# Wallet Screening Risk Categories

When wallet screening surfaces a risk signal on a payment, each entry in `risk_status_reasons[]` carries a `risk_status_reason_category` identifying the specific risk. This page lists the values that field can carry, by `risk_status_reason_type`. Wallet screening is performed by a blockchain analytics provider.

## Ownership indicators

`OWNERSHIP` reasons report risk from the screened wallet's own activity — the wallet is directly associated with or controlled by an entity engaged in the flagged activity. The category is one of the [supported risk categories](#supported-risk-categories).

## Counterparty indicators

`COUNTERPARTY` reasons report risk from wallets the screened wallet has directly transacted with. The category is one of the [supported risk categories](#supported-risk-categories).

## Indirect indicators

`INDIRECT` reasons report risk from wallets the screened wallet has indirect exposure to — two or more hops removed in the flow of funds. The category is one of the [supported risk categories](#supported-risk-categories).

## Entity categories

`ENTITY` reasons report risk from the entity the screened wallet is attributed to. The category depends on the reason's `risk_status_reason_severity`:

- For `Low`, `Medium`, `High`, or `Severe`: one of the [supported risk categories](#supported-risk-categories), describing the attributed entity.
- For `ALLOWLISTED` or `BLOCKLISTED`: the role of the participant that matched your allowlist or blocklist — `ORIGINATOR`, `ORIGINATOR_VASP`, `BENEFICIARY`, `BENEFICIARY_VASP`, `CUSTODY_SERVICE`, or `INTERMEDIARY_VASP`.

## Error categories

`ERROR` reasons carry one of two categories:

- `SCREENING_FAILED` — wallet screening could not be completed. The payment is rejected because it could not be screened, not because of an identified risk signal.
- `Token Contract` — the screened wallet is attributed to a token contract. Direct interaction with a token contract is not expected behavior for an end-user wallet, so the payment is routed to manual review. The reason's `risk_status_reason_participant_id` links it to the payment's `CONTRACT` participant — see [Payment Participants](/overviews/payment-participants).

## Supported risk categories

The categories below are the full set the screening provider may return. On the payment record, `risk_status_reason_category` carries the category name; the category ID appears in the raw screening payload in the payment's `provider_metadata[]` entry.

| Category ID | Category name |
| --- | --- |
| 1 | Wallet Cluster |
| 2 | Adult Content |
| 3 | Decentralized Application |
| 4 | Decentralized File Sharing Service |
| 5 | High-Risk dApp |
| 6 | Decentralized Exchange |
| 7 | P2P Crypto Marketplace |
| 8 | Exchange |
| 9 | Cash-to-Crypto |
| 10 | High-Risk Exchange |
| 11 | Decentralized Marketplace |
| 12 | Non-Custodial Exchange |
| 13 | Payment Processing Service |
| 14 | Crypto Payment Card |
| 15 | Faucet Service |
| 16 | Lending Service |
| 17 | Investment Services |
| 18 | Decentralized Finance |
| 19 | Custody Service |
| 20 | Financial Services |
| 21 | Unhosted Wallet |
| 22 | Hosted Wallet |
| 23 | Gambling Service |
| 24 | Sports Betting |
| 25 | Decentralized Gambling Service |
| 26 | Goods and Services |
| 27 | Gaming |
| 28 | In-Game Virtual Goods |
| 29 | Decentralized Gaming |
| 30 | Decentralized Collectibles |
| 31 | Online Username Reselling |
| 32 | Government Controlled |
| 33 | Hacking Victim |
| 34 | Hacked or Exploited Funds |
| 35 | Known Hacker Group |
| 36 | Human Trafficking |
| 37 | Sexual Exploitation |
| 38 | Child Sexual Abuse Material (CSAM) Vendor |
| 39 | Child Sexual Abuse Material (CSAM) Consumer |
| 40 | Child Sexual Abuse Material (CSAM) |
| 41 | Terrorist Financing |
| 42 | Violent Extremism |
| 43 | Escort Service / Prostitution |
| 44 | Carding / PII Shop |
| 45 | Cybercrime Services |
| 46 | Darknet Market |
| 47 | Banned or Controlled Substances |
| 48 | Counterfeit Goods |
| 49 | Piracy |
| 50 | Illicit Goods and Services |
| 51 | Internet Persona |
| 52 | Multi-Level Marketing Scheme |
| 53 | High Yield Investment Scheme |
| 54 | Ponzi Scheme |
| 55 | Investment Scheme |
| 56 | Decentralized Investment Scheme |
| 57 | Malware |
| 58 | Ransomware |
| 59 | Ransomware Victim |
| 60 | Imposter Site or Service |
| 61 | Scam |
| 62 | Extortion / Blackmail |
| 63 | Scam Victim |
| 64 | ICO Scam |
| 65 | Mining |
| 66 | Mixer |
| 67 | Non-Profit |
| 68 | Politically Exposed Person |
| 69 | Sanctions |
| 70 | Hot Wallet |
| 71 | Cold Wallet |
| 72 | Genesis Address |
| 73 | ICO Wallet Address |
| 74 | Token Contract |
| 75 | Transaction Spam or Dusting |
| 76 | TRON Foundation Address |
| 77 | TRON Representative |
| 78 | Donation Address |
| 79 | Validator Group |
| 80 | Validator |
| 81 | Foundation |
| 82 | Smart Contract |
| 83 | Founder Address |
| 84 | Stablecoin |
| 85 | Custom Cluster |
| 86 | Proxy Services |
| 584 | NFT Marketplace |
| 585 | NFT Project |
| 628 | Child Sexual Abuse Material (CSAM) Scam |
| 629 | Investment Fraud |
| 630 | Decentralized Investment Fraud |
| 633 | Special Measures |
| 636 | Blocklisted |
| 638 | Community Complaint |
| 639 | Trusted Community Complaint |

