Know Your VASP report Medium risk
Optimism Gateway is a bridge incorporated in Unattributed, assessed at 79/100 (medium risk) from a desk review of 58/100 and an on-chain review of 96/100. Licence status is out of scope with none evidence (not applicable (non-custodial protocol)), MiCA out of scope, KYC rigour none, Travel Rule absent. The largest single deduction is 24 points for counterparty controls: non-custodial protocol: no customer identification, Travel Rule or monitoring programme is possible. 1 clustered wallet(s) moved $21,973,532 in the reviewed window, of which $0 (0.00%) touched categories of severity 5 or above and 0.00% touched severity 8 or above. No confirmed Travel Rule capability, so originator and beneficiary data cannot be exchanged for VASP-to-VASP transfers.
Combined score weights the desk review at 45% and the on-chain review at 55%, because chain evidence is observed while the regulatory file is asserted.
Regulatory file
| Legal name | Optimism Gateway |
|---|---|
| Trading name | Optimism Gateway |
| Licence status | out of scope (none evidence) |
| Regulator | not applicable (non-custodial protocol) |
| Licence reference | — |
| MiCA status | out of scope |
| Jurisdiction | Unattributed (--), risk 3/10 |
| Operational hubs | RU, US |
Controls
| KYC rigour | none · No identity verification identified. |
|---|---|
| Withdrawal KYC threshold | no verification |
| Travel Rule | absent · No Travel Rule capability identified. |
| Transaction monitoring | absent |
| Sanctions screening | none identified |
| Source of funds checks | not performed |
| Custody model | non custodial |
Desk review deductions
42.0 points deducted from 100.
On-chain review of the provider's clusters
Risk composition of managed wallets
Screened wallets
| Address | Chain | Score | Risk | Inbound | Outbound | Transfers | Source |
|---|---|---|---|---|---|---|---|
| 0x99C9fc46f92E8a1c0deC1b1747d010903E884bE1 | Ethereum | 96 | Low | 6,058,430 | 15,915,102 | 300 | live:alchemy |
Compliance and provenance
| Travel Rule | counterparty not ready · No Travel Rule capability identified. |
|---|---|
| Data source | live:alchemy · 1 of 1 clustered address(es) screened |
| Directory | 41 VASP profiles, 2463 labelled entities |
Label sources
- Sanctions: 943 designated addresses from the US Treasury OFAC SDN list, published 08/28/2026.
- Token contracts: 927 identified from public token lists.
-
Cited public labels:
519 addresses from
34 source(s), each with a URL.
- Aave address book: V3 Ethereum (98 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Ethereum.json
- FBI/IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (51 addresses) — https://www.ic3.gov/PSA/2025/PSA250226
- Aave address book: AaveV3Polygon (45 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Polygon.json
- Aave address book: V2 Ethereum (40 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Ethereum.json
- Aave address book: AaveV3Arbitrum (39 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Arbitrum.json
- Aave address book: AaveV3Optimism (31 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Optimism.json
- Aave address book: AaveV3Base (25 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Base.json
- Tornado Cash smart contracts (24 addresses) — https://docs.tornado.cash/general/tornado-cash-smart-contracts
- Bybit: wallet addresses ownership explained (21 addresses) — https://www.bybit.com/en/help-center/article/Bybit-Wallet-Addresses-Ownership-Explained
- Circle CCTP EVM contract addresses (20 addresses) — https://developers.circle.com/cctp/evm-smart-contracts
- Aave address book: AaveV3BNB (18 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3BNB.json
- Bitfinex: published public wallets (16 addresses) — https://github.com/bitfinexcom/pub/blob/main/wallets.txt
- Aave address book: AaveV2Polygon (16 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Polygon.json
- Aave address book: AaveV3EthereumLido (12 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3EthereumLido.json
- Crypto.com: Transparency First cold-wallet list (10 addresses) — https://crypto.com/en/company-news/transparency-first
- Uniswap v3 Arbitrum deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/arbitrum-deployments
- Uniswap v3 Optimism deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/optimism-deployments
- Uniswap v3 Polygon deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/polygon-deployments
- Lido deployed contracts (6 addresses) — https://docs.lido.fi/deployed-contracts/
- Uniswap v3 Base deployments (6 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/base-deployments
- Uniswap v3 Ethereum deployments (3 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/ethereum-deployments
- Chainalysis: Euler Finance flash loan attack (2 addresses) — https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/
- Morpho deployed contracts (2 addresses) — https://docs.morpho.org/get-started/resources/addresses
- Compound III USDC Ethereum roots (2 addresses) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdc/roots.json
- Aave address book: GhoEthereum (2 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/GhoEthereum.json
- Railgun privacy system contracts (1 address) — https://docs.railgun.org/wiki/learn/helpful-links
- Linea network contracts (1 address) — https://docs.linea.build/network/build/contracts
- Starknet L1-L2 messaging (1 address) — https://docs.starknet.io/documentation/architecture_and_concepts/Network_Architecture/l1-l2-messaging/
- Chainalysis: Wormhole hack February 2022 (1 address) — https://www.chainalysis.com/blog/wormhole-hack-february-2022/
- Compound III USDS Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usds/roots.json
- Compound III USDT Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdt/roots.json
- Compound III WBTC Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wbtc/roots.json
- Compound III WETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/weth/roots.json
- Compound III WSTETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wsteth/roots.json
- Demonstration data: excluded — 118 synthetic entities were not scored.
Screen window
- Up to 500 transfers across 3 indexer page(s) · default 3 hops · hop-2 budget 16 · hop-3 budget 12.
Artefact integrity
-
sha256+hmac · SHA-256
1694c8c16fd6d3317506c36f3587a01fd28d9b9df8230df3e1294959b5edd3ff· sealed 2026-09-13T20:52:33+00:00 · HMAC present.
Frameworks covered
- FATF Recommendation 15 / 16 — Counterparty attribution and originator/beneficiary context.
- EU MiCA (Regulation 2023/1114) — Risk assessment record for crypto-asset service providers.
- EU AMLD / Transfer of Funds Regulation — Source and destination of funds with jurisdictional exposure.
- OFAC sanctions programmes — Direct and cluster-level exposure to designated addresses.
- FinCEN SAR / STR filing — Evidence pack: indicators, counterparties and transfer sample.
Informative
Notice / Disclaimer
Limits that apply to this artefact as a whole. Sources and hashes stay in provenance; this section is how to read them.
- ScoreGuard reports are a point-in-time assessment produced from public blockchain data and a seeded label set. Unlabelled counterparties are left unknown; they are not assigned a guessed risk category. Labels marked 'synthetic' in the seed are demonstration entities and must not be used as the sole basis for a compliance decision.
- Token-contract labels name contracts, not wallet owners.
- Demonstration data was excluded — 118 synthetic entities were not scored.
- Activity beyond the stated screen window is not in the score.
- Recompute the sha256+hmac digest against the JSON export to confirm this copy matches what was stored.