What Are the Main Types of Sanctions Screening?
Sanctions screening in cryptocurrency operates across four primary categories. Entity-based screening compares wallet addresses against official sanctions lists maintained by governments and international bodies. Transaction-pattern screening analyzes on-chain behavior to detect mixing services, rapid address-hopping, and layering techniques used to obscure coin origin. Behavioral screening flags unusual transaction volumes, rapid fund movement, or dormant wallets suddenly becoming active. Source-of-funds screening traces coins backward through the blockchain to identify whether they originated from legitimate exchanges, darknet markets, gambling platforms, or known theft incidents. Most comprehensive crypto wallet screening services combine all four approaches to produce a risk score. Each type catches different red flags: entity screening stops sanctioned counterparties, transaction-pattern screening reveals obfuscation attempts, behavioral screening detects account takeovers or money laundering, and source-of-funds screening prevents receiving stolen or blacklisted coins.
Entity-Based Sanctions Screening and Official Lists
Entity-based screening cross-references wallet addresses against official sanctions lists published by governments and international organizations. The primary lists include OFAC (US Office of Foreign Assets Control) SDN list, EU sanctions registers, UN Security Council designations, and similar bodies in other jurisdictions. These lists contain individuals, organizations, and sometimes cryptocurrency addresses explicitly prohibited from receiving or holding funds. When a wallet address appears on an official sanctions list, any transaction to or from that address violates sanctions law in most jurisdictions. Entity-based screening is the most straightforward type: it produces a binary result (sanctioned or not sanctioned). However, it only catches addresses that have been explicitly identified and added to a list. New wallets created by sanctioned entities, or addresses used by shell companies, may not yet appear on official lists. This is why entity-based screening alone is insufficient; it must be combined with transaction-pattern and behavioral analysis to catch sophisticated evasion attempts.
Transaction-Pattern Screening: Detecting Mixer Usage and Obfuscation
Transaction-pattern screening analyzes on-chain activity to detect mixing services, chain-hopping, and other obfuscation techniques. Mixing services (also called tumblers or mixers) deliberately break the transaction trail by combining funds from multiple sources and redistributing them to new addresses, making it difficult to trace coin origin. Chain-hopping involves moving funds rapidly across multiple wallets or blockchains to obscure the trail. Fake crypto wallet screening relies heavily on transaction-pattern detection: if a wallet receives funds from a known mixer, or exhibits rapid address-hopping behavior, it raises the risk score significantly. Blockchain analytics firms maintain databases of known mixer addresses and darknet market wallets. When a wallet's transaction history includes interactions with these flagged addresses, screening systems automatically elevate its risk classification. Transaction-pattern screening is particularly effective at catching money laundering attempts, because legitimate users rarely need to obscure their transaction history. However, it can produce false positives if a user legitimately uses privacy tools or moves funds between their own wallets across different exchanges.
Behavioral Screening: Detecting Unusual Activity and Account Takeovers
Behavioral screening monitors wallet activity patterns to identify anomalies that suggest compromise, money laundering, or fraud. Red flags include sudden spikes in transaction volume, rapid movement of large sums, dormant wallets becoming suddenly active, or transactions to multiple high-risk destinations in short timeframes. If a wallet has been inactive for months and then suddenly sends large amounts to a mixer or darknet address, behavioral screening flags this as suspicious. Behavioral screening also catches account takeovers: if a wallet's historical pattern shows small regular transactions, but suddenly executes a massive transfer to an unknown address, the system detects the deviation. This type of screening is probabilistic rather than deterministic; it assigns a risk score based on how far the activity deviates from the wallet's historical baseline and from normal user behavior. Behavioral screening is useful for detecting compromised wallets and catching money laundering in progress, but it requires historical data and can be slow to react to new threats. It also requires careful calibration to avoid flagging legitimate users who simply change their spending habits.
Source-of-Funds Screening: Tracing Coin Origin and Tainted Coins
Source-of-funds screening traces coins backward through the blockchain to identify their origin and detect tainted coins. This involves following the transaction chain from the current wallet back through previous owners to determine whether the coins came from a legitimate exchange, a darknet market, a theft, a scam, a gambling platform, or a sanctioned entity. If a coin's transaction history includes a link to a known theft (such as a major exchange hack), it is flagged as tainted. Similarly, coins that originated from darknet markets, ransomware payments, or gambling sites are marked as high-risk. Source-of-funds screening is the primary method for detecting dirty crypto before you receive it. When you run a crypto wallet screening check, the system traces the coins you are about to receive and assigns a risk score based on their history. A coin that has passed through multiple legitimate exchanges and has a clean transaction history receives a low risk score. A coin that originated from a mixer, passed through a darknet address, or came from a known theft receives a high risk score. This type of screening is essential for compliance: many exchanges and payment processors refuse to accept coins with high-risk source-of-funds scores, and receiving tainted coins can result in your own account being frozen or flagged.
