How WalletGenome Computes On-Chain Intelligence
A clear breakdown of the core algorithms, data pipelines, and security checks powering WalletGenome's on-chain analysis.
The scanner currently examines observable public activity on four supported EVM networks: Ethereum, Base, Arbitrum, and Optimism. Provider gaps remain explicitly partial or unavailable in the report.
Open Live Scanner11 documentation topics
TABLE OF CONTENTSMulti-Chain Pipeline & Rate-Resilient Data Gateway11 TOPICS
Multi-Chain Pipeline & Rate-Resilient Data Gateway
We use a dual-gateway system and caching to reduce the impact of provider rate limits and improve retrieval resilience.
Historical asset-days are deduplicated and sent through DefiLlama batch requests. CoinGecko receives only a small bounded fallback workload. Provider failures remain explicit partial or unavailable results.
Contract allowlists and known symbols limit pricing inputs. Every calculated USD value carries historical, spot-estimate, stablecoin-assumption, or unpriced provenance.
Calldata Decoding & Transaction Categorization Engine
Transactions are decoded and categorized into distinct semantic types using their method signatures and contract registries.
| Category | Method IDs / Heuristic Signatures | Classification Rules |
|---|---|---|
| approval | 0x095ea7b3, approve() | ERC-20 token allowance approvals to DEXs, bridges, or custom spenders. |
| bridge | 0xd2ce7d65, 0xe9e05c42, 0x0f5287e0 | Cross-chain bridging via Arbitrum Gateway, Optimism Portal, Across, Stargate, or Polygon. |
| swap | exactInput, multicall, execute | DEX trading across Uniswap, Sushiswap, Curve, Balancer, or 1inch routers. |
| lending | supply, borrow, repay | Money market operations on Aave, Compound, MakerDAO, or Morpho. |
| staking | stake, unstake, delegate | Liquid staking / delegation across Lido, Rocket Pool, or native validators. |
| nft | mint, safeTransferFrom | ERC-721 / ERC-1155 minting and marketplace trading on OpenSea, Blur, etc. |
| transfer | input === '0x' | Pure native ETH / BNB value transfer between EOA accounts. |
Timestamp-matched daily prices are requested in DefiLlama batches, with bounded CoinGecko ranges as fallback. Missing daily prices remain unavailable or are explicitly marked as current-price estimates; they never appear as exact historical values.
6-Dimension Behavioral Fingerprinting & Persona Modeling
Wallets are analyzed across 6 behavioral dimensions, each scored from 0 to 100.
Measures breadth of smart contracts and distinct protocols used.
Evaluates transaction execution frequency.
Ratio of transferred economic value to gas fees consumed.
Measures tolerance for unverified contracts and failed transactions.
Longevity from first transaction combined with active consistency.
Diversity of peers across native transactions and token transfers.
UniqueContracts > 50 OR DeFi Diversity > 60. Multi-year on-chain presence with broad multi-protocol routing.SwapCount > 40% of Txs AND Activity > 50. High-frequency DEX rotation.NFTCount > 30% of Txs. Heavy minting, marketplace trading, and collection transfers.BridgeCount > 20% of Txs. High cross-chain asset mobility across L1s/L2s.Activity > 40 AND UniqueContracts < 10 AND Maturity < 12 mo. Scripted repetitive interactions.Activity < 20 AND Maturity > 50. Long-term capital storage.Composite Security Risk Engine (Score 0–100 & Grades A–F)
The risk engine scores vulnerabilities from 0 (Safe) to 100 (Critical), mapping them to security grades A through F based on key risk factors.
| Risk Factor | Max Weight | Calculation Formula | Severity |
|---|---|---|---|
| 1. High-Risk Unlimited Approvals | 40 pts | min(40, HighRiskApprovals × 15) | Critical |
| 1b. Known-Contract Unlimited Approvals | 20 pts | min(20, UnlimitedCount × 3) if no high-risk approvals and UnlimitedCount > 3 | Warning |
| 2. Failed Transaction Ratio | 25 pts | min(25, round(FailedRatio × 120)) if FailedRatio > 5% | Warning |
| 3. Stale Approvals (>6 Months) | 15 pts | min(15, StaleCount × 3) if StaleCount > 2 | Warning |
| 4. Unidentified Contract Ratio | 10 pts | min(10, round(UnknownRatio × 20)) if UnknownRatio > 30% and UnknownCount > 5 | Info |
Sybil Radar & Local MEDIA-style Behavioral Heuristic
Sybil defense checks an illustrative 800K+ blacklist-cache scale and computes a local MEDIA-style behavioral heuristic to identify bot-like behavior. This behavioral risk score is not a live Trusta score. A positive non-behavioral blacklist match overrides the overall clean/organic headline; the behavioral score remains a separate secondary heuristic.
