Before you accept a deposit, pay a counterparty or list a client's wallet, one question matters more than any other: has this address touched sanctioned entities, stolen funds, darknet markets or scam infrastructure? A crypto AML check answers it in seconds. Yet most teams either skip the check entirely or run it without understanding what the result means — and both failures are expensive. This guide walks through what actually happens during a check, how the underlying data is assembled, how to read every field of the report, when in your workflow screening belongs, and what to do in the uncomfortable moment when an address comes back high-risk.

Wallet address screening with sanctions match and risk verdict
Wallet address screening with sanctions match and risk verdict

What an AML check actually verifies

An AML check takes a wallet address or a transaction hash and screens it against accumulated risk intelligence. That intelligence is not a single list — it is a merged picture assembled from government sanctions programmes, law-enforcement disclosures, exchange-reported abuse data, and investigative attribution built up over years of tracing real cases.

On Arya Crypto every check runs against more than 100 sanctions and risk sources, including the OFAC SDN list, the EU consolidated list, the UN Security Council list and the UK OFSI list, plus national registers and law-enforcement feeds that never make headlines. Behind those lists sits a database of over 7 million labeled entities and more than 2 million sanctioned addresses, spanning 43 blockchain networks.

The engine evaluates two distinct things at once. First, direct exposure: does this exact address appear in any source? Second, indirect exposure: where did the money in this wallet come from, and where has it gone? The second question is where most of the real risk hides, because sanctioned actors almost never receive funds on a publicly listed address.

Direct versus indirect exposure

Direct exposure is unambiguous and easy to act on. The address appears on a sanctions list, or it belongs to a cluster that investigators have labeled as a ransomware operator, a darknet marketplace, a known scam, or a mixing service. There is no interpretation required — you have a named match, with a named source.

Indirect exposure is subtler and far more common. The address received funds one, two or five transfers away from a flagged source. Nothing about the address itself is listed; the risk arrives through its counterparties. Evaluating this well is what separates a serious screening engine from a lookup table.

A good engine weighs three things. Hop distance: how many transfers separate your address from the risky source. Value share: what proportion of the wallet's total inflow is traceable to that source. Recency: whether the exposure happened last week or four years ago. A wallet that received 60% of its balance two hops from a sanctioned mixer yesterday is a genuine problem. A wallet with 0.05% exposure eight hops back in 2021 is statistical noise, and blocking it costs you a customer for nothing.

This is precisely why results come back as a risk score with a category breakdown rather than a binary yes/no. Reality does not fit in a boolean.

Where the underlying data comes from

It is worth understanding what you are actually buying when you pay for screening, because the quality of a check is entirely a function of the quality of its data.

Government sanctions lists are the hard floor. Since OFAC began publishing cryptocurrency addresses alongside SDN designations, sanctions compliance has been directly actionable on-chain. These lists are authoritative but incomplete — they name the addresses regulators know about at the moment of designation, and sanctioned actors move funds within minutes of a listing.

Entity attribution fills that gap. Analysts cluster addresses that provably belong to the same actor using on-chain heuristics — common-input ownership, change-address patterns, timing correlations — and then label those clusters from off-chain evidence: court filings, exchange disclosures, seized infrastructure, scam reports. This is why a database of 7 million labeled entities is more valuable than a list of 2 million sanctioned addresses: the labels tell you what an address is, not merely that someone designated it.

Category intelligence covers the rest of the risk surface: mixers and tumblers, darknet markets, gambling services, high-risk exchanges with weak or absent KYC, fraud and Ponzi clusters, and addresses tied to reported thefts. These categories carry different weights in different jurisdictions and under different risk appetites, which is why the report separates them rather than collapsing everything into one number.

How to read the risk verdict

Every check returns a score together with a category breakdown. The score is a triage signal; the breakdown is where the decision actually gets made.

A low score means no meaningful exposure was found across any category. Proceed, and archive the report — you will want the record later, even for the clean cases, especially for the clean cases.

A medium score is the interesting one, and the one teams handle worst. Open the category detail before you decide anything. Two wallets can carry identical medium scores for opposite reasons: one has a small but very recent sanctions trace, the other a large but ancient gambling share. The first needs escalation today; the second is probably acceptable under any sane risk policy. The headline number cannot tell them apart — the breakdown can.

A high score should stop the transaction until a human in compliance has read the full report. Do not automate away this step. High scores are rare enough that human review is affordable, and consequential enough that it is necessary.

  • Low: proceed, archive the report.
  • Medium: review categories, value share and recency before deciding.
  • High: hold funds, escalate to compliance, document the outcome.

Running a check, step by step

The mechanics are deliberately simple. Register an account, open the dashboard, and paste either a wallet address or a transaction hash into the check field. The network is detected automatically across all 43 supported chains — Bitcoin, Ethereum, TRON, BNB Chain, Solana, Polygon, Arbitrum, Base and the rest of the layer-2 ecosystem — so you do not need to know in advance which chain an address belongs to.

The result returns in seconds. New accounts receive gift tokens, which means your first real checks cost nothing; you can validate the tool against addresses whose history you already know before committing budget to it. That is a genuinely good way to evaluate any screening vendor: run it against a case you have already investigated and see whether it finds what you found.

Every completed check produces a downloadable PDF report containing the score, the category breakdown, the matched sources and a timestamp. Attach it to your case file. When somebody asks in eight months why you accepted a particular deposit, that PDF is your answer, and it is a far better answer than institutional memory.

