How the FreezeRadar risk score works
Every scan ends in one number between 0 and 100. This page explains what goes into it, what each band means in practice, and where the model stops being reliable. We publish the weights and the bands. We do not publish the exact trigger values behind individual detections, because those are trivially gamed.
Scoring model v4 · last changed 2026-09-29 · 40 finding types
1. Four axes, weighted by how certain each one is
Findings are grouped into four axes. Each axis is scored on its own, then blended. The weights are not arbitrary: an axis is worth more when the evidence behind it is harder to argue with.
Sanctions / issuer blacklist risk
40%Sanctions list matches and issuer blacklists, whether the wallet itself is listed or the money reached it from something listed.
Why: An official sanctions match and an on-chain issuer blacklist are distinct facts. This axis covers both; an issuer blacklist is not a legal sanctions designation.
Counterparty risk
30%Who the wallet actually trades with: mixers, darknet markets, scam and phishing addresses, high-risk exchanges, stolen-funds clusters.
Why: Counterparties are identified, not merely inferred, but the identification depends on labelling that is never complete. Strong evidence, one step below certainty.
Behavioral risk
20%Transaction patterns that fit known laundering shapes: peel chains, fan-in/fan-out, structuring, rapid pass-through, dormancy breaks.
Why: Patterns are suggestive, never conclusive. Plenty of legitimate wallets look busy and odd, so behaviour alone should not decide the verdict.
Freezeability risk
10%How much of the balance sits in assets an issuer can freeze or burn, and whether this wallet has been frozen before.
Why: This is exposure, not wrongdoing. Holding USDT is normal; it only matters as context for what a freeze would cost.
2. What each score band means
These are the exact cut-offs the product uses. A score of 75 or above is CRITICAL; 50 to 74 is HIGH. So a wallet scoring 75 sits at the bottom of the critical band: a direct, evidence-backed hit rather than an accumulation of weak signals.
Nothing found that argues against dealing with this wallet.
What to do: Proceed. Keep the report for your file.
Something is there, usually indirect, old, or a small share of the flow.
What to do: Proceed with a note. For a large amount, ask where the funds came from.
Real, source-backed exposure close to the wallet, such as a flagged counterparty or attributed high-risk provenance.
What to do: Do not accept the funds without an explanation you can document. Escalate internally.
A direct hit: a sanctions match, an active issuer blacklist, or a balance the issuer already destroyed.
What to do: Do not transact. Treat as reportable under your own policy.
3. The confidence score is a separate number
The risk score says how worried we are. The confidence score says how sure we are. A risk of 80 with confidence 45 is a different situation from a risk of 80 with confidence 90, and collapsing them into one number hides that.
Confidence measures the quality and coverage of the assessment, not the number of transactions. Behavioural or contextual-only results are capped at 45, source-backed indirect exposure at 70, and direct official or on-chain evidence at 90. A truncated activity window, limited tracing, or missing activity data lowers those ceilings.
4. Six adjustments applied to every finding
No finding is worth a flat number. The same detection is weighted up or down by the circumstances around it.
Flow direction
Receiving from a flagged address is not the same as paying one. A wallet cannot refuse an incoming transfer, so inbound-only exposure counts for less than money the wallet chose to send.
Hop distance
Direct exposure matters more than indirect exposure. A two-hop finding requires two same-asset transfers in a time-ordered path; sharing a counterparty alone does not raise the score.
Amount share
One percent of the volume is not eighty percent. A tainted trickle and a tainted majority do not score the same.
Recency
Exposure from last week weighs more than exposure from two years ago. Old contact decays; it does not disappear.
Attribution confidence
A counterparty identified by a named source counts for more than one inferred from on-chain behaviour alone.
Severity
Each finding carries its own severity, and a critical finding is not diluted down to the level of an informational one.
5. Why we do not add the findings up
Adding scores together means ten weak signals can out-score one decisive one, and any wallet with enough history eventually reaches 100. Instead, each finding reduces the remaining probability that the wallet is clean: the way independent pieces of evidence actually combine.
The practical effect is that the score saturates. The first strong finding moves it a long way, the fifth weak one barely moves it at all, and a pile of minor observations never adds up to a sanctions match.
6. Guarding against false positives
A single severe, source-backed signal should not be diluted by averaging. Sanctions and attributed counterparty exposure can carry the score on their own; behavioural patterns cannot raise a wallet above LOW without valid attribution.
A wallet with at least 100 tracked transfers and 40 distinct counterparties is treated as high-throughput activity, not as a verified exchange or service identity. Its volume-dependent patterns are retained as context but do not add risk points.
7. Mapping to standard industry categories
If your policy is written against the risk categories the rest of the industry uses, this is how ours line up.
| Industry category | What FreezeRadar screens for it |
|---|---|
| Sanctions and OFAC SDN | Sanctioned |
| Crypto Mixers and Tumblers | Mixer |
| Darknet Markets | Darknet |
| Stolen/Hacked Funds | Stolen funds, Exploit |
| Ransomware Wallets | Ransomware |
| Fraud and Scam Addresses | Scam, Phishing |
| Terrorism Financing | Terrorism financing |
| Gambling Platforms | Gambling |
| High-Risk Exchanges | High risk exchange |
| Tether Blacklisted Addresses | Direct issuer blacklist match |
8. What this score cannot tell you
- • The analysis window is finite. Activity outside that window is left unscored.
- • Address labelling is incomplete everywhere in this industry, ours included. An unlabelled counterparty is unknown, not clean.
- • On-chain attribution is probabilistic. A wallet grouped with an entity is a best inference, not a proven identity.
- • A high-throughput activity profile is not an exchange or entity attribution. Volume-dependent behavioural rules are not scored for that profile.
- • Time-of-day patterns are not assessed from a truncated transfer window.
- • A high score means exposure worth explaining, not proof of a crime. Plenty of high-scoring wallets belong to people who did nothing wrong.
- • This page is not legal advice and does not make a regulatory determination. It is an input to your own decision.
Model version and changes
New scans run on model v4. Existing reports keep the scoring version they were created with; a new scan can return a different number. Every change that can move a new score is listed here.
Related
The crime pattern catalog lists every finding type behind these axes, the sanctions database shows the lists we screen against, and you can run a scan to see the model applied to a wallet.