Your crypto's background check

Run AML screening on any wallet or transaction to detect risk, fraud, and blacklist exposure before you transact.

How to use AML Verifier

AML Check explanation

Why check your crypto wallet for AML risks?

Identify suspicious activity before it impacts your account or reputation.

Avoid Freezes

Regular AML checks reduce the risk of wallet blocks by exchanges.

Protect Reputation

Stay clear of flagged funds and keep your identity clean.

Earn Trust

AML reports show transparency to investors and partners.

Stay Compliant

Meet AML requirements for business and international use.

What You Get

Our Services

Detailed risk screening for crypto wallets and transactions — powered by AML data, blockchain forensics, and sanction lists.

Wallet Check

Full wallet activity analysis across supported blockchains

Detection of suspicious or unusual transaction patterns

Flags for links to sanctioned individuals or entities

Risk score with clear breakdown by threat level

Darknet and scam-related exposure indicators

Choose your check pack

Clear, Flat Pricing. No Surprises.

Pay only for what you need — $5 per check, no subscriptions, no hidden fees.

Add Checks

1 Check
$5
3 Checks
$15
5 Checks
POPULAR
$25
10 Checks
$50
20 Checks
$100
30 Checks
$150
50 Checks
$250

Pay with USDT, Bitcoin, Ethereum and more

Refer & get rewarded

Invite friends. Get free checks.

Share AML Verifier and earn 1 free check (worth $5) for every user who joins and makes a purchase using your referral link.

aml-verifier.com/ref=yourusername
Crazy Fox
Crazy Fox
Joined
+1 Check
Crazy Fox
Crazy Fox
Joined
+1 Check
Crazy Fox
Crazy Fox
Joined
+1 Check

TELEGRAM MINI APP

Run AML checks right inside Telegram

No install, no sign-up friction. Open our Mini App in one tap and verify wallets or transactions without leaving your chat.

What you get in the Mini App

One-tap access from any Telegram chat — no downloads

Full AML checks with the accuracy of our web platform

Share results with colleagues or clients in seconds

AML Verifier Telegram Mini App preview on iPhone

JOIN AS AN AFFILIATE

Earn up to 30% by promoting AML Verifier

Join our affiliate program and get paid for every customer you bring in. Perfect for creators, communities, and crypto marketers.

Up to 30% commission

45-day referral tracking

Payouts in crypto

Live performance dashboard

How it works

1
Sign up— fast approval
2
Share your link— anywhere: site, socials, newsletter
3
Get paid— for every customer you refer
Blog

Latest Articles

Stay updated with the latest in crypto security.

