37 crime pattern models we detect
Every finding type FreezeRadar can surface in a wallet scan, grouped by the stage of laundering it maps to. Each card links to the exact finding types behind it and shows up in your scan results when it fires.
Direct screening
Direct Sanctions Match
The scanned wallet itself appears on a sanctions or blacklist record — not a counterparty, the wallet.
On-Chain Issuer Blacklist Match
The issuer of a stablecoin has already blacklisted this exact address on-chain, independent of any sanctions list.
Issuer-Destroyed Funds
The issuer didn't just freeze the balance — it permanently burned it. This only follows a confirmed blacklist and can't be reversed.
Direct High-Risk Label Match
The wallet itself is directly labeled in curated risk data — mixer, darknet, scam, ransomware, or a similar high-risk category — without going through a sanctions list.
Previously Frozen, Now Released
The wallet was blacklisted by an issuer at some point and has since been released. It is not currently frozen.
Freezeable Asset Holding
The wallet holds or is being scanned for an asset whose issuer can unilaterally freeze or blacklist balances (e.g. USDT, USDC).
Mostly Reputable Activity
A clearance signal, not a risk pattern: outside one already-flagged factor, the analyzed activity does not show broader suspicious behavior.
No Suspicious Exposure Found
A clean-scan signal: none of the other patterns in this catalog fired for the scanned wallet.
Placement
Sanctions Adjacency
The wallet is not sanctioned directly, but the transfer graph connects it to a sanctioned entity within a small number of hops.
High-Risk Exchange Adjacency
The transfer graph connects the wallet to a high-risk exchange cluster — typically one with weak or absent KYC.
Darknet Market Exposure
The transfer graph connects this wallet to a darknet-market-linked counterparty.
Scam-Linked Exposure
The transfer graph connects this wallet to a counterparty labeled as scam-linked.
Ransomware-Linked Exposure
The transfer graph connects this wallet to a ransomware-linked counterparty.
Exploit-Linked Exposure
The transfer graph connects this wallet to funds linked to a known smart-contract exploit.
Phishing-Linked Exposure
The transfer graph connects this wallet to a counterparty labeled as phishing-linked.
Stolen-Funds Cluster Exposure
The transfer graph connects this wallet to a cluster of addresses associated with stolen funds.
Suspicious Service Exposure
The transfer graph connects this wallet to a service address with a general suspicious-activity label that does not fit a narrower category.
High-Risk Funding Source
The wallet's earliest observed funding came from a wallet labeled sanctioned, mixer, darknet, or another high-risk category.
Layering
Mixer Interaction
A direct, first-hop transfer to or from a wallet labeled as a mixing/tumbling service.
Cross-Chain Bridge Exposure
A direct, first-hop transfer to or from a cross-chain bridge protocol.
Peel Chain
A sequence of outbound transfers where each transfer sends progressively less than the one before, repeated several times in a row — a classic layering pattern, though benign treasury or payroll behavior can look similar.
Fan-In / Fan-Out
The wallet aggregates meaningful value from many distinct counterparties, distributes it to many distinct counterparties, or both, within the tracked window.
Circular Flow
A meaningful share of the tracked counterparties both sent funds to and received funds from this wallet.
Rapid Pass-Through
A meaningful share of an inbound transfer leaves the wallet again shortly after arriving.
Transaction Velocity Spike
The wallet processes an unusually high number of transactions per hour over the analyzed window.
Counterparty Concentration
A large majority of inbound or outbound volume flows to or from a single counterparty rather than being spread across many.
Structuring / Smurfing
Several small outbound transfers to distinct addresses, clustered in a short window, each individually below a materiality floor.
Integration
Behavioral signal
New or Young Wallet
The wallet was first funded recently and has little transaction history to analyze.
Smart Contract Wallet
The scanned address is a smart contract, not a standard externally-owned wallet.
Dormant Wallet Reactivation
The wallet resumed activity after a long stretch with no tracked transfers.
Dusting / Address Poisoning
The wallet has received several tiny transfers from distinct counterparties — a pattern used to pollute address history or impersonate a trusted address in a future transfer.
Round-Amount Pattern
A high share of the tracked transfers use suspiciously round amounts rather than the irregular amounts organic usage tends to produce.
Time-of-Day Anomaly
Tracked activity is heavily concentrated within a narrow window of the day rather than spread out the way organic human activity usually is.
Balance provenance
Deep Balance: Official Sanctions Provenance
Part of the wallet's current freezeable balance traces back, through the funding history, to an officially sanctioned upstream root — even though the wallet never transacted with that root directly.
Deep Balance: Curated Risk Provenance
Part of the wallet's current freezeable balance traces back to a curated high-risk upstream root — not an official sanctions designation, but a source flagged in curated risk data.