How the PublicAML risk score is derived

Methodology, updated 8 October 2026

The score is the output of a stated policy, not of a model. Everything the number is made of travels in the same response as the number itself, so it can be checked rather than trusted.

min(severity, rank)

the score at the point of origin

0 to 100

one trust rank per source, not per claim

per category

how far an accusation travels, trimmed by rank

human only

the only thing that clears an accusation

Two different claims, which are easy to confuse

Two statements live side by side in the API and they are not interchangeable. Attribution answers who an address is: an exchange, a token contract, a named person. Risk answers what it costs: sanctioned, hacked funds, mixer output. They are stored apart, they are proved to different standards, and only one of them is an accusation.

The shape of the graph is a third thing again, and it never becomes an identity. An address that many others pay into is published as a hub with a structural basis, not as an exchange. When nobody has named it, the category is empty, and empty means nobody named it, not nothing is known.

Two axes set the number

The first axis is the category register. It states what is being alleged and carries, for each category, its own severity, its own reach and its own decay. A sanction, a hack, a mixer and a deposit address of a gambling venue are different statements with different weight, and that weight belongs to the statement, not to whoever made it.

The second axis is the trust table: one rank from 0 to 100 per source. Sanctions authorities and stablecoin issuers sit at 100, community reports at 25. One number per source, not per claim, so a source cannot be strong about one address and weak about the next.

The two are joined by a minimum, not by a weighted blend. The score at the point of origin is the lower of the category severity and the source rank. A weak source therefore cannot carry a heavy accusation, and a strong source cannot make a soft category heavy. Both of those failures are what a weighted average quietly allows.

The minimum gate
sanction100

severity

sanctions authority100

rank

min100
hack90

severity

investigated incident90

rank

min90
hack90

severity

community report25

rank

min25
mixer80

severity

sanctions authority100

rank

min80

Severity is what is alleged. Rank is who alleges it. The score at the origin is the lower of the two.

One rank per source
100

sanctions authorities, stablecoin issuers, our own investigations

90

vendor sanction lists, investigated incidents

80

curated catalogue

50

vendor labels, our detectors

40

open datasets

25

community reports

20

block explorers, naming services

10

derivations from other fields

The trust table, by band. The rank is a ceiling on the score and a divisor on the reach, never a price.

How far an accusation travels

Reach belongs to the category and is trimmed by the rank, never the other way round. A sanction survives depth by design and keeps an explicit score at each hop. A hack reaches six hops and loses 30 per cent of its weight on each of them. A mixer is terminal: value passing through it does not carry the accusation onward, and interaction with it is a different, much lighter claim.

The rank enters as a fraction of that reach, with a floor of one hop, so a source we trust less does not get the same radius as the authority that published the list. Below, the same hack claim from three sources of different rank.

Score by distance
sanctionissuer freeze
02550751000123456100908070554025.

hops from the source

The same hack claim, three sources

rank 90

6 hops

rank 50

3 hops

rank 25

2 hops

reach = max(1, ceil(min(base hops, 8) x rank / 100))

A sanction holds its weight with depth and stops at a floor. An issuer freeze loses 30 per cent a hop and stops at five.

What neutral infrastructure does, and does not, do

Everybody pays an exchange, a bridge and a staking contract, so the neighbourhood of such an address is not evidence about it. Neutral categories therefore have their inherited exposure switched off. This is the one place where attribution touches the score, and it only ever lowers it.

It never touches the direct half. An accusation recorded against the address itself is published whatever the address is attributed as, and the only thing that clears it is a recorded human decision, held as its own row with its own author. No ranking, no category and no shape of the graph can retract an accusation on its own.

Which half the attribution can touch

Accusing category

Direct, the address itselfpublished
Indirect, what reached itpublished

Neutral infrastructure

Direct, the address itselfpublished
Indirect, what reached itswitched off

The only thing that clears the direct half is a recorded human decision.

A neutral attribution switches off inherited exposure. It never touches an accusation recorded against the address itself.

Where the provenance lives

Every source statement about an address is held as its own row in a claims registry. The owner of the published row is chosen by rank, not by who wrote last, and a claim that loses is kept rather than overwritten. So the question who said this, and when, is answered from the record and not from our memory.

