> For the complete documentation index, see [llms.txt](https://docs.compliance.phalcon.blocksec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.compliance.phalcon.blocksec.com/manual/addresses.md).

# Address Screening

Addresses represent blockchain wallets or contracts that users screen for risk. Typically, these are the customer addresses that interact with your platform. Proactive screening ensures high-risk entities are identified promptly, allowing for risk mitigation measures.

<figure><img src="/files/z2uRYoNVQPf3h95z9qqu" alt="Address screening page overview"><figcaption><p>Addresses</p></figcaption></figure>

### Labels

Labels provide human-readable identifiers to distinguish addresses, sourced from BlockSec's verified address database. Labels are system-generated and cannot be edited by users.

### Tags

Tags categorize addresses by attribute or behavior (e.g., deposit address, frozen).

* System Tags (Immutable):
  * Sourced from BlockSec's database (e.g., sanctioned, mixer).
  * Cannot be edited or deleted.
* Custom Tags (User-defined):
  * Add internal classifications (e.g., VIP customer, pending review).
  * Can be freely edited/deleted, but the total number of tags per address is ≤5 (System Tags + Custom Tags).

### Notes

Users can add notes to any address to record additional context or observations. Notes are visible to all team members and are logged in the address's Audit Log.

## Screening Addresses

Methods:

* Screening a single address
* Bulk screening via CSV

All addresses will be automatically screened and displayed in the address list.

### Add a Single Address

To add a single address for import and screening:

* Enter the address you want to add. Phalcon will automatically fetch data including the chain, tags, and system markers.
* Select the target address for screening.

### Bulk Screen via CSV

Users can also use a CSV file to screen multiple addresses at once.

<figure><img src="/files/AG53kfWPRudGAV8ZaUzX" alt="Bulk address screening via CSV upload"><figcaption></figcaption></figure>

* Download the CSV template from the "Addresses" page.
* Upload up to 100 addresses per file
* Fill in the template content:

| Field       | Description                                    |
| ----------- | ---------------------------------------------- |
| Chain       | The exact chain name in the template           |
| Address     | The blockchain address                         |
| Tag         | User-defined private tag (optional)            |
| Marker      | Custom marker (optional)                       |
| Customer ID | Existing or new customer identifier (optional) |

* Upload the CSV file.
* Review the import results in the pop-up window and ensure each target address has been successfully imported.

## Address List

Screened addresses are displayed in the address list, which includes information such as the address, risk summary, unresolved alerts, last screened time, markers, customer, and time added.

<figure><img src="/files/SEUdZshtB3aL6s6vsR8X" alt="Address list page"><figcaption></figcaption></figure>

## Exporting Addresses

You can export your address list as a CSV file by clicking the **Export** button on the Address List page. This feature is available to paid plan users only.

The exported CSV contains the following fields:

| Field                           | Description                                                                                                                      | Example                                 |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------- |
| Chain                           | Blockchain network                                                                                                               | ETH                                     |
| Address                         | The blockchain address                                                                                                           |                                         |
| Risk Level                      | Current risk level of the address                                                                                                | Critical                                |
| Entity Risk Tags                | Risk tags associated with the address itself. Multiple tags are separated by `;`                                                 | Scam; Blocked                           |
| Interaction Risk Breakdown      | Interaction risk indicators with details. Format: `{Risk Tag}: {Direction} {Value} ({Ratio})`. Multiple entries separated by `;` | No KYC Exchange: Incoming $0.02 (0.08%) |
| Entity Risk Details (JSON)      | Structured JSON for entity risk, for programmatic parsing                                                                        | See below                               |
| Interaction Risk Details (JSON) | Structured JSON for interaction risk, for programmatic parsing                                                                   | See below                               |
| Unresolved Alerts               | Number of unresolved alerts                                                                                                      | 2                                       |
| Last Screening Time             | Time of the most recent screening                                                                                                | 2026-03-31 10:23:45                     |
| Label                           | System label                                                                                                                     |                                         |
| Tags                            | System tags and user-defined tags                                                                                                | Scam; Blocked                           |
| Note                            | User-added note                                                                                                                  |                                         |
| Customer                        | Associated Customer ID                                                                                                           | Customer123                             |
| Added Time                      | Time the address was added                                                                                                       | 2026-03-30 15:20:11                     |

**Entity Risk Details (JSON) example:**

```json
[
  {
    "riskIndicator": "Scam",
    "riskLevel": "critical",
    "detail": "Fake_Phishing 123"
  },
  {
    "riskIndicator": "Blocked",
    "riskLevel": "high",
    "detail": "Blocked by USDT"
  }
]
```

**Interaction Risk Details (JSON) example:**

```json
[
  {
    "riskIndicator": "No KYC Exchange",
    "direction": "incoming",
    "minHop": 1,
    "exposureValue": 0.02,
    "exposurePercentage": 0.0008,
    "riskLevel": "medium"
  }
]
```

## Address Details Page

<figure><img src="/files/8fyiBfOQSsURKTwz46oK" alt="Address details page overview"><figcaption></figcaption></figure>

Clicking an address in the **Address List** opens its **Details Page**.