Check a TON Wallet for AML Risk | AML Verifier
Jul 27, 2026

Check a TON Wallet for AML Risk | AML Verifier

Check a TON Wallet for AML Risk Before sending or accepting Gram, formerly known as Toncoin, USDT, or another asset on The Open Network, it is important to understand whether the wallet may be connected to sanctions, scams, stolen funds, mixers, high-risk exchanges, fraudulent services, or other suspicious activity. A TON wallet can appear normal while still having direct or indirect exposure to risky transaction flows. AML Verifier helps users check a TON wallet and review its blockchain risk exposure before completing a transaction. Check a TON wallet What Is a TON Wallet? A TON wallet is a blockchain account used to manage assets and interact with applications on The Open Network. In everyday language, the term “TON wallet” is often used to describe the public address associated with that account. A TON wallet may be used to: - send and receive Gram; - hold and transfer USDT on TON; - manage other fungible tokens known as jettons; - interact with smart contracts; - use decentralized applications; - make payments; - receive assets from other users or services. A public TON address can be shared and analyzed using blockchain data. It is not the same as: - a private key; - a seed phrase; - a wallet password; - access to the wallet application. Private credentials must never be shared with an AML screening service or counterparty. Gram, Formerly Toncoin Gram is the current official name of the native cryptocurrency of The Open Network. It was previously known as Toncoin. Following a community vote in 2026, Toncoin was renamed to Gram. The blockchain itself continues to be called The Open Network, or TON. Gram may be used for: - transfers between TON accounts; - network and smart-contract fees; - staking-related activity; - payments; - interactions with applications; - transferring jettons; - processing messages on the network. Some wallets, exchanges, applications, and older materials may continue to display the former Toncoin name or the TON ticker during the transition. For this reason, users should confirm both the network and the asset before completing a transfer. Why Check a TON Wallet? TON transactions are publicly recorded, but the risk associated with a wallet cannot be determined simply by looking at its address. A TON wallet may have direct or indirect exposure to: - sanctioned entities; - stolen cryptocurrency; - scams and fraudulent services; - phishing operations; - compromised wallets; - crypto mixers; - darknet-related services; - ransomware; - high-risk exchanges; - unlicensed gambling services; - fraudulent investment platforms; - suspicious P2P counterparties; - high-risk payment processors; - money laundering networks; - other suspicious services. Checking a TON wallet before sending or receiving assets can help identify warning signs and provide additional context for the transaction. When Should You Check a TON Wallet? A TON AML check may be useful before: - accepting Gram from an unknown person; - receiving USDT or another jetton; - sending assets to a new counterparty; - completing a P2P transaction; - processing a customer withdrawal; - accepting a business payment; - completing an OTC transaction; - depositing assets to a centralized exchange; - interacting with an unfamiliar service or Mini App; - investigating a suspicious incoming transfer. A check may also be useful after receiving assets if an exchange, payment provider, auditor, bank, or compliance team asks for information about their origin. How to Check a TON Wallet The process is straightforward: 1. Copy the public TON address you want to analyze. 2. Open AML Verifier. 3. Select the TON network. 4. Paste the wallet address. 5. Start the AML check. 6. Review the risk score and risk level. 7. Examine the detected exposure categories. 8. Review the transaction relationships. 9. Save the report if necessary. Make sure that you enter a wallet address rather than a transaction hash. Start a TON wallet check TON Wallet Address vs Transaction Hash A wallet check and a transaction check answer different questions. TON wallet address A TON address identifies an account on The Open Network. A wallet check helps analyze the broader blockchain activity and risk exposure associated with that account. Transaction hash A transaction hash identifies a particular on-chain transaction. A transaction check may focus on: - the account processing the transaction; - incoming and outgoing messages; - the transferred asset; - the amount; - the transaction time; - the transaction status; - the risk connected to the specific transfer. Because TON uses message-based interactions, one user action may produce multiple related messages and transactions. For additional context, it may therefore be useful to review both the wallet and the relevant transaction chain. What Does a TON Wallet Check Show? The available results may include: - overall risk score; - risk level; - identified entity information; - sanctions-related exposure; - scam or fraud exposure; - stolen-funds exposure; - mixer exposure; - darknet-related activity; - ransomware connections; - high-risk exchange exposure; - gambling-related exposure; - suspicious service categories; - direct and indirect transaction relationships; - wallet activity information; - broader transaction-history context. The report helps transform raw TON blockchain data into risk information that can be reviewed by individuals, businesses, and compliance teams. TON Address Formats TON addresses can be represented in different formats. A user-friendly Mainnet address may commonly begin with: - EQ for a bounceable address; - UQ for a non-bounceable address. TON addresses may also be represented in a raw format containing the workchain and account identifier. Different representations can refer to the same underlying account. When performing an AML check, use a valid address format supported by the service and confirm that the TON Mainnet network is selected. Bounceable and Non-Bounceable Addresses TON user-friendly addresses contain metadata indicating whether a message should be bounceable or non-bounceable. Bounceable address A bounceable address is generally used when the receiving account is active and capable of processing the incoming message. If message processing fails, the remaining value may be returned according to the message rules. Non-bounceable address A non-bounceable address may be used when sending the first funds to an account that has not yet been initialized or when the receiving service specifically requests that format. The bounceable and non-bounceable versions can represent the same underlying TON account. This distinction is related to message delivery and does not create two separate wallet owners. Always use the address format provided by the recipient, wallet, exchange, or payment service. TON Wallets Are Smart Contracts A standard TON wallet is implemented as a smart contract. The wallet contract can: - verify an owner’s authorization; - process incoming external requests; - create outgoing internal