chainscore.net ScoreGuard

AML scenarios and thresholds

54 named scenarios across 6 groups, driven by 34 configurable thresholds. Editing a threshold changes when a scenario fires for every report generated afterwards; each report records the policy it was produced under.

behaviour · 20 scenario(s)

High transaction velocity Rapid pass-through of funds Peel chain pattern Structuring below reporting threshold Repeated round-value transfers Dormant address reactivated Funds forwarded almost in full Pass-through address Unusually broad counterparty set Concentrated funding source Large single transfer Deviation from stated customer profile Opening deposit inconsistent with stated identity Many-to-one inbound wallet shape New address with high volume Layering across single-use counterparties Dusting activity Heavy cross-chain bridging Limited activity window Unconfirmed Bitcoin transactions
ThresholdWhat it controlsUnit DefaultValue
Dormancy before reactivation
dormancy_min_days
Inactivity gap that makes renewed activity notable. days 180
Dust transfer ceiling
dusting_max_value_usd
Value below which an inbound transfer is dust. usd 1.0
Dust transfers
dusting_min_count
Sub-dollar inbound transfers treated as dusting. count 5
Low confidence sample
inactive_max_transfers
Transfers below which scores carry low confidence. count 5
Large single transfer
large_transfer_min_usd
Single transfer value treated as large. usd 250000
Single-use counterparty ratio
layering_min_single_use_ratio
Share of counterparties used exactly once. ratio 0.7
Broad counterparty set
many_counterparties_min
Distinct counterparties treated as unusually broad. count 60
New address window
new_address_max_days
Age below which an address counts as new. days 30
New address volume
new_address_min_volume_usd
Volume that makes a new address notable. usd 100000
Outflow ratio
outflow_min_ratio
Share of received value forwarded on. ratio 0.95
Pass-through retention ceiling
passthrough_max_retention
Balance retained below which an address is transit only. ratio 0.01
Peel chain run length
peel_chain_min_run
Successively smaller outbound transfers required. count 4
Rapid pass-through pairs
rapid_passthrough_min_pairs
Matched in/out pairs within an hour before firing. count 3
Round-amount ratio
round_amount_min_ratio
Share of transfers using round native amounts. ratio 0.5
Concentrated funding share
single_source_min_share
Share of inbound value from one counterparty. ratio 0.8
Structuring band ceiling
structuring_band_high_usd
Reporting threshold that structuring sits just below. usd 10000
Structuring band floor
structuring_band_low_usd
Lower bound of the value band treated as structuring. usd 8000
Structuring transfers required
structuring_min_count
Transfers inside the band before the scenario fires. count 3
Velocity, transfers per active day
velocity_min_per_day
Transfers per active day treated as high velocity. ratio 6.0
Velocity minimum sample
velocity_min_transfers
Transfers required before velocity is meaningful. count 20

defi · 4 scenario(s)

Stablecoin concentration Protocol round trips inside minutes Liquidity pool concentration Cross-chain and swap routing
ThresholdWhat it controlsUnit DefaultValue
Cross-chain share
cross_chain_min_share
Share of flow through bridges and swap routers. ratio 0.25
DeFi round trips
defi_roundtrip_min_count
In-and-out cycles with one protocol inside minutes, consistent with flash loan or arbitrage activity. count 2
Liquidity pool concentration
liquidity_pool_min_share
Share of value sitting with a single DeFi counterparty. ratio 0.35
Stablecoin concentration
stablecoin_min_share
Share of value carried in stablecoins. ratio 0.6

entity · 19 scenario(s)

Direct sanctions exposure Terrorism financing exposure Child abuse material exposure Ransomware exposure Darknet marketplace exposure Mixing service exposure Stolen funds exposure Scam and fraud exposure Fraud shop exposure High-risk exchange exposure Unlicensed P2P broker exposure Gambling service exposure Subject is a designated entity Subject attributed to an illicit service Indirect sanctions nexus Majority unattributed counterparties Possible nested service Expansion into newly seen clusters Value concentrated in unlabelled clusters
ThresholdWhat it controlsUnit DefaultValue
Cluster expansion, new clusters
cluster_expansion_min_new
Newly seen single-use clusters before the scenario fires. count 8
Nested service counterparties
nested_min_counterparties
Counterparty count suggesting a service. count 25
Nested service exchange share
nested_min_exchange_share
Exchange flow share suggesting a nested service. ratio 0.35
Unattributed counterparty share
unattributed_min_share
Share of counterparties with inferred attribution only. ratio 0.6
Unidentified cluster share
unidentified_cluster_min_share
Share of value with unlabelled counterparty clusters. ratio 0.4

geography · 5 scenario(s)

Sanctioned jurisdiction exposure High-risk jurisdiction exposure FATF grey list jurisdiction exposure Offshore secrecy jurisdiction exposure Wide jurisdictional spread

This group has no tunable threshold; its scenarios fire on the presence of exposure alone.

indirect · 1 scenario(s)

Severe exposure at a distance
ThresholdWhat it controlsUnit DefaultValue
Indirect exposure floor
indirect_exposure_min_usd
Modelled indirect value below which exposure is noise. usd 1000
Indirect exposure severity
indirect_min_severity
Category severity that makes indirect exposure reportable. severity 7

regulatory · 5 scenario(s)

Single transfer limit breached Cumulative volume limit breached Travel Rule transfers present Counterparty cannot meet the Travel Rule Majority unhosted counterparties
ThresholdWhat it controlsUnit DefaultValue
Cumulative volume limit
cumulative_volume_limit_usd
Institution limit for total value in the review window. usd 10000000
Single transfer limit
single_transfer_limit_usd
Institution limit for one transfer; a breach is alerted. usd 1000000
Travel Rule de minimis
travel_rule_min_usd
Transfer value at or above which originator and beneficiary data must be exchanged. usd 1000