Case Study
ONyc: Real-time screening of every wallet before it reaches the buy screen
Open access does not exempt a venue from its obligations; it shifts the obligation to a control that runs when wallets connect.

A growing number of regulated financial products now reach their customers onchain. A tokenized fund, a curated vault, a yield-bearing asset: the product sits inside a licensed structure with a named regulator attached, and customers arrive through a wallet. That arrangement does not change the obligation. A licensed entity cannot provide financial services to a sanctioned or high-risk party.
What changes is the evidence available at the moment of entry. Institutional onboarding produces a name, a jurisdiction, a beneficial owner and a file that a compliance team can review. A wallet connection produces a public key. The control has to be built out of that public key, and it has to run before a position exists.
OnRe is licensed to accept digital assets as collateral for writing reinsurance, which puts onchain capital behind real-world risk. Investors take that exposure through ONyc, a yield-bearing dollar asset issued on Solana that combines reinsurance premium income with collateral returns. ONyc has moved past OnRe's own front end: it is supplied as collateral on Kamino and Loopscale, holds liquidity pools on Orca and Raydium, and has its yield traded on Exponent. Range’s own client base reflects the same pattern more broadly - it works with permissionless secondary-market venues generally at subsequent stages, after a token like ONyc passes through initial issuance.
One product, different points of access
The distribution model is what creates the control problem. ONyc reaches holders through different paths: one in which the acquirer completes full KYC before OnRe issues to them, and one in which OnRe has no direct relationship with the end holder. On that second path, the financial crime obligation doesn't disappear - it has to sit with whoever controls the point of access, enforced before a wallet can act.
For entities operating as secondary market venues, a standard set of risk rules is required to produce a risk rating that can compare wallets and identify whether a wallet is exposed to sanctions, financial crime and, where possible, mixer use. What that describes is a score that a compliance team can reason about and use to measure risks, which is where Range comes in.
The address is the only evidence, so the control has three constraints
The compliance and risk screen must run when a wallet connects to the dApp interface, before the user can transact, since there is no later point at which a user can be reviewed.
It must return something the secondary market venue’s application can act on automatically, because an open-access channel has no queue and no reviewer behind it.
And it has to explain itself, because a compliance officer who blocks a customer needs a reason on the record and an examiner will eventually ask for it.
The control
Every wallet arriving on specified open-access channels can be routed through Range's Risk API before that wallet can buy tokens such as ONyc.
Range returns a single risk score from 1 to 10. The venue sets thresholds based on its own policy: the threshold sits with the venue, not in a setting Range imposes. If the score exceeds that limit, the design blocks access before the user reaches the buy screen.
The venue’s application turns that score into a decision. What makes the decision defensible afterward is what the response carries alongside the number: a plain-English explanation of why the score was assigned, whether that is sanctions-list exposure, direct malicious activity or another signal. It also includes the underlying evidence rather than a summary, and shows how closely the address is connected to known malicious activity, measured in transfer steps.
That last point lets you set a threshold deliberately. An address one step removed from a sanctioned entity presents a different level of risk from one four steps removed, and the response gives the venue the context to treat them differently.
Coverage is not limited to the moment of entry either. The same screen can cover existing holders plus new arrivals. Alerting can be included with the API on the venue's plan, and the venue receives usage notifications before it reaches its allocation.
Three questions behind one number
The score is not a single measurement. It stems from three independent categories of signal, each answering a different question about the same public key.
Attribution: Is this address itself flagged? Range matches the key against designation lists and threat intelligence: OFAC and other national sanctions programs, the stablecoin issuers' blacklists maintained by Tether, Circle, Coinbase, and Paxos, and confirmed exploits, scams, and phishing addresses. Attribution also runs in the other direction. Verified non-malicious addresses, including system programs, major exchanges and established protocols, are labeled as such, so ordinary onchain activity does not read as exposure.
Exposure: Who has it transacted with? Most addresses that should not reach a regulated product are not on any list. Exposure reads the counterparty graph around the address and reports how close the connection runs, measured in transfer steps, so a wallet one step from a sanctioned entity and a wallet four steps from one do not arrive as the same finding.
Behavior: Does the activity pattern look like something? Attribution and exposure both depend on something already being known. Behavior does not. It reads the shape of the activity itself: rapid movement of funds, structuring into many small transfers, peeling funds through a chain of wallets, which is what catches an address that carries no listing and no flagged counterparty but moves money the way laundered money moves.
For venues, the three questions are what make an automated decision defensible after the fact. They separate cleanly into different actions. An attribution hit against a sanctions list is not a judgment call, and the policy writes itself. An exposure finding is a risk appetite question, and the transfer distance is what a venue reasons over when setting where its own line sits. A behavioral pattern is the weakest signal standing alone and the strongest when sitting atop either of the others. A compliance officer explaining that a wallet is blocked is not defending a number. They name which of the three questions failed and point to the evidence underneath it.
The limit of a real-time score
Range's heuristic data runs against blocks indexed in near real time, so scoring itself is fast. Labeling an address caught up in a live, in-progress exploit is a different problem. Some labels are automatic, such as a stablecoin issuer blacklisting an address. Others involve human review and can take hours rather than seconds.
Range's guidance for that window is straightforward: for unusually large deposits where those minutes matter, hold the funds briefly rather than relying solely on the instant score. Screening infrastructure that overstates its own latency produces confident answers a compliance team cannot defend.
What a permissionless entry path requires
The shape of the requirement is now common across vault curators, RWAs and tokenized-asset issuers and yield products carrying exposure with an open-access path on Solana. The three constraints above are the starting point, and building the control against them adds two more that are easy to miss.
The threshold has to belong to the operator, because the risk appetite is theirs to set and defend, not a vendor's to assume. That is only possible if the operator can see which of the three questions produced the finding, since a sanctions match and a distant counterparty connection are not the same decision and cannot sit behind the same line.
And the coverage has to extend to positions already open, because an address that cleared the screen at entry can be flagged a month later.
Range covers all five: a single call when a wallet connects, a structured response venue's application acts on without a human in the loop, a score the operator thresholds itself, a stated reason and the evidence behind it for every response, and the same screen applied to the holders already on the book.
If you are opening an open-access entry point, the screen must exist before the first purchase clears.
Range is the platform for companies operating across stablecoins and fiat. To work through a connect-time control for your own product, get in touch.
Protect your time and money
Get your unified treasury dashboard in 30 minutes.