messages; - transfer Gram; - interact with other contracts; - initiate jetton transfers. A TON account may exist before its wallet contract has been deployed. After funding and deployment, the account can become an active wallet contract. Different wallet contract versions may provide different capabilities, but the public account address remains the key identifier used for blockchain analysis. TON Uses Message-Based Transactions TON has a message-oriented architecture. Accounts and smart contracts communicate by sending and processing messages. A user action may therefore produce: - an external request to a wallet; - an internal message from the wallet; - another message to a recipient or token contract; - additional messages generated during smart-contract execution; - several related transactions across the resulting message chain. This is especially important when reviewing: - jetton transfers; - decentralized application activity; - swaps; - payments processed by contracts; - transfers involving custodial services; - complex smart-contract interactions. The first visible transaction may not always represent the entire economic path of the assets. For a complete analysis, the related messages, contracts, and destination accounts may also need to be considered. Jettons on TON Jettons are fungible tokens issued on The Open Network. They serve a role similar to ERC-20 tokens on Ethereum. Jettons may include: - stablecoins; - payment tokens; - utility tokens; - assets issued by applications; - exchange-related tokens; - other fungible digital assets. USDT on TON is implemented as a jetton. A jetton normally uses: - a master contract that defines the token; - a separate jetton wallet contract for each holder. The jetton wallet contract is associated with the owner’s main TON address but is a separate on-chain contract. For this reason, a jetton transfer may involve more contracts and messages than a simple transfer of Gram. TON Wallet Check vs Jetton Check A general TON wallet check reviews the broader activity associated with the owner’s address. This may include: - Gram transfers; - jetton activity; - smart-contract interactions; - identified counterparties; - direct and indirect exposure; - broader wallet risk. A particular jetton transfer may also involve: - the jetton master contract; - the sender’s jetton wallet contract; - the recipient’s jetton wallet contract; - the owner addresses; - internal messages used to complete the transfer. The correct analysis should therefore consider both the main TON wallet and the relevant token-transfer path. USDT on TON USDT is available on The Open Network as a jetton. A TON wallet may be used to receive both Gram and USDT, but they are different assets. Gram Gram is the native cryptocurrency used for network fees, transfers, and smart-contract execution. USDT on TON USDT is a stablecoin issued as a jetton on TON. A wallet receiving USDT still needs a sufficient amount of Gram when network fees or further token transfers must be paid. Before accepting USDT on TON, confirm: - the correct network; - the recipient address; - the authentic jetton; - the amount; - any required comment or payment identifier; - the counterparty’s AML risk. USDT exists on several blockchains, so selecting the wrong network can result in loss of access to the assets. TON Wallet Check vs USDT TRC20 Check USDT is available on both TON and TRON, but these are separate blockchain networks. USDT on TON USDT on TON is implemented as a TON jetton and uses TON addresses and TON transaction architecture. USDT TRC20 USDT TRC20 is issued on the TRON network and uses TRON addresses and TRC-20 smart contracts. An address from one network should not be treated as an address from the other. For users handling USDT on TRON, use the dedicated guide: Check a USDT TRC20 wallet for AML risk Comments, Memos, and Payment Identifiers TON transfers can include a text comment or another payload. Some exchanges, payment processors, custodial services, or merchants may require a specific comment, memo, invoice identifier, or payment reference. Sending assets without a required identifier may make it difficult for the receiving service to credit the correct account. Before sending funds: 1. confirm the destination address; 2. confirm the network; 3. confirm the asset; 4. check whether a comment or memo is required; 5. copy the identifier exactly; 6. verify the wallet’s AML risk; 7. send a small test amount when appropriate. An AML check evaluates blockchain risk but does not replace correct payment instructions. Direct and Indirect Exposure TON AML analysis should consider both direct and indirect exposure. Direct exposure Direct exposure exists when the checked wallet sends assets directly to or receives assets directly from an identified address, entity, or service. For example: TON wallet A → Identified high-risk service There is no intermediary wallet or service between the checked account and the identified entity. Direct exposure is generally easier to interpret because the relationship is immediate. Indirect exposure Indirect exposure exists when assets pass through one or more intermediary wallets, smart contracts, or services. For example: TON wallet A → Intermediary contract → High-risk service Indirect exposure does not automatically prove that the wallet owner knowingly interacted with the final high-risk entity. Its significance may depend on: - the number of transaction or message hops; - the amount involved; - the percentage of wallet activity involved; - how recently the exposure occurred; - whether the pattern is repeated; - whether an intermediary belongs to an identified cluster; - the type of high-risk service; - the purpose of the transaction. A small historical connection several hops away may require a different response from a recent and repeated flow involving substantial value. How to Understand the TON Wallet Risk Score A risk score summarizes multiple blockchain risk signals into one result. In general: - Low risk indicates that no significant high-risk exposure was detected in the available data. - Medium risk indicates that some exposure, uncertainty, or unusual activity requires additional review. - High risk indicates stronger connections to identified high-risk entities, services, or transaction patterns. The score should not be interpreted in isolation. You should also review: - which categories were detected; - whether exposure is direct or indirect; - which asset was transferred; - the amount involved; - the percentage of activity involved; - the timing of the activity; - how frequently the pattern appears; - whether an identified entity is involved; - the context of the current transaction. Learn how to understand a crypto wallet risk score Risk Score and Risk Categories Are Different The overall risk score provides a summary. The detected categories explain why the score was assigned. Two TON wallets may have the same risk level but very different underlying exposure. For example: - one wallet may have limited indirect exposure to a mixer; - another may have direct exposure to stolen funds; - another may repeatedly