How to Perform Crypto Wallet Screening Before Accepting Transfers
Before accepting a cryptocurrency transfer, perform a comprehensive crypto wallet screening check to verify the coins are not tainted and the sender is not a high-risk counterparty. The process involves: (1) Obtain the sender's wallet address and the transaction hash or the receiving address. (2) Use a blockchain analytics or AML screening service to run a check on the address. (3) Review the risk score and detailed report, which should show the source-of-funds history, any sanctions list matches, transaction patterns, and behavioral flags. (4) Interpret the risk score: scores below 20 are typically considered low-risk and acceptable; scores between 20–50 indicate medium risk and warrant further investigation; scores above 50 are high-risk and should be rejected. (5) If the report shows the coins came from a mixer, darknet market, or known theft, decline the transfer. If the report shows a sanctions list match, you are legally required to reject it. If the report is unclear or shows medium risk, contact the sender for clarification or request an alternative payment method. Many exchanges and payment processors now require wallet screening before accepting deposits; using a verified AML service from our curated list of AML services ensures you have a defensible compliance record.
Risk Score Thresholds and Acceptable Screening Levels
Risk scores from crypto wallet screening typically range from 0–100, with different thresholds indicating different compliance decisions. A score of 0–20 represents low risk: the coins have a clean transaction history, originated from legitimate sources, and show no sanctions list matches or suspicious patterns. Most exchanges and payment processors accept transfers from low-risk wallets without additional review. A score of 20–50 represents medium risk: the coins may have passed through a mixer, show some unusual transaction patterns, or have unclear source-of-funds history. Medium-risk transfers warrant additional due diligence, such as contacting the sender or requesting documentation of the coin source. A score of 50–100 represents high risk: the coins are likely tainted, show clear evidence of mixing or darknet involvement, or match a sanctions list. High-risk transfers should be rejected to avoid compliance violations and account freezes. Some jurisdictions and institutions set stricter thresholds; financial institutions often reject anything above 30, while smaller businesses may accept up to 50. Your acceptable risk threshold depends on your jurisdiction, your business model, and your risk tolerance. Always err on the side of caution: receiving tainted coins can result in your own account being frozen, your funds being seized, or legal penalties.
Frequently asked questions
What is the difference between entity-based and transaction-pattern sanctions screening?
Entity-based screening checks wallet addresses against official sanctions lists (OFAC, EU, UN). Transaction-pattern screening analyzes on-chain behavior to detect mixing, chain-hopping, and obfuscation. Entity-based screening catches explicitly designated addresses; transaction-pattern screening catches evasion techniques and suspicious activity that may not yet be on official lists.
How do I know if a wallet has tainted coins or is high-risk?
Run the wallet address through a crypto wallet screening service that performs source-of-funds analysis. The report will show the coin's transaction history, any mixer or darknet involvement, and a risk score. Scores above 50 indicate high risk; scores 20–50 warrant investigation; scores below 20 are generally acceptable.
What happens if I receive coins flagged as tainted by sanctions screening?
Receiving tainted coins can result in your exchange account being frozen, your funds being seized, or legal penalties depending on jurisdiction. Most exchanges now screen deposits and reject high-risk transfers automatically. If you unknowingly receive tainted coins, report it to your exchange immediately and cooperate with compliance investigations.
Can behavioral screening produce false positives?
Yes. Behavioral screening flags unusual activity patterns, which can occur legitimately (e.g., changing spending habits, moving funds between your own wallets). However, combined with other screening types, false positives are rare. Always review the full report before rejecting a transfer.
Which types of sanctions screening should I use before accepting crypto payments?
Use a comprehensive service that combines all four types: entity-based (official lists), transaction-pattern (mixers and chain-hopping), behavioral (unusual activity), and source-of-funds (coin origin). Verified AML services on our curated list provide this full-stack screening and give you a defensible compliance record.





