Crypto wallet screening: querying address history
In crypto assets, risk lies not in the individual but in the history of the address. TruvaLI evaluates the wallet address against sanctions records, mixer exposure, and risky clusters, combining the result with customer risk.
Crypto wallet screening is the evaluation of a blockchain address against sanctions records, known risky clusters, and fund history. It differs from traditional screening in its subject: here, it is not a person being screened, but an address, and the history of that address is publicly visible.
What is analyzed in an address?
| Control | What it queries |
|---|---|
| Direct sanctions match | Is the address directly listed in a sanctions decision |
| Distance | How many steps away is the address from a listed address |
| Mixer exposure | Has the fund passed through a service designed to obscure its origin |
| Cluster relationship | Does the address belong to a known exchange, service, or risky entity |
| Fund age and path | Where, when, and in how many steps did the fund arrive |
The concept of distance is decisive here. Funds coming directly from a sanctioned address and funds coming through three intermediaries are not the same, but the latter is not considered clean either. Which distance an institution accepts is a decision of its own risk appetite and is written as a rule.
Who does address screening affect?
An address flagging as risky does not automatically make the customer risky, but it enters the customer risk score. Similarly, the customer's own profile affects the address evaluation: funds coming from a clean address for a high-risk customer may be evaluated with a different threshold than those of a low-risk customer.
This is why combining both sides is important. The customer side is explained on the customer onboarding and ongoing monitoring pages, while the screening infrastructure is detailed on the sanctions, PEP, and adverse media screening page.
When the source of funds question moves to the wallet
In a high-value crypto transfer from a customer, the question remains the same, only the form of proof changes: where did the funds come from, and does this match the customer's known profile? Address history is part of the answer to this question, not the whole; declarations and documentation are still required. The source of funds review page explains this aspect.
How is a rule set up?
Rules on the crypto side are generally written based on distance and amount: a match below a certain distance or a transaction above a certain amount is suspended. What the threshold will generate is measured against historical transfer traffic before going live. The rule is written in the rule and scenario engine, and its impact is observed through rule simulation.
The result is linked to a case
A match opens a case. In the case, the address, matching record, distance, fund path, and the reviewer's justification reside together; the decision is written to an immutable audit trail. The sectoral framework is covered on the crypto and VASPs page.
Common questions
- What is screened in crypto wallet screening?
- Not a person, but a blockchain address. The address's direct match with sanctions records, its distance to a listed address, mixer exposure, cluster relationship, and the path of the funds are evaluated.
- What does distance mean?
- It is how many steps away the address is from a listed address. Funds coming directly and funds coming through three intermediaries are not the same, but the latter is not considered clean either.
- Who decides which distance is acceptable?
- The institution. Risk appetite is written as a rule, and what the threshold will generate is measured against historical transfer traffic before going live.
- Does a risky address automatically make the customer risky?
- It does not. The address evaluation enters the customer risk score; the customer's own profile also affects the threshold with which the address is evaluated.
- How is the source of funds documented in a crypto transfer?
- Address history is part of the answer, not the whole. Declarations and supporting documentation are still required; all three are evaluated together.
- Is mixer usage a violation on its own?
- It is not a ground for a decision on its own, but having passed through a service designed to obscure the origin of funds is a strong signal and can suspend the transaction depending on the institution's threshold.
- How is the result recorded?
- A match opens a case; the address, matching record, distance, fund path, and the reviewer's justification reside together, and the decision is written to an immutable audit trail.
- Does screening data leave the institution?
- It does not in an on-premise deployment; evaluations and records remain within the institution's own infrastructure.