Skip to main content
Range’s risk scoring engine aggregates data from multiple independent sources. This page describes the feeds behind risk scoring methodology.
Access to our most sensitive intelligence requires KYB verification. This includes full wallet attribution, cross-chain identity mapping, and advanced risk intelligence. To prevent misuse, these capabilities are available only to verified teams with legitimate use cases.

Sanctions and compliance lists

Range ingests designations from official government and authority publications. Coverage is network-agnostic for published crypto addresses, so an address listed by a sanctioning body is screened regardless of which chain you query. Sanctions and related designations are used by: Many packages designate entities rather than publishing every wallet those entities operate. Range also attributes related addresses from entity footprints and onchain relationships. Inferred associations are distinguished from direct list hits so you can treat them differently in policy and review.

Stablecoin issuer blacklists

Range monitors onchain blacklist events emitted by stablecoin issuer contracts. When an issuer blacklists an address, it is blocked from transferring their tokens. Both blacklist and unblacklist events are tracked, providing current status and event history. See Supported Tokens for the complete coverage matrix.

Onchain indexing

Range operates its own indexing infrastructure across supported networks. Counterparty graphs, volume context, and behavioral signals used by Address Risk (v2) are built from Range’s own parsing of blocks and transactions, not from a third-party reseller feed sitting between confirmation and score.

Threat intelligence

Range maintains a curated attribution dataset from multiple intelligence sources:

Attribution labels

Attributed addresses typically include:
  • name_tag, human-readable label
  • entity, known organization or cluster
  • category, type of activity (e.g. hack_funds, scam, phishing)
Blank attribution fields usually mean confidential sources that cannot be disclosed, or ML-flagged addresses without traditional labels.

Machine learning models

Range’s ML models extend coverage beyond traditional list matching by identifying previously undetected threats through behavioral analysis: payment patterns, timing, and counterparty interactions. Addresses flagged by these models are incorporated into risk scoring alongside traditionally attributed addresses.

Verified non-malicious addresses

Range maintains verified infrastructure attributions to reduce false positives, including:
  • System programs, core blockchain infrastructure (e.g. Solana Token Program, System Program)
  • Major exchanges, verified exchange deposit and operational wallets
  • Verified protocols, established DeFi protocol and program addresses
On Address Risk (v1), these addresses receive the minimum score. On Address Risk (v2), they are treated as known-good attribution so volume alone does not inflate severity. See Understanding Risk Scores.

Data freshness

Once a designation is in Range’s attribution set, related addresses across supported networks can be reflected in subsequent screens without waiting for a separate per-chain republication.

Coverage requests

If you have intelligence about malicious addresses or need coverage for specific threat categories, contact us. We continuously expand data sources based on customer needs and emerging threats.
Last modified on July 29, 2026