Skip to main content

Scoring Methodology

WalletWall scores wallet exposure — how much attention a wallet warrants and how urgent its migration-readiness planning is. This page explains the factors in plain English, the inputs and outputs, the shared risk tiers, a worked example, and the limits of the method.
Exposure scores are forward-looking heuristics for risk prioritization and long-term migration planning. They do not indicate that a wallet is currently vulnerable to theft or exploitation by any existing technology, and they are not investment advice.

Intuition pump: the RuneScape wall

Before the formal model, a warm-up. WalletWall’s methodology is easier to trust once you have a mental model of what it is doing — so we borrow one from an unlikely place: the trading economy of the online game RuneScape.
What’s an “intuition pump”? It’s a memorable, deliberately simplified story that helps you build a first mental model of an idea before the real, precise version arrives. It is a teaching device — not evidence, and not part of how WalletWall actually scores a wallet. The formal model in the next section replaces every piece of it.
Why a game? Because RuneScape accidentally rehearses the exact problems a wallet analyst faces: one persistent identity that shows up in different places, observers who only ever see part of the story, value that moves between accounts without an obvious handshake, and reputations that can be manufactured. Those are the same problems on-chain — just with more money and no game moderators.

One account, many worlds

A RuneScape account is a persistent thing. The player can hop between dozens of near-identical server worlds, and the account — its name, its level, its inventory — comes along. What changes is only which world you happen to be looking at. The useful idea here is the split between identity and where you observe it. If your friend only ever logs into World 302, they might swear an account is “inactive” — when really it has been busy on World 419 the whole time. Their conclusion isn’t lying; it is just incomplete. Missing observation is not proof of inactivity. There is also a quantum-flavored way to say it: until you actually observe the account, you can only associate it with a set of possible worlds and states. Observation collapses the possibilities into what you can see.
This is an analogy about identity, state, observation, and incomplete knowledge — nothing more. It is not literal quantum superposition, entanglement, or teleportation, and RuneScape worlds are not technically equivalent to blockchain networks. A single character occupies one active world at a time; the account persists across worlds, and one person may control several accounts. Keep those three things — account, session, and controller — distinct.

Many accounts, one player, and drop trading

Now the twist that makes it interesting. One person can run several accounts. And RuneScape has a folk mechanic called drop trading: one account drops an item on the ground, and — a moment later, in the same spot — another account picks it up. No trade window, no explicit handshake between the two accounts. Value moved; the mechanism deliberately hides the relationship. An observer watching that spot sees a relationship between Account A and Account B. That relationship is evidence worth weighing — but on its own it does not prove common ownership, a real-world identity, coordination, or bad intent. Two strangers can use the same drop spot by accident; a guildmate can pick up a genuinely lost item. The relationship is a lead, not a verdict.

Manufactured trust

RuneScape is also full of confidence tricks, and they teach the last lesson. A scammer will show up on an old, high-level account wearing expensive gear, sometimes flanked by friends who vouch for them, and offer to “double your gold.” A dormant account that suddenly reactivates with unusual behavior deserves a second look. None of these signals — age, visible wealth, social proof, a sudden return — is trustworthy on its own, and a convincing-looking account can still have very thin evidence underneath. The takeaways carry over one-for-one to wallets:
  • A single indicator rarely proves anything. Account age alone is weak. Visible wealth doesn’t guarantee legitimacy. Coordinated accounts can manufacture social proof.
  • Context changes the meaning of a signal. Dormancy followed by unusual activity can matter — or have a perfectly boring explanation.
  • Missing evidence is not low risk. An account you can’t see clearly is unknown, not safe.
  • Evidence, confidence, and risk are different things. You can have a scary-looking situation with weak evidence, or a calm one with strong evidence. A score presented without its evidence quality is false confidence.

Mapping the analogy to WalletWall

An account keeps its identity as it hops worlds; you might only ever watch one world; a drop trade links two accounts without a handshake; an old, rich, well-vouched account can still be a scam.
  • The doubling-money scam. “Give me 1M and I’ll send back 2M.” The bait is a fast, irreversible action framed by a trustworthy-looking account. On-chain, the wallet equivalent is a trusted-looking counterparty requesting a one-way approval or transfer. The lesson is the same: reputation is not verification, and irreversibility deserves suspicion.
  • Item lending and the sudden return. A long-idle account reactivates, borrows or gathers valuable items, and behaves unlike its history. Worth attention — but a returning player is also just a returning player. It is a signal to weigh, not a conviction.

From intuition to the formal model

That is the whole point of the warm-up: identity can persist across changing environments, observations are incomplete, indirect interactions can connect apparently separate accounts, and manufactured signals must be weighed together. Now WalletWall replaces the analogy with explicit, observable evidence — defined inputs, a fixed weighting, an honest confidence level, and documented limits.