interact with a high-risk service; - another may receive assets from a scam-related cluster; - another may have suspicious P2P activity. The same score should not always lead to the same decision. The detected categories, messages, contracts, and transaction paths often provide more useful context than the headline score alone. Sanctions Exposure on TON A TON wallet may be associated with a person, organization, service, or cluster included in a sanctions list. Sanctions-related exposure may be: - direct; - indirect; - historical; - recent; - limited; - substantial. A sanctions connection does not always have the same meaning in every jurisdiction. Businesses should consider: - applicable legal obligations; - internal compliance policies; - the transaction context; - the specific sanctions information detected; - the asset involved; - whether exposure is direct or indirect. A sanctions-related match may require escalation or enhanced review. Stolen Funds and Scam Exposure A TON wallet may receive assets associated with: - compromised wallets; - phishing attacks; - fraudulent investment schemes; - fake trading services; - impersonation scams; - malicious Mini Apps or bots; - unauthorized withdrawals; - stolen payment funds; - other fraudulent activity. A wallet may receive stolen assets directly or indirectly through several wallets or smart contracts. Direct receipt of recently stolen assets may require greater scrutiny than a distant historical connection. However, exposure alone does not automatically prove who committed the original theft or fraud. Review: - the complete transaction and message route; - the amount; - the asset involved; - the timing; - the counterparty; - the explanation for the transaction. Mixer and Obfuscation Exposure Some users may interact with services or transaction patterns intended to make tracing more difficult. Obfuscation exposure can increase analytical uncertainty. However, this exposure alone does not automatically prove criminal activity. Its significance depends on: - whether the exposure is direct or indirect; - the amount; - the timing; - the frequency; - other detected categories; - the complete transaction context. A single distant indirect connection may require a different response from repeated direct interaction. High-Risk Exchanges and Services A TON wallet may interact with: - centralized exchanges; - decentralized applications; - payment processors; - custodial services; - gambling platforms; - OTC services; - P2P counterparties; - Telegram-based applications; - unidentified services. Some services may be classified as high risk because of: - weak customer verification; - exposure to illicit activity; - regulatory concerns; - suspicious transaction patterns; - use by fraudulent networks; - insufficient or unreliable attribution. Interaction with a high-risk service is an important indicator, but it should still be interpreted in context. TON and Telegram-Based Transactions TON is closely connected with the Telegram ecosystem. Users may encounter TON-based activity through: - wallet applications; - Mini Apps; - bots; - digital-asset marketplaces; - payments; - collectible assets; - P2P transfers; - services using TON Connect. Convenient access does not eliminate counterparty or blockchain risk. A Telegram username, bot interface, or Mini App does not by itself prove that the operator is trustworthy. Before sending assets, confirm: - the recipient; - the wallet address; - the asset; - the network; - the payment purpose; - the AML result; - any required memo or comment. P2P Activity on TON P2P transactions may involve counterparties whose identity and source of funds are not fully known. Before accepting Gram, USDT, or another jetton through a P2P transaction, it may be useful to check the sender’s wallet for exposure to: - stolen assets; - scams; - mixers; - sanctioned entities; - high-risk services; - fraudulent payment schemes; - suspicious P2P clusters; - other high-risk activity. A wallet check does not replace: - identity verification; - proof of payment; - source-of-funds review; - full due diligence. It adds blockchain context to support a more informed decision. Does a Low-Risk TON Wallet Guarantee Safe Funds? No. A low-risk result means that no significant high-risk exposure was identified based on the data available at the time of the check. It does not guarantee that: - the counterparty is trustworthy; - the transaction is legitimate; - the assets were obtained legally; - every relevant account or contract has been identified; - the wallet will remain low risk; - an exchange will accept the assets; - another analytics provider will reach the same result. Blockchain intelligence may change when: - new wallet clusters are identified; - stolen assets are traced; - scam reports are confirmed; - sanctions lists are updated; - law-enforcement information becomes public; - historical accounts or contracts receive new attribution. For important transactions, it may be useful to save the report and repeat the check later. Can a TON Transaction Be Reversed? Confirmed TON transfers generally cannot be reversed through the blockchain protocol. If assets are sent to: - the wrong address; - a scammer; - a compromised wallet; - a high-risk counterparty; - an unsupported service; - a service without the required memo; there may be no simple way to recover or credit them. That is why checking the wallet and payment instructions before sending assets is usually more useful than investigating only after a problem occurs. Checking a TON Wallet for OTC Transactions OTC transactions may involve large values and complex settlement arrangements. Before completing an OTC transaction, it may be useful to: 1. verify the counterparty; 2. confirm the TON address; 3. confirm whether the asset is Gram, USDT, or another jetton; 4. confirm any required memo or identifier; 5. perform an AML wallet check; 6. review the risk score and categories; 7. analyze the transaction and message path; 8. request source-of-funds information if needed; 9. document the final decision; 10. save the report. The exact procedure depends on the transaction value, jurisdiction, counterparty profile, and applicable compliance obligations. TON Wallet Checks for Businesses Businesses that accept, send, or process TON-based assets may use wallet screening as part of a risk-based AML process. A possible workflow includes: 1. collecting the customer or counterparty address; 2. confirming the TON network; 3. confirming the asset; 4. confirming any required payment identifier; 5. performing the AML check; 6. reviewing the overall risk score; 7. reviewing the detected categories; 8. escalating medium- or high-risk results; 9. requesting additional information when necessary; 10. documenting the final decision; 11. repeating the check when the wallet is used again. The appropriate response depends on: - the business model; - transaction value; - customer profile; - jurisdiction; - applicable regulation; - internal risk appetite; - the asset involved; - the detected risk category. Wallet screening should be treated as one component of a broader