Risk Scoring
Every address in a trace receives a risk score (0–100) computed from multiple signals. The overall incident risk score is the weighted maximum across all nodes.
Risk Levels
Critical (81–100)
OFAC sanctioned, Lazarus Group, confirmed hacker
High (61–80)
Mixer interaction, phishing, Forta Attacker flag
Medium (41–60)
Suspicious patterns, unverified risk signals
Low (21–40)
Minor flags, low-confidence signals
Clean (0–20)
Known exchange, DeFi protocol, verified entity
Risk Signals
| Signal | Weight | Source |
|---|---|---|
| Sanctions match | +50 → 100 | OFAC / EU / UN / UK lists — floors the score to 100 (critical) |
| Known sanctioned entity | +30 → 100 | ChainHint entity DB, same floor to 100 |
| Restricted-asset exposure | +45 | Holds or moved an asset the EU prohibits transactions in (Annex LIII — A7A5), matched by contract against the restricted-asset registry; one factor per address, never a sanctions listing; on its own it lands in the medium band — a holder of a prohibited asset never prints Low Risk |
| Restricted-asset contract | → 70 | The asset contract itself (entity category restricted_asset) floors to 70 / high — the contract is not a person |
| GoPlus malicious flag | +30 | GoPlus Security API |
| Known hacker/exploiter | +40 | ChainHint entity DB, min floor 70 |
| Known scam entity | +25 | Scam Sniffer / Forta / entity DB |
| Mixer interaction | +20 | Tornado Cash / on-chain |
| High-risk labels | +15 | Forta Attacker, blacklists |
| Contract not verified | +10 | Etherscan source verification |
| New address (< 7 days) | +5 | On-chain age check |
| High tx velocity | +5 | Behavioral analysis |
