Risk scale
| Range | Level | Recommended action |
|---|---|---|
| 0 | Verified | Verified legitimate entity |
| 1-19 | Minimal | No action needed |
| 20-39 | Low | Passive monitoring |
| 40-59 | Medium | Investigation recommended |
| 60-79 | High | Priority investigation |
| 80-100 | Critical | Immediate action / regulatory report |
How the score is calculated
The risk score combines three factors:Detected patterns
Detected patterns
The system analyzes the transaction graph to detect suspicious patterns like mixing, peel chains, structuring, and more. Each pattern has a weight and confidence score that contribute to the final risk score.
Address context
Address context
The system considers what type of address is being analyzed. A registered exchange with high transaction volume is treated differently than an unknown wallet with the same patterns.
Volume scaling
Volume scaling
Detection thresholds adjust based on the wallet’s transaction volume to reduce false positives for high-activity addresses.
Address categories
The score varies depending on the type of address being analyzed.| Address type | No patterns | Minor patterns | Critical patterns | Discount |
|---|---|---|---|---|
| Registered exchanges | 0 | 0-20 | 20-40 | 80% |
| Public figures | 5-10 | 30-60 | 60-100 | None |
| Verified protocols | 5-10 | 30-60 | 60-100 | None |
| Foundations / DAOs | 5-10 | 30-60 | 60-100 | None |
| Labeled addresses | 5 | 5-20 | 20-40 | None |
| Smart contracts | 5 | 15-35 | 35-65 | None |
| Unknown | 10 | 30-60 | 60-100 | None |
Only registered exchanges receive a discount (80%). Other known categories are recognized for metadata purposes but their patterns are evaluated at full weight.
Actions by risk level
| Level | Monitoring | Investigation | Report | Block |
|---|---|---|---|---|
| Minimal (0-19) | Standard | No | No | No |
| Low (20-39) | Increased | Optional | No | No |
| Medium (40-59) | Intensive | Yes | Evaluate | No |
| High (60-79) | Continuous | Urgent | Yes | Evaluate |
| Critical (80-100) | Real-time | Immediate | Required | Yes |
Suspicious activity flag
ThesuspiciousActivity field is set to true when any of the following conditions are met:
- Risk score is 70 or higher
- Any pattern with
criticalseverity is detected - Three or more patterns with
highseverity are detected
Risk analysis
See the full technical reference with pattern weights, severity levels, confidence thresholds, and detailed examples.