AI-powered alert analysis rules and methodology
Each Chainalysis KYT alert is scored on a 0–100 scale across six weighted components, with auto-rules overriding the score for zero-tolerance categories or trivial exposure. The resulting FLAG / REVIEW / DISMISS band drives the analyst's next action.
Six components sum to a 0–100 risk score. Each row below is a band; a row's score applies when the alert's value falls within the listed condition. Auto-rules (right) override the score when triggered.
| Component | Max | Score | Condition |
|---|---|---|---|
| Category | 30 | 30 | Child Abuse Material, Sanctioned Entity, Sanctioned Jurisdiction, Terrorist Financing |
| 24 | Darknet Market, Drug Vendor, Mixing, Special Measures | ||
| 20 | Fraud Shop, Illicit Actor / Org, Malware, Ransomware, Scam, Stolen Funds | ||
| 18 | Protocol Privacy | ||
| 15 | No KYC Exchange, P2P Exchange | ||
| 10 | Gambling | ||
| 8 | ATM | ||
| 5 | Infrastructure as a Service | ||
| 0 | All other categories (KYT rules = N or unmapped) | ||
| Severity | 15 | 15 | SEVERE |
| 10 | HIGH | ||
| 5 | MEDIUM | ||
| 0 | LOW | ||
| Exposure (%) | 15 | 15 | 100% |
| 12 | 80–99% | ||
| 9 | 60–79% | ||
| 6 | 40–59% | ||
| 3 | 20–39% | ||
| 1 | 4–19% | ||
| 0 | 0–3% | ||
| Exposure (USD) | 15 | 15 | ≥ $5M |
| 10 | $1M – < $5M | ||
| 5 | $500K – < $1M | ||
| 4 | $100K – < $500K | ||
| 3 | $501 – < $100K | ||
| 0 | ≤ $500 | ||
| Hops | 20 | 20 | < 2 hops (or DIRECT fallback when reactor missing) |
| 15 | 2–5 hops | ||
| 10 | 6–10 hops | ||
| 5 | 11–15 hops | ||
| 0 | > 15 hops (or INDIRECT fallback when reactor missing) | ||
| Pattern | 5 | 5 | > 20 prior alerts on user |
| 4 | 10–20 prior alerts | ||
| 3 | 5–9 prior alerts | ||
| 2 | 2–4 prior alerts | ||
| 1 | 1 prior alert | ||
| 0 | No prior alerts | ||
| Total | 100 | Σ | Sum of all six components → ≥ 60 FLAG 40–59 REVIEW < 40 DISMISS |
Direction (SENT/RECEIVED) is retained on the alert for display but is not scored. The Hops fallback covers the case where reactor data is unavailable.
| FLAG Auto-FLAG | |
|---|---|
| Direct Exposure | DIRECT to any KYT-rule category — 20 categories incl. TF, CSAM, sanctions, mixing, ransomware, fraud shop, etc. |
| High Percentage | Exposure > 25% |
| User Pattern | 50+ prior flags on user |
| DISMISS Auto-DISMISS (INDIRECT only) | |
|---|---|
| Threshold | Amount < $500 and Exposure < 3% |
| Negligible | Exposure < 0.1% and Amount < $500 |
DIRECT exposure is never auto-dismissed. All dismissal rules require INDIRECT exposure.
The "KYT-rule category" set in the Auto-FLAG table mirrors every category marked KYT rules = Y in AI TM logic.xlsx; INDIRECT alerts in those same categories flow through normal scoring instead of auto-flagging.
Not sure how an alert would score? Enter the inputs below and the v1.3 logic computes the per-component breakdown and the resulting decision band live.