# The budget is 1,000,000 CU total and the rate ladder is 5, 8, then 15 minutes

> A read-only, locally run scanner that puts meme-token candidates on a chain-specific hot list and labels them as a first pass rather than an audit. Its own documentation is the interesting part: named CU budgets, a rate-limit ladder with a 24-hour probe lockout, four numeric initial filters, and a disclosure that the Windows launcher has never been tested on Windows.

**nhovongoc0-max/meme-radar** — Meme雷达开源版：本地只读、多链 Meme 候选扫描与人工复核工具

- Repository: https://github.com/nhovongoc0-max/meme-radar
- Stars: 499 · Forks: 193
- Language: JavaScript
- License: AGPL-3.0
- Published: 2026-09-17 · Updated: 2026-09-17 · Language: en
- Canonical page: https://hysenlabs.com/projects/nhovongoc0-max-meme-radar

## Read-only by construction, and the author says so before the features

The second paragraph of the README is a boundary statement, and it comes before anything about scanning.

The tool does not include wallet private keys, on-chain transaction signing, swap, or order placement. The system provides filtering evidence only. It is not investment advice, and it does not guarantee that a candidate token is safe or will rise.

The security boundaries section repeats the same limits as implementation facts rather than promises. The HTTP service listens only on the local loopback address. The settings interface handles local scan configuration, favourites, notes and the AVE key, and has no signing or order endpoint. The AVE key is written only to this project's restricted state file, and does not enter parameters, logs, HTTP responses or browser storage. And the browser receives state filtered through a field allowlist, never the raw upstream response.

That last one is the design detail that makes the rest coherent. If the browser only ever sees allowlisted fields, there is no path by which an upstream payload reaches a page unfiltered.

The project also describes itself as the open-source edition isolated from the author's own use, containing only local read-only scanning, automatic filtering and evidence display, with Windows and macOS sharing the same scanning logic. The licence is AGPL-3.0, and the latest push was on 2026-09-30.

## 1,000,000 CU cumulative, 30,000 a day, 1,250 an hour

The budget is the most precisely specified thing in the documentation, and the numbers are given without hedging.

The default local cumulative budget is 1,000,000 CU, at most 30,000 CU per day, and at most 1,250 CU per UTC clock hour. All AVE requests share a global queue and cache. About 3,000 CU per day is reserved for hot-list discovery, and when the hourly or daily budget runs out the tool waits for the matching window rather than lowering its standards.

Then the sentence that matters for anyone with several tools on one account: this is local consumption protection, not an AVE account balance or a plan commitment, and usage from other software on the same account, along with history from before the migration, is outside the local estimate.

So the budget is a self-imposed brake, not a measurement. A user who also runs the vendor's own tooling will not see that usage reflected here, and the README says so before the numbers rather than after.

The rollover rules are specific enough to trip over. Only the daily counter changes day at 08:00 Beijing time, while the hourly counter refreshes on the hour, and the cumulative budget does not reset automatically. Once the total is exhausted you must reconcile the account quota yourself and adjust manually, because the tool will not buy anything.

## The rate ladder is 5, then 8, then 15 minutes, with a 24 hour probe lockout

The handling of HTTP 429 is described in more detail than anything else in the README, and it reads like a state machine.

On a 429 the global hot-list interval backs off to eight minutes. If limiting continues, it slows to fifteen minutes where necessary, and it obeys a longer Retry-After when the server sends one. Only after a stable recovery does it cautiously probe the five-minute tier again. If that probe receives another 429 it returns to eight minutes immediately and does not probe five minutes again for the next twenty-four hours, while continuing to poll at the current safe interval.

That twenty-four hour rule is the part worth copying. Without it, a probe that succeeds on a single lucky response resets the ladder, and a service that has told you to slow down gets asked to speed up once a day for no reason other than optimism.

During recovery the probe is deliberately cheap. Only a single-page hot list is used, with no extra paging, no per-coin supplementation, no deep review and no historical sampling. Backoff state is kept in the ledger and survives a restart, while a definite quota exhaustion is surfaced separately as a quota problem rather than as a rate limit.

The diagnostics are scoped the same way. The connection diagnostic shows only the interface category, the HTTP status and the reason category, and does not store raw error bodies or the key. Version 0.1.12's changelog is largely about this area: connection tests no longer queue for minutes and get misreported as network failures, and waiting for the request channel is no longer presented as an invalid key.

