Section 4 · Lesson 4.4
False positives: when a high score does not mean guilt
One of the most harmful mistakes of a novice compliance specialist is reading the risk score as a verdict. "Yellow — half guilty, red — a criminal." This is wrong and dangerous: it blocks honest people and misses the point of the work. A risk score is a probabilistic assessment of connections, not proof of guilt. In this lesson we examine why an absolutely clean wallet can receive a yellow or red score, how to distinguish a false positive from a real risk, and what to do about it. This is a professional skill that separates an analyst from a button-pusher.
What the score actually means
A risk score answers not the question "is the owner guilty?" but the question "how connected is the address to risky sources, and how much does that connection need to be checked manually?". It is an indicator for attention, not a verdict.
- The score is indirect. It assesses counterparties and chains, not a person's intentions. The owner may not know or control where the coins came from.
- The score is probabilistic. It is built on heuristics and labels that are sometimes wrong (recall the false merging of clusters from Lesson 2.6).
- The score is context-dependent. The same connection can be innocent for a retail user and alarming for a business.
Hence the golden rule: a high score launches an investigation, it does not end one. Automatic refusal on a single number is bad compliance and reputational damage.
Why an honest wallet gets a yellow or red score
Let's examine the most common causes of false positives — scenarios in which a decent person quite lawfully ends up with a high score.
Cause 1: a P2P swap "with a history"
A person bought USDT from a P2P counterparty on an exchange — an honest deal. But the seller had previously run funds of dubious origin through their wallet. As a result, the coins you received carry a "trail" of the seller's risky past.
- Why the score is high: the system sees a recent link between your coins and a risky source through the counterparty.
- Why there is no guilt: the buyer did not choose the coins' history and could not check it at the moment of the deal. They are a victim of a "dirty" seller, not an accomplice.
Cause 2: a dusting attack
An attacker or spammer mass-mails microscopic amounts ("dust") to thousands of addresses — sometimes straight from a mixer or a flagged address, for the sake of de-anonymisation or spam. Your wallet receives 0.00000-"nothing" from a risky sender, and the link is recorded.
- Why the score is high: formally there is an incoming transaction from a risky address.
- Why there is no guilt: the recipient of dust cannot refuse an incoming transfer. They did nothing — the "dirt" arrived on its own.
A practical nuance: dust is dangerous to spend together with clean funds — then you yourself link them in one transaction (common-input!). Merely receiving dust creates no guilt; the problem arises if you "mix" it.
Cause 3: an old or distant contact
Five years ago you sent a friend a little crypto. Later that friend's address turned out to be involved in a scam. Or: you received funds from a counterparty who is linked to a mixer through several "jumps" (2–3 hops), even though directly with you everything is clean.
- Why the score is high: many engines account for indirect links (indirect exposure) several hops out and for old episodes.
- Why there is no guilt: you are not responsible for what your counterparties did before or after interacting with you, and even less so for their counterparties.
Cause 4: label and clustering errors
An address is mistakenly attributed to a risky entity because of an inaccurate label in a database or the false merging of clusters by a heuristic. Different providers (Chainalysis, Elliptic, TRM) not infrequently disagree in their assessment of one address.
This is exactly why serious analysis does not rely on a single source and always allows that a label may be wrong.
More common innocent sources of a high score: use of a legitimate service with a "noisy" reputation (some bridges, gambling platforms in jurisdictions where it is legal); receiving a payout from an exchange whose hot wallet also serves risky clients; a refund from a DEX contract previously used by launderers.
How to distinguish a false positive from a real risk
This is where genuine mastery begins. The analyst looks not at the number but at five dimensions of a connection.
- Direct or indirect link. Money came directly from a mixer/sanctioned address — serious. A link through 3–4 hops is usually a weak signal, characteristic of a false positive. Directness decides.
- Direction of flow. An incoming risky transfer is not controlled by the recipient (a possible false positive). A deliberate sending of funds to a mixer, or receiving them directly from darknet, is already the owner's behaviour. What you received ≠ what you did.
- Share and volume (exposure). 0.1% of "dirty" exposure from dust is noise. 60% of the balance came straight from a hacked exchange is a red flag. Look at the percentage, not the fact.
- Recency and repetition. A single old episode from five years ago is almost always a false positive. Regular fresh inflows from risky sources are a pattern, not chance. One-off vs system.
- Category of the source. Sanctions and terror (Lesson 3.6) — zero tolerance even for a small link. A "noisy" but legitimate service is a reason to investigate, not to block. Not all risks are equal.
Rule of thumb. Real risk = a direct link + outgoing/direct receipt + a high share + recency/repetition + a heavy category. A false positive = an indirect link through several hops + involuntary incoming + a negligible share + an old one-off episode + a "noisy" but legitimate source.
What to do about a high score: the algorithm
- Do not block automatically. A high score is a signal to check, not to refuse. Auto-refusal on a number breeds injustice and complaints. A pause, not a verdict.
- Open the breakdown. Look at what exactly the risk was charged for: the category of the source, the number of hops, the exposure share, the date. One click into the details often removes the alarm. Read the "why", not just the "how much".
- Assess across the five dimensions. Run the connection through directness / direction / share / recency / category from the block above. Structured judgement.
- Request context (RFI). If doubts remain — ask the user to explain the source of funds. An honest person usually answers easily: "bought it on P2P, here's the deal." Dialogue, not a silent ban.
- Document the decision. Record why you deemed the trigger false (or real). This protects both you and the client in the event of future questions from a regulator. An auditable trail.
- Escalate heavy categories. Sanctions/terror — always up the chain and by procedure, with no "writing it off as a false positive". A red line stays red.
Balancing two errors. A false positive (blocking an honest person) hurts clients, reputation and revenue. A false negative (letting a real criminal through) hurts your licence and threatens a criminal case. Professionalism lies not in zeroing out one of the errors, but in consciously balancing them: strict where the category is heavy, and with a presumption of good faith where the link is indirect and involuntary.
Lesson summary. A score is an assessment of connections and a reason to check, not proof of guilt. An honest wallet gets a high score because of a P2P counterparty with a history, a dusting attack, an old or distant contact, and label and clustering errors. Distinguishing a false positive is helped by analysing five dimensions: is the link direct, incoming or outgoing, what is the share, is it fresh and repeated, what is the category of the source. The right response is not an auto-block but a breakdown, an assessment, a request for context and documentation, with mandatory escalation of sanctions and terror. That is exactly why AMLConsensus shows not only a number but a breakdown of the "why" — so that a thinking person makes the decision, not a blind traffic light.
This material is for educational purposes only.