Sanctions Lists
Range cross-references addresses against major international sanctions lists. Sanctions data is sourced from official government publications and is network-agnostic - any address published by a sanctioning body is covered.
Sanctions data is used by:
- Sanctions & Blacklist Check - Direct sanctions screening
- Address Risk Score - Incorporated into proximity analysis
- Payment Risk Assessment - Attributed address checks
Stablecoin Issuer Blacklists
Range monitors onchain blacklist events emitted by stablecoin issuer contracts in real-time. When an issuer blacklists an address, it is blocked from transferring their tokens.
Both
blacklist and unblacklist events are tracked, providing current status and full event history. See Supported Tokens for the complete coverage matrix.
Threat Intelligence
Range maintains a curated attribution dataset compiled from multiple intelligence sources. This dataset provides off-chain context that enriches onchain risk analysis.Sources
Attribution Labels
Each attributed address includes metadata:name_tag- Human-readable label describing the activityentity- Known organization or clustercategory- Type of activity (e.g.,hack_funds,scam,phishing)
Machine Learning Models
Range’s proprietary ML models extend coverage beyond traditional attribution by identifying previously undetected threats through behavioral analysis.Capabilities
Addresses flagged by ML models are incorporated into risk scoring identically to those from traditional attribution sources. The
maliciousAddressesFound array in API responses includes both ML-flagged and traditionally attributed addresses.
Verified Non-Malicious Addresses
Range maintains a database of verified non-malicious addresses to prevent false positives. This includes:- System programs - Core blockchain infrastructure (e.g., Solana Token Program, System Program)
- Major exchanges - Verified exchange deposit and withdrawal addresses
- Verified protocols - Established DeFi protocols and their program addresses
attribution field in API responses provides transparency about this override. See Understanding Risk Scores for details.
Data Freshness
Sanctions list updates are ingested within one hour of official publication by the sanctioning body. Once ingested, cross-chain address relationships are resolved immediately, so an address sanctioned on one network is flagged across all supported networks without additional delay.
Stablecoin issuer blacklist events (
blacklist and unblacklist) are detected in real-time as they are emitted onchain. Associated addresses on other chains are propagated instantly.
Threat intelligence ingestion timelines vary depending on the source and the level of verification required. Confirmed exploit addresses are typically ingested within minutes. Reports requiring additional investigation (e.g., community-submitted scam reports) may take hours as the research team validates the data before it enters the scoring pipeline.