That is also what makes a disagreement legible. When a curated catalogue calls an address a utility contract and an authority calls it sanctioned, both statements are on file, the authority owns the published row, and the disagreement itself is visible instead of being averaged away.

Claims on one address
100

sanction

sanctions authorities, stablecoin issuers, our own investigations

owns the published row

80

utility contract

curated catalogue

on the record

25

phishing

community reports

on the record

Write order decides nothing, which is why a late low-rank import cannot quietly take over an address.

Rank picks the owner of the published row. The claims that lose are kept, not overwritten.

One response, read line by line

Each entry that contributed to the score names the source address, the source, its rank, the alleged severity, the resulting score and the distance in hops. The arithmetic can therefore be reproduced from a single response, without access to anything of ours. Below, an abridged live answer for a wallet of Chatex, listed by OFAC.

A live response, abridged

100.0

CRITICAL

100

Direct, the address itself

90

Indirect, what reached it

CHATEX

sanction

HopsCategorySourceSeverityRankScoreSource address
0sanctionofac:sdn_advanced1001001000x6f1ca1…2a8352
CHATEX
1sanctionofac:sdn_advanced100100900x5512d9…0121b0
CHATEX
1issuer-freezecircle:blacklist90100630x26e0d0…2a2cfd
issuer-frozen
2sanctionofac:sdn_advanced100100800x1999ef…0c5ade
Magomedov Khadzhi Murat Dalgatovich
2issuer-freezetether:blacklist9010044.10x7f232c…7ab3bd
issuer-frozen
3sanctionofac:sdn_advanced100100700x098b71…3e2f96
Lazarus Group
3hackincident:news-pipeline909030.870x959a90…b12bd2
uniBTC exploit

Rows beyond three hops are omitted here for length; the response carries them.

Every row carries its own arithmetic: severity, rank, score and distance.

Read the first row and the policy is visible: severity 100, rank 100, score 100, zero hops. Read the last and so is the decay: a hack alleged by an investigated incident is worth 90 at its origin and 30.87 three hops away. The halves above the table are the same arithmetic summarised: the direct half comes from the address itself, the indirect half is the strongest thing that reached it.

Checks you can run without us

The primary evidence is not ours and does not need us. A sanction names the authority, the list, the date of the snapshot and the publication. An issuer freeze names the block and the transaction hash, which either exists on chain or does not. An incident names its documentary sources with their evidence tier and a link.

Verify the primary evidence

Sanction

authoritylistsnapshot datepublication

Open the authority publication and look the address up in it.

Issuer freeze

blocktransaction hash

Look the transaction up on chain. It is there or it is not.

Incident

documentary sourceevidence tierlink

Open the cited source and read what it attributes to the address.

Signed assessment

subjectrisk levelvalidity window

Recover the signer with ecrecover. The score and category are not covered.

Four checks, none of which requires an account with us.

We also issue signed assessments in EIP-712 form, which any third party verifies with one ecrecover call and no account with us. One caveat, stated here rather than discovered later: the signature covers the subject address, the risk level and the validity window. The numeric score and the category travel alongside it, unsigned.

Limits we state up front

A methodology that only lists its strengths is not one. These are the places where the number is weaker than it looks, and each is a property of the current policy rather than a bug we are hiding.

  • Propagation has no notion of time. A transfer made long before the accusation existed carries the same weight as one made after it.
  • The score is not calibrated against outcomes. We publish no precision or recall figures, because we have not measured them, and a number we have not measured is not something to put in a table.
  • Part of the trust ranks are still in editorial review. They are in force, and they are not all confirmed.
  • Risk does not cross a chain boundary. The single exception is a direct sanction seed mirrored between EVM networks, and only for plain accounts, never contracts.
  • Clustering is a structural inference. It never becomes an identity claim, but a wrong cluster can still place an address next to one.
  • A claim is only as fresh as its last sync. Sanction and freeze sources are pulled daily, incident sources hourly, and between two runs we hold the previous snapshot.

Questions about a specific number

If a score looks wrong in either direction, ask us for the derivation of that address. We answer with the rows, not with an opinion.

Check an address