Sanctuary Research

A crypto risk score is a single number, usually on a 0-100 scale, that tells you how much of a wallet's history touches money someone has already reported as criminal. That is what the score means: exposure. It comes from labels attached to the address and to the addresses it has transacted with — sanctions listings, darknet marketplaces, ransomware reports, scam databases — 14,488,795 entity labels from 20+ intelligence sources in Sanctuary's label set as of August 2026. What the number does not mean is a verdict on the person holding the wallet. A score is the beginning of a decision, not the end of one. You can get that number on any address in about sixty seconds, free, in the Sanctuary Telegram bot — three free checks a day, no registration.
Exposure to money that has already been named, and nothing beyond that. A screening service holds a large set of addresses that someone identified: a regulator publishing a sanctions listing, a police force naming a ransomware wallet, a victim filing a scam report, an exchange documenting a fraud case. The check asks two questions — is this address one of them, and has this address moved value to or from one of them.
A wallet risk score explained in one line: it is a measure of the money, not a measure of the owner. The score says where value has been. It says nothing about who holds the keys, what they intended, or what they knew.
That gap is why two people read the same 72 differently. An exchange sees a documented link it will have to explain to an auditor. A P2P seller sees a trade to decline. Same number, different obligation — and both are reasonable readings of it.
Read the band, not the digit. The distance between 41 and 44 is noise. The distance between 41 and 84 is your decision. Nearly every service groups the scale into five levels, and the level is the part you act on.
| Score | Level | What it means for the decision |
|---|---|---|
| 0-9 | Clean | Nothing found against the address or its counterparties. Proceed. |
| 10-33 | Low | Only weak or distant signals. Proceed, and keep the result on file. |
| 34-66 | Medium | Something real surfaced, but it is not conclusive. Look closer before you send. |
| 67-89 | High | Direct or close links to named criminal activity. Hold the transfer and ask for an explanation. |
| 90-100 | Critical | Sanctions listing or confirmed criminal attribution. Do not complete the transaction, and check what your jurisdiction requires of you. |
Medium is the band people misread. It does not mean "probably fine". It means the check found something it cannot resolve on its own: a counterparty with a poor history, a cluster with mixed activity, a source that names the address without evidence you can inspect. Medium is a request for one more question, usually to the counterparty — where did these coins come from, and can you show it?
An AML risk score is the same number read against a legal obligation. Exchanges, payment processors, OTC desks and licensed exchangers have to know where incoming funds came from and to record the basis on which they accepted or refused them. The score is what makes that basis writable: a result with a timestamp, a level and a reason, attached to a specific deposit.
The screening happens on the transaction rather than on the customer's passport, and those are two different controls that people routinely merge into one. The split between checking the money and checking the person is covered in KYT vs KYC.
A retail user meets the same number from the other side: a withdrawal is held, an exchange asks where the coins came from, a P2P counterparty refuses your USDT. Each of those means someone ran a score on an address in your history and got a level they were not willing to sign off. Running the check yourself, before the transfer, is the cheapest way to never be on that end of the conversation.
You do not need a plan, an account or a card to see a crypto risk score on an address. Send it to @sanctuaryapp_bot and the free check answers in about sixty seconds: the level, what the address is, whether it appears on a sanctions list, which sources named it and what they named it as. Three free checks a day.
The bot runs on buttons rather than commands — press check, paste the address, read the result — so the whole thing fits inside the pause before you confirm a transfer. What comes back is a level with its reasons attached, and that is what makes it usable in an argument with a counterparty and defensible in a conversation with a compliance desk.
Paid plans are for the point where one answer at a time stops being enough: a PDF report to file next to the decision, monitoring that tells you when a saved address picks up something new, bulk screening for a counterparty list, and an API that puts the same check inside your own deposit flow. Professional is $199 a month for 1,000 checks; Business is $499 a month for 5,000.
Because the scales and the data underneath them are not the same. That is expected, not a sign that one of them is broken. Three reasons cover nearly all of it:
Compare the levels and the stated reasons, not the digits. If two tools disagree on the band, treat the higher one as the question you have to answer, and look at what each shows as evidence. A service that hands you a number with no reason attached has given you nothing you can act on, and nothing you can defend later.
None of this makes the number weak. It makes it the cheapest question you can ask before money moves — which is exactly how a compliance officer treats it, and how a trader should.
All five steps run on a check that costs nothing: send the address to the Sanctuary Telegram bot, read the level and the reasons behind it, keep the result. No registration, three checks a day, every day.
We publish what feeds a score. We do not publish how it is assembled. As of August 2026 our label set holds 14,488,795 entity labels drawn from 20+ intelligence sources across 42 entity types — among them 510,605 sanctioned-entity labels, 82,347 ransomware labels and 16,591 phishing labels — on 10 chains with full AML coverage. Those are label rows rather than distinct addresses: one address can carry several labels, and one label can describe an entity rather than a single wallet. The distinction matters, because a vendor who quietly converts label counts into wallet counts is inflating the only asset this work has.
When an address matches one of those labels, or moves value with an address that does, that is what the level responds to. The weighting behind it stays unpublished, here and at every serious vendor, for a plain reason: a published formula is a map for the people the lists exist to catch. What you should demand instead is the evidence — which sources named the address, what they named it as, and how close the connection is. What crypto wallet screening covers walks through what a full check looks at.
The short version: a crypto risk score is a question, not an answer, and the question is free to ask. Check the address before the transfer, keep the result, decide on the level rather than the digit. Paste the address you are about to pay into the Telegram bot — three free checks a day, a verdict in about sixty seconds, and one fewer conversation with an exchange later.
No. A high score means the address is linked to money that someone has already reported as criminal — a sanctions listing, a ransomware report, a scam complaint. It is a documented link, not a legal finding. Establishing that an offence occurred is a matter for law enforcement and courts; the score is what makes a business stop and ask a question before it moves value.
Anything in the clean or low bands, 0-33 on a 0-100 scale, means the check found nothing meaningful against the address or its counterparties. Medium, 34-66, is not bad in itself but is not finished either: something surfaced that the check could not resolve. High and critical, 67 and above, mean the transaction needs to stop until the link is explained.
Yes, and it regularly does. New labels arrive continuously, and an address can be named weeks after it received funds — that is how most ransomware and scam wallets end up on lists. A screening result is a statement about the data at the moment it ran, which is why the timestamp matters and why a repeat counterparty is worth re-checking.
Not automatically. Every business sets its own tolerance, and different services run different data, so an address that scores low on one check can land in another provider’s medium band. A low result before you send is still worth having: it is the difference between choosing your counterparty and finding out afterwards.