What WalletShield checks, and what your MLRO gets back.

We screen a wallet address against forty risk categories across five chains, from sanctioned entities and ransomware through to mixers and unregulated exchanges, then return a report your compliance team can file. This page walks through every part of it.

Chains: Bitcoin, Ethereum, BNB Chain, Tron and Litecoin. Sanctions lists: OFAC Specially Designated Nationals, OFSI, EU Consolidated and UN Consolidated. Risk categories: forty, every one reported.


WalletShield is a screening tool. It gives your MLRO (Money Laundering Reporting Officer, the person accountable for a firm's anti-money-laundering sign-off) the evidence to make a decision. It does not make the decision, and it is not regulated advice.


Built by the team behind Greengage, banking partner to crypto-native firms across the UK.


Watch a check run end to end

How a check works, from address to filed report

1. Paste a wallet address

Sign in, open Lookups, paste the address you need to screen and pick the network. There is no integration project, no data feed to build and no procurement cycle to clear first. One credit screens one address, so a reviewer can check a counterparty in the middle of an onboarding call without raising a ticket with anyone.

2. Read the risk score

We trace the address across its transaction graph and return a score from 0 to 100 with a threat level, in minutes rather than days. Alongside the score sit the findings, each with a severity and the share of exposure behind it, so a reviewer can see at a glance what the address is connected to and how much value is involved.

3. File the report

Every check produces a PDF carrying the address, the network, the times it was submitted and completed, the findings, the full risk matrix and a footer on every page with a generation timestamp and a page count. Download it and drop it straight into the case file.

What the risk score is built from

A WalletShield risk report showing a score of 82 out of 100 with sanctions exposure flagged

A score on its own is not evidence. WalletShield shows the working behind it.


- Direct or indirect exposure. Direct means the address transacted with a flagged address itself. Indirect means it is connected through intermediary addresses, and the report gives the hop distance for each source.

- Share of exposure. Every finding carries the percentage of volume behind it, rather than a yes or no.

- Severity, not just a flag. Findings are graded, so a reviewer can tell a critical hit from something that merely warrants a note.

- The categories that came back clear. The report prints the complete risk matrix, so a reviewer can see what was checked and cleared, not only what was found.


Forty risk categories, every one of them reported

Sanctioned entities

We report on-chain identifiers listed or blocked by sanctions authorities, separating direct matches from indirect ones and giving the hop distance for each source. Sanctions findings carry the most regulatory weight of anything on the report, so we never let a summary score bury them.

Ransomware and terrorism financing

We screen for addresses linked to ransom demands and ransomware operations, and for value movement in support of designated terrorist organisations. These are the two findings most likely to end a counterparty relationship on the spot, and they are graded at the top of the severity scale.

Obfuscation and privacy services

We flag funds routed through services that pool and redistribute value to break on-chain linkability, and report the share of volume involved. This exposure rarely has an innocent explanation at any scale, and it is one of the first things a reviewer gets asked to account for.

Illicit marketplaces

We report exposure to marketplaces dealing in illicit goods, stolen credentials and payment data on their own lines rather than folding them into a general high-risk figure, so your reviewer can weigh each as the distinct finding it is.

Stolen funds and exploits

We flag addresses connected to known thefts, wallet compromises and protocol exploits, and quantify the exposure. This is the category that most often turns up on a counterparty that looked entirely ordinary until someone screened it.

Unregulated and high-risk venues

We mark volume traced to exchanges with weak compliance controls, peer-to-peer platforms with limited customer due diligence and high-risk jurisdictions. On its own none of that is a reason to decline a counterparty, but it is a reason to look closer, and the report says so in those terms.

The report your MLRO files

Every screen produces the same document, whether the result comes back clear or flagged.


- Lookup information: the full address, the network, the status, and the times the check was submitted and completed, in UTC.

- The risk score, with its threat level, ahead of any of the detail.

- A plain-English risk assessment, followed by the assessment details behind it.

- The findings, each with a severity grade, a category and the share of exposure behind it.

- The complete risk matrix: all forty categories with a status against each, so the reader sees what was cleared as well as what was found.

- Source exposure, listing each source with its hop distance from the address you screened.

- The exposure breakdown, split into direct and indirect.

- A footer on every page carrying the generation timestamp and the page number.


Read a real report before you sign up

Download a full WalletShield report and judge the output yourself. It is the same document your team would file, with illustrative data in place of a real address.

Download a sample report

Built for a compliance team, not one person's laptop

Shared workspaces

Screening lives in a workspace the whole team can see, not in one reviewer's browser history. Everyone works from the same record, so holiday cover and handovers stop being a gap in your audit trail.

Role-based access

Give each person the access their role actually needs, so reviewers can screen and file while control of billing and workspace settings stays where it belongs.

