by its hash. Includes sender, recipient, value, data, and more.
gnfd_create_bucketwriteCreate a new bucket in Greenfield storage
gnfd_create_filewriteUpload a file to a Greenfield bucket
gnfd_create_folderwriteCreate a folder in a Greenfield bucket
gnfd_create_payment_accountwriteCreate a new payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
gnfd_delete_bucketdestructiveDelete a bucket
gnfd_delete_objectdestructiveDelete an object from a bucket
gnfd_deposit_to_paymentreadDeposit funds into a payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
gnfd_download_objectreadDownload an object from a bucket
gnfd_get_account_balancereadGet the balance for an account
gnfd_get_all_spsreadGet a list of all storage providers in the Greenfield network
gnfd_get_bucket_full_inforeadGet bucket basic information and quota usage
gnfd_get_bucket_inforeadGet detailed information about a bucket
gnfd_get_object_inforeadGet detailed information about an object in a bucket
gnfd_get_payment_account_inforeadGet the info for a payment account
gnfd_get_payment_accountsreadGet the payment accounts for a given address
gnfd_list_bucketsreadList buckets owned by the account with pagination. Returns totalCount and hasMore for paging.
gnfd_list_objectsreadList objects in a bucket with pagination. Returns totalCount and hasMore for paging.
gnfd_withdraw_from_paymentreadWithdraw funds from a payment account. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
is_contractreadCheck if an address is a smart contract or an externally owned account (EOA)
read_contractreadRead data from a smart contract by calling a view/pure function. Response is truncated if it exceeds maxResponseSize bytes.
register_erc8004_agentreadRegister an agent on the ERC-8004 Identity Registry. Mints an on-chain agent identity (NFT) and returns the agent ID. Use BSC or BSC Testnet; the agentURI should point to a JSON metadata file (AgentURI format) with name, description, image, and services (e.g. MCP endpoint).
set_erc8004_agent_uriwriteUpdate the metadata URI for an existing ERC-8004 agent. Caller must be the owner of the agent NFT.
transfer_erc1155writeTransfer ERC1155 tokens to another address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
transfer_erc20writeTransfer ERC20 tokens to an address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
transfer_native_tokenwriteTransfer native tokens (BNB, ETH, MATIC, etc.) to an address. By default returns a preview and confirmToken—call confirm_transfer with the token to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
transfer_nftwriteTransfer an NFT to an address. By default returns a preview and confirmToken—call confirm_transfer to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
write_contractwriteWrite data to a smart contract by calling a state-changing function. By default returns a preview and confirmToken—call confirm_transfer with the token to execute. Set skipConfirmation=true or BNBCHAIN_MCP_SKIP_TRANSFER_CONFIRMATION=true to execute immediately.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMInventory / provenance · inv.binary · CWE-1104
bun.lockb
bun.lockb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/evm/services/tokens.ts:172
Logger.info(`Deployed new ERC20 token (${name} - ${symbol}): ${hash}`)
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/evm/services/abi/erc20.ts:351
"0x608060405234801561000f575f5ffd5b506040516118df3803806118df833981810160405281019061003191906104b7565b828281600390816100429190610746565b5080600490816100529190610746565b5050506100893361006761009160201
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
gnfd_delete_bucket, gnfd_delete_object
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/pr-review.yml:52
- Imports must use the `@/*` alias (maps to `src/*`). Flag relative `../../` paths beyond one level up.
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/client-with-anthropic/package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/client-with-langchain/package.json
@langchain/core, @langchain/langgraph, @langchain/mcp-adapters, @langchain/openai, @modelcontextprotocol/sdk, dotenv, @types/node, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@bnb-chain/greenfield-js-sdk, @bnb-chain/reed-solomon, @modelcontextprotocol/sdk, cors, dotenv, express, mime, reflect-metadata
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 86985b0e6d87full audit observations/trust-audit/mcp-server/bnb-chain__bnbchain.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0786985b0e6d87CAUTIONB89first audit
06

Questions

What is the Bnbchain MCP server?

A MCP server for BNB Chain that supports BSC, opBNB, Greenfield, and other popular EVM-compatible networks.

What tools does Bnbchain expose?

45 in total: 30 read-only, 13 that write, and 2 that can delete or overwrite (gnfd_delete_bucket, gnfd_delete_object). Every one is listed on this page with its risk.

Is Bnbchain safe to connect to an agent?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Bnbchain need?

It reads ANTHROPIC_API_KEY, DEEPSEEK_API_KEY, OPENAI_API_KEY and PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bnbchain run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @bnb-chain/mcp at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (86985b0e6d87), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement