Facts first. Interpretation second.
ScamSift separates source observations from the policy that turns those observations into a warning.
Validate the subject
Wallets are checked for supported network format and checksum rules. URLs are normalized to their registrable public domain. Secret phrases, private keys, and passwords must never be submitted.
Compare documented sources
The normalized subject is compared with enabled sanctions, phishing, and public scam-report sources. Ethereum-compatible addresses also receive a live GoPlus malicious-address check and, when applicable, a token-contract check. An outage, timeout, or disabled feed is recorded as missing coverage rather than treated as a clean result.
Add context
For domains, registration information can provide age and registrar context. A young domain is a caution signal, not proof of malicious intent; an old domain is not proof of legitimacy.
Assess the evidence
Official sanctions matches and maintained phishing-list matches create strong warnings. Historical or unverified reports receive lower confidence and are described as reports, not ScamSift findings.
Expose uncertainty
A no-match result means only that no listed warning appeared in the sources successfully checked at that time. New scams, delayed feeds, compromised legitimate domains, and changing wallet ownership remain possible.
Result language
High-risk warning means strong supporting evidence was found. Use caution means a relevant warning signal or lower-confidence report was found. No listed warning found is an unknown-safety state—not a low-risk rating.