## Four numeric initial filters, and everything unknown stays unknown

The initial screening pass is four thresholds, all numeric, all stated.

A record is excluded if known liquidity is below 3,000 dollars, if DEV holdings exceed one percent, if either buy or sell tax exceeds five percent or the two differ by more than two percentage points, or if there is an explicit zero-trade reading in the last five minutes. Anything else stays in, and anything unknown is not treated as confirmed safe.

Two clarifications are attached and both matter. Eight thousand dollars is described as a stricter deep-review liquidity reference line, and the README is explicit that it will not be passed off as the initial threshold. And a sold label cannot override DEV's actual holdings figure, and a missing holdings value cannot be treated as zero.

The card label is the point of the whole section. In free mode the tool has not completed a per-coin contract security audit, so cards are marked as a first pass and unverified, and the README states plainly that this cannot guarantee every honeypot or scam token is excluded.

The same honesty runs through the upstream data section. When the corresponding upstream data is available the tool composites contract permissions, liquidity pool state, tax and honeypot risk, holding structure, ordinary wallet proxy samples, smart money, and five-minute market and price behaviour. Where a field is not obtained it is marked unknown rather than passed. The GoPlus and DexScreener modules can add contract risk, market cap, liquidity and website cross-verification during deep review, and the open-source edition has automatic per-coin deep review disabled by default.

## A 35 percent candle body and a 60 percent retracement

Beyond the initial thresholds there is a pattern filter, and its design constraint is stated first: it reuses the roughly twenty minutes of one-minute candles already held, and adds no per-coin API request.

Among valid closed-trade samples, a record is excluded when a single-minute candle body rises at least thirty-five percent and then at least three closes hold within a fifteen percent narrow platform, or when an earlier closing high is followed by two consecutive closes retracing at least sixty percent.

What happens when the data is bad is the more interesting half. All-zero trades, time gaps, significant cross-minute price discontinuities, duplicate conflicts and expired data are marked as pending verification rather than asserted to be scams. The last five minutes of trade and drawdown checks are still retained separately.

Confirmed pattern exclusions are stored per chain and contract address in the local `state/radar.json` under a `riskExclusions` key, and are not cancelled by later sideways movement, switching chains, a restart, or a candidate list expiring.

The limits are stated just as precisely. Only windows actually obtained are checked, so it cannot trace back before the first scan, outside the window, or to second-level moves. It does not guarantee blocking every scam. And when there are no candidates the thresholds are not relaxed to fill the list, which means an empty screen is a possible and intended outcome. Existing candidates must re-pass the new rules before they can be announced.

## The Windows process guard ships without having been tested on Windows

One disclosure in the README deserves to be read on its own.

The desktop install launcher includes a local process guard that recovers automatically from a crash. It waits up to ninety seconds for the local service to start, retries on a brief connection reset, and stops if another program is holding the port. AVE rate limiting or a dropped network does not trigger repeated restarts. Then: the Windows portable launcher shares this guard, and this has not been verified on real Windows hardware.

That sentence sits inside a feature description rather than in a limitations section, which is unusual and worth crediting. A crash-recovery guard is exactly the kind of code that behaves differently on a real machine than on a developer's, and shipping it while saying so lets a user decide.

The rest of the runtime picture is concrete. A computer that is powered off or asleep cannot scan, and this version does not install a system auto-start entry. Running the system Node's `npm start` is a foreground debug mode with no guard at all.

The Windows install path also has its own honest note. If Windows shows the protected-PC message, you confirm the file came from this repository and then choose More info and Run anyway. The portable package already includes its runtime, so Node.js does not need to be installed separately. The service listens on `http://127.0.0.1:3791/` if the browser does not open on its own, and the black console window must stay open because closing it stops the radar.

On macOS the launcher is a `.command` file that downloads a project-specific Node.js build from nodejs.org and verifies its SHA-256 when no compatible environment is found.

## One page per round, one chain every five minutes, and tabs cost nothing

The polling arithmetic is the other thing worth understanding, because it explains what the tool does and does not see.

In production, globally, at most one chain's hot-list request is issued every five minutes. With one, two or three chains enabled, each chain turns roughly every five, ten or fifteen minutes. Each round reads a single page of the hot list, capped at a hundred items, alternating between the front page and later pages so the popular front page cannot permanently crowd out the rest of the list. A bad tail page sends the next round back to the front rather than retrying it in the same round.