compliance process. What to Do If a TON Wallet Has High Risk A high-risk result should not be ignored. Possible next steps include: - reviewing the detected categories; - checking whether exposure is direct or indirect; - confirming which asset is involved; - reviewing the amount and percentage involved; - analyzing related messages and transaction paths; - identifying the relevant entity, contract, or service; - requesting an explanation from the counterparty; - requesting source-of-funds documentation; - checking the specific transaction; - escalating the case to compliance; - delaying or rejecting the transaction where appropriate; - documenting the final decision. The appropriate response depends on the transaction context and applicable obligations. The score alone should not be treated as automatic proof of illegal activity. Example: Low-Risk TON Wallet Imagine a TON wallet that mainly interacts with identified exchanges and ordinary services and has no significant exposure to high-risk categories. The report may show: - a low overall risk score; - no sanctions exposure; - no direct stolen-funds exposure; - ordinary Gram and jetton activity; - limited unidentified counterparties. This result may support proceeding with the transaction, but the address, asset, memo, and counterparty should still be confirmed. Example: Medium-Risk TON Wallet Imagine a wallet with mostly ordinary activity but some indirect exposure to a high-risk service through several intermediary contracts or accounts. The report may show: - a medium overall risk score; - indirect exposure; - a limited amount involved; - no direct sanctions exposure; - an older message and transaction path. This result may require additional review rather than automatic rejection. The amount, timing, asset, transaction purpose, and explanation from the counterparty should be considered. Example: High-Risk TON Wallet Imagine a wallet that recently received a substantial amount directly from an identified cluster associated with stolen assets or fraud. The report may show: - a high overall risk score; - direct stolen-funds or scam exposure; - recent activity; - a significant percentage of wallet activity involved; - an identified high-risk counterparty. This result may require escalation, additional documents, or a decision not to proceed, depending on the applicable compliance process. Do You Need to Connect Your TON Wallet? No. A public TON address can be analyzed without connecting the wallet. You do not need to provide: - a private key; - a seed phrase; - a wallet password; - access to the wallet application; - authorization through TON Connect. Never share private credentials with an AML screening service or counterparty. The public address is sufficient for blockchain risk analysis. TON Wallet Check vs General Crypto Wallet Check A TON-specific guide focuses on the addresses, assets, jettons, smart contracts, messages, and transactions of The Open Network. A general crypto wallet AML check explains broader principles that apply across multiple blockchains. These include: - risk scores; - risk categories; - direct and indirect exposure; - sanctions screening; - transaction context; - wallet and transaction checks; - business compliance workflows. Learn how to perform a general AML check on a crypto wallet AML Wallet Check Guides Use the relevant guide for the wallet or network you want to analyze: - Learn how to perform a general AML check on a crypto wallet - Check a USDT TRC20 wallet for AML risk - Understand a crypto wallet risk score - Check a Bitcoin address for AML risk - Check an Ethereum wallet for AML risk - Check a TRON wallet for AML risk Check a TON Wallet Before Sending or Accepting Assets TON wallet risk is not visible from the address alone. An AML check can help identify exposure to sanctions, scams, stolen funds, mixers, high-risk services, suspicious P2P activity, and other risky connections. Review the risk score together with the detected categories, message and transaction paths, assets, amounts, timing, entity information, and counterparty context. Check a TON wallet now Frequently Asked Questions Is Gram the same as Toncoin? Yes. Gram is the current official name of the native cryptocurrency previously known as Toncoin. The blockchain itself continues to be called The Open Network, or TON. Can I check any TON wallet? You can check a valid public TON address supported by the service. You do not need the private key or seed phrase. Does a TON address always begin with EQ or UQ? No. EQ and UQ are common prefixes for user-friendly Mainnet address representations. The same underlying account may also be represented in another valid format. What is the difference between an EQ and UQ address? An EQ address is normally represented as bounceable, while a UQ address is represented as non-bounceable. Both can refer to the same underlying account. Can the same TON wallet receive Gram and USDT? A TON owner address can hold Gram and control the jetton wallet contracts used for USDT and other jettons. Gram and USDT remain separate assets. Is USDT on TON the same as USDT TRC20? No. USDT on TON is implemented on The Open Network. USDT TRC20 is issued on the TRON blockchain. Always confirm the correct network before transferring assets. What is a jetton? A jetton is a fungible token on TON. Jettons serve a role similar to ERC-20 tokens on Ethereum and can represent stablecoins, payment tokens, utility tokens, and other assets. Is a low-risk TON wallet automatically safe? No. Low risk only means that no significant high-risk exposure was detected in the available data at the time of the check. Does indirect exposure prove illegal activity? No. Indirect exposure is a risk indicator. It does not prove that the wallet owner knowingly interacted with the final high-risk entity or controls every account in the transaction path. Can a TON wallet risk score change? Yes. The score may change because of new transactions, new entity attribution, sanctions updates, scam reports, law-enforcement information, or newly traced stolen assets. Can an AML report guarantee that an exchange will accept my assets? No. Each exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds. Should I check the wallet or the transaction? They provide different information. A wallet check reviews broader account history, while a transaction check focuses on a particular on-chain operation. Because TON is message-based, related messages and transactions may also need to be reviewed. Do I need to include a memo or comment? It depends on the recipient. Some exchanges, custodial services, merchants, or payment processors require a specific memo, comment, or payment identifier. Always follow the destination service’s instructions exactly. Should I check the wallet before or after receiving funds? Whenever possible, check it before completing the transaction. A post-transaction check may still help investigate the origin or destination of the assets and document a compliance decision. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that a TON wallet is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

