Stolen funds is the screening category for value taken from someone without their consent — a protocol hack, a drained wallet, a phishing loss, a theft under coercion — traced forward from the victim's address. It describes the money rather than the method, which is why it can appear alongside a hack, drainer or phishing label on the same result. For anyone receiving a payment, it is the category that most often arrives unannounced, because stolen value is cashed out through the same retail channels as everything else.
Every theft creates a starting point that is public: an address the victim controlled and a transaction that emptied it. From there the trail forward is reconstructable, and intelligence data keeps the connection attached as the value moves. The label therefore attaches to money, not to people, and it can reach a wallet whose owner has done nothing at all.
That is the part worth internalising before it happens to you. A clean transaction history on your own side does not immunise you against a counterparty's.
Because the cost of finding out late is asymmetric. A pre-deal check takes seconds and, at worst, loses you one trade. A deposit review at an exchange holding your working balance can run for days or weeks while you assemble documents you did not keep at the time. For an exchanger with settlement obligations, that gap is the business.
Screen the counterparty address before you accept the transfer. The Telegram bot is free for three checks a day and returns the verdict in seconds; desks run the same check in the workspace and keep the export.
The category is named in plain words in the result and sits beside the verdict — CLEAN, LOW, MEDIUM, HIGH or CRITICAL — with a recommendation of Proceed, Caution, Review or Reject and the decision drivers spelled out. A wallet attributed as a thief's own address reads differently from one that received value downstream, and the result keeps those apart because your obligations differ.
For teams, the workspace turns the category into a case-queue filter and a signed report you can hand to a bank, a partner or an auditor without rewriting your notes. Plans are on the pricing page.
Jurisdictions differ, but in practice what protects you is documentation: the check you ran, the counterparty details you kept, and the fact that you stopped rather than moved the funds on.
The result reflects what is known about the address at the time you check it, and intelligence about an incident develops over time. Re-checking before a later deal is worth doing rather than relying on a result from months ago.
Because it has to become spendable. Cash-out runs through the same retail rails everyone uses, so the last honest party in the chain is often a small seller or exchanger.
Also available in: · · ·
Not on your own initiative. Sending value back to an address involved in a theft can worsen your position; document what happened and take direction from the platform and law enforcement.
Send any wallet to the Telegram bot and get a verdict in seconds. Three checks a day, free, no signup. Desks that screen every deposit run it on plans from $199/mo.