Ransomware payment addresses
Addresses tied to ransomware campaigns and extortion demands, drawn from curated datasets of tracked incidents. A verdict that cites one names the incident, not a guess.
Bitcoin address check · BTC · on-chain risk
Paste a Bitcoin address and traql screens it against ransomware and darknet market datasets, sanctions lists, scam reports, mixer registries and the counterparties one hop away — then returns a 0–100 risk score with every contributing signal named. Once a Bitcoin transfer confirms, there is no way to undo it, so check before you send.
no card required · no subscription · pay per check
or check it in Telegram — @traqlcheckbot
1… · P2PKH3… · P2SHbc1… · bech32
// check a Bitcoin address — no signup
partial result — some sources were unavailable
3 free demo checks · no signup · or try the bot
// what a Bitcoin check looks at
Addresses tied to ransomware campaigns and extortion demands, drawn from curated datasets of tracked incidents. A verdict that cites one names the incident, not a guess.
Wallets attributed to darknet marketplaces and the vendors moving funds through them, sourced from the same curated incident datasets.
Direct hits against the US OFAC SDN list, the UK sanctions list, the EU consolidated list and the UN consolidated list, plus addresses attributed to a listed entity through traql's overlay designations. A direct hit sits at the top of the scale.
Addresses reported by community anti-scam feeds such as ScamSniffer — collection wallets behind fake-support scripts, romance scams and other reported fraud.
Registries of Bitcoin mixers and tumblers, plus behavioral patterns that look like layering regardless of any label: pass-through addresses, freshly created wallets that touch a mixer immediately.
Who paid the address, and who it paid. traql follows one hop of value in both directions and weighs the risk it carries by the share of volume involved and the confidence behind the label.
// no issuer, no undo
Bitcoin has no issuer and no smart contract sitting between a sender and a receiver. Nobody holds a key that can freeze a balance or reverse a confirmed transfer — not traql, not an exchange, not the people who wrote the protocol.
A Bitcoin transfer is a signed entry in the ledger, not a call into logic that can check who's on a list. Nothing stands between a valid signature and a confirmed transfer.
Once a transaction confirms, the coins belong to whoever controls the receiving keys. No wallet, no exchange, no developer team, and not traql, can freeze the balance or reverse the transfer after the fact.
Screening only works before the transaction confirms. After that, whatever risk was in the address is now in the transaction, permanently, and there is nothing on-chain to undo it.
This is the opposite of how USDT works: Tether can immobilise a balance inside its own token contract after the fact. Bitcoin has no equivalent mechanism — there is no undo, ever. Sending USDT to a risky counterparty at least leaves the issuer able to act; sending Bitcoin to one does not. See how that plays out on the USDT address checker.
// addresses, not wallets
Most Bitcoin wallet software hands out a new receiving address for every payment rather than reusing one — that is how the UTXO model is meant to be used. History attaches to the address that was actually used, not to the wallet as a whole, so the right thing to screen is the exact string you were given, not "the wallet" behind it.
Need to check a transaction instead of an address? Submit the transaction hash — traql retrieves it, decodes the transfers it contains and screens both sides of the largest one.
// the score
One REST call returns the same verdict, so a deposit can be screened while it is still unconfirmed and a withdrawal address before the payout is signed. Per-check pricing runs from $0.45 down to $0.20 depending on pack size, with nothing to subscribe to.
// faq
No. Bitcoin has no issuer and no smart contract standing between sender and receiver, so there is nothing built into the protocol that can immobilise a balance or reverse a confirmed transfer. Not traql, not an exchange, not the people who maintain the software — once a transaction confirms, it is final. That is the opposite of USDT, where the issuer can freeze a balance inside the token contract after the fact.
They are three different encodings of the Bitcoin protocol, not three different assets. Addresses starting with 1 use the original P2PKH format, addresses starting with 3 wrap a script such as a multisig setup (P2SH), and addresses starting with bc1 use native SegWit bech32 encoding. traql screens all three the same way.
Yes. Paste the transaction hash instead of an address and traql retrieves the transaction, decodes the transfers it contains and screens both sides of the largest one.
One hop. traql follows who paid the address and who it paid, in both directions, and weighs that exposure by the share of volume it represents and the confidence behind the underlying label. It does not attempt to trace exposure indefinitely through the graph.
Read the reasons before deciding anything — each one names its source, the entity, the category and a confidence level, so you can judge whether it applies to your situation. Because a Bitcoin transfer cannot be reversed once it confirms, this is a decision to make before you send, not after.
No. A low score means no matching signal was found at that moment, not that the funds are proven clean. Public data can be incomplete or delayed, and a newly created address has no history yet to flag. Treat the score as a screening signal, not a guarantee.
The checker on this page runs a few demo checks without a signup. For the full itemised verdict — every signal with its source, entity, category and confidence — create an account and get 3 free checks, or screen from your own code with the REST API.
no card · verdict in seconds · sign in