Half of analysed Base contract traffic crosses an implementation boundary

This fixed window measures every Base transaction with a recipient; it does not classify senders as human, bot, or autonomous. It shows the execution structures present in the contracts reached by that traffic.

Head block 50,489,206 Window 60 blocks Transactions 10,954 Code-bearing recipients 289 Coverage 94% Measured 2026-08-26
43.9%

of analysed code-bearing recipients use implementation or delegated-execution indirection. They carry 49.9% of analysed contract traffic and 44.2% of all recipient traffic in the window.

52.6%

hold at least one of: execution indirection, DELEGATECALL, pause, freeze, mint, or SELFDESTRUCT.

15.6%

contain executable DELEGATECALL but no supported implementation target could be resolved. The API marks those observations incomplete.

Method

A fixed 60-block window of Base mainnet was read through head block 50,489,206 — 10,954 transactions, including 10,948 with a recipient and 6 contract creations. Every transaction's recipient was counted, and the 300 most-transacted recipients were analysed against bytecode and proxy storage at that same block with the engine that serves the production endpoint.

Those 300 recipients account for 94% of transactions with a recipient. This is a non-curated snapshot of what the chain was doing in that window, not a forecast and not a sample labelled by sender type. 289 were code-bearing recipients; 11 returned no deployed code at the sampled block. Analysis is static, with supported proxies and EIP-7702 delegated accounts resolved to the code observed at that block.

Findings

Base mainnet · 289 code-bearing recipients · fixed head 50,489,206
Static observation Recipients Of code-bearing Of analysed contract tx Of all window recipient tx
Implementation or delegated-execution indirection12743.9%49.9%44.2%
Contains DELEGATECALL9833.9%31.0%27.4%
Exposes a pause selector3311.4%10.4%9.2%
Exposes a freeze selector00.0%0.0%0.0%
Exposes a mint selector155.2%8.6%7.6%
Contains SELFDESTRUCT113.8%3.0%2.7%
Any selected observation above15252.6%54.0%47.8%
Proxy/delegation path not fully resolved4515.6%16.5%14.6%

The two transaction columns answer different questions. One is conditional on analysed contract traffic; the last uses every non-creation transaction in the complete window.

isProxy is deliberately not labelled “upgradeable”: the aggregate contains EIP-1167 minimal proxies, EIP-7702 delegations, standard proxy slots, and unresolved executable-DELEGATECALL heuristics. The bytecode proves indirection; it does not prove that an administrator currently retains the power to change a target.

What the indirection aggregate contains

Machine classifications, not claims of current administrative mutability
Proxy/delegation typeRecipientsTransactions
EIP1967_DIRECT662,804
DELEGATECALL_PROXY_SUSPECTED451,601
EIP1167_MINIMAL_PROXY825
EIP7702_DELEGATED_EOA453
ZEPPELINOS_LEGACY3351
EIP1967_BEACON13

All 45 incomplete paths were DELEGATECALL_PROXY_SUSPECTED: an executable DELEGATECALL was observed, but no supported slot or embedded implementation address established a target. All 45 were labelled PROXY_RESOLUTION_INCOMPLETE. The downloadable distribution carries the aggregate breakdown and a SHA-256 digest of the normalized observations.

What this API returns for those cases

The 15.6% only matters if the answer distinguishes incomplete resolution. For a sampled address with executable DELEGATECALL and no resolved implementation target, /v1/audit/{address} returned:

Representative response shape for an incomplete resolution
FieldValue
capabilityRatingUNVERIFIED
reasonPROXY_RESOLUTION_INCOMPLETE
reachabilityNOT_ESTABLISHED
executableCapabilities["DELEGATECALL", "SELFDESTRUCT"]

Not an empty capability list, and not a passing grade. A caller reading capabilityRating cannot mistake this for a clean result — which is the whole point, because the failure mode being guarded against is an integration that treats nothing found as nothing there.

Reproducibility

The head block fixes both the recipient window and every state-bearing bytecode, storage, and beacon read. The checked-in distribution publishes deterministic ranking parameters, aggregate proxy/reason breakdowns, and a SHA-256 digest of normalized observations. The command reconstructs the same address population without publishing a raw address list.

node scripts/research/measure_agent_exposure.js --head=50489206 --blocks=60 --max=300

Canonical head block hash: 0xd7c55f551c27980ddbd21371ef8fabcbb46ddcea15961522b2f929ee399f5160.

The sample is published as machine-readable JSON: base-agent-exposure-sample.json.

What this is not

For a pre-signing human or automated workflow, the implementation boundary is invisible unless something reads the bytecode first. This traffic snapshot motivates that use case; it does not claim that the sampled transactions came from agents. The product does not say what is safe. It reports selected capabilities and says when the execution path could not be established.

Check an address yourself

The same engine that produced this table, on any Base address.

Open the Inspector API Docs Pricing