Half of analysed Base contract traffic crosses an implementation boundary
This fixed window measures every Base transaction with a recipient; it does not classify senders as human, bot, or autonomous. It shows the execution structures present in the contracts reached by that traffic.
of analysed code-bearing recipients use implementation or delegated-execution indirection. They carry 49.9% of analysed contract traffic and 44.2% of all recipient traffic in the window.
hold at least one of: execution indirection, DELEGATECALL, pause, freeze, mint, or
SELFDESTRUCT.
contain executable DELEGATECALL but no supported implementation target could
be resolved. The API marks those observations incomplete.
Method
A fixed 60-block window of Base mainnet was read through head block 50,489,206 — 10,954 transactions, including 10,948 with a recipient and 6 contract creations. Every transaction's recipient was counted, and the 300 most-transacted recipients were analysed against bytecode and proxy storage at that same block with the engine that serves the production endpoint.
Those 300 recipients account for 94% of transactions with a recipient. This is a non-curated snapshot of what the chain was doing in that window, not a forecast and not a sample labelled by sender type. 289 were code-bearing recipients; 11 returned no deployed code at the sampled block. Analysis is static, with supported proxies and EIP-7702 delegated accounts resolved to the code observed at that block.
Findings
| Static observation | Recipients | Of code-bearing | Of analysed contract tx | Of all window recipient tx |
|---|---|---|---|---|
| Implementation or delegated-execution indirection | 127 | 43.9% | 49.9% | 44.2% |
Contains DELEGATECALL | 98 | 33.9% | 31.0% | 27.4% |
| Exposes a pause selector | 33 | 11.4% | 10.4% | 9.2% |
| Exposes a freeze selector | 0 | 0.0% | 0.0% | 0.0% |
| Exposes a mint selector | 15 | 5.2% | 8.6% | 7.6% |
Contains SELFDESTRUCT | 11 | 3.8% | 3.0% | 2.7% |
| Any selected observation above | 152 | 52.6% | 54.0% | 47.8% |
| Proxy/delegation path not fully resolved | 45 | 15.6% | 16.5% | 14.6% |
The two transaction columns answer different questions. One is conditional on analysed contract traffic; the last uses every non-creation transaction in the complete window.
isProxy is deliberately not labelled “upgradeable”: the aggregate contains
EIP-1167 minimal proxies, EIP-7702 delegations, standard proxy slots, and unresolved
executable-DELEGATECALL heuristics. The bytecode proves indirection; it does not
prove that an administrator currently retains the power to change a target.
What the indirection aggregate contains
| Proxy/delegation type | Recipients | Transactions |
|---|---|---|
EIP1967_DIRECT | 66 | 2,804 |
DELEGATECALL_PROXY_SUSPECTED | 45 | 1,601 |
EIP1167_MINIMAL_PROXY | 8 | 25 |
EIP7702_DELEGATED_EOA | 4 | 53 |
ZEPPELINOS_LEGACY | 3 | 351 |
EIP1967_BEACON | 1 | 3 |
All 45 incomplete paths were DELEGATECALL_PROXY_SUSPECTED: an executable
DELEGATECALL was observed, but no supported slot or embedded implementation
address established a target. All 45 were labelled
PROXY_RESOLUTION_INCOMPLETE. The downloadable distribution carries the
aggregate breakdown and a SHA-256 digest of the normalized observations.
What this API returns for those cases
The 15.6% only matters if the answer distinguishes incomplete resolution. For a sampled
address with executable DELEGATECALL and no resolved implementation target,
/v1/audit/{address} returned:
| Field | Value |
|---|---|
capabilityRating | UNVERIFIED |
reason | PROXY_RESOLUTION_INCOMPLETE |
reachability | NOT_ESTABLISHED |
executableCapabilities | ["DELEGATECALL", "SELFDESTRUCT"] |
Not an empty capability list, and not a passing grade. A caller reading
capabilityRating cannot mistake this for a clean result — which is the whole
point, because the failure mode being guarded against is an integration that treats
nothing found as nothing there.
Reproducibility
The head block fixes both the recipient window and every state-bearing bytecode, storage, and beacon read. The checked-in distribution publishes deterministic ranking parameters, aggregate proxy/reason breakdowns, and a SHA-256 digest of normalized observations. The command reconstructs the same address population without publishing a raw address list.
node scripts/research/measure_agent_exposure.js --head=50489206 --blocks=60 --max=300
Canonical head block hash:
0xd7c55f551c27980ddbd21371ef8fabcbb46ddcea15961522b2f929ee399f5160.
The sample is published as machine-readable JSON: base-agent-exposure-sample.json.
What this is not
- Not a safety measurementA pause selector is a fact about deployed bytecode. Most of these contracts are ordinary, well-run, and hold these powers for good reasons. Nothing here says any contract is unsafe; the report publishes aggregates rather than a raw address list.
- Not dynamic analysisPresence of an opcode is not proof it is reachable. Reachability is reported separately and is never asserted.
- Not the whole chainThe 6% of recipient transactions beyond the top 300 recipients, plus six contract-creation transactions with no pre-existing recipient, were not analysed.
- Not an agent-identified cohortThe block data does not establish whether a sender was human-controlled, automated, or autonomous. These figures describe all recipient traffic in the sampled window.
For a pre-signing human or automated workflow, the implementation boundary is invisible unless something reads the bytecode first. This traffic snapshot motivates that use case; it does not claim that the sampled transactions came from agents. The product does not say what is safe. It reports selected capabilities and says when the execution path could not be established.
Check an address yourself
The same engine that produced this table, on any Base address.
Open the Inspector API Docs Pricing