Check a TRON Wallet for AML Risk | AML Verifier
Jul 24, 2026

Check a TRON Wallet for AML Risk | AML Verifier

Check a TRON Wallet for AML Risk Before sending or accepting TRX or a token on the TRON network, it is important to understand whether the wallet may be connected to scams, stolen funds, sanctioned entities, mixers, high-risk exchanges, suspicious P2P activity, or other risky services. A TRON wallet can appear normal while still having direct or indirect exposure to suspicious transaction flows. AML Verifier helps users check a TRON wallet and review its blockchain risk exposure before completing a transaction. Check a TRON wallet What Is a TRON Wallet? A TRON wallet is a tool used to manage assets and interact with applications on the TRON blockchain. In practice, the phrase “TRON wallet” is also commonly used to describe a public TRON address. A TRON address can receive and send: - TRX, the native cryptocurrency of TRON; - TRC-10 tokens; - TRC-20 tokens; - USDT issued as a TRC-20 token; - other compatible assets on the TRON network. TRON addresses normally begin with the letter T. A public address can be shared and analyzed through blockchain data. It is not the same as: - a private key; - a seed phrase; - a wallet password; - access to the wallet application. Private credentials must never be shared with an AML screening service or counterparty. Why Check a TRON Wallet? TRON transactions are publicly recorded, but risk is not immediately visible from the address alone. A wallet may have direct or indirect exposure to: - sanctioned entities; - stolen cryptocurrency; - scams and fraudulent services; - phishing schemes; - crypto mixers; - darknet-related services; - ransomware; - high-risk exchanges; - unlicensed gambling services; - fraudulent investment platforms; - suspicious P2P counterparties; - high-risk payment processors; - money laundering networks; - other suspicious services. Checking a TRON wallet before sending or receiving funds can help identify warning signs and provide additional context for the transaction. When Should You Check a TRON Wallet? A TRON AML check may be useful before: - receiving TRX from an unknown person; - accepting a TRC-20 token payment; - completing a P2P trade; - sending funds to a new counterparty; - processing a customer withdrawal; - accepting a business payment; - completing an OTC transaction; - depositing assets to a centralized exchange; - interacting with an unfamiliar service; - investigating a suspicious incoming transfer. A check may also be useful after receiving funds if an exchange, payment provider, auditor, bank, or compliance team asks for information about the source of the assets. How to Check a TRON Wallet The process is straightforward: 1. Copy the TRON address you want to analyze. 2. Open AML Verifier. 3. Select the TRON network. 4. Paste the public wallet address. 5. Start the AML check. 6. Review the risk score and risk level. 7. Examine the detected exposure categories. 8. Save the report if necessary. Make sure that you enter a wallet address rather than a transaction hash. A TRON wallet address normally starts with T. Start a TRON wallet check TRON Wallet Address vs Transaction Hash A wallet check and a transaction check answer different questions. TRON wallet address A TRON address is a public blockchain identifier used to receive TRX and compatible tokens. It normally begins with T. A wallet check helps analyze the broader blockchain activity and risk exposure associated with that address. Transaction hash A transaction hash identifies one specific transaction on the TRON blockchain. A transaction check may focus on: - the sender; - the recipient; - the transferred asset; - the transferred amount; - the transaction time; - the confirmation status; - the risk connected to that specific transfer. For additional context, it may be useful to check both the wallet and the transaction. What Does a TRON Wallet Check Show? The available results may include: - overall risk score; - risk level; - identified entity information; - sanctions-related exposure; - scam or fraud exposure; - stolen-funds exposure; - mixer exposure; - darknet-related activity; - ransomware connections; - high-risk exchange exposure; - gambling-related exposure; - suspicious service categories; - direct and indirect transaction relationships; - wallet activity information; - broader transaction-history context. The report helps transform raw TRON blockchain data into information that can be reviewed by individuals, businesses, and compliance teams. TRX, TRC-10, and TRC-20 Assets A TRON wallet may interact with several types of assets. TRX TRX is the native cryptocurrency of the TRON blockchain. It may be used for: - transfers; - network fees and resources; - staking-related activity; - interactions with applications; - payments. TRC-10 tokens TRC-10 is a token standard supported directly by the TRON blockchain. A TRON address may receive and hold TRC-10 assets alongside TRX and other compatible tokens. TRC-20 tokens TRC-20 is a smart-contract-based token standard. TRC-20 tokens may include: - stablecoins; - utility tokens; - exchange-issued assets; - payment tokens; - other tokenized assets. USDT TRC20 is one of the most widely used examples. The same TRON address can normally receive both TRX and compatible TRC-20 tokens. TRON Wallet Check vs USDT TRC20 Check A general TRON wallet check and a USDT TRC20 wallet check are closely related, but they focus on different user needs. TRON wallet check A TRON wallet check reviews the broader activity of the address across the TRON network. This may include: - TRX transfers; - TRC-10 activity; - TRC-20 token activity; - interactions with smart contracts; - identified counterparties; - broader wallet risk exposure. USDT TRC20 check A USDT TRC20 guide focuses specifically on users sending, receiving, or accepting Tether on the TRON network. It is especially relevant for: - P2P transactions; - merchant payments; - OTC settlements; - exchange deposits; - international crypto transfers; - receiving stablecoin payments. Check a USDT TRC20 wallet for AML risk TRON Uses an Account-Based Model TRON uses an account-based blockchain model. A TRON address has an associated balance and visible transaction activity. The activity may include: - incoming TRX transfers; - outgoing TRX transfers; - TRC-10 token movements; - TRC-20 token transfers; - smart-contract calls; - interactions with exchanges and payment services; - repeated activity with specific counterparties. A wallet’s visible TRX balance does not necessarily show the full scope of its activity. A wallet may have limited TRX but still process significant volumes of TRC-20 tokens. For AML analysis, it is therefore important to review the broader address history rather than only the current native-coin balance. Smart-Contract Activity on TRON The TRON network supports smart contracts. A wallet may interact with contracts used for: - token transfers; - decentralized applications; - exchanges; - staking; - payment processing; - gaming; - custody; - other blockchain services. Not every smart-contract interaction is risky. However, contract-based activity may create more complex transaction routes. When reviewing a TRON wallet, it may be important to consider: - which contract was used; - whether the contract belongs to an identified service; - which assets moved; - which wallets ultimately received the funds; - whether the pattern is repeated; - whether the service is classified as high risk. Direct and Indirect Exposure TRON AML analysis should consider both direct and indirect exposure. Direct exposure Direct exposure exists when the checked wallet sends assets