VikingIntel/methodologyHow VikingIntel produces a score, and why it always comes with evidence attached.
Every score VikingIntel returns — a sybil cluster confidence, a wallet risk score, a token risk flag — is backed by the specific signals that produced it. A cluster confidence of 0.91 is never shown as a bare number; it comes with the shared fee-payer, shared funder, behavior-fingerprint, timing-correlation, and smart-money-dampening evidence that fed into it. If you can't see why a score landed where it did, that's a bug — tell us.
funded_by, bridged_to, labeled_as, sanctioned, and similar edges) rather than leaving them as unlabeled graph connections.Detection thresholds (what counts as "high risk," what confidence triggers a sybil flag, and similar cutoffs) are tuned against observed outcomes, not fixed at launch and left alone. As real investigation outcomes accumulate, thresholds are revisited so the system's confidence tracks reality rather than drifting stale. A score you see today reflects the thresholds in effect as of that calibration pass, not a static, one-time-tuned constant.
VikingIntel produces investigative signal, not a legal or compliance determination. A high sybil confidence or risk score is evidence to investigate further, not automatic proof of wrongdoing — see Known Limitations for where the methodology above is weakest and what can produce false positives or false negatives.