StableOps
Guides

Deposit Risk Notices

Review StableOps deposit risk notices for sanctions, theft, phishing, scam tokens, and suspicious addresses, with screening results, timestamps, and limits.

StableOps shows address risk notices in order and chain-event details to help merchants review recorded deposits. Fixed addresses, shared addresses, and address pools work without temporary wallets or access to your private keys.

Where to review results

  1. Select Live in the console and open an order or chain-event detail page.
  2. Review “Risk notice.” Orders screen the associated deposits and possible asset-mismatch events currently shown. Public sanctions list results and address risk labels appear separately.
  3. For matches, review the address, listing evidence or labels, and whether screening completed for both sender and recipient.
  4. Compare timestamps. “Refresh screening” reuses valid caches and continues checking addresses that have not been screened.

Results appear after a deposit is recorded. Screening covers the displayed events, does not scan a wallet’s entire history, and cannot prevent a transfer.

Risk categories

CategoryHow to interpret it
Sanctions associationAn address matches an explicitly listed digital currency address or has a separate sanctions label. Listing evidence and address labels are displayed independently
Theft attacksAn address has a theft-related label. Review the transaction and relevant incident records
Phishing and blackmailAn address has phishing or blackmail labels. Review the payment context
Scam-token associationsAn address may be linked to scam tokens, counterfeit tokens, or creation of malicious contracts. This does not establish that every deposit is fraudulent
Suspected malicious behaviorAn address is flagged as suspicious. This alone does not establish wrongdoing or the source of funds
Mixer associationsAn address has a mixer label and needs further review. The label alone does not establish criminal activity
Other address concernsLabels may cover dark web transactions, money laundering, financial crime, fake identity verification, malicious mining, or contract concerns. Review the specific category shown

Coverage varies by network and category. Screening cannot guarantee detection of all scams or thefts. Labels describe address information in available data and do not establish that a particular deposit is unlawful.

What the statuses mean

StatusMeaning
Sanctions list matchAn address exactly matches an explicit listing. The panel shows the entity, listed currency, and program identifiers
No sanctions list matchNeither address matched the current valid list. This does not establish that funds are safe
Risk labels foundAt least one address has known labels. Missing fields or incomplete screening of the other address are shown separately
No known risk labels foundAll known screening fields for both addresses explicitly returned zero. Other risks may still exist
Screening unavailable or incompleteData is missing, expired, unavailable, limited, or not yet queried. A current no-match result cannot be provided
Not applicableSandbox does not query real addresses. Unsupported networks do not substitute results from another network

Addresses appear in label results only when risk labels are found. Addresses with no matches or no labels are hidden. If one address has no matches and the other remains unchecked, overall label screening is incomplete. Known matches remain visible with details of any incomplete checks.

Payment confirmation describes on-chain state, while screening describes address information. Results do not change confirmation, freeze funds, issue refunds, or stop fulfillment automatically. Merchants review business orders and chain records to decide how to proceed.

Scope and limitations

Screening checks the deposit’s immediate sender and receiving address. EVM matching ignores hexadecimal letter case. TRON and Solana retain their case. The listed currency may differ from the deposit asset, such as a TRON address receiving USDT listed under TRX.

The sender may be an exchange or intermediary contract and does not identify the actual payer. Screening does not trace earlier transfers, cross-chain routes, or indirect exposure. Queries use only public addresses and network identifiers, without orders, amounts, merchant identities, or private keys.

No list or known-label match does not establish that funds are safe. Address notices cannot replace full source-of-funds analysis or serve as the sole basis for releasing funds or fulfilling an order.

Updates, caching, and incomplete results

Public sanctions data updates periodically. Publication, download, and screening times are shown separately. Failed updates preserve the last snapshot. After 24 hours, it cannot produce a current no-match result. Known matches remain visible with a stale-list notice.

Address labels are queried when details are viewed. Complete matches are cached for one hour, complete no-match results for fifteen minutes, and failed or incomplete results for one minute. The panel retains the original query time and marks cached results. Refreshing does not bypass valid caches.

Pages with many new addresses may need several queries. Reasons for incomplete screening are shown, and refreshing continues screening. If a request limit is reached or data is temporarily unavailable, refresh later. Unchecked addresses cannot produce a no-match result.

Results are available in the console without changes to the public API, SDKs, or payment webhook payloads.

How is this guide?

Last updated

On this page