How to check a crypto wallet for AML risk

To check a wallet for AML risk is to assess the address and incoming assets before a transfer, not to obtain a verdict. Review the risk category, exposure depth, and report date rather than only the indicator color: one indirect hop from a mixer does not mean an automatic ban. Before depositing, save the PDF report and TxID. Never enter a seed phrase or private key into a screening tool. For transaction-path analysis, use blockchain analytics.
What AML wallet screening actually means
Checking a wallet for anti-money laundering (AML) risk means screening a public address and related transactions against attribution data for sanctions, scams, mixers, darknet activity, stolen funds, and other high-risk categories. Exchanges use similar screening for deposits and withdrawals. They compare counterparties with known entities and assess direct and indirect exposure through intermediate hops.
A public checker and an exchange's internal risk controls are different tools. A free service offers an indication, while the platform may use different alert thresholds and manual-review rules. A "green" screenshot does not guarantee a trouble-free deposit, and a "yellow" result does not always mean rejection. Understanding the logic is especially useful if you have already encountered common reasons exchanges freeze accounts.
Screening asks, "What is this address associated with?" It does not decide whether a person is clean. Identity, know your customer (KYC), and Source of Funds (SoF) are separate review layers. If an exchange requests evidence of origin after a deposit, see what exchanges ask for in a Source of Funds review.
How to interpret a risk score without panic
A risk score is a model-based measure of risk exposure, not a legal finding. Review four fields: the category, such as sanctions, scam, mixer, or ransomware; whether the exposure is direct or indirect; the number of hops; and the share of the balance or incoming transfer associated with risk. Direct contact with a sanctioned address and an indirect hop through a large exchange are different facts for a reviewer.
Common sources of false alarms include a shared exchange or bridge hot wallet in the transaction path, an outdated label, or a tiny amount touching a high-risk cluster while the main flow comes from a documented source. Do not route assets through a mixer to make the history "green"; this usually makes the AML picture worse. A perfect zero score is less useful than an understandable transaction trail supported by documents.
| Signal | How to interpret it |
|---|---|
| Direct sanctions or stolen-funds match | Do not send a large test deposit without first reviewing the source |
| Indirect hop from a mixer | Check the depth, share, and date; one hop does not mean an automatic ban |
| "Green" public checker | An indication, not a guarantee of a specific exchange policy |
| Outdated label | Check the report date because labels change |
Verify a sanctions match separately. OFAC and similar lists publish known digital currency addresses, but those lists are not exhaustive, and indirect exposure may also matter. If you need analysis of the hops rather than an indicator color, use blockchain analytics.
Checklist before depositing to an exchange
- Screen the sending address and, where relevant, the exchange deposit address. Save a screenshot and a dated PDF report.
- Record the TxID, amount, network, and counterparty.
- Never enter a seed phrase, private key, or phrase fragments into an AML service, extension, or support chat. A public address is sufficient for screening.
- If the risk score is high or the category is critical, such as sanctions or stolen funds, do not send a large deposit without reviewing the source first.
- Keep one evidence package. Send the exchange only the information it requests.
Before a large deposit, it can be useful to screen the address sending the assets, not just save a balance screenshot. If the assets came through P2P or OTC trading, preserve the conversation and transaction context in advance. Do not confuse phishing and malicious token approvals with AML screening. Any urgent request to enter a seed phrase for cleaning is a warning sign; see the first hour after a malicious approval.
What not to do and when a screenshot is insufficient
- Do not enter a seed phrase or private key into a third-party AML service; screening requires only a public address.
- Do not route assets through a mixer to obtain a green indicator.
- Do not rely on one checker color without a dated PDF and hop context.
- Do not send a large deposit when the category is critical, such as sanctions or stolen funds, without first reviewing the source.
A green or red screenshot does not replace transaction tracing when an exchange has already paused the account, the exposure is indirect across several hops, or the dispute concerns a specific incoming amount. In those cases, you need a counterparty map, dates, exposure shares, and links to your supporting documents. A timestamped PDF report may be useful as an attachment to a request, but it is not proof of "innocence."
No outcome is guaranteed. Platform policies and analytics vendors may differ, and labels change. If a restriction is already in place, also review exchange unfreezing and case assessment, while using analytics for the transaction trail rather than relying on chat advice. The goal is to interpret risk calmly from evidence, not react to a single indicator.
Risks and limitations
- A public checker and an exchange's internal risk screening may produce different results for the same address.
- A low risk score does not guarantee a trouble-free deposit or withdrawal, and a high score does not always mean final rejection.
- Labels and lists, including sanctions lists, change; an older PDF report may be outdated.
- Entering a seed phrase or private key into a third-party AML service creates a direct risk of asset loss and is not part of screening.
- This article describes common screening logic, not legal advice for any particular jurisdiction.
Sources used
- Chainalysis — What Is Wallet Screening?
- FATF — Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs (2021)
- OFAC FAQ 594 — querying digital currency addresses in Sanctions List Search
- DefCrypt blockchain analytics practice (anonymized case patterns)