Get advice from AML Crypto experts
Receiving cryptocurrency with a risky history may lead to questions from an exchange. The platform may restrict your account or freeze the assets because of links to illegal activity in which you may never have participated.

With centralized stablecoins, the consequences may arise directly at the blockchain-address level. The issuer can freeze your USDT or USDC: the tokens will remain visible in the wallet, but you will no longer be able to transfer or exchange them. The terms of Tether and Circle allow tokens or addresses to be blocked in cases involving sanctions, suspected illegal activity, or legally valid requests from competent authorities.
An AML check is therefore not a formality or an attempt to obtain an attractive green indicator. It should help you understand what is known about an address or transfer, which risk factors have been identified, and whether the operation can proceed without further analysis.
Key Takeaways

  • An AML check may include address screening, analysis of a specific transfer, and continuous KYT monitoring.
  • A risk score is based on labels, source of funds, taint level, proximity to risky entities, and other factors.
  • A high score requires attention, but it does not prove that the address owner is guilty of wrongdoing.
  • The practical outcome of a check should be one of three decisions: proceed, decline, or escalate the case for deeper analysis.

What Processes Can an AML Check Include?

The term “AML check” is often used to describe several separate processes. There are fundamental differences between them.
Wallet Screening answers the question: “How risky is this address right now?” Transaction Screening evaluates a particular transfer. Transaction Monitoring looks more broadly at what is happening with the funds and the customer’s behavior over time. In industry practice, screening and monitoring are treated as separate but complementary layers of control.

A one-time address check does not replace continuous monitoring. An address may appear safe during onboarding but later begin interacting with new counterparties, follow an unusual sequence of operations, and develop a higher-risk profile.

What Data Do AML Services Analyze?

An AML system does not assess a single attribute. It evaluates a combination of qualitative and quantitative risk factors. These include characteristics of the address, the transaction, and their surrounding blockchain activity that may indicate undesirable or illegal behavior.

The calculation may include known address labels, the history and origin of funds, wallet behavior, associated counterparties, distance from risky entities, the share of assets connected to them, and the sequence of transactions. Additional inputs may include clustering, mathematical heuristics, investigation results, and OSINT data.
Another metric is the taint level. In simplified terms, it reflects what share of the funds, or their transaction history, is associated with particular high-risk sources. It is an analytical characteristic, not legal proof that the assets are illicit or that their current owner participated in a crime.

What Risky Connections Can an AML Check Identify?

An AML service may detect interactions with scam projects, addresses used by attackers after hacks, stolen assets, sanctioned infrastructure, darknet markets, mixers, and other high-risk entities.

The existence of a label alone is not enough. An address may have received assets directly from a known attacker, or it may be connected through several intermediary wallets and services. These situations should not be assessed in the same way.

A proper analysis should answer at least four questions:
  • What kind of risky entity is involved?
  • How close is the connection?
  • What share of the funds does it affect?
  • When did the interaction occur?

How Risky Assets Can Affect Individuals and Businesses

For an individual user, the most obvious risk is an account or asset freeze after depositing cryptocurrency on an exchange. With USDT and USDC, however, holding funds in a personal non-custodial wallet does not provide absolute protection. Stablecoins can also be frozen directly in your crypto wallet.
Tether explicitly states that it may freeze tokens when a transfer is attempted to a sanctioned or suspicious address. Circle provides for the blocking of on-chain addresses and the freezing of associated USDC. This means restrictions may be applied at the token level, not only to an account on a centralized platform.
This is not merely theoretical. Tether has publicly reported freezing addresses associated with illegal activity and terrorist financing.

In addition to losing access to assets, a user may be required to explain the source of funds, participate in a compliance review, or become one link in a transaction chain under investigation.

For a business, the consequences are broader: direct financial losses, frozen assets, regulatory claims, termination by banking or payment partners, risks to a VASP licence, and reputational damage. This is why an address should ideally be checked before funds are received or sent, and the result should be retained as evidence that the check was performed. This approach is also reflected in Btrace’s positioning.

What You Can See in an AML Report

The contents of AML reports vary. Some services display only an overall risk level, for example from 0 to 100. Others disclose the source of funds, risk categories, distance from identified sources, and the grounds for the assessment.

In the current Btrace report, users can see the final risk score, risk factors and comments, the composition of funds, and their source. The unlabelled portion is displayed separately: our service does not replace an unknown origin with an assumed category merely to produce a visually complete 100% allocation.

Example of the Btrace interface showing crypto-address screening data:
The correct way to read a report is from the reasons to the final score, not the other way around. The percentage is useful for quick orientation, but the decision should be based on what produced that percentage.

How to Assess Direct and Indirect Connections

A direct connection exists when the screened address has interacted directly with a risky address or service. An indirect connection runs through one or more intermediary wallets. With an indirect connection, there is generally less reason to assume that your counterparty was involved in the risky activity.

Receiving funds directly from a sanctioned address is not the same as having a remote connection through several intermediaries. The assessment should account for the entity category, the number of hops, the direction of movement, the share of affected assets, and the timing of the transactions.

Particular care is required with transaction chains passing through large exchanges, exchangers, and other custodial services. It is often assumed that such a service has already screened its customers and that there is therefore no risk. Once assets enter a common hot wallet, however, funds belonging to many customers are pooled, while the platform’s internal accounting is not visible on-chain.

