Loading ForensicBlock
Preparing your blockchain forensics platform...
Preparing your blockchain forensics platform...
ForensicBlock's risk scoring model is designed to be transparent, reproducible, and legally defensible. Every score can be traced back to specific on-chain data and verifiable risk factors.
Model version: v1.7.6 | Last updated: July 2026
The ForensicBlock risk score is a tiered, evidence-weighted composite of independent risk signals. Every finding is classified by evidence tier — HARD (attributed, anchored evidence), STRONG (corroborated behavioral signals), SOFT (uncorroborated indicators) — before any aggregation. HARD evidence floors the verdict at CRITICAL; SOFT evidence alone can never push a score into HIGH. The model uses no black-box components — every factor, threshold, and floor is documented here and versioned.
Scoring is tier-ordered, not flat-weighted: entity attribution overrides, exposure analysis is primary, graph and behavioral signals are supplementary context. The final score is reconciled so a lower-tier signal can never dilute higher-tier evidence.
Verified ground-truth entity match. When an address matches a known entity in our curated database (450+ active entities including OFAC SDN, state actors, known hackers, with 2,300+ address attributions), the entity's risk score is used directly. Entity attribution always overrides all other scoring methods. Every attribution carries source and explicit confidence.
Data source: ForensicBlock Intelligence Database, OFAC SDN List
Deterministic scoring based on counterparty transaction exposure. For each transaction, the counterparty address is categorized (sanctions, darknet, mixer, fraud, exchange, DeFi, unknown) and exposure contributes by category weight and confidence. As of methodology v1.7.6, sanctioned exposure floors the verdict at CRITICAL only when it is SUBJECT-LINKED — a directed fund-flow path between the subject and the sanctioned counterparty within the traced graph. Sanctioned entities present elsewhere in the graph render as contextual intelligence with hop distance, never as a verdict override.
Data source: Graph analysis, pre-computed exposure_analysis, entity database lookups
Risk derived from the full transaction graph traversal — node-level risk aggregation, high-risk path detection, and cluster analysis. Used when exposure analysis data is not yet available or as supplementary context.
Data source: ForensicBlock Graph Engine, Alchemy Asset Transfers API
AI agent-based behavioral scoring — transaction velocity, pattern detection, anomaly analysis. Used as supplementary context when entity and exposure data are unavailable. The MAX of all tiers is used as the final score — behavioral analysis never dilutes a higher-tier score.
Data source: ForensicBlock AI Agent Pipeline (6 agents)
Sanctions/OFAC (weight 1.0), Terrorist Financing (1.0), State Actor (1.0), Darknet Market (0.85), Ransomware (0.85), Stolen Funds (0.85), Mixer/Tumbler (0.80), Fraud/Scam (0.80), Cybercrime (0.80), High-Risk Exchange (0.55), P2P Exchange (0.45), Gambling (0.35), Unregulated Service (0.40), Cross-chain Bridge (0.30), Regulated Exchange (0.05), DeFi Protocol (0.10), NFT Marketplace (0.05), Unknown (0.15).
Data source: lib/risk-categories.ts — FATF typology framework
LOW: 0–39. MEDIUM: 40–69. HIGH: 70–89. CRITICAL: 90–100. Same address + same blockchain state = identical score every time. Methodology version: v1.7.6.
Data source: Deterministic computation — reproducible and court-defensible
Number of distinct token types held or transacted. Unusually high token diversity may indicate DeFi farming, airdrop harvesting, or wash trading.
Data source: Alchemy getTokenBalances
Time since the address's first on-chain activity. Addresses less than 30 days old receive elevated risk scores (up to 70 for brand-new addresses) as they are more likely to be disposable addresses used in laundering schemes.
Data source: First transaction timestamp
score = baseline; HARD evidence → floor at 90 (+2 per additional HARD factor, max +10); STRONG factors → saturating sum (cap 70); SOFT factors → log-saturating sum (cap 35); level = canonical band lookup
The caps are chosen so evidence tiers cannot impersonate each other: STRONG signals alone can reach HIGH but never CRITICAL (CRITICAL requires HARD, attributed evidence), and SOFT signals alone top out at the bottom of MEDIUM. Verdict floors (sanctions, attributed mixer, illicit-entity) apply only to subject-linked exposure — see the v1.7.6 changelog entry below. Every scored result carries its full derivation: base score, each factor, each floor that fired, and which subject-linked address triggered it.
