AMLRadar
AMLRadar
← Back to Blog
Compliance3 July 2026·6 min read

Why Basic Sanctions Screening Fails in Crypto

Checking whether a wallet address is directly on a sanctions list catches almost nothing. Here's why indirect exposure — mixers, multi-hop transfers, and cross-chain bridges — is where the real compliance risk lives, and how to screen for it.


Most crypto sanctions screening today does exactly one thing: it checks whether a wallet address appears, character for character, on a sanctions list. If the address matches, it's flagged. If it doesn't, it's cleared.

This is necessary. It is also, on its own, close to useless as a compliance control — because almost nobody sanctioned is careless enough to move funds directly from a designated address into your platform.

What "basic" screening actually catches

A direct-match screener answers one narrow question: is this exact address on a list? That question has a shrinking pool of "yes" answers, because sanctioned actors know the lists exist and route around them accordingly.

Consider how the OFAC-designated Lazarus Group actually moves stolen funds. After the $625M Ronin Bridge hack, proceeds didn't sit in the address that eventually got designated — they moved through dozens of intermediate wallets, were split into smaller amounts, passed through mixing services, and in some cases crossed to other chains via bridges before reaching an exchange or OTC desk. By the time OFAC formally designates a specific address, the funds it once held have usually already moved on.

A wallet that receives funds two hops downstream from a sanctioned address will pass a direct-match check every time. So will a wallet that routed funds through Tornado Cash — itself an OFAC-designated entity since August 2022 — as long as the wallet's own address was never individually listed.

Direct-match screening isn't wrong. It's just answering a much smaller question than "is this transaction connected to sanctioned activity," which is the question regulators actually expect a compliance program to be able to answer.

Why this gap matters more under the EU's new AML framework

The EU AML Package changes the standard compliance teams are held to. Historically, filing a suspicious transaction report required identifying a plausible predicate offense — some specific underlying crime the funds were connected to. Under the new regulation, that bar drops: a mere suspicion of a link to illicit activity or terrorist financing is enough to trigger a reporting obligation.

That shift matters directly for screening design. A program that only checks direct address matches is built around the old, narrower standard — a confirmed hit. A program built for the new standard needs to surface the kind of ambiguous, indirect signals that "mere suspicion" is meant to capture: a wallet that received funds from a mixer three hops ago, or bridged assets in from a chain where a sanctioned entity was active. Under AMLR, that's no longer something a compliance program can reasonably decide not to look for.

The three gaps in direct-match-only screening

1. Mixer exposure. Tornado Cash, Sinbad, Blender, and ChipMixer are all OFAC-designated, but the wallets that use them to obscure fund origin are, individually, usually not designated at all. A wallet with three transactions through a sanctioned mixer's smart contract carries real compliance risk — but a direct-match screener sees a clean address.

2. Multi-hop transfers. Funds rarely move in one step from a sanctioned wallet to a customer-facing platform. They move through a chain of intermediate addresses first, sometimes deliberately structured in small amounts to avoid pattern-detection thresholds. Each individual hop looks unremarkable in isolation; the pattern only becomes visible when you trace the chain.

3. Cross-chain bridges. An address that looks clean on Ethereum may have received funds bridged in from a chain where the same actor was active under a different, already-designated address. Bridge transactions break the on-chain trail that a single-chain screener follows, which is precisely why they're a common laundering step.

None of these three gaps are edge cases. They're the standard playbook for moving illicit crypto funds, which is exactly why a screening program that doesn't account for them is checking the wrong thing.

What indirect exposure detection actually requires

Closing these gaps means the screening result needs to answer more than a yes/no on direct listing:

Basic screeningIndirect exposure detection
Exact address match against a listDirect match, plus transaction history analysis
Single point-in-time checkMulti-hop tracing across recent transaction history
No mixer awarenessKnown mixer smart-contract interaction detection
Single-chain viewCross-chain bridge tracking to flag chain-hopping
Binary result (clear / match)Composite risk score with typology classification

The output that actually supports a defensible compliance decision isn't a single binary flag — it's a risk score built from several independent checks, with enough detail (which mixer, how many hops, which bridge, when) that an MLRO can document why a decision was made, not just what the decision was.

How AML Radar approaches this

The AML Radar Wallet Screener runs five checks on every address, not one:

  • Direct match against OFAC, EU, and UK sanctions lists
  • Known mixer detection (Tornado Cash, Blender, Sinbad, ChipMixer, and others)
  • Indirect mixer exposure — has the wallet transacted with a known mixer, even without a direct hit?
  • Cross-chain bridge detection, flagging when funds have moved to a chain that needs separate screening
  • Typology classification, labeling the pattern (state-sponsored hack, sanctions evasion, obfuscation, and others) rather than just a raw score

Every check result — and the composite 0–100 risk score built from it — is logged to the MLRO Audit Trail with a timestamp, so the documentation a regulator asks for already exists by the time they ask for it.

What to check before trusting a screening tool

If you're evaluating (or re-evaluating) a sanctions screening setup, a few direct questions cut through the marketing copy quickly:

  • Does it check indirect exposure through mixers, or only direct address matches?
  • Does it trace multi-hop transaction history, or stop at the first hop?
  • Does it flag cross-chain bridge activity, or only screen the chain you searched?
  • Does the audit trail record why a result was reached, not just the final flag?

If the answer to any of these is no, the tool is doing direct-match screening with better branding — which, per the EU's new "mere suspicion" standard, is a narrower compliance program than most CASPs now need.

Conclusion

Direct address matching is table stakes, not a compliance program. The actual risk in crypto AML lives in the indirect exposure — the mixer three hops back, the bridge that moved funds to another chain, the wallet that's never been designated but has touched sanctioned infrastructure repeatedly. Screening built only for exact matches will keep missing exactly the activity it exists to catch.

Try the AML Radar Wallet Screener — five checks per address, including mixer and cross-chain exposure, free to start.


This article is for informational purposes only and does not constitute legal advice. Always consult a qualified compliance professional for guidance specific to your jurisdiction and business.

Ready to screen a wallet address?

Use AMLRadar's free screener to check any crypto address against OFAC, EU, and UK sanctions lists instantly.

Try the Screener