BLOCKSEC WALLET SCREENING HUB

Crypto Wallet Screening: The Wallet Risk Hub

Wallet Screening
September 29, 20269 min read6 guides

Wallet risk has two halves, and this hub maps both. The first half is who you deal with: screening a wallet address for risk before you accept it, which is the check exchanges, payment services, and custody providers run at onboarding. The second half is what you sign: reading a transaction before your key approves it. The sections below cover each half, then the guides.

The page reads in workflow order. First what screening is and why it stopped being optional, then where it sits in your process, what a result contains, and how teams grow from manual checks to automation. The second half turns to the signing side of wallet risk, for people who hold their own funds. A navigation table at the end lists every guide in the family.

What Wallet Screening Is

The check you run before you accept a wallet

Screening is a risk check on a wallet address. The address is compared against databases of risk labels and behavior signals, and the output is a risk rating that informs a business decision: accept this wallet, review it, or walk away. It runs before funds move, when a customer first deposits, and again whenever the relationship continues.

The question it answers is narrow and public: what has this address been doing? An address on a blockchain is a visible record of every transfer it has ever made. Screening turns that history into a risk picture, so whoever approves the deposit is looking at evidence rather than a bare string of characters.

What counts as accepting a wallet depends on the business. An exchange accepts one when a deposit lands; a payment service when a payout is requested; a custody provider when a client brings an address in. The check is the same in each case, and in each case it runs before the relationship starts rather than after.

How it differs from KYC and transaction monitoring

The two checks screening gets confused with are identity and monitoring. KYC answers to documents and settles who the person claims to be; screening answers to the chain and settles what the address has been doing. Run only the first, and a fully identified customer can still deposit from a wallet tied to stolen funds, which is the gap screening exists to close.

Transaction monitoring is the third member of the set, and the border runs along time. Screening is a point in time check: run it now, get a picture of now, decide. Monitoring is continuous: after a wallet is accepted, watching continues, because risk attached to an address can change with new behavior. Screening is the door check; monitoring is what happens after the door opens.

Why Screening Became Non-Negotiable for VASPs

The compliance floor, not a bonus

Virtual asset service providers used to treat wallet checking as a differentiator. Regulators have moved it to the floor. The FATF recommendations, applied through national rules, expect firms to understand where funds are coming from, and the Travel Rule extends that to passing originator information along with transfers. In Europe, MiCA pulled the same expectations into a single market framework.

What this means in daily terms: a platform receiving deposits that have passed through cross chain bridges, decentralized exchanges, or mixing services is expected to know that, and to have checked the wallets involved. That is exactly the job screening does. It is no longer evidence of extra care; it is the minimum a licensed business shows its examiner.

Examiners, for their part, ask a plain question: show me how you check wallets and what you did with what you found. A screening record answers the first half, and a written policy with decisions attached answers the second. Neither half is optional anymore, and neither can be reconstructed honestly after the fact.

Where the deep regulatory guides live

This hub stays on the practical side: how to check wallets and how to read what you sign. The regulatory layer underneath, framework by framework, is its own topic. For the anti money laundering side of the house, the AML hub collects the deeper guides, and this family links into them where workflows connect.

Where Screening Sits in Your Workflow

Screening is not one event but a position in a sequence. The map below shows the stations most teams recognize, and each one has a dedicated guide.

Screen at onboarding

The first check is the cheapest and most useful one you will ever run on a relationship: one address, one risk rating, before any funds move and before a wrong acceptance becomes a dispute. Your written policy, not the moment, decides what each rating means. The full four step version, from first check to audit ready records, is How to Screen a Crypto Wallet.

Keep watching after you approve

A wallet that passes today can receive tainted funds tonight, which is why approval starts monitoring rather than ending it. Risk ratings move with new activity, and the alert that matters is a level change on an address you already accepted. The question that comes up most often on this point, whether a clean wallet can turn risky, has its own deep dive in the KYT family.

Scale up and respond

When daily volume passes what a person can check well, the checks move into the pipeline: batch endpoints, automated results, and alert channels instead of copy and paste. The last station is response: every alert gets a decision, and the ones that cross the line become the backbone of a suspicious activity report. The automation route has its own guide, covered two sections below.

Read Next

What a Screening Result Contains

A result is built to be read fast and defended slowly. The headline is a risk rating on five levels, none through critical, returned in under 100 milliseconds for a single address (per BlockSec). Underneath it sits the evidence: more than 600 million risk labels maintained around the clock, over 200 risk signals, 17 risk indicator categories, and coverage of about 10 screening chains.

The two layers do different jobs. Labels are the memory: sanctions listings, scam operations, stolen funds, mixing services, each tying an address to a known risk category. Signals are the behavior: patterns in how an address is moving now, which move a score even when no label applies yet.

Reading the levels into actions is where policy takes over. None means ordinary today; low and medium mean exposure worth a human look; high and critical mean direct ties most policies route to rejection or a freeze. The band boundaries come from the tool; what happens inside each band is written by the operator, in advance, and applied the same way every time.

The third property is explainability. A rating a regulator cannot question is worth little at audit time, so the result needs to show its evidence: which labels, which signals, which chain. The reasoning behind risk scores, and how to defend them, gets the explainable scoring treatment in the AML family.

