Every wallet screening tool returns a number, and almost every team misuses it. A risk score is a triage signal that tells you where to spend attention — it is not a verdict, and treating it as one produces both false positives that cost you customers and false negatives that cost you far more. This guide explains what an address risk score actually measures, how the underlying factors are weighted, what low, medium and high should mean in your process, and how to set thresholds that your team can operate without drowning in alerts.

Wallet screening result showing risk score with category breakdown
Wallet screening result showing risk score with category breakdown

What the score is actually measuring

An address risk score condenses several independent findings into one number. Understanding what went into it is what lets you use it properly.

The engine screens the address against 100+ sanctions and risk sources — OFAC, EU, UN and UK lists among them — and against a database of over 7 million labeled entities covering mixers, darknet markets, gambling services, fraud clusters, high-risk exchanges and addresses tied to reported thefts, across 43 networks.

It then evaluates two things. Direct exposure: does this exact address appear in any source? Indirect exposure: where did the funds come from and where have they gone? Most real risk lives in the second question, because sophisticated actors rarely receive funds on a publicly listed address.

How the factors are weighted

Not all exposure is equal, and a scoring engine that treated it as equal would be useless. Three factors do most of the work.

  • Hop distance: how many transfers separate the address from the risky source. One hop is a direct relationship; eight hops is background noise in a well-used chain.
  • Value share: what proportion of the wallet's total inflow traces back to that source. A 60% share is a finding; 0.05% is a rounding error.
  • Recency: whether the exposure happened last week or four years ago. Risk decays, and treating a 2021 trace like a current one blocks legitimate users.

A wallet that received most of its balance two hops from a sanctioned mixer yesterday is a genuine problem. A wallet with trace exposure eight hops back in 2021 is not. Both may show as non-zero; only the breakdown tells you which is which.

Low, medium and high in practice

Low means no meaningful exposure was found in any category. Proceed and archive the report. You want that record even for clean cases — especially for clean cases, because those are the ones you will be asked to justify years later.

Medium is where teams perform worst. Open the category detail before deciding anything. Two wallets can share an identical medium score for opposite reasons: one has a small but very recent sanctions trace, the other a large but ancient gambling share. The first needs escalation today; the second is acceptable under any sane policy. The headline number cannot separate them.

High should stop the transaction until a human has read the full report. Do not automate this away. High scores are rare enough that human review is affordable and consequential enough that it is necessary.

Setting thresholds you can actually operate

The most common mistake is setting thresholds too sensitively, then quietly ignoring the resulting alerts. A team that receives forty flags a day stops reading them within two weeks, and at that point you have bought a feeling of safety rather than safety.

Set thresholds so that the volume reaching human review matches what your team can genuinely investigate in a working day. Five flags properly investigated beat fifty auto-closed. Start conservative — high thresholds, direct exposure prioritised — and tighten once you know what proportion actually warrants escalation.

Your thresholds should also differ by context. A retail platform might act at 5% indirect exposure; an OTC desk dealing with institutions might set 1%. Neither is wrong; they reflect different risk appetites.

Self-custody versus exchange deposit addresses

A single score means different things depending on what kind of address produced it, and conflating the two is a reliable source of bad decisions.

A self-custody wallet is controlled by one party, so its history reflects that party's behaviour directly. Exposure found there is attributable to your counterparty.

An exchange deposit address belongs to a custodial service holding funds for many customers. Its history reflects the platform's aggregate flows, not your counterparty's conduct. Flagging a customer because the exchange they withdrew from once processed sanctioned funds would flag most of the industry. What matters there is the service's risk profile — does it enforce KYC, is it licensed, has it been named in enforcement actions — which is exactly what entity attribution tells you.

From score to documented decision

A score you acted on but cannot evidence is, to a regulator, a check you never ran. Every screening on Arya Crypto produces a timestamped PDF containing the score, the category breakdown, the matched sources and the counterparties involved. Attach it to the case file.

Write down your policy too, even if it is one page: what thresholds trigger what action, who reviews, and within what timeframe. Auditors rarely fault firms for missing a bad actor — that standard is impossible. They fault firms for having no reasonable process, or for being unable to demonstrate the one they claim.

Scores expire — monitoring is the other half

A screening is a point-in-time assessment. It describes the chain as it exists at that moment, which is a genuine strength, but it means today's clean result promises nothing about next month.

An address that scores low today can receive ransomware proceeds in three weeks or be designated by OFAC next quarter. For counterparties you deal with repeatedly, put the address under continuous KYT monitoring so it is re-analysed on a schedule — as often as every two hours — and you are alerted when the picture changes rather than discovering it during an audit.

For onboarding, pair screening with identity verification, and add KYB when the counterparty is a company. Screening tells you what the money did; it cannot tell you who is holding the key.

Common mistakes worth avoiding

Blocking on any exposure at all. Trace amounts of historical mixer exposure are extremely common in ordinary wallets, particularly older ones. A policy that blocks every non-zero result will reject a large share of legitimate customers and train your team to override the system — which is worse than having no system.

Screening deposits but not withdrawals. Deposit screening protects you from receiving tainted funds. Withdrawal screening protects you from sending funds to a sanctioned address, which in most jurisdictions is the more serious violation. Teams neglect the second far more often.

Reading the score without the categories. The number tells you how urgently to look. The breakdown tells you what to do. Automating purely on the number guarantees you will act on the wrong cases.

Screen your first wallet address free — Pricing · Services · KYT · KYC · KYB · Exchange · Prop