Jump to the formal Quantum Exposure Score

The exact signal weights, labels, and caveat layers that replace the analogy.

Plain-English overview

WalletWall reads public, on-chain data for a wallet and asks a few practical questions:
  • Has the wallet revealed its public key on-chain (by sending a transaction)?
  • How much value is at stake?
  • How dormant is it?
  • What does its transaction history look like?
  • How hard would migration be (EOA vs. smart-contract / multisig)?
  • How concentrated are its holdings, including stablecoins?
  • What behavioral patterns does the activity show?
  • How complete is the underlying data?
It combines these into a normalized exposure score, places the wallet in a shared risk tier, and recommends a migration-readiness path. Every result carries a confidence level and source caveats.

Scoring factors

The Quantum Exposure Score itself is built from a small, fixed set of signal groups. Each contributes at most the points shown; missing data never adds points — an unavailable signal lowers confidence instead. These are the only inputs to the number. The composite is normalized to 0–100 (or null on insufficient evidence) and labeled Low (below 25), Moderate (≥ 25), Elevated (≥ 50), or Migration priority (≥ 75). For the exact weights and caveat layers, see Quantum Intelligence. These shape how a wallet is reviewed and reported; they are not components of the numeric exposure score.

Try it — which inputs actually move the number

The same calculator used on Quantum Intelligence, embedded here to make the split above concrete: only the scored signal groups have controls. The related signals are listed as context that contributes zero points, and switching an axis to not observed lowers confidence rather than lowering the score.

Inputs

  • Wallet transaction history — from public providers (Etherscan, Alchemy, The Graph).
  • Chain signature metadata — a derived lookup of each chain’s default signature scheme.
  • Scheduled Dune feeds — dormancy, signature exposure, value-at-risk, and migration-readiness facts (scheduled/cached, never live-streamed).
  • Market & concentration context — token/stablecoin pricing and holdings (CoinGecko, Stable Seer feeds).

Outputs

  • Quantum Exposure Score — normalized 0–100, or null when data is insufficient.
  • Exposure label — Low / Moderate / Elevated exposure, Migration priority, or Unknown.
  • Shared risk tier — Monitor, Review, Migrate, or Vault Candidate.
  • Migration-readiness recommendation — a recommended path with urgency, difficulty, blockers, and a next action.
  • Confidence level and a caveats array describing data completeness and staleness.
  • Source provenance — which feeds contributed, and whether data is live or scheduled/cached.

Shared risk tiers

WalletWall normalizes every assessment into one of four shared tiers. The tiers are the common language across modules and reports.
Tiers are prioritization bands, not verdicts. A “Migrate” tier means a wallet should be near the top of a migration queue, not that it is unsafe today. The Vault Candidate tier always carries the research-prototype disclosure — it is conditional and research-oriented, never a custody recommendation.
Tiers map onto the underlying migration-readiness paths as follows: See Migration Readiness for the full path definitions and recommended actions.

Example interpretation

A wallet holds ~$2.4M, mostly in one asset and a large stablecoin position. It has sent transactions (public key revealed), shows address reuse, and has been dormant for ~8 months. It is a plain EOA with no detected upgrade path.
WalletWall would read this as:
  • Exposure: Elevated — significant value in a classical EOA with a revealed public key.
  • Concentration: Elevated — single-asset plus stablecoin concentration.
  • Dormancy: Cold (180–730 days) — raises readiness risk.
  • Migration friction: High — EOA with no automated rotation path.
  • Recommended path: multisig or treasury-custody.
  • Risk tier: Migrate.
  • Confidence: Moderate-to-high if all feeds are fresh; reduced with a caveat if Dune data is stale.
The report would recommend prioritizing this wallet for migration and distributing signing across a multisig with an upgrade path — while noting that the score reflects long-term planning urgency, not current exploitability.

Limitations

  • Heuristic, not deterministic truth. Scores are estimates derived from observable on-chain signals and weighted heuristics.
  • Data-dependent. Missing transaction history, unknown wallet type, or stale Dune data lowers confidence or yields “Unknown.”
  • Chain scope. WalletWall scores Ethereum/EVM EOAs and contract wallets. Solana and other non-EVM chains are documented as general categories only, not scored.
  • Behavioral signals are observations. They use language like “may indicate” and “resembles,” carry confidence levels, and are never findings of wrongdoing, intent, or legal status.
  • Scheduled data is not live. Dune-sourced facts are scheduled/cached and labeled as such; they can lag the latest on-chain state.

What the score does not mean

  • It does not mean a wallet is currently vulnerable, hacked, or compromised.
  • It does not predict when a quantum computer will break ECDSA, or name a “Q-Day.”
  • It is not a claim that the wallet is “unsafe” or “quantum-vulnerable.”
  • It is not a measure of the owner’s intent, identity, or legal standing.
  • It is not investment advice or a basis for valuing assets.