chainscore.net ScoreGuard
Re-run now VASP directory
100of 100

Know Your VASP report Low risk

Rheinland Kustodie
Custodian · incorporated in Germany · founded 2020 · attribution: synthetic
Desk review100
On-chain review100
Cluster volume 0

Rheinland Kustodie is a custodian incorporated in Germany, assessed at 100/100 (low risk) from a desk review of 100/100 and an on-chain review of 100/100. Licence status is licensed with verified evidence (Germany prudential regulator), MiCA authorised, KYC rigour strict, Travel Rule ready. 1 clustered wallet(s) moved $0 in the reviewed window, of which $0 (0.00%) touched categories of severity 5 or above and 0.00% touched severity 8 or above. Attribution covers too little of the traced value to treat this as a clear result. Review required; a low-risk score here means little was identified, not that little is there. Original: Licensed, supervised and Travel Rule capable; standard measures apply.

Combined score weights the desk review at 45% and the on-chain review at 55%, because chain evidence is observed while the regulatory file is asserted.

What this assessment rests on

45% of the score is a desk review of the regulatory file. Licence status, controls and monitoring maturity are asserted in the directory record rather than observed on chain, and no attribution measurement grades them. This directory record is a demonstration entry, so the paperwork it describes belongs to no real business.

55% of the score is the on-chain review of 1 of 1 clustered address(es), which moved no counterparty value in the reviewed window. That half therefore reflects an absence of observed exposure, not traffic that was examined and found clean.

The attribution figure covers the on-chain review only. There is no single coverage percentage for this score, because the desk review half is not measured over counterparty value.

Regulatory file

Legal nameRheinland Kustodie
Trading nameRheinland Kustodie
Licence statuslicensed (verified evidence)
RegulatorGermany prudential regulator
Licence referenceDE-E778FE0D
MiCA statusauthorised
JurisdictionGermany (DE), risk 1/10
Operational hubsDE, GB, MM

Controls

KYC rigourstrict · Identity verification before first withdrawal, no anonymous tier.
Withdrawal KYC threshold $0
Travel Ruleready · Originator and beneficiary data exchanged for VASP-to-VASP transfers.
Transaction monitoringmature
Sanctions screening in place
Source of funds checks performed
Custody modelcustodial

Desk review deductions

0 points deducted from 100.

No control deficiencies identified in the regulatory file.

On-chain review of the provider's clusters

Clustered addresses 1
Wallets screened 1
Inbound 0
Outbound 0
Illicit share 0.0%

Risk composition of managed wallets

No on-chain activity was returned for the clustered wallets.

Screened wallets

AddressChainScoreRisk InboundOutboundTransfersSource
0x5f182e15f79489143eb015f78f88515913fba85c Ethereum 100 Low 0 0 0 live:alchemy

Compliance and provenance

Travel Rule counterparty ready · Originator and beneficiary data exchanged for VASP-to-VASP transfers.
Data sourcelive:alchemy · 1 of 1 clustered address(es) screened
Directory41 VASP profiles, 2463 labelled entities

Label sources

  • Sanctions: 943 designated addresses from the US Treasury OFAC SDN list, published 08/28/2026.
  • Token contracts: 927 identified from public token lists.
  • Cited public labels: 519 addresses from 34 source(s), each with a URL.
    • Aave address book: V3 Ethereum (98 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Ethereum.json
    • FBI/IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (51 addresses) — https://www.ic3.gov/PSA/2025/PSA250226
    • Aave address book: AaveV3Polygon (45 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Polygon.json
    • Aave address book: V2 Ethereum (40 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Ethereum.json
    • Aave address book: AaveV3Arbitrum (39 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Arbitrum.json
    • Aave address book: AaveV3Optimism (31 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Optimism.json
    • Aave address book: AaveV3Base (25 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Base.json
    • Tornado Cash smart contracts (24 addresses) — https://docs.tornado.cash/general/tornado-cash-smart-contracts
    • Bybit: wallet addresses ownership explained (21 addresses) — https://www.bybit.com/en/help-center/article/Bybit-Wallet-Addresses-Ownership-Explained
    • Circle CCTP EVM contract addresses (20 addresses) — https://developers.circle.com/cctp/evm-smart-contracts
    • Aave address book: AaveV3BNB (18 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3BNB.json
    • Bitfinex: published public wallets (16 addresses) — https://github.com/bitfinexcom/pub/blob/main/wallets.txt
    • Aave address book: AaveV2Polygon (16 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Polygon.json
    • Aave address book: AaveV3EthereumLido (12 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3EthereumLido.json
    • Crypto.com: Transparency First cold-wallet list (10 addresses) — https://crypto.com/en/company-news/transparency-first
    • Uniswap v3 Arbitrum deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/arbitrum-deployments
    • Uniswap v3 Optimism deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/optimism-deployments
    • Uniswap v3 Polygon deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/polygon-deployments
    • Lido deployed contracts (6 addresses) — https://docs.lido.fi/deployed-contracts/
    • Uniswap v3 Base deployments (6 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/base-deployments
    • Uniswap v3 Ethereum deployments (3 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/ethereum-deployments
    • Chainalysis: Euler Finance flash loan attack (2 addresses) — https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/
    • Morpho deployed contracts (2 addresses) — https://docs.morpho.org/get-started/resources/addresses
    • Compound III USDC Ethereum roots (2 addresses) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdc/roots.json
    • Aave address book: GhoEthereum (2 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/GhoEthereum.json
    • Railgun privacy system contracts (1 address) — https://docs.railgun.org/wiki/learn/helpful-links
    • Linea network contracts (1 address) — https://docs.linea.build/network/build/contracts
    • Starknet L1-L2 messaging (1 address) — https://docs.starknet.io/documentation/architecture_and_concepts/Network_Architecture/l1-l2-messaging/
    • Chainalysis: Wormhole hack February 2022 (1 address) — https://www.chainalysis.com/blog/wormhole-hack-february-2022/
    • Compound III USDS Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usds/roots.json
    • Compound III USDT Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdt/roots.json
    • Compound III WBTC Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wbtc/roots.json
    • Compound III WETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/weth/roots.json
    • Compound III WSTETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wsteth/roots.json
  • Demonstration data: excluded — 118 synthetic entities were not scored.

Screen window

  • Up to 500 transfers across 3 indexer page(s) · default 3 hops · hop-2 budget 16 · hop-3 budget 12.

Artefact integrity

  • sha256+hmac · SHA-256 fcd9da38f868f4b7d0540b9558b9bcba4309f80d0791b57ecb66b6276d346f89 · sealed 2026-09-13T20:16:20+00:00 · HMAC present.

Frameworks covered

Informative

Notice / Disclaimer

Limits that apply to this artefact as a whole. Sources and hashes stay in provenance; this section is how to read them.