Anti-Fraud · Early Access

Wallet Risk Protection: Detect & Prevent Fraud

Flag fraud rings, money laundering patterns, and bonus 
abuse, with the wallet-level evidence behind each flag.
Cluster Analysis

Catch the ring, not the wallet

Your rules clear a wallet because on its own it looks fine. We show you the six others behind it run by the same actor, and what they've taken together.
Every rule you already have re-runs across the whole group - total gain, deposit addresses, platforms hit, win streaks. Individually each account passes. Together they're obviously a ring, and now you can act on it.

Know which fraud you're looking at,
not just that something's off.

Each flag arrives named - signup-bonus abuse, a referral ring, pass-through laundering. Your analyst starts from a fraud type with the evidence attached, instead of a score they have to reverse-engineer.

Signup-bonus abuse

Accounts created to collect the incentive and exit.

Referral abuse

Self-referral rings and farmed referral chains.

Arbitrage exploitation

Sustained positive gain that the house edge says shouldn't happen.

Rakeback wash trading

Volume generated purely to harvest rakeback.

Pass-through laundering

Value in, value out, minimal play in between.

Multi-account farming

One actor, many accounts, 
shared funding and infrastructure.

Explainability

Give your analyst a
reason, not a number

Every flag comes back as something a person can check - 'matches a known referral-abuse signature,' 'two transfers from a known-risky entity.' They verify it in minutes and act, or they clear it and that becomes a label we learn from.

A flag your team can't verify is a flag they won't use.
Wallet
0xb85d...7f22
Evidence
2 hops from a known-risky entity
Signature
Referral abuse
Reasons code
R-14
R-07
R-22
Evidence
Transfer 1
Transfer 2
Flagged Wallet
Intermediate
Known-risky
Uncertain cases route to analyst review
How Detection Works

Four stages, one verdict

One suspicious wallet becomes a complete picture of the actor behind it.
01

Surface

On-chain rules flag a candidate wallet from public activity alone.

02

Expand

The graph pulls in every other wallet and session belonging to the same actor.

03

Re-score

Our rules re-run across the whole cluster, where the totals look nothing like the parts.

04

Classify

The pattern gets named, and independent signals have to agree before anything is flagged.

Policy & Actions

Your thresholds.
Your actions. Your call.

Set your own thresholds, weights and bands, and choose what each one triggers - allow, monitor, hold, or deny. Uncertain cases go to your review queue, not to an automatic decision.

Test any change against the last thirty days before it goes live, so you see what it would have flagged before it flags anything.
Three data panels: 1) Rule Weight with purple bars showing deposit-address count at 0.60, aggregated gain streak at 0.35, and platform coverage at 0.85; 2) Score bands & actions scale with Allow in green (0-40), Monitor in orange (40-65), Review in purple (65-85), and Deny in red (85-100); 3) Dry-run - Trailing 30d showing flag volume at 18% in bold and a bar chart comparing current vs proposed policy with seven purple bars of varying heights.
Diagram showing 'Session Signals' on the left and 'Your existing vendor' on the right, connected to a central logo by three labeled blocks: Device Fingerprint, Behavioural Biometrics, and Verification, with five hexadecimal code blocks below the logo.
Coexistence

Keep the stack
you already run

We don't replace your device fingerprinting or your verification tooling. We add the layer neither side can see on its own - device-first tools watch the session but never the wallets behind it, and chain analytics watches wallets but never the actor.

Every fraud platform has added crypto. This one was built from the chain outward.

Fraudsters work through platforms one by one. Don't be the one that pays

When an actor is flagged anywhere in the network, their risk on your platform rises the same day - before they've done anything to you yet. Your data never leaves your tenant; only the verdict travels.

Separated by contract, not by policy

Isolated infrastructure

Risk engagements run separately from any other Addressable product line.

Tenant separation

Your data never crosses into another client's environment. Only derived risk state is shared across the network.

Contractually enforced

Retention limits, deletion timelines and reuse terms written into the agreement.

Human review by default.

Uncertain cases route to your analysts instead of an automatic decision, and you configure what happens at every band. We don't perform verification ourselves, and we don't disclose our detection methodology or underlying wallet mappings.

Uncover your highest-risk users

Public deposit addresses are all we need to start. Nothing installed on your properties, nothing shared, no integration. We'll come back with the actors costing you money - the wallets, the clusters, and what they've taken.