Continuing to trace transactions beyond that point does not always improve accuracy. In some cases, it merely creates false confidence.

Why a Risk Score Is Not Proof of a Crime

A risk score is a decision-making indicator, not evidence that the law has been broken.
Scoring is a probabilistic judgment. It may incorporate mathematical heuristics, address attribution, known labels, transaction connections, and OSINT data. A high score means that significant risk factors have been detected, but it does not establish the owner’s identity or prove guilt.

The reverse is also true: a low score is not a permanent certificate of “cleanliness.” A service evaluates the data available to it at a particular point in time.

Why Different Services Produce Different Results

AML providers analyze the same blockchain, but their attribution databases and analytical models differ. One service may already know that an address belongs to a particular exchanger or criminal infrastructure, while another may still classify it as an unlabelled wallet.

The final result may be influenced by factors such as:
  • the completeness and freshness of labels;
  • clustering rules;
  • depth of analysis;
  • weighting of individual categories;
  • methods used to calculate indirect risk;
  • speed of response to publicly known incidents;
  • treatment of particular jurisdictions.
A difference in scores does not always mean that one of the services is wrong. The comparison should cover not only the percentages, but also which entities were detected, how close the connections are, and what data supports the attribution.

How to Read the Result of an AML Check Correctly

Start by identifying the object of analysis. Was the service checking an address, a particular transaction, or the customer’s behavior over a period of time? Mixing these levels often leads to incorrect conclusions.

You can then follow a short process:
Review the final risk score as an initial indicator.
Identify the categories and labels that affected the score.
Examine the source and taint level of the funds.
Analyze direct and indirect connections, including their distance, share, and timing.
Compare the result with the context: the amount, purpose of the operation, and the counterparty’s explanation.
Save the report together with the date of the check and the basis for the decision.
The same score may be produced for entirely different reasons. It may result from one critical direct connection or from a combination of several weak indirect factors. This is why a decision should never be based on the number alone.

When an Automated Report Is Not Enough

Automated screening works well for a quick initial decision. However, it is insufficient when a critical category has been detected, the source of the high risk is unclear, a significant portion of the funds has no established origin, or the counterparty’s explanation contradicts the blockchain data.
Further analysis is also justified when the amount is substantial and the cost of an incorrect decision is high. In such cases, the specific transaction should be examined, the route should be reconstructed on a graph, associated addresses or clusters should be checked, and source-of-funds information may need to be requested.

Btrace provides fast automated scoring, while a graph-based tool such as Bholder allows analysts to investigate the movement of funds, counterparties, and connections between addresses manually. When the company lacks the expertise required to interpret the graph, the case should be referred to a specialist.

Screenshot of Bholder, a solution for visual analysis of connections between blockchain addresses

Why the Result of a Check May Change

A risk score does not change only because of new transactions. Retrospective labelling is also possible: an address or service that previously had no established attribution may later be connected to fraud, sanctions, a hack, or another risk category.

For example, a crypto scammer’s address may initially appear completely clean when checked before the criminal activity becomes publicly known.

As a result, the score may increase even if the screened address has not made any new transactions since the original check. This is why the report should be saved as a snapshot of the data available on the date when the decision was made.

What Decision Should Be Made After the Check?

The practical outcome of an AML check should be one of three actions.
Proceed with the operation when the reasons for the score are clear, the risk is acceptable, and the data is consistent with the context.
Decline the operation when critical connections have been identified and cannot be reasonably explained, or when the risk exceeds the acceptable threshold.
Escalate the case for further analysis when the available information is insufficient, the route is ambiguous, or the consequences of an error would be too serious.
The value of an AML check lies not in obtaining an attractive percentage, but in enabling an informed and documented decision.

Conclusion

An AML check may analyze an address, an individual transaction, or user behavior over time. To use the result correctly, looking at the risk score is not enough. You need to understand the source of funds, the taint level, the nature of the connections, and the limits of the available data.

AML services such as Btrace help assess the risk of a crypto address quickly and show the factors that influenced the result. When an automated report is insufficient, the connections can be investigated more deeply using solutions such as Bholder or referred to a specialist.

Check an address in Btrace before an operation, and assess not only the final score but also the reasons behind it.

FAQ

  • What Is the Difference Between Wallet Screening and Transaction Screening?
    Wallet Screening evaluates the overall risk profile of a crypto address at a particular point in time. Transaction Screening analyzes a specific transfer and the risks associated with the funds involved in that transaction.
  • What Is Transaction Monitoring or KYT?
    It is the continuous analysis of transactions and customer behavior. It helps identify anomalies, transaction splitting, unusual routes, and other suspicious patterns.
  • Can USDT or USDC Be Frozen Directly in a Personal Wallet?
    Yes. Issuers of centralized stablecoins are technically able to restrict the movement of tokens at a specific on-chain address when grounds exist under their rules and the applicable law.
  • Does a High Risk Score Prove That the Funds Are Illegal?
    No. It indicates significant risk factors, but it does not establish the owner’s guilt and does not replace an analysis of the context.
  • When Is an Automated AML Check Not Enough?
    When the reasons for the score are unclear, critical connections have been detected, the amount is significant, or the route of funds and related counterparties must be examined manually.
Want to learn more and get expert advice? Leave your email and we will contact you promptly!
We also recommend