chainscore.net ScoreGuard
Re-run now VASP directory
87of 100

Know Your VASP report Low risk

PayStream Processor
Merchant · incorporated in United Kingdom · founded 2018 · attribution: synthetic
Desk review72
On-chain review100
Cluster volume 0

PayStream Processor is a merchant incorporated in United Kingdom, assessed at 87/100 (low risk) from a desk review of 72/100 and an on-chain review of 100/100. Licence status is registered with claimed evidence (United Kingdom payments registry), MiCA transitional, KYC rigour standard, Travel Rule partial. The largest single deduction is 6 points for travel rule: Partial Travel Rule capability; some corridors unsupported.. 1 clustered wallet(s) moved $0 in the reviewed window, of which $0 (0.00%) touched categories of severity 5 or above and 0.00% touched severity 8 or above. No confirmed Travel Rule capability, so originator and beneficiary data cannot be exchanged for VASP-to-VASP transfers.

Combined score weights the desk review at 45% and the on-chain review at 55%, because chain evidence is observed while the regulatory file is asserted.

What this assessment rests on

45% of the score is a desk review of the regulatory file. Licence status, controls and monitoring maturity are asserted in the directory record rather than observed on chain, and no attribution measurement grades them. This directory record is a demonstration entry, so the paperwork it describes belongs to no real business.

55% of the score is the on-chain review of 1 of 2 clustered address(es), which moved no counterparty value in the reviewed window. That half therefore reflects an absence of observed exposure, not traffic that was examined and found clean.

The attribution figure covers the on-chain review only. There is no single coverage percentage for this score, because the desk review half is not measured over counterparty value.

Regulatory file

Legal namePayStream Processor
Trading namePayStream Processor
Licence statusregistered (claimed evidence)
RegulatorUnited Kingdom payments registry
Licence referenceGB-A9806817
MiCA statustransitional
JurisdictionUnited Kingdom (GB), risk 1/10
Operational hubsGB, KP, SC

Controls

KYC rigourstandard · Identity verification above a low withdrawal threshold.
Withdrawal KYC threshold $1,000
Travel Rulepartial · Partial Travel Rule capability; some corridors unsupported.
Transaction monitoringdeveloping
Sanctions screening in place
Source of funds checks performed
Custody modelcustodial

Desk review deductions

28.0 points deducted from 100.

Travel Rule -6.0 pts
Partial Travel Rule capability; some corridors unsupported.
Licence evidence -5.0 pts
licence evidence is claimed
KYC rigour -5.0 pts
Identity verification above a low withdrawal threshold.
Transaction monitoring -5.0 pts
monitoring programme developing
Licence status -4.0 pts
registered — United Kingdom payments registry
MiCA status -3.0 pts
MiCA transitional

On-chain review of the provider's clusters

Clustered addresses 2
Wallets screened 1
Inbound 0
Outbound 0
Illicit share 0.0%

Risk composition of managed wallets

No on-chain activity was returned for the clustered wallets.

Screened wallets

AddressChainScoreRisk InboundOutboundTransfersSource
0xecd6ff508e9b0cfae1863ba8f1d3d3c703ec634d Ethereum 100 Low 0 0 0 live:alchemy
bc1qlzs7hvjfv4u9k76xr8jxvt289pfhdjp5v5f0ga Bitcoin provider error (ProviderError)

Compliance and provenance

Travel Rule counterparty not ready · Partial Travel Rule capability; some corridors unsupported.
Data sourcelive:alchemy · 1 of 2 clustered address(es) screened
Directory41 VASP profiles, 2463 labelled entities

Label sources

  • Sanctions: 943 designated addresses from the US Treasury OFAC SDN list, published 08/28/2026.
  • Token contracts: 927 identified from public token lists.
  • Cited public labels: 519 addresses from 34 source(s), each with a URL.
    • Aave address book: V3 Ethereum (98 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Ethereum.json
    • FBI/IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (51 addresses) — https://www.ic3.gov/PSA/2025/PSA250226
    • Aave address book: AaveV3Polygon (45 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Polygon.json
    • Aave address book: V2 Ethereum (40 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Ethereum.json
    • Aave address book: AaveV3Arbitrum (39 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Arbitrum.json
    • Aave address book: AaveV3Optimism (31 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Optimism.json
    • Aave address book: AaveV3Base (25 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Base.json
    • Tornado Cash smart contracts (24 addresses) — https://docs.tornado.cash/general/tornado-cash-smart-contracts
    • Bybit: wallet addresses ownership explained (21 addresses) — https://www.bybit.com/en/help-center/article/Bybit-Wallet-Addresses-Ownership-Explained
    • Circle CCTP EVM contract addresses (20 addresses) — https://developers.circle.com/cctp/evm-smart-contracts
    • Aave address book: AaveV3BNB (18 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3BNB.json
    • Bitfinex: published public wallets (16 addresses) — https://github.com/bitfinexcom/pub/blob/main/wallets.txt
    • Aave address book: AaveV2Polygon (16 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Polygon.json
    • Aave address book: AaveV3EthereumLido (12 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3EthereumLido.json
    • Crypto.com: Transparency First cold-wallet list (10 addresses) — https://crypto.com/en/company-news/transparency-first
    • Uniswap v3 Arbitrum deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/arbitrum-deployments
    • Uniswap v3 Optimism deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/optimism-deployments
    • Uniswap v3 Polygon deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/polygon-deployments
    • Lido deployed contracts (6 addresses) — https://docs.lido.fi/deployed-contracts/
    • Uniswap v3 Base deployments (6 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/base-deployments
    • Uniswap v3 Ethereum deployments (3 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/ethereum-deployments
    • Chainalysis: Euler Finance flash loan attack (2 addresses) — https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/
    • Morpho deployed contracts (2 addresses) — https://docs.morpho.org/get-started/resources/addresses
    • Compound III USDC Ethereum roots (2 addresses) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdc/roots.json
    • Aave address book: GhoEthereum (2 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/GhoEthereum.json
    • Railgun privacy system contracts (1 address) — https://docs.railgun.org/wiki/learn/helpful-links
    • Linea network contracts (1 address) — https://docs.linea.build/network/build/contracts
    • Starknet L1-L2 messaging (1 address) — https://docs.starknet.io/documentation/architecture_and_concepts/Network_Architecture/l1-l2-messaging/
    • Chainalysis: Wormhole hack February 2022 (1 address) — https://www.chainalysis.com/blog/wormhole-hack-february-2022/
    • Compound III USDS Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usds/roots.json
    • Compound III USDT Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdt/roots.json
    • Compound III WBTC Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wbtc/roots.json
    • Compound III WETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/weth/roots.json
    • Compound III WSTETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wsteth/roots.json
  • Demonstration data: excluded — 118 synthetic entities were not scored.

Screen window

  • Up to 500 transfers across 3 indexer page(s) · default 3 hops · hop-2 budget 16 · hop-3 budget 12.

Artefact integrity

  • sha256+hmac · SHA-256 80d53a5d7d764fa0405e76b01a9dacd3b93ab3a97e9fc5c272749c554a681dc3 · sealed 2026-09-13T20:52:04+00:00 · HMAC present.

Frameworks covered

Informative

Notice / Disclaimer

Limits that apply to this artefact as a whole. Sources and hashes stay in provenance; this section is how to read them.