The Short Answer
Address screening is the check you run on a wallet address before you do business with it. The address is compared against label databases and risk signals, and you get back a risk rating that informs the call to accept, review, or walk away. Exchanges, payment services, and custody providers run it at onboarding and again whenever money moves.

The question it answers is simple: what has this address been doing? An address is a public record of everything it has sent and received. Screening turns that record into a risk picture, so that the person approving a deposit or a withdrawal is looking at evidence rather than a bare string of characters.
It is worth separating this from identity checking right away, because the two get confused constantly. KYC asks who the person is, and answers with documents. Address screening asks what the wallet has done, and answers with blockchain history. A platform needs both, but they are different checks run on different inputs, and this page is about the second one.
What Actually Gets Checked
Three layers go into a screening result. A label database holds more than 600 million risk labels on addresses, refreshed around the clock (per BlockSec). Over 200 risk signals weigh how an address behaves, and 17 risk indicator categories give the patterns names. And chain coverage, about 10 screening chains, decides how much of that behavior is even visible.
The label layer is the memory. Sanctions lists, scam and phishing operations, addresses linked to stolen funds, mixers and other laundering services: each label ties an address to a known risk category. Sanctions lists such as the OFAC SDN list are one of the primary sources a screening database builds on, which is why the OFAC SDN list is where the underlying listings live. The global expectation that crypto businesses screen comes from the risk-based approach set by the Financial Action Task Force. It treats knowing who your funds are coming from as a baseline duty rather than an optional extra.
The signal layer is the behavior. Labels tell you what an address was called; signals tell you what it just did. Rapid movement through fresh wallets, interaction with high-risk contracts, links to addresses that later got flagged: these patterns move a risk score even when no clean label applies yet.
The chain layer is the field of view. Screening runs per chain, so a database covering about 10 chains sees activity on each of those networks and nothing on the rest. When you read a result, you are reading it for the chains the tool covers.
When you open a result, read it in that order: the rating is the headline, the labels are the heaviest evidence behind it, and the signals explain movement the labels do not yet cover. A high rating backed by a sanctions label is a different decision from a medium driven by indirect signals, and a policy worth having treats the two differently.
What the Risk Score Means
A screening result lands on a five level scale: none, low, medium, high, and critical, produced in under 100 milliseconds for a single address (per BlockSec). The score is evidence, not a verdict. It tells your team how much scrutiny a wallet deserves, and your written policy decides what happens next at each level.
None means the address looks ordinary today. Low and medium usually mean some exposure worth a human look, often through an indirect connection. High and critical mean direct ties to sanctioned or criminal activity, and most policies route those straight to rejection or a freeze for review.
| Level | What it usually means | A common policy response |
|---|---|---|
| None | No labels or signals attached today | Accept, keep watching |
| Low | Some exposure, often indirect | Accept or review, per policy |
| Medium | Exposure worth a human look | Review before deciding |
| High | Direct ties to sanctioned or criminal activity | Reject or escalate |
| Critical | The strongest direct ties in the evidence | Reject and consider reporting |
Two habits make scores actually usable. First, the decision rules belong to your policy, not to the tool: whether medium means review or decline is a compliance call, written down in advance, applied the same way every time. Second, the score has to explain itself. When a regulator asks later why a deposit was allowed, "the tool said medium" is not an answer; the underlying labels and signals are. Choose screening that shows its evidence, and keep the records.
A Snapshot Is Not a Promise
A clean result is a statement about today, not a promise about tomorrow. An address can pass screening in the morning and receive stolen funds at night, which is why the check at onboarding is the first step of a workflow, not the whole workflow. What follows the snapshot is monitoring.
This is the half of the question that trips people up. Users ask whether crypto wallets can be clean one day and risky the next, and the honest answer is yes: risk is attached to behavior, and behavior continues. The full explanation of how a wallet's risk changes over time is covered in Can a Crypto Wallet Become Risky After Being Clean?, which is the deep dive on that exact question.
The practical shape of the workflow is: screen at the door, watch after you let someone in, and rescreen when something changes. This page is the first step; the rest of the family, from the four step manual to the automated pipeline, is mapped in the wallet screening hub.
Trying One Address Yourself
You can see what a result looks like before any contract. Register on the BlockSec site and three risk checks a month are free: paste an address, and the five level rating comes back in seconds. Trying one address is the fastest way to see what the labels and signals add up to.
That is the search-first model: check a single address for free, see the evidence behind the score, and only then think about workflow. When checks become a daily habit or a team routine, the next steps are the four step manual for making screening repeatable, and the API route for making it automatic. The manual is How to Screen a Crypto Wallet, which turns this concept into a working procedure: check, connect, watch, and keep records.
What you are looking at in a result: the five level rating at the top, then the evidence underneath, the labels with their categories and the signals that fired. A rating with no visible evidence behind it is a gap worth noticing, because a number alone cannot be defended later.