XRPAuthority
Authority Risk / Methodology

Evidence-led wallet intelligence.

How XRPAuthority detects unusual public XRPL behavior without turning an algorithmic pattern into an unsupported allegation.

Check a public XRPL wallet →
01

What the score means

The XRPAuthority Risk Score is a configurable 0–100 behavioral assessment. It is not a legal finding and it does not identify an account as malicious by itself. Every score is accompanied by the contributing signals, evidence, ruleset version, and confidence.

02

Risk and confidence are separate

Risk summarizes the weight of detected patterns. Confidence summarizes the completeness, volume, and consistency of the available validated transaction history. A high score with low confidence should be interpreted cautiously.

03

Delivered XRP and public data

For validated Payment transactions, XRPAuthority uses delivered_amount from transaction metadata when available rather than assuming the requested Amount was delivered. XRP drops are normalized to XRP for analytics. Private keys, seeds, and recovery phrases are never requested.

04

Micro-payments are contextual

A single tiny payment never creates a malicious classification. Detection considers payment count, share of outgoing activity, unique recipients, repeated amounts, velocity, memo patterns, funding, downstream behavior, account age, and network relationships.

05

Domains and network proximity

A URL or domain appearing in a memo is an observation—not proof the domain is malicious. Likewise, interaction with a reviewed wallet is weighted by direction, strength, frequency, distance, and confidence rather than treated as guilt by association.

06

Human review

Algorithmic flags, community reports, Under Review, Confirmed Malicious, and Cleared are distinct evidence states. Confirmed Malicious requires stronger evidence and an administrator decision recorded in the audit log. Community reports cannot directly confer that status.

07

Bounded analysis

Public lookups and graphs use bounded histories and node limits. Incremental checkpoints prevent unnecessary full-history downloads. Historical assessments remain available so score changes can be audited across ruleset versions.