The 50 Riskiest Wallets in Plastron's Data Are Hackers, Not Scammers

By Alexandr Kerya · · 5 min read

Only 50 of Plastron's 3,901 labeled addresses carry a critical risk score, and 48 of them trace back to bridge or DeFi hack exploits, not sanctions lists or garden-variety scam reports.

Run enough wallet checks and eventually one comes back marked critical, the tier Plastron reserves for confirmed bad actors, not casual scam flags. That result means something specific, and the dataset behind it is public.

What's Actually in the Critical-Risk Tier?

Plastron's labeled corpus holds 3,901 addresses split across four risk levels: high (3,478), medium (259), neutral (114), and critical (50). Critical is the smallest tier by far, 1.3% of the whole set, and it doesn't behave like the rest of the corpus.

The overall dataset skews toward scam and fraud labels: 3,354 addresses tagged scam, 280 tagged fraud. Inside the critical tier, that pattern disappears. Forty-eight of the 50 critical addresses carry an entityType of hack_exploit. The other two are mixer addresses, Blender.io and Sinbad.io. Not one is labeled plain scam.

Critical, in this dataset, means one thing: money moved through a confirmed exploit, not a phishing link or a fake giveaway.

Comparison chart: the critical-risk tier split into 48 hack-exploit and 2 mixer addresses, next to list-size context showing the tier's 50 addresses against 4 OFAC overlaps and the full 780-address OFAC SDN list.Critical tier by type (50)List sizes compared- hack_exploit - 48- Critical tier - 50- mixer - 2- Also on OFAC list - 4- Full OFAC SDN list - 780
Of the 50 critical-risk addresses, 48 are hack-exploit entries, and only 4 also appear on the separate 780-address OFAC SDN list.

Which Named Hacks Show Up in the Data?

About a dozen of the 48 hack_exploit entries carry a specific incident name. The rest are generic "Heist address" rows sourced from Forta's labelled-datasets feed, flagged for exploit activity without a named event attached.

The named ones read like a timeline of DeFi's worst weeks. Wormhole's bridge lost roughly $325 million on February 2, 2022. Ronin, the sidechain behind Axie Infinity, lost close to $540 million on March 23, 2022, an attack the U.S. Treasury attributed to North Korea's Lazarus Group, sanctioning one of the addresses on April 14, 2022. Nomad's bridge leaked about $190 million on August 2, 2022, after a contract upgrade let anyone copy the first successful exploit transaction. Euler Finance took a $196 million flash-loan hit on March 13, 2023. Multichain lost roughly $130 million to unauthorized withdrawals starting July 6, 2023. FTX's own wallets were drained for roughly $477 million on November 11, 2022, the night the exchange filed for bankruptcy.

How Much Overlap Is There With the Separate OFAC List?

Plastron also maintains a second, independent dataset: 780 crypto addresses pulled from the U.S. Treasury's Specially Designated Nationals list, mirrored via the 0xB10C SDN extraction feed. It's built from government designations, not incident forensics, and it's roughly a sixth the size of the labeled corpus's high-plus-critical tiers combined.

Cross-referencing the two files by address turns up four matches. Lazarus Group's Ronin hacker address and both Ronin Bridge Exploit Attacker addresses sit on the OFAC list because Treasury named them directly. The Nomad Bridge Exploiter address matches too. That's 4 of the 50 critical addresses, 8%, appearing on both lists.

The other 46 never touched a sanctions designation. They're flagged for the hack alone, which is the whole point of keeping the two datasets separate: a sanctions hit and a hack-exploit label are different claims, and conflating them overstates what either one actually proves.

You can look up whether a single address shows up on Etherscan's public tag list, but that only tells you a label exists, not which risk tier it sits in or whether it also matches a sanctions filing. Screen the address with Plastron instead and get the risk tier, sanctions match, and cross-chain exposure in one pass.

What About the Medium and Neutral Tiers?

Medium risk holds 259 addresses: 251 fraud, 4 gambling, 4 mixer. That's the tier for confirmed bad activity that doesn't rise to a large-scale exploit, think smaller scam operations and unlicensed gambling fronts.

Neutral holds 114 addresses, and here the composition flips entirely: 45 defi, 41 exchange, 25 bridge, 3 contract. Neutral doesn't mean clean. It means identified infrastructure, an exchange hot wallet or a bridge contract, that isn't itself flagged as malicious. A neutral tag on a bridge contract says nothing about who used it.

Four tiers, four different stories. Scam volume lives in high. Fraud and small-time schemes live in medium. Known infrastructure sits in neutral. And the rare critical tag means a specific exploit, confirmed and traceable, not a hunch.

Methodology

Every number above comes from two committed files in Plastron's repository: data/known-addresses.json, 3,901 labeled addresses each carrying a riskLevel and an entityType, and data/ofac-sdn.json, 780 crypto addresses mirrored from the OFAC Specially Designated Nationals list via the 0xB10C extraction tool.

Risk-tier and entity-type counts came from grouping known-addresses.json entries by riskLevel, then, within the critical subset, by entityType. The OFAC overlap count came from a case-insensitive set intersection between the address fields of both files. Every figure is reproducible by filtering and grouping those two files directly; nothing here is extrapolated or rounded beyond the reported integers.

FAQ

How many addresses does this corpus label in total?

3,901, spread across four risk tiers: high, medium, neutral, and critical.

What does a critical risk score mean in this dataset?

It means the address is tied to a confirmed hack or exploit, not a scam report or an unverified flag. Only 50 of the 3,901 labeled addresses qualify.

Are all critical-risk addresses also on the OFAC sanctions list?

No. Only 4 of the 50, all connected to the Ronin and Nomad bridge exploits, appear on Plastron's separate 780-address OFAC dataset. The other 46 are flagged for the hack alone.

Does a mixer address count as critical risk?

Sometimes. Two of the 50 critical entries are mixer addresses, Blender.io and Sinbad.io, alongside the 48 hack_exploit entries.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

What 3,887 Labeled Crypto Addresses Reveal About RiskHow to Check If Your Wallet Is Exposed to Lazarus Group (North Korea) CryptoWhat Happens If Your Wallet Touched a $292M Hacked Bridge?Samourai Wallet Is Dead. Is Your Wallet Still Flagged?