chainscore.net ScoreGuard

Scoring methodology

Published in full so a report can be defended to an auditor or regulator.

How the score is produced

  1. Every transfer is attributed to a counterparty entity and its risk category.
  2. Flows are split into inbound and outbound. Within each direction the share of value transacted with each category is computed.
  3. A category contributes penalty x min(1, (share / saturation) ^ 0.5) to that direction's penalty. The square root keeps the curve concave: small exposure to sanctions still matters, large exposure to a regulated exchange stays cheap.
  4. Direction penalty = largest single contribution + 35% of the rest, capped at 99. Score = 100 - penalty, clamped to 1-100, so lower means riskier.
  5. Zero tolerance: any non-zero flow with a severity-10 category (sanctioned, terrorism financing, CSAM) sets that direction to 1 regardless of size, because sanctions liability does not scale with the amount transferred.
  6. The overall score averages both directions, unless severity 9-10 exposure is present, in which case the worse direction is used. An address that is itself designated always scores 1.
ScoreRisk level
80 - 100Low
60 - 79Medium
40 - 59High
20 - 39Severe
1 - 19Critical

Risk categories (20)

CategorySeverity PenaltySaturation
Sanctioned entity or designated address
sanctioned
10 99.0 0.1%
Terrorism financing
terrorism_financing
10 99.0 0.1%
Child sexual abuse material
child_abuse_material
10 99.0 0.1%
Ransomware operator or affiliate
ransomware
9 90.0 0.1%
Darknet marketplace
darknet_market
9 90.0 0.1%
Mixing or anonymising service
mixer
8 80.0 3.0%
Proceeds of hacks and exploits
stolen_funds
8 80.0 3.0%
Scam, phishing or investment fraud
scam
7 70.0 3.0%
Fraud shop / stolen data vendor
fraud_shop
7 70.0 3.0%
Exchange with weak or absent KYC
high_risk_exchange
6 60.0 20.0%
Unlicensed peer-to-peer broker
unlicensed_p2p
5 50.0 20.0%
Gambling or betting service
gambling
5 50.0 20.0%
Cross-chain bridge
bridge
3 12.0 50.0%
Decentralised finance protocol
defi
2 4.0 60.0%
Unattributed address
unknown
2 4.0 60.0%
Regulated exchange or VASP
exchange
1 2.0 60.0%
Mining pool
mining
1 2.0 60.0%
Merchant or payment processor
merchant
1 2.0 60.0%
Regulated custodian
custodian
1 2.0 60.0%
Token contract
token_contract
1 2.0 60.0%

Risk indicators (54)

Entity

SANCTIONS_DIRECT Direct sanctions exposure
TERRORISM_FINANCING Terrorism financing exposure
CSAM_EXPOSURE Child abuse material exposure
RANSOMWARE_EXPOSURE Ransomware exposure
DARKNET_EXPOSURE Darknet marketplace exposure
MIXER_EXPOSURE Mixing service exposure
STOLEN_FUNDS_EXPOSURE Stolen funds exposure
SCAM_EXPOSURE Scam and fraud exposure
FRAUD_SHOP_EXPOSURE Fraud shop exposure
HIGH_RISK_VASP High-risk exchange exposure
UNLICENSED_P2P Unlicensed P2P broker exposure
GAMBLING_EXPOSURE Gambling service exposure
SUBJECT_DESIGNATED Subject is a designated entity
SUBJECT_ILLICIT_ATTRIBUTION Subject attributed to an illicit service
SANCTIONS_INDIRECT Indirect sanctions nexus
UNATTRIBUTED_MAJORITY Majority unattributed counterparties
NESTED_SERVICE Possible nested service
CLUSTER_EXPANSION Expansion into newly seen clusters
UNIDENTIFIED_VOLUME Value concentrated in unlabelled clusters

Behaviour

HIGH_VELOCITY High transaction velocity
RAPID_PASSTHROUGH Rapid pass-through of funds
PEEL_CHAIN Peel chain pattern
STRUCTURING Structuring below reporting threshold
ROUND_AMOUNTS Repeated round-value transfers
DORMANT_REACTIVATION Dormant address reactivated
HIGH_OUTFLOW_RATIO Funds forwarded almost in full
ZERO_BALANCE_PASSTHROUGH Pass-through address
MANY_COUNTERPARTIES Unusually broad counterparty set
SINGLE_SOURCE_DEPENDENCE Concentrated funding source
LARGE_SINGLE_TRANSFER Large single transfer
PROFILE_DEVIATION Deviation from stated customer profile
OPENING_DEPOSIT Opening deposit inconsistent with stated identity
MANY_TO_ONE_WALLETS Many-to-one inbound wallet shape
NEW_ADDRESS_HIGH_VOLUME New address with high volume
MULTI_HOP_LAYERING Layering across single-use counterparties
DUST_INBOUND Dusting activity
BRIDGE_HEAVY Heavy cross-chain bridging
INACTIVE_ADDRESS Limited activity window
MEMPOOL_UNCONFIRMED Unconfirmed Bitcoin transactions