Every risk assessment includes a confidence score (0.20–0.95) reflecting the completeness and quality of available data:
One scale governs every surface — this page, the product UI, and the sealed report verdict all map scores through the same published bands (engine constant TIER_THRESHOLDS, unchanged since v1.5.0 so historical scores stay comparable).
No significant risk indicators. Standard due diligence sufficient. Scores 0–9 carry no elevated risk indicators at all.
Some risk indicators present. Enhanced due diligence recommended.
Multiple corroborated risk indicators. Investigation and compliance review required.
Severe risk backed by hard evidence — subject-linked sanctions exposure, attributed mixer usage, or confirmed illicit activity.
During full investigations, ForensicBlock employs six specialized AI agents. Each agent produces independent findings that are cross-validated by the orchestrator:
Findings must be verified against on-chain evidence before being included in the final report. The overall confidence score is reduced proportionally to unverified findings: adjusted = confidence * (0.5 + 0.5 * verificationRate)
Primary blockchain data provider. Real-time transaction data, asset transfers, token balances, and webhook-based monitoring across EVM chains.
Secondary provider for historical transaction data. Multi-chain support via chain ID parameter.
Official U.S. Treasury Specially Designated Nationals list. Updated regularly and cached locally with 5-minute refresh cycles.
Curated database of 450+ active entities and 2,300+ address attributions covering exchanges, DeFi protocols, bridges, mixers, scams, and sanctioned entities — every attribution with source and explicit confidence.
ForensicBlock is designed for legal proceedings:
Methodology changes ship as new, dated versions. A sealed report permanently cites the version (and its SHA-256 content hash) it was generated under — prior sealed reports are never retroactively re-scored or re-versioned. That discipline is what makes the version stamp on a report mean something.
v1.7.62026-08-10activeSeeding-origin floor. When a subject's SEEDING funding — its first observed inbound transfer AND the dominant share of its capitalization window (inflow up to first outflow) — is attributed to a catalogued illicit entity (theft, hack, exploit, ransomware, sanctioned, and the related categories), that origin floors the verdict: HIGH for an illicit-catalog funder, SEVERE for a sanctioned one, graded by the shared entity-risk classifier. The floor is deliberately narrow: it applies only to seeding, never to incidental receipt. An exchange deposit address that receives from a designated entity, a victim wallet receiving returned funds, and an unsolicited above-dust transfer into an already-funded wallet are all excluded, because in each the illicit inflow is neither the first funding nor the dominant share. The floor is disclosed as a statement about the wallet's origin, not a determination that the subject itself is designated; the earlier funding-source signal (an origin lead, not a floor) is unchanged for non-seeding cases.
v1.7.52026-08-03Authorship and evaluability disclosure. Text-pattern classification into the STRONG evidence tier now requires the finding to carry high or critical severity, matching the bar already applied to the highest tier. A finding authored by the analytical model itself — a disclosed model diagnostic — can no longer be classified above the lowest evidence tier by text pattern; typed evidence produced by a deterministic engine remains the authoritative path and is unaffected. Where subject-linkage could not be evaluated for a finding because it carries no typed address, the finding remains floor-eligible (conservative) and the report states that linkage was not evaluated for it rather than presenting a linkage determination. Where a categorical floor rests on findings that carry no evidence anchor, the report states the anchor state alongside the floor: a designation is never withheld on a bookkeeping ground, and the exhibit no longer asserts one exclusion rule while applying another.
v1.7.42026-07-05Affirmative-evidence text classification. Text-pattern evidence-tier classification requires affirmative, non-negated language: a finding whose prose negates the matched term (for example, "no sanctioned addresses identified") is treated as a disclosure of a clean result, not as a hit. High-tier text classification additionally requires the finding to carry high or critical severity. Typed evidence attribution (entity category, factor tier) remains the authoritative classification path and is unaffected.