The README is explicit about the consequence: this is a hot-list sample, not full-chain coverage of new tokens. It is also not a WebSocket push or a front-running tool.

Staleness is handled by refusing to lie. The page shows separately the earliest attempt time for the current chain and the true quote time. A forecast is not a guarantee of success, and under rate limiting it keeps being deferred rather than rewriting an old quote as a new one. Opening more tabs does not increase AVE requests.

Chain selection has its own small state machine. Clicking an enabled chain only switches the view. Clicking a disabled one changes the polling configuration: it is added if fewer than three are enabled, and it replaces the currently viewed chain if three are already on. The change waits for background scheduling rather than firing an immediate extra scan. The interface marks each chain's secondary data source coverage, and a chain marked as connected is not a promise that every query will succeed.

## Migrating state is an explicit script with a refusal list

Updates are manual by design, and the README says so in the first sentence of that section.

The download button only opens the official GitHub latest release page. The program does not download a release package, does not overwrite the current directory, and does not exit, restart or install anything. You pick the Windows x64 or macOS archive yourself and verify the SHA-256 against the matching `SHA256SUMS-<version>.txt` file.

The supported migration path is a script you run before first launch in the new directory:

```bash
node scripts/migrate-local-state.mjs --from "/旧版雷达的完整路径" --confirm-stopped
```

The Windows portable build uses its bundled `runtime\node.exe` in place of that `node`. The tool copies only an explicitly listed set: the AVE key, the quota ledger, settings and history, preserving cumulative usage as-is. It does not move old files, and does not migrate a `.env`, logs, or legacy data-source credentials.

What makes this readable is the refusal list. The migration is declined when the new directory already has state, when a running task is detected, when files are abnormal, or when the key has no corresponding ledger. It does not overwrite existing data.

And it names its own blind spot: a foreground debug process that has not been stopped may not be detected automatically, so you must close it yourself. That is why the flag is named `--confirm-stopped`.

The remaining data paths follow the same narrowness. Exported records are JSON without the key, holding per-chain audits, shadow samples, favourites, notes and current browser marks, and the README warns against publishing an export that contains personal notes. Clearing and disconnecting the API removes only this project's AVE key and stops new requests, leaving legacy data source config files alone.

## Conclusion

Use meme-radar if you want a shortlist you can look at, with the evidence for each exclusion recorded, since the value is in the recorded thresholds rather than in the ranking. Do not treat its output as a safety judgement, because the project labels its own cards unverified, states it cannot guarantee it excluded every honeypot or scam token, and offers a per-coin audit only in a flow it disables by default. Two things to check before you rely on it: whether your AVE key's real quota matches the local CU budget, since the README says those are different things, and whether a Windows host can accept a process guard that the author says has not been verified on real Windows hardware.

## FAQ

### Is meme coin risky?

The project treats that as something a scanner can narrow and never close. Its cards are labelled a first pass and unverified, unknown fields are never counted as passing, four numeric thresholds do the initial exclusion, and the README states the tool cannot guarantee every honeypot or scam token is filtered out.

### Does meme-radar ever sign transactions or place orders?

No. The README states it does not include wallet private keys, on-chain transaction signing, swap or order placement, and that the settings interface has no signing or order endpoint. Any actual trading is confirmed by the user on the AVE page.

### What does the local AVE budget in meme-radar cover?

A cumulative 1,000,000 CU, at most 30,000 CU per day and 1,250 CU per clock hour, shared across all AVE requests, with about 3,000 CU per day reserved for discovery. The README describes this as local consumption protection rather than an AVE account balance, and excludes usage from other software on the same account.

### How do I update meme-radar?

Manually. The download button only opens the GitHub latest release page, and the program does not download, overwrite or restart anything. Extract the new package into a new writable directory, verify SHA-256 against the matching SHA256SUMS file, and run scripts/migrate-local-state.mjs with --from and --confirm-stopped before first launch if you want to carry the key, ledger, settings and history across.

## Sources

- [Issues](https://github.com/nhovongoc0-max/meme-radar/issues)
- [License: AGPL-3.0](https://github.com/nhovongoc0-max/meme-radar/blob/main/LICENSE)
- [nhovongoc0-max/meme-radar on GitHub](https://github.com/nhovongoc0-max/meme-radar)
- [README](https://github.com/nhovongoc0-max/meme-radar/blob/main/README.md)
- [Releases](https://github.com/nhovongoc0-max/meme-radar/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nhovongoc0-max-meme-radar
