What WalletShield checks, and what your MLRO gets back.
We screen a wallet address against forty risk categories across five chains, from sanctioned entities and ransomware through to mixers and unregulated exchanges, then return a report your compliance team can file. This page walks through every part of it.
Chains: Bitcoin, Ethereum, BNB Chain, Tron and Litecoin. Sanctions lists: OFAC Specially Designated Nationals, OFSI, EU Consolidated and UN Consolidated. Risk categories: forty, every one reported.
WalletShield is a screening tool. It gives your MLRO (Money Laundering Reporting Officer, the person accountable for a firm's anti-money-laundering sign-off) the evidence to make a decision. It does not make the decision, and it is not regulated advice.
Built by the team behind Greengage, banking partner to crypto-native firms across the UK.
Watch a check run end to end
How a check works, from address to filed report
1. Paste a wallet address
Sign in, open Lookups, paste the address you need to screen and pick the network. There is no integration project, no data feed to build and no procurement cycle to clear first. One credit screens one address, so a reviewer can check a counterparty in the middle of an onboarding call without raising a ticket with anyone.
2. Read the risk score
We trace the address across its transaction graph and return a score from 0 to 100 with a threat level, in minutes rather than days. Alongside the score sit the findings, each with a severity and the share of exposure behind it, so a reviewer can see at a glance what the address is connected to and how much value is involved.
3. File the report
Every check produces a PDF carrying the address, the network, the times it was submitted and completed, the findings, the full risk matrix and a footer on every page with a generation timestamp and a page count. Download it and drop it straight into the case file.
What the risk score is built from
A score on its own is not evidence. WalletShield shows the working behind it.
- Direct or indirect exposure. Direct means the address transacted with a flagged address itself. Indirect means it is connected through intermediary addresses, and the report gives the hop distance for each source.
- Share of exposure. Every finding carries the percentage of volume behind it, rather than a yes or no.
- Severity, not just a flag. Findings are graded, so a reviewer can tell a critical hit from something that merely warrants a note.
- The categories that came back clear. The report prints the complete risk matrix, so a reviewer can see what was checked and cleared, not only what was found.
Forty risk categories, every one of them reported
Sanctioned entities
We report on-chain identifiers listed or blocked by sanctions authorities, separating direct matches from indirect ones and giving the hop distance for each source. Sanctions findings carry the most regulatory weight of anything on the report, so we never let a summary score bury them.
Ransomware and terrorism financing
We screen for addresses linked to ransom demands and ransomware operations, and for value movement in support of designated terrorist organisations. These are the two findings most likely to end a counterparty relationship on the spot, and they are graded at the top of the severity scale.
Obfuscation and privacy services
We flag funds routed through services that pool and redistribute value to break on-chain linkability, and report the share of volume involved. This exposure rarely has an innocent explanation at any scale, and it is one of the first things a reviewer gets asked to account for.
Illicit marketplaces
We report exposure to marketplaces dealing in illicit goods, stolen credentials and payment data on their own lines rather than folding them into a general high-risk figure, so your reviewer can weigh each as the distinct finding it is.
Stolen funds and exploits
We flag addresses connected to known thefts, wallet compromises and protocol exploits, and quantify the exposure. This is the category that most often turns up on a counterparty that looked entirely ordinary until someone screened it.
Unregulated and high-risk venues
We mark volume traced to exchanges with weak compliance controls, peer-to-peer platforms with limited customer due diligence and high-risk jurisdictions. On its own none of that is a reason to decline a counterparty, but it is a reason to look closer, and the report says so in those terms.
The report your MLRO files
Every screen produces the same document, whether the result comes back clear or flagged.
- Lookup information: the full address, the network, the status, and the times the check was submitted and completed, in UTC.
- The risk score, with its threat level, ahead of any of the detail.
- A plain-English risk assessment, followed by the assessment details behind it.
- The findings, each with a severity grade, a category and the share of exposure behind it.
- The complete risk matrix: all forty categories with a status against each, so the reader sees what was cleared as well as what was found.
- Source exposure, listing each source with its hop distance from the address you screened.
- The exposure breakdown, split into direct and indirect.
- A footer on every page carrying the generation timestamp and the page number.
Read a real report before you sign up
Download a full WalletShield report and judge the output yourself. It is the same document your team would file, with illustrative data in place of a real address.
Download a sample reportBuilt for a compliance team, not one person's laptop
Shared workspaces
Screening lives in a workspace the whole team can see, not in one reviewer's browser history. Everyone works from the same record, so holiday cover and handovers stop being a gap in your audit trail.
Role-based access
Give each person the access their role actually needs, so reviewers can screen and file while control of billing and workspace settings stays where it belongs.
Lookup history
Every check your team has run stays in one place with its date and its result, so re-opening a case six months later takes seconds instead of a hunt through somebody's inbox.
Enforced two-factor authentication
Members secure their account with an authenticator app or a code to their mobile, and an administrator can require it across the whole workspace in one setting. Existing sessions can be revoked the moment the policy changes, and the change is recorded against the person who made it.
Self-serve credits and billing
Subscribe, watch your remaining credits and change plan yourself from inside the product. One credit screens one wallet address, allowances reset each month, and there is no setup fee.
No integration project
You can be screening the same day you subscribe. There is no data feed to build, no vendor onboarding pack to complete and no procurement cycle to clear before your first check.
Coverage in full
- Chains screened: Bitcoin (BTC), Ethereum (ETH), BNB Chain (BNB), Tron (TRX) and Litecoin (LTC).
- Sanctions lists checked: OFAC Specially Designated Nationals (United States), OFSI Consolidated List (United Kingdom), EU Consolidated List, UN Consolidated List.
- Risk categories screened: 40, from sanctioned entities and ransomware through to mining pools and network fees. Every category appears on the report with a status against it.
- Report format: A4 PDF. Length follows the findings, so a clean address produces a shorter document than a heavily exposed one.
- Where screened data is held: the United Kingdom. Completed lookups and their reports are retained for five years.
What WalletShield is not
We would rather you knew the limits before you bought than after.
- It is not a compliance decision. WalletShield is a screening tool. It gives your MLRO the evidence; your MLRO decides what to do with it and remains accountable for that decision.
- It is not regulated advice. A risk score is a signal, not a determination.
- It is not a KYC platform. WalletShield does KYT (Know Your Transaction, screening the money flows behind an address). Verifying who your customer is sits elsewhere in your stack.
- It is not a black box. Every score arrives with the working: the flags, the hops, the value exposed and the lists checked.
You can see the output before you buy any of it. The sample report is a full WalletShield report with illustrative data in place of a real address.
Monthly plans, no enterprise contract
One credit screens one wallet address. Allowances reset each month and the per-check cost falls as volume rises. No setup fee, no long-term commitment.
Subscription Plans
Starter
Pre-revenue VASPs, OTC desks, family offices doing periodic counterparty screening
- 100 credits/month
Compliance
Established VASPs, EMIs, crypto-OTC desks with a real MLRO function
- 400 credits/month
Enterprise
Scaled exchanges, neobanks, payments platforms
- 1500 credits/month
Questions we get asked
Start screening, or read a report first
Create an account and subscribe to start screening today. If your team wants to see the output before committing to anything, download a sample report instead.
Get startedScreening at higher volume, or need something bespoke? Talk to our team