Lookup history

Every check your team has run stays in one place with its date and its result, so re-opening a case six months later takes seconds instead of a hunt through somebody's inbox.

Enforced two-factor authentication

Members secure their account with an authenticator app or a code to their mobile, and an administrator can require it across the whole workspace in one setting. Existing sessions can be revoked the moment the policy changes, and the change is recorded against the person who made it.

Self-serve credits and billing

Subscribe, watch your remaining credits and change plan yourself from inside the product. One credit screens one wallet address, allowances reset each month, and there is no setup fee.

No integration project

You can be screening the same day you subscribe. There is no data feed to build, no vendor onboarding pack to complete and no procurement cycle to clear before your first check.

Coverage in full

- Chains screened: Bitcoin (BTC), Ethereum (ETH), BNB Chain (BNB), Tron (TRX) and Litecoin (LTC).

- Sanctions lists checked: OFAC Specially Designated Nationals (United States), OFSI Consolidated List (United Kingdom), EU Consolidated List, UN Consolidated List.

- Risk categories screened: 40, from sanctioned entities and ransomware through to mining pools and network fees. Every category appears on the report with a status against it.

- Report format: A4 PDF. Length follows the findings, so a clean address produces a shorter document than a heavily exposed one.

- Where screened data is held: the United Kingdom. Completed lookups and their reports are retained for five years.


What WalletShield is not

We would rather you knew the limits before you bought than after.


- It is not a compliance decision. WalletShield is a screening tool. It gives your MLRO the evidence; your MLRO decides what to do with it and remains accountable for that decision.

- It is not regulated advice. A risk score is a signal, not a determination.

- It is not a KYC platform. WalletShield does KYT (Know Your Transaction, screening the money flows behind an address). Verifying who your customer is sits elsewhere in your stack.

- It is not a black box. Every score arrives with the working: the flags, the hops, the value exposed and the lists checked.


You can see the output before you buy any of it. The sample report is a full WalletShield report with illustrative data in place of a real address.


Monthly plans, no enterprise contract

One credit screens one wallet address. Allowances reset each month and the per-check cost falls as volume rises. No setup fee, no long-term commitment.

Subscription Plans

Starter

Pre-revenue VASPs, OTC desks, family offices doing periodic counterparty screening

£299.00 /month
  • 100 credits/month

Compliance

Established VASPs, EMIs, crypto-OTC desks with a real MLRO function

£999.00 /month
  • 400 credits/month

Enterprise

Scaled exchanges, neobanks, payments platforms

£2,500.00 /month
  • 1500 credits/month

Questions we get asked

Minutes, not days. You submit an address, we trace it, and the report is ready in your lookup history when it completes. There is no scheduling, no analyst queue and no waiting on a vendor to come back to you.

Chains: Bitcoin, Ethereum, BNB Chain, Tron and Litecoin. Sanctions lists: OFAC Specially Designated Nationals, OFSI, EU Consolidated and UN Consolidated. Risk categories: forty in total, ranging from sanctioned entities, ransomware and illicit marketplaces through to low-risk classifications such as mining pools and network fees. Every one of the forty appears on the report with a status against it.

Direct exposure means the address you screened transacted with a flagged address itself. Indirect exposure means it is connected through one or more intermediary addresses, which we call hops, and the report states how many. Both are reportable, and your MLRO decides the treatment.

The address, network and status, the times the check was submitted and completed, a risk score from 0 to 100 with its threat level, a plain-English risk assessment and the assessment details behind it, the findings with a severity and share of exposure against each, the complete matrix of all forty risk categories with a status for every one, source exposure with the hop distance for each source, the exposure breakdown split into direct and indirect, and a footer on every page carrying the generation timestamp and the page number.

One credit screens one wallet address. Each plan includes a monthly allowance that resets at renewal, and unused credits do not roll over. If you run out mid-month, further checks are held until you buy a credit bundle or move up a plan. Nothing is charged automatically beyond your plan, so you cannot run up an unexpected bill.

Yes. The sample report page carries a full WalletShield report with illustrative data in place of a real address, so you can judge the document itself before you buy.

Your screening data is hosted in the United Kingdom. We keep completed lookups and the reports they produced for five years, which matches the record-keeping period your own anti-money-laundering obligations run to, so the evidence behind a decision outlives the decision itself. After five years it is deleted.

No, and we would not claim it does. WalletShield is a screening tool that produces evidence. Your MLRO reviews that evidence, makes the decision and remains accountable for it.

Yes. Workspaces are shared and access is role-based, so reviewers work from the same record and the audit trail sits in one place rather than on individual laptops.

Start screening, or read a report first

Create an account and subscribe to start screening today. If your team wants to see the output before committing to anything, download a sample report instead.

Get started

Screening at higher volume, or need something bespoke? Talk to our team