How the FreezeRadar risk score works

Every scan ends in one number between 0 and 100. This page explains what goes into it, what each band means in practice, and where the model stops being reliable. We publish the weights and the bands; we do not publish the exact trigger values behind individual detections, because those are trivially gamed.

Scoring model v2 · last changed 2026-08-26 · 40 finding types

1. Four axes, weighted by how certain each one is

Findings are grouped into four axes. Each axis is scored on its own, then blended. The weights are not arbitrary: an axis is worth more when the evidence behind it is harder to argue with.

Sanctions risk

40%

Sanctions list matches and issuer blacklists, whether the wallet itself is listed or the money reached it from something listed.

Why: A sanctions match is a fact on a published list, not an interpretation. It carries the most weight because it is the least arguable.

Counterparty risk

30%

Who the wallet actually trades with: mixers, darknet markets, scam and phishing addresses, high-risk exchanges, stolen-funds clusters.

Why: Counterparties are identified, not merely inferred, but the identification depends on labelling that is never complete. Strong evidence, one step below certainty.

Behavioral risk

20%

Transaction patterns that fit known laundering shapes: peel chains, fan-in/fan-out, structuring, rapid pass-through, dormancy breaks.

Why: Patterns are suggestive, never conclusive. Plenty of legitimate wallets look busy and odd, so behaviour alone should not decide the verdict.

Freezeability risk

10%

How much of the balance sits in assets an issuer can freeze or burn, and whether this wallet has been frozen before.

Why: This is exposure, not wrongdoing. Holding USDT is normal; it only matters as context for what a freeze would cost.

2. What each score band means

These are the exact cut-offs the product uses. A score of 75 or above is CRITICAL; 50 to 74 is HIGH. So a wallet scoring 75 sits at the bottom of the critical band — a direct, evidence-backed hit rather than an accumulation of weak signals.

LOW Risk024

Nothing found that argues against dealing with this wallet.

What to do: Proceed. Keep the report for your file.

MEDIUM Risk2549

Something is there, usually indirect, old, or a small share of the flow.

What to do: Proceed with a note. For a large amount, ask where the funds came from.

HIGH Risk5074

Real exposure close to the wallet — a flagged counterparty or a laundering pattern with evidence behind it.

What to do: Do not accept the funds without an explanation you can document. Escalate internally.

CRITICAL Risk75100

A direct hit: a sanctions match, an active issuer blacklist, or a balance the issuer already destroyed.

What to do: Do not transact. Treat as reportable under your own policy.

3. The confidence score is a separate number

The risk score says how worried we are. The confidence score says how sure we are. A risk of 80 with confidence 45 is a different situation from a risk of 80 with confidence 90, and collapsing them into one number hides that.

Confidence goes down when there are few findings, when the evidence behind them is thin, when the exposure is indirect rather than direct, and when a counterparty could not be attributed or the activity coverage for the wallet is uncertain. Gaps in the data lower confidence; they never raise risk on their own.

4. Six adjustments applied to every finding

No finding is worth a flat number. The same detection is weighted up or down by the circumstances around it.

Flow direction

Receiving from a flagged address is not the same as paying one. A wallet cannot refuse an incoming transfer, so inbound-only exposure counts for less than money the wallet chose to send.

Hop distance

Money that touched a flagged address directly matters more than money that passed through several wallets first. Weight falls with every hop.

Amount share

One percent of the volume is not eighty percent. A tainted trickle and a tainted majority do not score the same.

Recency

Exposure from last week weighs more than exposure from two years ago. Old contact decays; it does not disappear.

Attribution confidence

A counterparty identified by a named source counts for more than one inferred from on-chain behaviour alone.

Severity

Each finding carries its own severity, and a critical finding is not diluted down to the level of an informational one.

5. Why we do not add the findings up

Adding scores together means ten weak signals can out-score one decisive one, and any wallet with enough history eventually reaches 100. Instead, each finding reduces the remaining probability that the wallet is clean — the way independent pieces of evidence actually combine.

The practical effect is that the score saturates. The first strong finding moves it a long way, the fifth weak one barely moves it at all, and a pile of minor observations never adds up to a sanctions match.

6. Guarding against false positives

A single severe signal should not be diluted by averaging, so each axis can pull the overall score up on its own. But that floor is proportional to how certain the axis is: sanctions can carry the score by itself, while the softer axes have to clear a real severity bar first.

Without that, a busy exchange-adjacent wallet landed in the critical band on transaction-volume heuristics alone. Precision matters as much as sensitivity here: a score everyone has to second-guess is worth nothing.

7. Mapping to standard industry categories

If your policy is written against the risk categories the rest of the industry uses, this is how ours line up.

Industry categoryWhat FreezeRadar screens for it
Sanctions and OFAC SDNSanctioned
Crypto Mixers and TumblersMixer
Darknet MarketsDarknet
Stolen/Hacked FundsStolen funds, Exploit
Ransomware WalletsRansomware
Fraud and Scam AddressesScam, Phishing
Terrorism FinancingTerrorism financing
Gambling PlatformsGambling
High-Risk ExchangesHigh risk exchange
Tether Blacklisted AddressesDirect issuer blacklist match

8. What this score cannot tell you

  • The analysis window is finite. Activity outside it is not scored.
  • Address labelling is incomplete everywhere in this industry, ours included. An unlabelled counterparty is unknown, not clean.
  • On-chain attribution is probabilistic. A wallet grouped with an entity is a best inference, not a proven identity.
  • A high score means exposure worth explaining, not proof of a crime. Plenty of high-scoring wallets belong to people who did nothing wrong.
  • This is not legal advice and it is not a regulatory determination. It is an input to your own decision.

Model version and changes

New scans run on model v2. Scores are not frozen: when the model changes, a rescan of the same wallet can return a different number. Every change that can move an existing score is listed here.

2026-08-26 · v2Provenance tracing reaches deeper into a wallet funding history, so upstream exposure that was previously out of range can now surface.
2026-08-11 · v2A wallet that was frozen and has since been released no longer keeps a critical score for a freeze that is over.
2026-08-06 · v2Behavioural heuristics alone can no longer push a busy but clean wallet into the critical band; the softer axes must clear a real severity bar first.
2026-06-12 · v2Direction, recency, amount share, and attribution confidence became continuous adjustments instead of fixed steps, and inbound-only exposure was dampened.
2026-04-04 · v1First public scoring model.

Related

The crime pattern catalog lists every finding type behind these axes, the sanctions database shows the lists we screen against, and you can run a scan to see the model applied to a wallet.