How it works
Short version: every finding names its source, a source that cannot be reached is reported as not checked rather than clean, and a report that contradicts itself is never published.
1 · Validation runs before any lookup
Every address is checked against its own chain's checksum first — EIP-55 for EVM, Base58Check for TRON and Bitcoin, Bech32 for native segwit, length and encoding for Solana. This is offline and instant. An address that fails cannot have received funds as written, so screening it would be meaningless, and this engine says so instead of returning a score for it.
2 · Sources
The OFAC Specially Designated Nationals list is matched directly and is the authoritative sanctions signal. Alongside it: GoPlus address security (behavioural flags sourced from SlowMist and BlockSec), TRM Labs' public sanctions screener, the Chainalysis on-chain sanctions oracle, community scam-address and phishing-domain blocklists, on-chain activity via Blockscout and TronGrid, and domain age via RDAP and Certificate Transparency.
The two independent sanctions screeners are used as corroboration only. Measured against the current OFAC Ethereum entries, each flags roughly two-thirds and about 30% are caught by neither — which is exactly why the authoritative list is matched directly rather than trusted to a third party.
3 · Four statuses, and the difference matters
Flagged — the source returned a positive finding. Checked, no flag — reached, returned nothing. Not checked — could not be reached, and excluded from the score. N/A — the source does not cover that chain. A source that timed out and a source that came back clean are different facts, and collapsing them is how an engine with a dead API key reports every address as low risk.
4 · The score cannot outrun the evidence
The score is a pure function of signals that actually fired. Narrative language describing a fraud is real evidence that a fraud is being described, but it is not confirmation about a specific wallet, so narrative-only cases are capped below CRITICAL. Confidence measures how much of the picture we could see, not how alarming it is, and cannot exceed 75% without technical confirmation.
5 · The coherence gate
Before anything is published, the assessment is checked against a set of invariants: the band matches the score, urgency matches the assessed situation, a CRITICAL rating requires at least one confirmed technical finding, an elevated score requires a non-empty findings list. If any invariant fails, the report is withheld and the failure is logged. A document that contradicts itself is worse than no document, because the contradiction is what a defence lawyer leads with.
6 · What we will not tell you
We will not quote you a recovery rate. No government agency or credible research body publishes one for crypto fraud, and every percentage circulating online traces back to marketing by firms selling recovery services. We will not tell you an address belongs to a person — an address is not a person. And we will not take a percentage of anything recovered, because that would give us a reason to promise a recovery.