directly to or receives assets directly from an identified address, entity, or service. For example: TRON wallet A → Identified high-risk service There is no intermediary wallet between the checked address and the identified entity. Direct exposure may be easier to interpret because the transaction relationship is immediate. Indirect exposure Indirect exposure exists when assets pass through one or more intermediary wallets or services. For example: TRON wallet A → Intermediary wallet → High-risk service Indirect exposure does not automatically prove that the wallet owner knowingly interacted with the final high-risk entity. Its significance may depend on: - the number of transaction hops; - the amount involved; - the percentage of wallet activity involved; - how recently the exposure occurred; - whether the pattern is repeated; - whether an intermediary belongs to an identified cluster; - the type of high-risk service; - the purpose of the transaction. A small historical connection several hops away may require a different response from a recent and repeated flow involving significant value. How to Understand the TRON Wallet Risk Score A risk score summarizes multiple blockchain risk signals into one result. In general: - Low risk indicates that no significant high-risk exposure was detected in the available data. - Medium risk indicates that some exposure, uncertainty, or unusual activity requires additional review. - High risk indicates stronger connections to identified high-risk entities, services, or transaction patterns. The score should not be interpreted in isolation. You should also review: - which categories were detected; - whether the exposure is direct or indirect; - which asset was transferred; - the amount involved; - the percentage of activity involved; - how recently the activity occurred; - how frequently the pattern appears; - whether an identified entity is involved; - the context of the current transaction. Learn how to understand a crypto wallet risk score Risk Score and Risk Categories Are Different The overall risk score provides a summary. The risk categories explain why the score was assigned. Two TRON wallets may have the same risk level but very different underlying exposure. For example: - one wallet may have limited indirect mixer exposure; - another may have direct exposure to stolen funds; - another may repeatedly interact with a high-risk exchange; - another may receive payments from a scam-related cluster; - another may have suspicious P2P activity. The same score should not always lead to the same decision. The detected categories and transaction paths often provide more useful context than the headline score alone. Sanctions Exposure on TRON A TRON wallet may be associated with a person, organization, service, or cluster included in a sanctions list. Sanctions-related exposure may be: - direct; - indirect; - historical; - recent; - limited; - substantial. A sanctions connection does not always have the same meaning in every jurisdiction. Businesses should consider: - applicable legal obligations; - internal compliance policies; - the transaction context; - the specific sanctions information detected; - the asset involved; - whether the exposure is direct or indirect. A sanctions-related match may require escalation or enhanced review. Stolen Funds and Scam Exposure A TRON wallet may receive assets associated with: - exchange hacks; - compromised wallets; - phishing attacks; - fraudulent investment schemes; - fake trading platforms; - impersonation scams; - unauthorized withdrawals; - stolen payment funds; - other fraudulent activity. A wallet may receive stolen assets directly or indirectly through several intermediary addresses. Direct receipt of recently stolen funds may require more scrutiny than a distant historical connection. However, exposure alone does not automatically prove who committed the original theft or fraud. It is important to review: - the transaction route; - the amount; - the asset involved; - the timing; - the counterparty; - the explanation for the transaction. Mixer and Obfuscation Exposure Some users may interact with mixers or other services intended to make transaction tracing more difficult. Mixer exposure can increase analytical uncertainty. However, the presence of mixer exposure does not automatically prove criminal activity. Its significance depends on: - direct or indirect exposure; - the amount involved; - the timing; - the frequency; - other detected categories; - the transaction context. A single distant indirect connection may require a different response from repeated direct interaction. High-Risk Exchanges and Services A TRON wallet may interact with: - centralized exchanges; - decentralized services; - payment processors; - gambling platforms; - OTC desks; - custodial services; - P2P counterparties; - unidentified services. Some services may be classified as high risk because of factors such as: - weak customer verification; - exposure to illicit activity; - regulatory concerns; - suspicious transaction patterns; - use by fraudulent networks; - lack of reliable attribution. Interaction with a high-risk service is an important indicator, but it should still be interpreted in context. P2P Activity on TRON TRON is widely used for fast and relatively inexpensive cryptocurrency transfers. This makes it common in P2P transactions. P2P activity may involve counterparties whose identity and source of funds are not fully known. Before accepting TRX or TRC-20 tokens through a P2P deal, it may be useful to check the sender’s wallet for exposure to: - stolen assets; - scams; - mixers; - sanctioned entities; - high-risk exchanges; - fraudulent payment schemes; - suspicious P2P clusters; - other high-risk activity. A wallet check does not replace: - identity verification; - proof of payment; - source-of-funds review; - full due diligence. It adds blockchain context to support a more informed decision. Does a Low-Risk TRON Wallet Guarantee Safe Funds? No. A low-risk result means that no significant high-risk exposure was identified based on the available data at the time of the check. It does not guarantee that: - the counterparty is trustworthy; - the transaction is legitimate; - the assets were obtained legally; - every relevant address has been identified; - the wallet will remain low risk; - an exchange will accept the assets; - another analytics provider will reach the same result. Blockchain intelligence can change when: - new wallet clusters are identified; - stolen assets are traced; - scam reports are confirmed; - sanctions lists are updated; - law-enforcement information becomes public; - historical transactions receive new attribution. For important transactions, it may be useful to save the report and repeat the check later. Can a TRON Transaction Be Reversed? Confirmed TRON transactions are generally irreversible. If assets are sent to: - the wrong address; - a scammer; - a compromised wallet; - a high-risk counterparty; - an unsupported service; there may be no simple way to recover them. That is why checking the wallet before sending TRX or a TRC-20 token is usually more useful than investigating only after a problem occurs. Checking a TRON Wallet for OTC Transactions OTC transactions may involve large values and complex settlement arrangements. Before completing an OTC transaction, it may be useful to: 1. verify the counterparty; 2. confirm the TRON address; 3. confirm the asset being transferred; 4. perform an AML wallet check; 5. review the risk score and categories; 6. analyze the transaction path; 7. request source-of-funds information if needed; 8. document the final decision; 9. save the report. The