Official community bounty hunter reports and algorithmic script execution loops.
Graph analysis flagging co-funded multi-sig parent roots.
Identified stealth address routing clusters.
Specially Designated Nationals registry.
ERC-20 Approval & Capital at Risk Exposure Engine
WalletGenome estimates approval exposure from the latest observed non-revoked approval states reconstructed from returned ERC-20 approval transactions, reconstructed token balances, and current token prices. This is not a live allowance query: a later on-chain change may not appear in returned history. It does not treat an unknown balance or price as zero exposure.
Byte slice
input[34:74] = 20-byte spender contract address.Byte slice
input[74:138] = 32-byte uint256 allowance amount.•
Unlimited: If amount starts with ffff... or equals $2^256-1$.•
Revoked: If amount equals 0x0.•
Custom: Specific finite integer allowance.24×7 Temporal Matrix & Continuous Streak Engine
Transaction times are mapped to a 24x7 matrix to identify bot patterns and timezone activity.
Intensity per cell (day, hour) is normalized against maximum hourly volume:Intensity(d, h) = Count(d, h) / max(Count)
Calculates consecutive active transaction days by sorting calendar keys and measuring date deltas:DeltaDays = (Time[i] - Time[i-1]) / 86400s
Capital Flow Topology & Cluster Linkage Matrix
We visualize funds using Capital Flow Graphs for single addresses and Cluster Matrices for multiple wallets.
Direct links require a native, internal, or ERC-20 transfer whose source and target are both submitted wallets. Evidence is deduplicated by chain, transaction hash, direction, asset type, and asset identifier, then aggregated by source, target, and chain.
Every linkage retains unique evidence hashes, transaction count, direction, last date, and USD completeness. Shared counterparties are computed from the full evidence set; only rendering is truncated. These are observed direct-transfer and shared-counterparty signals, not proof of common control. The Arbitrum Foundation match is limited to published sample addresses and does not reproduce its full graph-based clustering model.
• Column 1 (X=160): Inbound funding sources & CEX withdrawals.
• Column 2 (X=550): User core address.
• Column 3 (X=940): Destination DeFi protocols & recipient addresses.
• Line widths: Volume-weighted stroke
W = min(8, 1.5 + log10(USD_Volume)).• Orbital Radius:
R = max(320, WalletCount × 24.5) px.• Angle per wallet:
theta = (2π × i / N) - π/2.• Coordinates:
X = Xc + R × cos(theta), Y = Yc + R × sin(theta).• Shared Hubs placed at gravitational center with force links.
Decentralized Identity & Platform Priority Hierarchy
Web3 identities (like ENS, Farcaster) are resolved using Web3.bio, picking the most trusted handle based on our priority matrix.
| Platform | Priority Weight | Deep Link Resolution Format |
|---|---|---|
| ENS (.eth) | 10 (Highest) | https://app.ens.domains/{name} |
| Farcaster (Warpcast) | 9 | https://warpcast.com/{handle} |
| Lens Protocol | 8 | https://hey.xyz/u/{handle} |
| BaseNames (.base.eth) | 7 | https://base.org/names?query={name} |
| Unstoppable Domains | 6 | https://unstoppabledomains.com |
Reporting metric definitions
In plain language: flow fields describe value that entered or left, risk fields describe a heuristic rather than a loss probability, and approval exposure estimates value covered by the latest observed approvals rather than a live allowance. Missing history or price inputs stay partial or unavailable instead of being guessed.
These definitions are imported from the same contract used by API responses and dashboard labels. Use the stable field anchors in the table when linking to an exact definition; USD metrics are withheld when their required provider or price inputs are incomplete.
