Risk score and grade

A wallet audit produces two layers of risk information: a score and severity for every submitted wallet, and a single grade for the whole list. This page explains both, and the review tools that sit on top of them.

Per-wallet risk factors

Every wallet is checked against a fixed set of risk factors. Each factor that applies is attached to the wallet with a severity, a one-line explanation, and the evidence behind it.

FactorWhat it means
Direct labelThe wallet itself appears on a blocklist: sanctions, hack, drainer, mixer or scam. Always critical.
Restricted assetThe wallet holds, or once held, an asset the audit was told to watch for. Holding it now is worse than having held it in the past.
Outbound exposureThe wallet has sent funds to a labelled address.
Taint proximityFunds reached the wallet within a few hops of a labelled address. See Threat intelligence and taint.
Shared funding source, coordinated buys, uniform trade sizes, circular flowThe cross-wallet patterns described under Wallet relationships.
Bot cadenceRuns of transactions fired faster than a person could plausibly act.
ConcentrationA single token makes up most of the wallet's value.
Illiquid holdingsMeaningful value in tokens with no confirmed exit liquidity.
Dormant valueA large balance with no activity for a long time.
Fresh high valueA wallet that is new but already holds a lot. Low severity, since it can be entirely innocent.
Hub-heavy activityMost counterparty volume goes through exchanges. Informational only.
Institutional custodyThe wallet is a multisig or smart account, or a public source names it as a business. Informational only.

Severities run info, low, elevated, high, critical. Informational factors are shown for context but excluded from every calculation that follows.

Wallet severity and score

A wallet's severity is simply its worst non-informational factor. A wallet with no factors is marked clear when coverage was full, and unknown when coverage was limited.

The score starts at 100 and loses a fixed penalty for every factor, larger for more severe ones. A single critical factor is enough to reach zero. The score is a quick way to compare wallets; the severity and the factor list are what the grade and findings use.

Coverage is reported as full or limited per wallet. Coverage is limited when the chain has fewer blocklist sources, when the history window did not reach the wallet's earliest activity, or when the taint check could not run. A limited wallet with no factors reads as unknown, never as clear.

The grade

The audit grade is driven by one ratio: the share of the group's total holdings value that sits in wallets rated elevated or worse. Five bands map that percentage to A through F. Two rules sit on top:

  • Any critical wallet in the list caps the grade at D, however small its share of value.
  • The value used is holdings value, not realizable value, so an illiquid position still counts fully toward risk exposure.

The report shows the percentage, the dollar value at risk, and the count of wallets in each severity, so the grade is always traceable to its inputs.

Findings

Findings are the report's narrative layer. Each is either a risk finding, which points at wallets whose factors already contributed to the grade, or an interesting finding, which is descriptive and has no grade effect. Token checks, holder reconciliation results, a dominant wallet, or dense connectivity between submitted wallets are all interesting findings.

Each risk finding also carries an impact: the grade the audit would have received if the factor behind that finding did not exist. This is a true counterfactual computed at finalize, so a finding that says "removing this would move the grade from D to B" is reporting the recomputed grade, not an estimate.

Review and the adjusted grade

Auditors can resolve or hide findings and attach notes. That review never changes the engine's grade. Instead the report shows an adjusted grade: the grade recomputed as if the factors behind reviewed findings were absent, replayed over the review history so the trend chart shows both the engine's line and the adjusted line. A hidden finding also disappears from shared reports and exports, but the underlying wallet risk is preserved so nothing is silently lost.

Realizable value

Alongside holdings value, every wallet shows a realizable value: native tokens, stablecoins and tokens with confirmed exit liquidity. Tokens whose liquidity could not be confirmed are excluded from realizable value, and tokens with no liquidity at all also raise the illiquid factor. The two numbers together tell you what a wallet is worth on paper versus what could plausibly be sold.

Revisions

Every completed run is recorded as a numbered revision. Re-running an audit, or editing its wallet list, produces a new revision, and the History tab shows how the grade moved between them and why. Auditors can attach a declaration to a revision to record context that the engine cannot know.