At the top of the page, the address is displayed alongside its entity and category.

### Basic Information

Displays key details such as chain, markers, tags, balance, total inflow, and total outflow.

### Screening Result

The screening result shows the risk analysis from the most recent screening, organized into the following areas:

#### Risk Summary

A quick overview of all detected risks, grouped into three categories: **Entity Risk**, **Interaction Risk**, and **Behavior Risk**. Each category has a link to jump to its detailed view.

<figure><img src="/files/tW2QDF9sg6OUSCZ6D9us" alt="Risk Summary showing Entity Risk, Interaction Risk, and Behavior Risk categories"><figcaption></figcaption></figure>

#### Entity Risk

Lists all risk attributes associated with the address itself — such as sanctions designations, known attack involvement, or blacklist/whitelist membership.

Each attribute is displayed as a row showing:

* **Risk Indicator** — The risk category (e.g., Sanctioned, Attack, Scam, Blacklisted).
* **Details** — Specific risk details for the attribute. A single indicator may have multiple detail entries displayed on separate lines.
* **Source** — For sanctioned addresses, the name of the sanctions list (e.g., OFAC, NBCTF) with a link to the official record. For blacklisted/whitelisted addresses, a link to the list management page.
* **Triggered Rule** — Which risk engine rule was triggered. Hover the rule icon to view the rule's configuration and risk level.

<figure><img src="/files/oLIWp58vLcpeqCbpzNp6" alt="Entity Risk table showing risk indicators, details, source, and triggered rules"><figcaption></figcaption></figure>

#### Interaction Risk

Shows how the address has interacted with risky counterparties through fund flows. This section includes:

* **Indicator Breakdown** — Bar charts comparing incoming and outgoing exposure across risk indicators (e.g., Sanctioned, Mixing, Scam). Each bar distinguishes between direct (1-hop) and indirect (2+ hop) exposure, and shows whether the exposure triggered a rule or not. Hover a bar for a detailed breakdown; click to filter the sections below.
* **Risk Addresses** — A table of counterparty addresses associated with triggered risk indicators, showing direction, shortest hop distance, and exposure amounts. Expand any row to view detailed risk indicator information, including specific risk details and sanctions list sources (where applicable). You can filter by direction, indicator, or hop distance, and search by address or label. You can also export the risk addresses list as a CSV file.
* **Fund Flow** — A visual graph of fund flows between the screened address and risky counterparties. Filter by risk indicator or specific address. Click **"View Detailed Fund Flow"** to open the full analysis in MetaSleuth.

<figure><img src="/files/45VEByESdo806Z2mI0p2" alt="Interaction Risk showing Indicator Breakdown bar charts and Risk Addresses table"><figcaption></figcaption></figure>

{% hint style="info" %}
**Triggered vs. Not Triggered**: An indicator is "Triggered" when its exposure meets the threshold of a rule in your active Risk Engine, generating an alert. "Not Triggered" means exposure was detected but did not reach any threshold — shown for reference only.
{% endhint %}

#### Behavior Risk

Lists suspicious transaction patterns detected on the address, such as large transfers, high-frequency transfers, or transit address behavior. Each row shows the behavior type, key metrics (e.g., max value, matched events, time window), and the triggered rule.

Hover the info icon next to any behavior type for an explanation of what it means and why it may be suspicious.

<figure><img src="/files/CvVL58QRba44M8PagLOl" alt="Behavior Risk showing Large Transfer, High-Frequency Transfer, and Transit Address patterns"><figcaption></figcaption></figure>

### Alerts, Audit Logs, and Comments

* **Alerts** — All alerts triggered by this address. Filter by status and click through to Alert Hub for details.
* **Audit Logs** — System-generated records of screening events, risk level changes, and other activities.
* **Comments** — Team members can leave notes and collaborate on investigations.

### Available Actions

* **Monitor Now** — Enable continuous risk monitoring for the address. See [Monitor](/manual/monitor.md) for details.
* **Re-screen Now** — Immediately perform a new risk screening. While re-screening is in progress, the previous result remains visible so you can continue your investigation.
* **Add to List** — Add the address to a blacklist or whitelist.
* **Share** — Generate a shareable link to the screening result. Recipients can view the report without logging in.
* **More** — Access additional actions:
  * **KYA Report** — Export the address risk details as a report.
  * **Delete** — Remove the address from the system.

## Blacklisting an Address

Clicking ***Add to List -> Blacklisted Address*** in the address list will blacklist an address. This action will:

* Automatically mark the address as **Critical Risk**.
* Exclude the address from standard risk engine screening.
* Mark any address that transacts directly with the blacklisted address as **Critical Risk**.

## Whitelisting an Address

Clicking ***Add to List -> Whitelisted Address*** in the address list will whitelist an address. This action will:

* Automatically mark the address as **No Risk**.
* Exclude the address from standard risk engine screening.

## Deleting an Address

An address can be deleted from the system by clicking the ***Delete*** button in the last column of the address list or on the address details page. After deleting an address, all alerts associated with it will expire.