What each field in the report means

The report is designed to be read by a compliance officer, not only by an engineer. The score and risk level give you the triage verdict. The category breakdown shows which kinds of exposure contributed and in what proportion — this is the field that drives your actual decision.

Matched sources names the specific lists or datasets that produced a hit, which matters enormously when you need to justify a decision to a regulator or a banking partner: "OFAC SDN match" and "elevated proximity to a high-risk exchange" are very different statements with very different obligations attached.

Counterparty detail shows the labeled entities this address has transacted with, giving you the shape of the relationship rather than just a verdict. Timestamps matter more than people expect: a check is a point-in-time assessment, and a report from three months ago describes a world that may no longer exist.

When to screen in your workflow

Screen at every trust boundary — every point where value crosses from someone else's control into yours, or out again.

In practice that means: before crediting a customer deposit; before releasing a withdrawal to a new destination address; before settling an OTC trade; when onboarding a market maker, liquidity provider or payment partner; and before any large or unusual transfer regardless of counterparty history.

The withdrawal case is the one teams most often neglect, and it carries real risk. Screening deposits protects you from receiving tainted funds. Screening withdrawal destinations protects you from sending funds to a sanctioned address, which in most jurisdictions is the more serious violation.

For counterparties you deal with repeatedly, one-time screening is not enough. Risk is not static: an address that screens clean today can receive ransomware proceeds next month or be designated by OFAC next quarter. Put standing counterparties under continuous KYT monitoring so their addresses are re-analyzed on a schedule — as frequently as every two hours — and you get an alert when the picture changes rather than discovering it during an audit.

Common mistakes worth avoiding

Treating the score as a verdict. The number is a triage signal. The category breakdown is the decision input. Teams that automate purely on the score generate both false positives that cost customers and false negatives that cost far more.

Screening once and considering the matter closed. A point-in-time check has a shelf life measured in weeks, not years.

Ignoring indirect exposure. If you only check whether an address is directly listed, you will miss nearly all real sanctions risk, because sophisticated actors never receive on listed addresses.

Blocking on any exposure at all. Trace amounts of historical mixer exposure are extremely common in ordinary wallets, particularly older ones. A policy that blocks every non-zero exposure will reject a large share of legitimate customers and train your team to override the system, which is worse than having no system.

Failing to keep records. The check that you ran but cannot produce evidence of is, from a regulator's perspective, a check you did not run.

Automating screening through the API

Manual dashboard checks work at low volume. Past that, screening belongs in your transaction pipeline. The same engine is available over a REST API: a single POST request submits an address or transaction, and the response carries the score, categories and matched sources in structured JSON.

The usual integration pattern is to call the API in your deposit-crediting path and your withdrawal-approval path, apply your thresholds programmatically, auto-approve the clean majority, and route only medium and high results into a human review queue. Register a webhook and results are delivered to you when analysis completes, so you are not polling.

Because the API and the dashboard share one token balance and one audit trail, an analyst reviewing a flagged case in the dashboard sees exactly what the pipeline saw. That coherence matters when you are reconstructing a decision months later.

Exchange deposits versus self-custody wallets

Not every address means the same thing, and treating them identically produces bad decisions. A self-custody wallet is controlled by one party, so its transaction history reflects that party's behaviour directly. Exposure found there is attributable to your counterparty.

An exchange deposit address is different. It belongs to a custodial service holding funds for many customers, and its history reflects the platform's aggregate flows, not your counterparty's conduct. Flagging a customer because the exchange they withdrew from has processed sanctioned funds somewhere in its history would flag most of the industry.

What matters with custodial addresses is the service's risk profile: does it enforce KYC, is it licensed in a credible jurisdiction, has it been named in enforcement actions? This is exactly what entity attribution provides — the report tells you an address belongs to a specific exchange, and whether that exchange is classified as high-risk.

The practical rule: for self-custody addresses, weigh the exposure. For custodial addresses, weigh the institution. Confusing the two generates false positives on ordinary users and false negatives on genuinely risky platforms.

What a check cannot tell you

Honest limitations matter, because a team that misunderstands what screening proves will over-trust it in exactly the wrong places.

A check tells you about on-chain history and known attribution. It cannot tell you who physically controls a private key, whether your customer is acting under duress, or whether a wallet with a spotless history belongs to a criminal who has simply never been caught. A clean result means "no known exposure found", not "this person is safe".

Attribution also has coverage limits. Newly created infrastructure may not be labeled yet; a scam launched last week may take time to appear in any dataset. This is why screening complements rather than replaces other controls — identity verification, behavioural monitoring, sensible transaction limits and staff who are permitted to escalate a bad feeling.

Finally, a check is a point-in-time assessment. It describes the chain as it exists at that moment. That is a genuine strength — the data is current — but it means today's clean result carries no promise about next month. Continuous monitoring exists precisely because single checks expire.

Records, audits and the paper trail

A defensible AML programme is as much about documentation as about detection. Regulators rarely fault firms for failing to catch every bad actor — that standard is impossible. They fault firms for having no reasonable process, or for being unable to demonstrate the process they claim to have.

So keep everything. Every check on Arya Crypto produces a timestamped record with the score, the category breakdown and the data sources consulted, exportable as PDF. For monitored addresses, a nightly PDF report summarises the current risk posture across everything you track — a ready-made artifact for auditors, banking partners and your own board.

When a partner bank asks how you screen counterparties, the strong answer is not a description of your intentions. It is a report, with a date on it, showing the check you ran before you moved the money.

Run your first AML check free — Pricing · Services · KYT · KYC · KYB · Exchange · Prop