TL;DR - The same wallet gets different risk scores because each tool uses its own address labels, clustering rules, chain coverage, and exposure weighting, so a score reflects one vendor's model rather than a single objective truth.
You check an address on one screening tool and it comes back high risk. You check it somewhere else and the score looks fine. Nothing about the wallet changed between the two lookups, yet the verdicts disagree. This is the moment most people realise there is no official, universal risk score for a crypto wallet. There are only separate vendor opinions, and they were never built to match.
Why do screening tools give the same wallet different risk scores?
There is no central registry that stamps a wallet with one agreed score. Each analytics provider builds its own. Chainalysis, TRM Labs, and Elliptic each run separate datasets, separate clustering logic, and separate scoring models. When you feed them the same address, you are asking three different systems for an opinion, so three different answers are the expected result.
The gap is not a defect in any one tool. It reflects the fact that on-chain risk is an estimate, not a measured quantity. A score is a vendor's best read of how close a wallet sits to illicit activity, given the data that vendor holds today. Change the data or the method, and the number moves.
The same wallet routed through three engines lands in three different risk bands. None is the single correct answer; each is one model's read.
What data does each screening tool actually look at?
The first source of disagreement is the underlying intelligence. Every provider keeps its own set of labelled addresses: sanctioned entities, known mixers, scam wallets, hack proceeds, and the like. These lists are compiled independently, so one vendor may have tagged a fresh scam cluster that another has not added yet. If a label is missing, the exposure tied to it does not show up in the score.
Chain coverage is the second source. Some tools index more networks and bridges than others. A wallet that is busy on a chain one provider does not track will look quieter, and therefore cleaner, on that provider than on a rival that follows the funds across more chains.
Timing matters too. Labels and attributions update constantly. A new sanctions designation, or a hack that gets attributed to a known group, can raise a wallet's exposure overnight. Score the address before that update and after it, and you get two different numbers from the very same tool.
How do clustering and exposure models change the score?
Even with identical labels, the scoring would still diverge because the models differ. Analytics tools group addresses they believe share one owner, a process called clustering. Each vendor uses its own heuristics to draw those boundaries. Wider clusters pull in more activity and more exposure; tighter clusters attribute less. The same wallet can therefore inherit a different amount of risk depending on whose cluster map you use.
Exposure modelling is the bigger lever. Tools weight direct exposure, value received straight from a flagged address, far more heavily than indirect exposure that arrives through intermediate hops. How many hops a tool traces, and how quickly it lets risk decay with each hop, is a design choice that varies by vendor. You can read more on that split in our guide to direct versus indirect exposure.
Finally, each provider draws its own line between low, medium, and high. The same raw exposure can land in a medium band on one tool and tip into high on another, simply because the thresholds sit in different places. The arithmetic underneath may be close; the label on top is a policy decision.
Five independent choices stack up. Two tools can share most of their data and still report different scores once clustering, exposure depth, and thresholds differ.
Which tool does my exchange use, and can I see its score?
Exchanges and other regulated platforms each pick a screening vendor, or build their own engine in house. They rarely tell you which one, and they almost never show you the raw score. What you see is the outcome: a deposit held for review, a withdrawal rejected, or an account frozen. The number that triggered it stays behind the counter.
That is why a clean result on a public checker does not guarantee your exchange agrees. Its vendor may carry a label yours does not, or weight a hop you treated as harmless. If you have been flagged on a score you cannot reproduce, a clean read elsewhere is useful context, but it is not a veto. Our note on a high-risk false positive covers how to handle that case.
How do I check what a screening tool sees before an exchange does?
A block explorer such as Etherscan shows the transactions in and out of an address, so you can see your direct counterparties. It will not tell you which clusters those counterparties belong to, and it will not walk the funds backward through several hops, so most exposure stays invisible on a manual lookup. Rather than checking one source at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six chains at once.
Knowing your own exposure picture in advance is the practical takeaway. You will not match any single exchange's vendor exactly, because their model is private. You can, though, spot the obvious problems early, document where your funds came from, and avoid accepting a transfer that turns a clean wallet into a flagged one.
FAQ
Is one crypto screening tool more accurate than the others?
There is no single ground truth to measure against, so no tool is correct in an absolute sense. Each provider is stronger in different areas, depending on its labels, chain coverage, and how aggressively its model traces exposure. Accuracy is better judged per case than as one ranking.
Can I dispute a flag if another tool says my wallet is clean?
A clean read from a second tool is useful supporting evidence, but the exchange's own vendor decides the outcome. The stronger move is to provide source-of-funds documentation that explains how you received the funds, rather than relying on a competing score alone.
Do exchanges use more than one screening vendor?
Some larger platforms combine multiple data sources or run an in-house engine on top of a vendor feed, while others rely on a single provider. You usually cannot see which setup a given exchange uses, which is part of why the score you trigger is hard to reproduce.
Why did my score change when I made no new transactions?
Scores move when the underlying data moves. A new sanctions listing, a hack attribution, or a freshly labelled scam cluster upstream of your wallet can raise its indirect exposure without any new activity on your address.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.