Since OFAC started adding cryptocurrency addresses to the SDN list, sanctions compliance stopped being a banks-only problem. Exchanges, OTC desks, payment processors — anyone touching crypto flows can end up holding sanctioned funds, and "we didn't know" is not a defense regulators accept. Here is how sanctions screening works on-chain, and how to keep up when the lists change weekly.

Globe with flagged jurisdictions next to a screening list
Globe with flagged jurisdictions next to a screening list

Sanctions lists now name wallets directly

Modern designations frequently include cryptocurrency addresses: mixers, ransomware operators, fraud networks and exchange operators have all been listed with their wallets. The four heavyweight sources are OFAC (US), the EU consolidated list, the UN Security Council list and the UK OFSI list — but real coverage needs far more: national lists, law-enforcement data and investigative attributions. Arya Crypto screens every check against 100+ sources covering more than 2 million sanctioned addresses.

The listed address is just the start

Sanctioned actors do not keep funds on their listed addresses — they move them within minutes through fresh wallets. That is why serious screening evaluates indirect exposure: how close your counterparty sits to a listed cluster in the transaction graph, how much value flowed, and how recently. An address that received 40% of its funds two hops from a listed mixer deserves very different treatment from one with trace dust ten hops away.

Strict liability raises the stakes

US sanctions rules apply on a strict-liability basis: intent does not matter, and processing sanctioned funds can trigger penalties even if you had no idea. What regulators do weigh heavily is whether you ran a reasonable screening program. Documented checks — with timestamps, sources and scores — are the difference between an enforcement case and a corrected incident.

  • Screen every deposit before crediting it.
  • Screen withdrawal destinations before release.
  • Keep every report; you will want the paper trail.

Lists change weekly — your data must too

Designations land continuously, and a counterparty that was clean at onboarding can be listed a month later. Point-in-time screening therefore has a shelf life. Put standing counterparties under KYT monitoring so they are re-screened automatically — on Arya Crypto tracked addresses are re-analyzed as often as every two hours, and the nightly PDF report gives your compliance team a daily sanctions posture across all monitored wallets.

When you get a match

Do not panic, and do not quietly return the funds — returning sanctioned money is itself a violation in many regimes. Freeze the transaction, document everything, and follow your jurisdiction's reporting procedure (blocking report, SAR or local equivalent). The full check report — score, matched source, category breakdown — downloadable as PDF, is exactly the artifact your lawyer and regulator will ask for first.

Which lists you are actually screened against

"Sanctions screening" is a broad phrase, and what it covers varies enormously between providers. It is worth knowing the layers.

The core designations are OFAC's SDN list, the EU consolidated list, the UN Security Council list and the UK OFSI list. These are authoritative and non-negotiable — a match here stops the transaction, full stop.

Beyond them sit national registers and law-enforcement feeds that never make headlines but carry real weight in specific jurisdictions. On Arya Crypto the total is 100+ sanctions and risk sources, backed by 7 million labeled entities and over 2 million sanctioned addresses across 43 networks.

Ask any provider for that breakdown before buying. A tool screening two lists and a tool screening a hundred both describe themselves as "sanctions screening".

Indirect exposure is where the real risk sits

Screening only for direct list matches will catch almost nothing, because designated actors move funds within minutes of a listing and never receive on a published address again.

What matters is the money's path. Did funds reach this wallet one, two or five transfers from a designated cluster? What share of total inflow traces back there? How recently? A wallet that received 60% of its balance two hops from a sanctioned mixer yesterday is a genuine sanctions problem even though the address itself appears on no list.

This is why a serious result comes back as a risk score with a category breakdown rather than a yes/no. Reality does not fit in a boolean, and a compliance decision built on one will be wrong in both directions.

Screening withdrawals, not just deposits

The single most common gap in a sanctions programme is screening incoming funds while ignoring where funds are going.

Deposit screening protects you from receiving tainted assets. Withdrawal screening protects you from sending assets to a designated address — and in most jurisdictions that is the more serious violation, because it is the one that provides value to a sanctioned party.

Practically, that means a screening call in your withdrawal approval path, before funds are released, on the destination address. It is one API request and it closes the exposure that regulators care about most.

Building the evidence trail

Sanctions compliance is judged on process and documentation as much as on outcomes. Regulators do not expect you to catch everything; they expect a reasonable, consistently applied process that you can demonstrate.

Every check on Arya Crypto produces a timestamped record with the score, the category breakdown and the specific sources consulted, exportable as PDF. For monitored addresses a nightly PDF report summarises the current position across everything you track — a ready-made artefact for auditors and banking partners.

Pair this with identity verification at onboarding and KYB for corporate counterparties, so you can name the person or entity behind any address you flagged.

What to do when a match comes back

A direct sanctions hit is not a judgement call. Stop the transaction, do not release funds, and escalate to whoever owns compliance in your organisation — before anyone contacts the customer.

Preserve everything: the screening report, the transaction details, the timestamps. If your jurisdiction requires reporting, that record is what the report is built from. Do not tip off the counterparty, because in many jurisdictions doing so is itself an offence.

For indirect exposure the response is proportionate rather than absolute. Read the category breakdown, look at value share and recency, and document the reasoning behind whatever you decide. A written rationale for accepting a 2% four-year-old exposure is defensible; the same decision with no record is not.

Keeping data current without doing it yourself

Sanctions lists change constantly. OFAC adds designations with no notice, the EU updates on its own cycle, and newly identified addresses attached to existing designations appear continuously.

Maintaining that yourself means monitoring multiple government feeds, normalising inconsistent formats, handling transliteration of names across alphabets, and mapping designations to on-chain addresses. It is a permanent team, not a project.

The alternative is that your provider does it and you consume the result. What you should verify is refresh frequency: how quickly does a new designation reach the screening engine? Anything measured in days is too slow, because the first hours after a listing are exactly when funds move.

Automating screening in your pipeline

Manual dashboard checks work at low volume. Beyond that, screening belongs in code. A single POST submits an address or transaction and the response returns score, categories and matched sources as structured JSON.

Call it in your deposit-crediting path and your withdrawal-approval path, apply thresholds programmatically, auto-clear the clean majority, and route only medium and high results to human review. Register a webhook so results arrive when analysis completes rather than polling.

Because API and dashboard share one balance and one audit trail, the analyst reviewing a flagged case sees exactly what the pipeline saw — which matters when you reconstruct a decision months later.

Screen your counterparties against 100+ sanctions sources — Pricing · Services · KYT · KYC · KYB · Exchange · Prop