How the FreezeRadar risk score works
Every scan ends in one number between 0 and 100. This page explains what goes into it, what each band means in practice, and where the model stops being reliable. We publish the weights and the bands; we do not publish the exact trigger values behind individual detections, because those are trivially gamed.
Scoring model v2 · last changed 2026-08-26 · 40 finding types
1. Four axes, weighted by how certain each one is
Findings are grouped into four axes. Each axis is scored on its own, then blended. The weights are not arbitrary: an axis is worth more when the evidence behind it is harder to argue with.
Sanctions risk
40%Sanctions list matches and issuer blacklists, whether the wallet itself is listed or the money reached it from something listed.
Why: A sanctions match is a fact on a published list, not an interpretation. It carries the most weight because it is the least arguable.
Counterparty risk
30%Who the wallet actually trades with: mixers, darknet markets, scam and phishing addresses, high-risk exchanges, stolen-funds clusters.
Why: Counterparties are identified, not merely inferred, but the identification depends on labelling that is never complete. Strong evidence, one step below certainty.
Behavioral risk
20%Transaction patterns that fit known laundering shapes: peel chains, fan-in/fan-out, structuring, rapid pass-through, dormancy breaks.
Why: Patterns are suggestive, never conclusive. Plenty of legitimate wallets look busy and odd, so behaviour alone should not decide the verdict.
Freezeability risk
10%How much of the balance sits in assets an issuer can freeze or burn, and whether this wallet has been frozen before.
Why: This is exposure, not wrongdoing. Holding USDT is normal; it only matters as context for what a freeze would cost.
2. What each score band means
These are the exact cut-offs the product uses. A score of 75 or above is CRITICAL; 50 to 74 is HIGH. So a wallet scoring 75 sits at the bottom of the critical band — a direct, evidence-backed hit rather than an accumulation of weak signals.
Nothing found that argues against dealing with this wallet.
What to do: Proceed. Keep the report for your file.
Something is there, usually indirect, old, or a small share of the flow.
What to do: Proceed with a note. For a large amount, ask where the funds came from.
Real exposure close to the wallet — a flagged counterparty or a laundering pattern with evidence behind it.
What to do: Do not accept the funds without an explanation you can document. Escalate internally.
A direct hit: a sanctions match, an active issuer blacklist, or a balance the issuer already destroyed.
What to do: Do not transact. Treat as reportable under your own policy.
3. The confidence score is a separate number
The risk score says how worried we are. The confidence score says how sure we are. A risk of 80 with confidence 45 is a different situation from a risk of 80 with confidence 90, and collapsing them into one number hides that.
Confidence goes down when there are few findings, when the evidence behind them is thin, when the exposure is indirect rather than direct, and when a counterparty could not be attributed or the activity coverage for the wallet is uncertain. Gaps in the data lower confidence; they never raise risk on their own.
4. Six adjustments applied to every finding
No finding is worth a flat number. The same detection is weighted up or down by the circumstances around it.
Flow direction
Receiving from a flagged address is not the same as paying one. A wallet cannot refuse an incoming transfer, so inbound-only exposure counts for less than money the wallet chose to send.
Hop distance
Money that touched a flagged address directly matters more than money that passed through several wallets first. Weight falls with every hop.
Amount share
One percent of the volume is not eighty percent. A tainted trickle and a tainted majority do not score the same.
Recency
Exposure from last week weighs more than exposure from two years ago. Old contact decays; it does not disappear.
Attribution confidence
A counterparty identified by a named source counts for more than one inferred from on-chain behaviour alone.
Severity
Each finding carries its own severity, and a critical finding is not diluted down to the level of an informational one.
5. Why we do not add the findings up
Adding scores together means ten weak signals can out-score one decisive one, and any wallet with enough history eventually reaches 100. Instead, each finding reduces the remaining probability that the wallet is clean — the way independent pieces of evidence actually combine.
The practical effect is that the score saturates. The first strong finding moves it a long way, the fifth weak one barely moves it at all, and a pile of minor observations never adds up to a sanctions match.
6. Guarding against false positives
A single severe signal should not be diluted by averaging, so each axis can pull the overall score up on its own. But that floor is proportional to how certain the axis is: sanctions can carry the score by itself, while the softer axes have to clear a real severity bar first.
Without that, a busy exchange-adjacent wallet landed in the critical band on transaction-volume heuristics alone. Precision matters as much as sensitivity here: a score everyone has to second-guess is worth nothing.
7. Mapping to standard industry categories
If your policy is written against the risk categories the rest of the industry uses, this is how ours line up.
| Industry category | What FreezeRadar screens for it |
|---|---|
| Sanctions and OFAC SDN | Sanctioned |
| Crypto Mixers and Tumblers | Mixer |
| Darknet Markets | Darknet |
| Stolen/Hacked Funds | Stolen funds, Exploit |
| Ransomware Wallets | Ransomware |
| Fraud and Scam Addresses | Scam, Phishing |
| Terrorism Financing | Terrorism financing |
| Gambling Platforms | Gambling |
| High-Risk Exchanges | High risk exchange |
| Tether Blacklisted Addresses | Direct issuer blacklist match |
8. What this score cannot tell you
- — The analysis window is finite. Activity outside it is not scored.
- — Address labelling is incomplete everywhere in this industry, ours included. An unlabelled counterparty is unknown, not clean.
- — On-chain attribution is probabilistic. A wallet grouped with an entity is a best inference, not a proven identity.
- — A high score means exposure worth explaining, not proof of a crime. Plenty of high-scoring wallets belong to people who did nothing wrong.
- — This is not legal advice and it is not a regulatory determination. It is an input to your own decision.
Model version and changes
New scans run on model v2. Scores are not frozen: when the model changes, a rescan of the same wallet can return a different number. Every change that can move an existing score is listed here.
Related
The crime pattern catalog lists every finding type behind these axes, the sanctions database shows the lists we screen against, and you can run a scan to see the model applied to a wallet.