How the FreezeRadar risk score works

Every scan ends in one number between 0 and 100. This page explains what goes into it, what each band means in practice, and where the model stops being reliable. We publish the weights and the bands. We do not publish the exact trigger values behind individual detections, because those are trivially gamed.

Scoring model v4 · last changed 2026-09-29 · 40 finding types

1. Four axes, weighted by how certain each one is

Findings are grouped into four axes. Each axis is scored on its own, then blended. The weights are not arbitrary: an axis is worth more when the evidence behind it is harder to argue with.

Sanctions / issuer blacklist risk

40%

Sanctions list matches and issuer blacklists, whether the wallet itself is listed or the money reached it from something listed.

Why: An official sanctions match and an on-chain issuer blacklist are distinct facts. This axis covers both; an issuer blacklist is not a legal sanctions designation.

Counterparty risk

30%

Who the wallet actually trades with: mixers, darknet markets, scam and phishing addresses, high-risk exchanges, stolen-funds clusters.

Why: Counterparties are identified, not merely inferred, but the identification depends on labelling that is never complete. Strong evidence, one step below certainty.

Behavioral risk

20%

Transaction patterns that fit known laundering shapes: peel chains, fan-in/fan-out, structuring, rapid pass-through, dormancy breaks.

Why: Patterns are suggestive, never conclusive. Plenty of legitimate wallets look busy and odd, so behaviour alone should not decide the verdict.

Freezeability risk

10%

How much of the balance sits in assets an issuer can freeze or burn, and whether this wallet has been frozen before.

Why: This is exposure, not wrongdoing. Holding USDT is normal; it only matters as context for what a freeze would cost.

2. What each score band means

These are the exact cut-offs the product uses. A score of 75 or above is CRITICAL; 50 to 74 is HIGH. So a wallet scoring 75 sits at the bottom of the critical band: a direct, evidence-backed hit rather than an accumulation of weak signals.

LOW Risk0–24

Nothing found that argues against dealing with this wallet.

What to do: Proceed. Keep the report for your file.

MEDIUM Risk25–49

Something is there, usually indirect, old, or a small share of the flow.

What to do: Proceed with a note. For a large amount, ask where the funds came from.

HIGH Risk50–74

Real, source-backed exposure close to the wallet, such as a flagged counterparty or attributed high-risk provenance.

What to do: Do not accept the funds without an explanation you can document. Escalate internally.

CRITICAL Risk75–100

A direct hit: a sanctions match, an active issuer blacklist, or a balance the issuer already destroyed.

What to do: Do not transact. Treat as reportable under your own policy.

3. The confidence score is a separate number

The risk score says how worried we are. The confidence score says how sure we are. A risk of 80 with confidence 45 is a different situation from a risk of 80 with confidence 90, and collapsing them into one number hides that.

Confidence measures the quality and coverage of the assessment, not the number of transactions. Behavioural or contextual-only results are capped at 45, source-backed indirect exposure at 70, and direct official or on-chain evidence at 90. A truncated activity window, limited tracing, or missing activity data lowers those ceilings.

4. Six adjustments applied to every finding

No finding is worth a flat number. The same detection is weighted up or down by the circumstances around it.

Flow direction

Receiving from a flagged address is not the same as paying one. A wallet cannot refuse an incoming transfer, so inbound-only exposure counts for less than money the wallet chose to send.

Hop distance

Direct exposure matters more than indirect exposure. A two-hop finding requires two same-asset transfers in a time-ordered path; sharing a counterparty alone does not raise the score.

Amount share

One percent of the volume is not eighty percent. A tainted trickle and a tainted majority do not score the same.

Recency

Exposure from last week weighs more than exposure from two years ago. Old contact decays; it does not disappear.

Attribution confidence

A counterparty identified by a named source counts for more than one inferred from on-chain behaviour alone.

Severity

Each finding carries its own severity, and a critical finding is not diluted down to the level of an informational one.

5. Why we do not add the findings up

Adding scores together means ten weak signals can out-score one decisive one, and any wallet with enough history eventually reaches 100. Instead, each finding reduces the remaining probability that the wallet is clean: the way independent pieces of evidence actually combine.

The practical effect is that the score saturates. The first strong finding moves it a long way, the fifth weak one barely moves it at all, and a pile of minor observations never adds up to a sanctions match.

6. Guarding against false positives

A single severe, source-backed signal should not be diluted by averaging. Sanctions and attributed counterparty exposure can carry the score on their own; behavioural patterns cannot raise a wallet above LOW without valid attribution.

A wallet with at least 100 tracked transfers and 40 distinct counterparties is treated as high-throughput activity, not as a verified exchange or service identity. Its volume-dependent patterns are retained as context but do not add risk points.

7. Mapping to standard industry categories

If your policy is written against the risk categories the rest of the industry uses, this is how ours line up.

Industry categoryWhat FreezeRadar screens for it
Sanctions and OFAC SDNSanctioned
Crypto Mixers and TumblersMixer
Darknet MarketsDarknet
Stolen/Hacked FundsStolen funds, Exploit
Ransomware WalletsRansomware
Fraud and Scam AddressesScam, Phishing
Terrorism FinancingTerrorism financing
Gambling PlatformsGambling
High-Risk ExchangesHigh risk exchange
Tether Blacklisted AddressesDirect issuer blacklist match

8. What this score cannot tell you

  • • The analysis window is finite. Activity outside that window is left unscored.
  • • Address labelling is incomplete everywhere in this industry, ours included. An unlabelled counterparty is unknown, not clean.
  • • On-chain attribution is probabilistic. A wallet grouped with an entity is a best inference, not a proven identity.
  • • A high-throughput activity profile is not an exchange or entity attribution. Volume-dependent behavioural rules are not scored for that profile.
  • • Time-of-day patterns are not assessed from a truncated transfer window.
  • • A high score means exposure worth explaining, not proof of a crime. Plenty of high-scoring wallets belong to people who did nothing wrong.
  • • This page is not legal advice and does not make a regulatory determination. It is an input to your own decision.

Model version and changes

New scans run on model v4. Existing reports keep the scoring version they were created with; a new scan can return a different number. Every change that can move a new score is listed here.

2026-09-29 · v4Two-hop exposure requires a same-asset, time-ordered transfer path through the direct counterparty. Shared graph neighbors do not raise the score; valid paths use their observed direction, share and recency.
2026-09-09 · v3High-throughput activity is treated as an operational profile, not an entity attribution. Behavioural patterns no longer raise a wallet above LOW without source-backed risk evidence, and confidence now reflects evidence quality and coverage rather than transaction volume.
2026-08-26 · v2Provenance tracing reaches deeper into a wallet funding history, so upstream exposure that was previously out of range can now surface.
2026-08-11 · v2A wallet that was frozen and has since been released no longer keeps a critical score for a freeze that is over.
2026-08-06 · v2Behavioural heuristics alone can no longer push a busy but clean wallet into the critical band; the softer axes must clear a real severity bar first.
2026-06-12 · v2Direction, recency, amount share, and attribution confidence became continuous adjustments instead of fixed steps, and inbound-only exposure was dampened.
2026-04-04 · v1First public scoring model.

Related

The crime pattern catalog lists every finding type behind these axes, the sanctions database shows the lists we screen against, and you can run a scan to see the model applied to a wallet.