## Behavioral signatures

`BEHAVIORAL` reasons report transaction patterns commonly associated with illicit activity or funds obfuscation. On the payment record, `risk_status_reason_category` carries the signature's identifier in snake case (for example, `cross_chain_swap` for Cross-Chain Swap); `risk_status_reason_message` carries a plain-English description.

| Signature | Description |
| --- | --- |
| Cross-Chain Swap | Also known as an Atomic Swap. A type of currency exchange used as a mechanism to allow for the movement of tokens, typically via a smart contract, from one blockchain to another. |
| Mixer | A service that programmatically co-mingles assets from multiple users into a centralized pool, often moving the funds in smaller chunks to multiple addresses, before sending funds to the intended recipient. Mixers (sometimes referred to as "tumblers") are often used in an attempt to obfuscate the ownership and source of funds. |
| Peeling Chain | A single address begins with a relatively large amount of cryptocurrency. A small amount is "peeled off" and transferred to one address, often to be deposited at an exchange, while the remainder is transferred to another address owned by the entity. This pattern repeats until the original cryptocurrency has been fully broken up in smaller amounts. This pattern may indicate an attempt to obfuscate the source and destination of funds. |
| Binary Tree | Funds are moved through a series of 1-to-2 transactions into similar amounts, creating a branching pattern. This may indicate layering or an attempt to make the source of funds difficult to detect. |
| Mass Registration | A single address moves funds to multiple separate addresses belonging to the same entity. This may indicate structuring, or the use of multiple individuals and/or transactions to stay under a currency reporting threshold. |
| CoinJoin Transaction | CoinJoin is a method of combining Bitcoin payments from multiple senders into a single transaction in order to obfuscate which senders are paying which recipients. |
| Web Flow Pattern | A single address or entity sends to multiple other addresses in a web-like pattern, before flowing funds back to a single address or entity. This may indicate layering or an attempt to make the source of funds difficult to detect. |
| Extortion with a Common Destination | An address or group of addresses linked to Extortion/Blackmail sends funds to a single, common destination address. This may indicate an entity aggregating proceeds from extortion or blackmail scams. |
| Graphton | Funds are moved through a sequence of transactions that form a notable "trail" on the blockchain. The transactions appear to be conducted by the same entity because they share common traits (e.g., amount, timing, structure). |
