| Direct and indirect exposure to darknet markets, mixers, ransomware and reported theft |
Chain data
ChainTrace hop tracing · ScoreGuard exposure
|
Exposure is traced out over multiple hops with the share decayed by distance, so a counterparty that is clean at hop 1 and dirty at hop 3 still reaches the report. |
| Mixing and tumbling services used to obscure flow between known wallets and darknet marketplaces |
Chain data
Category exposure
|
Mixer contact is a named category with its own value share, not a footnote. |
| Transfers to high-risk wallet addresses or service clusters |
Chain data
Attribution and cluster labels
|
Counterparties resolve to a labelled entity where one is documented. Where none is, they stay unknown rather than being guessed from the hash. |
| Dealings with designated individuals, entities and their addresses |
Chain data
OFAC SDN address designation
|
Screened as an address designation, not a name match, so it does not depend on the customer having given a matching name. |
| Accumulation from many unrelated wallets in small amounts, then a single transfer out or full exchange to fiat |
Chain data
Graph and flow analysis
|
A fan-in followed by a single exit is a shape, and the graph is where a shape is visible. |
| Structuring under reporting thresholds, round amounts, round trips and transactions with no commercial basis |
Chain data
Named behavioural scenarios
|
Each scenario is named in the report, so a reviewer can see which one fired and why. |
| Multiple high-value transfers in short succession, or a staggered pattern followed by long silence |
Chain data
Velocity and pass-through scenarios
|
Includes the rapid in-then-out signature of layering, timed across the transfer set. |
| Dormant accounts that become active after a full year |
Chain data
Dormancy detection
|
Measured from the observed transfer history rather than from an account-opening date. |
| Rising or sustained activity with higher-risk geographies and entities |
Chain data
Jurisdiction exposure
|
Exposure is attributed by jurisdiction where the label book records one. |
| Sending to or receiving from a service with weak or non-existent CDD |
Chain data
ScoreGuard KYV
|
VASP due diligence covers licensing, jurisdiction and the provider's own cluster behaviour. |
| Moving value across chains, or into an exchange and straight out into a privacy coin |
Chain, in part
Out-of-sight legs
|
Hosted venues (exchanges, custodians, merchants) and mixers are marked out of sight: the deposit is attributed, but onward hops — including a privacy-coin withdrawal inside the venue — are not in this score. Bridge far-sides stay modelled. An unindexed or unavailable chain is named as opaque, not scored empty-and-clean. Permissioned ledgers (GS DAP, Citi Token Services) are disclosed even when no address matched. The internal hop itself is still not observable. |
| Funds suspected stolen, or received from addresses linked to holders of stolen funds |
Chain, in part
Label book categories
|
Answerable for published incidents in the cited overlay (FBI/IC3 Bybit theft cluster, Chainalysis Euler and Wormhole exploiter addresses). An unreported hack is still not in any label set, including this one. |
| Activity that deviates from the customer's normal transactional behaviour |
Chain, in part
Stated customer profile
|
When the institution supplies a stated customer profile (expected volume, transfer size, counterparties, jurisdictions, direction), deviation from that profile is scored. Without one, this flag cannot fire — the wallet's own history is still in the report. Opening-deposit versus declared income is a separate stated-identity indicator. |
| A large opening deposit inconsistent with the customer's stated profile, or a new user withdrawing the full balance |
Chain, in part
Stated identity (account age, income)
|
When the institution supplies account opening date, a new-customer flag, or declared income, a large first inbound or a new-user full withdrawal is scored. Without those CDD facts the flag cannot fire — first-seen on chain is not account age. PEP and source-of-wealth remain an identity stack. An institution can attest PEP or SoW status on the report; that is disclosure, not a name-list or document screen. |
| Repeated transfers to one account by several people, or from a single IP address |
Chain, in part
Many-to-one wallet shape
|
Many distinct inbound wallets in a short window are named as a many-to-one shape. That they are several people, or that they share an IP, remains an identity check. |
| Politically exposed persons, their family members and close associates |
Identity stack
PEP screening vendor
|
A name-list obligation. Nothing on chain marks an address as belonging to a PEP. An institution can attest a PEP or RCA status on the report; that is recorded as disclosure, not a screen. |
| Source of funds and source of wealth, verified against documentary evidence |
Identity stack
Enhanced due diligence file
|
Where funds came from on chain is traceable. Whether the documents explaining them are truthful is not a chain question. An institution can attest that SoW documents are on file; that is recorded as disclosure, not a review of those documents. |