From Manual Checks to Automated Screening

Most programs climb the same ladder, one rung at a time.

Start with one address

The entry point is deliberately light: register on the BlockSec site and three risk checks a month are free, and each one returns the five level rating for a single address in seconds. This is the search-first model, and it is also the fastest way to see what labels and signals add up to before any workflow discussion.

When volume demands the API

The trigger for the next rung is honest: the first check that gets skipped because there was no time for it. At that point screening has stopped being a control, and batch endpoints take over: whole lists of addresses in, structured ratings out, run inside your own pipeline. The endpoints, rate limits, and alert wiring are covered in Automated Address Screening.

Let monitoring watch for changes

The top rung closes the loop. Accepted addresses go onto watch lists, risk change events push alerts through the channels a team actually reads, and the workflow becomes screen, approve, watch, respond, with records at every step. That is the shape an examiner expects to see, and the shape that survives an incident.

The discipline worth naming is response latency. An alert that sits unread for a weekend is a monitoring program in name only. The design question is not just which channels but how fast a level change reaches a person who can act, and what that person does first.

Read Next

The Other Half of Wallet Risk: What You Sign

The first half of wallet risk is who you deal with. The second half is what you approve: a hardware wallet showing a screen of hexadecimal you cannot read is asking you to sign something you cannot see. The largest thefts of the past two years happened exactly there, with keys never stolen and owners signing willingly. This half of the hub is for people who hold their own funds.

When you cannot read what you are approving

Blind signing is the name for approving a transaction whose content you cannot read. Contract calls travel as encoded data, and a signing device with a small screen often cannot turn them back into words, so it shows the raw form instead. In the Bybit incident of February 2025, close to 1.5 billion dollars left an exchange after an interface presented a transfer while the transaction actually performed a contract upgrade.

This is the layer Safe{Wallet} Monitor, a separate tool in our security line rather than part of the compliance stack, works on. It translates transaction payloads into clear, human-readable explanations, checks what a transaction would actually do, and can warn in the window before signing finishes and before the transaction reaches the chain. The concept, the cases, and the honest limits of what translation fixes are covered in the blind signing guide.

The four routes into signing safety

Four guides cover this half, each one a different question. The blind signing guide answers what is happening when the screen shows unreadable data. The multisig guide answers when signing power should be split across several keys, and what that trade costs. The seed phrase storage guide answers how the recovery words themselves should be kept. And the multisig check routine walks one transaction through four checks before the final signature.

One boundary note: transaction ordering attacks, MEV, and sandwich attacks are a different risk and are not covered here.

Read Next

Phalcon Compliance

What the screening engine covers

Phalcon Compliance runs a KYA and KYT pair of engines: address screening and transaction screening on the same data. The label library holds more than 600 million risk labels, updated around the clock, across about 10 screening chains. On speed, screening responses come back in under 100 milliseconds (per BlockSec), which is what high volume deposit and withdrawal pipelines need at peak.

The two engines split the work cleanly. KYA screens the address itself, the right check for onboarding and deposit review; KYT screens the transaction, following the funds as they move. Most workflows call both, and the results land in the same record shape, which keeps the audit file in one place.

How pricing is shaped

Pricing starts with a free tier: registering on the BlockSec site brings three free checks a month. Past that, credit packages can be bought as needed, or a team can move onto a monthly subscription as screening becomes routine. The intent is that a team can start screening one address at a time and grow into automation without a procurement cycle in between.

Honest limits

Three limits belong in any honest description. Screening lowers risk; it does not remove it, because a snapshot is a statement about today, not a promise about tomorrow. API access sits on the Scale and Enterprise plans, so teams should confirm their plan before building against it. And the tool provides ratings and evidence, while the decisions and the written policy around them remain the operator's own work. The full product details are on the Phalcon Compliance page; for the signing side of wallet risk, the tool is Safe{Wallet} Monitor, which sits in our security line rather than the compliance stack.

Explore the Wallet Risk Family

The family splits into two lines, and every guide holds one position.

Address screening, for compliance teams:

Guide What it covers
What Is Address Screening in Crypto Compliance? The concept: what gets checked, what a risk score means
Automated Address Screening APIs, webhooks, and alert channels at volume
How to Screen a Crypto Wallet The four step manual from first check to audit records

Signing safety, for self custody holders:

Guide What it covers
What Is Blind Signing in Crypto? Why screens show unreadable data, and what a signature really approves
Multisig Wallets When to split signing power, and the honest costs of doing it
Seed Phrase Storage Five storage mistakes that empty wallets, and the discipline that avoids them
How to Check a Multisig Transaction Four checks to run before any large signature

The neighboring KYT hub adds transaction monitoring depth. If you are evaluating where to start: compliance teams begin with the screening concept, self custody holders begin with blind signing.

New guides join this hub as the family grows, and the two lines stay separate on purpose. A compliance team does not need signing habits to run a screening program, and a self custody holder does not need a suspicious activity report workflow to protect a seed phrase. Skim the table, take the one page that matches the day you are having.

Frequently Asked Questions

Screen Wallet Addresses with Phalcon Compliance

Risk screening built on 600M+ labels and 200+ signals: five level ratings in under 100 milliseconds, API and webhooks for scale