| Field | Unit / window | Sources and rules | Completeness / pricing |
|---|---|---|---|
inflowUSDInflow | USD Full history returned by the selected explorers. | Successful native, internal, and ERC-20 transfers to the scanned wallet. Includes priced inbound transfer legs; excludes failed and unpriced legs. Sum across selected chains; each transfer leg is counted once. | Publishes a verified subtotal when history is complete and at least one eligible leg is historically priced; otherwise unavailable. Historical or stablecoin assumption only. Spot estimates and unpriced legs are excluded and reported in capitalFlowCoverage. |
outflowUSDOutflow | USD Full history returned by the selected explorers. | Successful native, internal, and ERC-20 transfers from the scanned wallet. Includes priced outbound transfer legs; excludes failed and unpriced legs. Sum across selected chains; each transfer leg is counted once. | Publishes a verified subtotal when history is complete and at least one eligible leg is historically priced; otherwise unavailable. Historical or stablecoin assumption only. Spot estimates and unpriced legs are excluded and reported in capitalFlowCoverage. |
netFlowUSDNet flow | USD Same window as inflowUSD and outflowUSD. | Canonical inflowUSD and outflowUSD fields. No additional records are introduced. inflowUSD minus outflowUSD. | Available when both verified flow subtotals are available; inherits their partial coverage status. Combined provenance of the inflow and outflow inputs. |
grossVolumeUSDGross transfer volume | USD Same window as inflowUSD and outflowUSD. | Canonical inflowUSD and outflowUSD fields. Counts both directions; it is not net flow or portfolio value. inflowUSD plus outflowUSD. | Available when both verified flow subtotals are available; inherits their partial coverage status. Combined provenance of the inflow and outflow inputs. |
protocolVolumeUSDProtocol interaction volume | USD Full history returned by the selected explorers. | Priced transfer legs correlated to recognized protocol transactions and contracts. Excludes unpriced legs and ordinary counterparty transfers. Sum by protocol contract and chain, then across chains without removing chain provenance. | Unavailable unless transaction, transfer, and price inputs are complete. Combined provenance of attributed protocol transfer legs. |
approvalExposureUSDEstimated approval exposure | USD Latest observed approval state in returned history. | Latest non-revoked observed ERC-20 approvals, reconstructed token balances, and current token prices. Includes priced positive balances for latest non-revoked observed approvals; revoked, zero-balance, and unpriced exposure are not converted to zero proof. Sum of per-approval estimated exposure across selected chains. | Unavailable when any latest non-revoked observed approval balance or required price is unknown. Current spot quote, stablecoin assumption, or unpriced when no current quote is available. |
riskScoreWorst-chain risk score | score_0_100 Full history returned by the selected explorers. | The documented approval, failure, stale-approval, and unknown-contract factors. Higher is riskier; this is a heuristic, not a loss probability. Maximum chain risk score across selected chains. | Unavailable when wallet history is incomplete. Not applicable. |
riskGradeWorst-chain risk grade | grade Same window as riskScore. | Canonical riskScore. Grades A, B, C, D, and F map to documented score thresholds. Grade derived from the maximum chain risk score. | Unavailable when wallet history is incomplete. Not applicable. |
sybilProbabilityBehavioral Sybil risk (heuristic) | risk_percent Full returned cross-chain behavior history. | Local MEDIA-style behavioral dimensions; blacklist matches are reported separately. A local behavioral heuristic, not a live Trusta score and not a blacklist verdict. Computed once from the combined selected-chain dataset. | Unavailable when wallet history or the behavioral report is incomplete. When historical prices are incomplete, the monetary dimension is omitted and the remaining behavioral dimensions are reweighted. |
blacklistStatusBlacklist status | status Latest blacklist snapshots checked for the scan. | Configured external and bundled blacklist datasets; excludes the Trusta behavioral heuristic. Flagged when any non-behavioral blacklist source positively matches. flagged overrides clear; unavailable when checks did not complete. | Unavailable when the Sybil/blacklist report is absent. Not applicable. |
activeDaysActive days | days Full transaction history returned by selected explorers. | Successful and failed normal transactions with valid timestamps. A UTC calendar date counts once even when activity occurs on multiple chains. Cardinality of the union of UTC activity dates. | Unavailable unless transaction history is complete. Not applicable. |
longestStreakDaysLongest activity streak | days Full transaction history returned by selected explorers. | The union of UTC activity dates across selected chains. Consecutive UTC calendar dates; same-day cross-chain activity counts once. Longest consecutive run in the sorted date union. | Unavailable unless transaction history is complete. Not applicable. |
totalUnlimitedApprovalsUnlimited approvals | count Latest observed approval state in returned history. | Decoded ERC-20 approval transactions. Counts unlimited approvals in the latest observed state; observed revoked states are excluded. Sum across selected chains. | Unavailable unless transaction history is complete. Not applicable. |
Algorithmic Complexity & Execution Guarantees
Algorithmic complexity and cache policies. The cache-size and timing figures are illustrative, not reproducible benchmark results or production capacity guarantees.
| Subsystem | Time Complexity | Space Complexity | Execution Layer | Cache Policy |
|---|---|---|---|---|
| Sybil Blacklist Check | O(1) lookup | O(M) in-memory set (~800K entries, illustrative) | Server Memory | 24h Global TTL |
| Behavioral Fingerprint | O(N) transactions | O(U) unique contracts | Server / Client | Session / Per-Scan |
| Risk Scoring Engine | O(A + G + D) summary | O(F) factor list | Server / Client | Instant Compute |
| Cluster Linkage Graph | O(W × C) pair analysis | O(W + L) nodes & links | Server Route | Per-Batch Run |
| Daily Price OHLC Feed | O(1) cache read | O(K) token day pairs | Server Memory | Process Lifecycle |
| Web3.bio Identity Graph | O(1) async HTTP | O(P) profile records | Server Gateway | force-cache HTTP |