v1.7.32026-07-05Evidence-grade linkage. The subject-linkage fund-flow analysis traverses native-value edges only; token-denominated transfers contribute undirected graph-proximity context but never a verdict floor. When a traced graph is evaluated, attributions that cannot be located within it are treated as contextual intelligence rather than verdict drivers. A conservative unscoped mode applies, and is disclosed, when no traced graph is available.
v1.7.22026-07-02Verdict floors (sanctions / mixer / illicit-entity) now apply only to SUBJECT-LINKED exposure — attributions with a directed fund-flow path to or from the investigation subject. Peripheral attributions elsewhere in the traced graph render as contextual intelligence with hop distance, never as a verdict override. Published risk bands reconciled to the engine's canonical thresholds (Low 0–39, Medium 40–69, High 70–89, Critical 90–100).
v1.7.12026-06-12Finding hygiene ahead of scoring: pattern-class deduplication (corroboration raises confidence, not count), unanchored findings excluded from scoring, unattributed structural/mixer findings capped at STRONG — "potential X" never counts as "X confirmed".
v1.7.02026-03-15Tiered evidence-weighted scoring: every finding classified HARD / STRONG / SOFT before aggregation. HARD evidence floors the verdict at SEVERE; SOFT evidence alone can never reach HIGH. Methodology version + SHA-256 content hash stamped on every scored result.
Federal Rules of Evidence 902(13) and 902(14), in effect since 12/01/2017, allow electronic records to self-authenticate when accompanied by a qualified person's written certification. Rule 902(13) covers records generated by an electronic process; Rule 902(14) covers data copied from an electronic device. Both rules eliminate the need for a live custodian to authenticate at trial.
What our sealed reports carry:
What 902(13)/(14) does NOT do — the over-claim we never make:
Self-authentication is not the same as admissibility. The fact that a record self-authenticates means a court will accept that it is what it claims to be — a record generated by our electronic process. It does not resolve hearsay (FRE 801–807), relevance (FRE 401–403), or the Daubert qualification of the underlying methodology (FRE 702). Those remain separate hurdles your counsel argues independently. ForensicBlock packages for self-authentication; we never represent that a sealed report is "automatically admissible."
In U.S. v. Sterlingov (D.D.C.), the court admitted commercial blockchain analysis under FRE 702 after a Daubert challenge. The reliability inquiry turned on whether the method was documented and reproducible and whether the analyst could explain it — not on the vendor. ForensicBlock is built to answer that inquiry by handing over the derivation for the other side to re-run, rather than defending a black box from the stand.
The Daubert factors, mapped to ForensicBlock:
What we don't carry to court:
Every sealed court-ready report carries these 32 sections, in this order. This list is rendered from the same template definition the report generator executes — the published spec and the shipped report cannot drift apart. Standardization is part of the moat: opposing counsel can verify against a fixed spec; expert testimony lands on the same scaffolding every time. A section with no underlying data still appears, explicitly marked as unpopulated with the reason — honest empty, never a silent omission.
Every investigation can produce a single downloadable JSON envelope — the Audit Pack — that carries everything a defense expert, opposing counsel, or regulator needs to reproduce, challenge, or independently verify the report. The pack is sealed under a self-hash so any tampering is immediately detectable.
What the pack contains:
Why this is the moat:
What the proprietary incumbents cannot ship: attribution you can republish in an exhibit (their label databases are license-locked), a public verifier opposing counsel can open without an account, and an exportable, self-hashed Audit Pack that lets a defense expert re-derive the work. We win by going the other way: every methodology decision is public on this page, every input recorded, every output exportable, every audit-log entry hash-chained. Defense experts who try to invalidate our reports end up re-deriving the same conclusions — and that is precisely the surface our sealed certifications stand on.
The pack is available per investigation from the investigator's detail page ("Quick Actions → Audit pack") and from the report detail page once a report has been sealed. Authenticated users get the pack scoped to their own matters; for public audit of a specific sealed report, opposing counsel can request the pack from the issuing firm or use the public verifier.
Try a free risk check on any blockchain address, or sign up to run full forensic investigations with all six AI agents.