Geography

SANCTIONED_JURISDICTION Sanctioned jurisdiction exposure
HIGH_RISK_JURISDICTION High-risk jurisdiction exposure
FATF_GREYLIST FATF grey list jurisdiction exposure
OFFSHORE_SECRECY Offshore secrecy jurisdiction exposure
JURISDICTION_DIVERSITY Wide jurisdictional spread

Regulatory

SINGLE_TRANSFER_LIMIT Single transfer limit breached
CUMULATIVE_VOLUME_LIMIT Cumulative volume limit breached
TRAVEL_RULE_APPLICABLE Travel Rule transfers present
TRAVEL_RULE_GAP Counterparty cannot meet the Travel Rule
UNHOSTED_WALLET_MAJORITY Majority unhosted counterparties

Defi

STABLECOIN_CONCENTRATION Stablecoin concentration
FLASH_LOAN_PATTERN Protocol round trips inside minutes
LIQUIDITY_POOL_CONCENTRATION Liquidity pool concentration
CROSS_CHAIN_SWAPS Cross-chain and swap routing

Indirect

INDIRECT_SEVERE_EXPOSURE Severe exposure at a distance

Jurisdiction risk (48)

JurisdictionRiskFlags
North Korea KP 10 FATF call for action
Iran IR 10 FATF call for action
Syria SY 10 FATF grey list
Myanmar MM 10 FATF call for action
Afghanistan AF 8
Russia RU 7
Belarus BY 7
Venezuela VE 6 FATF grey list
Panama PA 5 offshore secrecy
Seychelles SC 5 offshore secrecy
British Virgin Islands VG 5 FATF grey list offshore secrecy
Cayman Islands KY 4 offshore secrecy
Curacao CW 4 offshore secrecy
Unattributed -- 3
United Arab Emirates AE 3
Malta MT 3
Cyprus CY 3
Angola AO 3 FATF grey list
Bosnia and Herzegovina BA 3 FATF grey list
Bulgaria BG 3 FATF grey list
Bermuda BM 3 offshore secrecy
Bolivia BO 3 FATF grey list
Belize BZ 3 offshore secrecy
Democratic Republic of the Congo CD 3 FATF grey list
Cote d'Ivoire CI 3 FATF grey list
Cameroon CM 3 FATF grey list
Haiti HT 3 FATF grey list
Iraq IQ 3 FATF grey list
Kenya KE 3 FATF grey list
Kuwait KW 3 FATF grey list
Lao PDR LA 3 FATF grey list
Lebanon LB 3 FATF grey list
Monaco MC 3 FATF grey list
Nepal NP 3 FATF grey list
Papua New Guinea PG 3 FATF grey list
South Sudan SS 3 FATF grey list
Vietnam VN 3 FATF grey list
Yemen YE 3 FATF grey list
Estonia EE 2
Lithuania LT 2
Luxembourg LU 1
Germany DE 1
France FR 1
United Kingdom GB 1
Switzerland CH 1
Singapore SG 1
United States US 1
Japan JP 1

Data sources

Live chain data comes from Alchemy for Ethereum, BSC, Base, Optimism, Polygon, Arbitrum and Solana when ALCHEMY_API_KEY is set (same key; enable each network in the dashboard). QuickNode is the per-chain failover when QUICKNODE_<CHAIN>_URL is set. Blockscout is the keyless path and failover. TronGrid covers TRX and TRC-20. Solana prefers Alchemy or QuickNode, then the public RPC. mempool.space is used for Bitcoin (paginated). Zero-value native transactions are kept so contract interaction without ETH is still visible. Native USD uses a CoinGecko daily close at the transfer date when the chart is available. Fiat-referenced tokens peg at 1 only when the contract or mint matches a stored issuer list (USDT/USDC/DAI and a handful of peers per chain); a spoofed ticker is left unpriced. Wrapped natives (WETH, WBTC) reuse the live ETH/BTC close. Other tokens use the indexer's spot rate or stay unpriced. Geography indicators read a compact FATF snapshot (call for action and increased monitoring as of 19 June 2026) stored in SQLite, not a live FATF feed. Travel Rule ($1,000) and CTR ($10,000) floors live in that same table. If Blockscout fails and ETHERSCAN_API_KEY is set, Etherscan v2 is used as a last failover. An indexer error with no failover is returned as a failure, not replaced with generated transfers. An address with no activity is scored on that empty window. Flux hop 1 is the subject's own transfers; hop 2 and 3 are a live indexer walk of the top counterparties (hosted exchanges, custodians, merchants, high-risk exchanges and mixers are terminals — out of sight, not a clean end of trail). Each report states the indexer in its provenance block. Flux reports include a server-rendered transfer diagram: Source 3 → Source 2 → Hop 1 sources → Subject → Hop 1 destinations → Hop 2 → Hop 3+, nodes ordered by first_seen, edge thickness by USD value.

The label set holds 2463 entities, including a public overlay of widely documented addresses. Entries marked public are documented addresses. Entries marked synthetic exist so the scoring models can be unit-tested; they are not applied unless a live counterparty matches a seeded address. Unlabelled counterparties stay unknown.

Cross-product glossary

Shared score scales, provenance data_source values, observed vs modelled fields, EVM failover order, and typology family IDs live in the repository file docs/compute-glossary.md.