exact process depends on the transaction value, jurisdiction, counterparty profile, and applicable compliance obligations. TRON Wallet Checks for Businesses Businesses that accept, send, or process TRON-based assets may use wallet screening as part of a risk-based AML process. A possible workflow includes: 1. collecting the customer or counterparty address; 2. confirming the TRON network; 3. confirming whether the asset is TRX, TRC-10, or TRC-20; 4. performing the AML check; 5. reviewing the overall risk score; 6. reviewing the detected categories; 7. escalating medium- or high-risk results; 8. requesting additional information when necessary; 9. documenting the final decision; 10. repeating the check when the wallet is used again. The appropriate response depends on: - the business model; - transaction value; - customer profile; - jurisdiction; - applicable regulation; - internal risk appetite; - the asset involved; - the detected risk category. Wallet screening should be treated as one component of a broader compliance process. What to Do If a TRON Wallet Has High Risk A high-risk result should not be ignored. Possible next steps include: - reviewing the detected categories; - checking whether the exposure is direct or indirect; - confirming which asset is involved; - reviewing the amount and percentage involved; - analyzing the transaction path; - identifying the relevant entity or service; - requesting an explanation from the counterparty; - requesting source-of-funds documentation; - checking the specific transaction; - escalating the case to compliance; - delaying or rejecting the transaction where appropriate; - documenting the final decision. The appropriate response depends on the transaction context and applicable obligations. The score alone should not be treated as automatic proof of illegal activity. Example: Low-Risk TRON Wallet Imagine a TRON wallet that mainly interacts with identified exchanges and ordinary services and has no significant exposure to high-risk categories. The report may show: - a low overall risk score; - no sanctions exposure; - no direct stolen-funds exposure; - ordinary TRX and token activity; - limited unidentified counterparties. This result may support proceeding with the transaction, but the address, asset, and counterparty should still be confirmed. Example: Medium-Risk TRON Wallet Imagine a wallet with mostly ordinary activity but some indirect exposure to a high-risk service through intermediary addresses. The report may show: - a medium overall risk score; - indirect exposure; - a limited amount involved; - no direct sanctions exposure; - an older transaction path. This result may require additional review rather than automatic rejection. The amount, timing, asset, transaction purpose, and explanation from the counterparty should be considered. Example: High-Risk TRON Wallet Imagine a wallet that recently received a substantial amount directly from a cluster associated with stolen assets or fraud. The report may show: - a high overall risk score; - direct stolen-funds or scam exposure; - recent activity; - a significant percentage of wallet activity involved; - an identified high-risk counterparty. This result may require escalation, additional documents, or a decision not to proceed, depending on the applicable compliance process. Do You Need to Connect Your TRON Wallet? No. A public TRON address can be analyzed without connecting the wallet. You do not need to provide: - a private key; - a seed phrase; - a wallet password; - access to the wallet application. Never share private credentials with an AML screening service or counterparty. The public address is sufficient for blockchain risk analysis. TRON Wallet Check vs General Crypto Wallet Check A TRON-specific guide focuses on the assets, transactions, and smart-contract activity of the TRON network. A general crypto wallet AML check explains broader principles that apply across multiple blockchains. These include: - risk scores; - risk categories; - direct and indirect exposure; - sanctions screening; - transaction context; - wallet and transaction checks; - business compliance workflows. Learn how to perform a general AML check on a crypto wallet AML Wallet Check Guides Use the relevant guide for the wallet or network you want to analyze: - Learn how to perform a general AML check on a crypto wallet - Check a USDT TRC20 wallet for AML risk - Understand a crypto wallet risk score - Check a Bitcoin address for AML risk - Check an Ethereum wallet for AML risk - Check a TON wallet for AML risk Check a TRON Wallet Before Sending or Accepting Assets TRON wallet risk is not visible from the address alone. An AML check can help identify exposure to sanctions, scams, stolen funds, mixers, high-risk exchanges, suspicious P2P activity, and other risky services. Review the risk score together with the detected categories, transaction routes, assets, amounts, timing, entity information, and counterparty context. Check a TRON wallet now Frequently Asked Questions Can I check any TRON wallet? You can check a valid public TRON address supported by the service. You do not need the private key or seed phrase. Does a TRON address always start with T? Standard public TRON addresses normally begin with the letter T. Always confirm that you selected the TRON network before starting the check. Can the same TRON address receive TRX and TRC-20 tokens? Yes. A TRON address can normally receive TRX and compatible TRC-20 tokens, including USDT. Is TRX the same as USDT TRC20? No. TRX is the native cryptocurrency of the TRON blockchain. USDT TRC20 is a Tether token issued on TRON using the TRC-20 standard. Is a low-risk TRON wallet automatically safe? No. Low risk only means that no significant high-risk exposure was detected in the available data at the time of the check. Does indirect exposure prove illegal activity? No. Indirect exposure is a risk indicator. It does not prove that the wallet owner knowingly interacted with the final high-risk entity or controls every address in the transaction path. Does mixer exposure automatically mean criminal activity? No. Mixer exposure may be relevant, but it should be interpreted together with the amount, timing, frequency, route, and other detected categories. Can a TRON wallet risk score change? Yes. The score may change because of new transactions, new entity attribution, sanctions updates, scam reports, law-enforcement information, or newly traced stolen assets. Can an AML report guarantee that an exchange will accept my TRX or tokens? No. Each exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds. Should I check the wallet or the transaction? They provide different information. A wallet check reviews broader address history, while a transaction check focuses on one specific transfer. For additional context, it may be useful to check both. Should I check the wallet before or after receiving funds? Whenever possible, check it before completing the transaction. A post-transaction check may still help investigate the origin or destination of the assets and document a compliance decision. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that a TRON wallet is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

Check an Ethereum Wallet for AML Risk | AML Verifier
Jul 20, 2026

Check an Ethereum Wallet for AML Risk | AML Verifier

Check an Ethereum Wallet for AML Risk Before sending, receiving, or accepting ETH, it is important to understand whether the wallet may be connected to sanctions exposure, scams, stolen funds, hacks, mixers, darknet activity, or other high-risk behavior. An Ethereum wallet can appear ordinary while still having direct or indirect exposure to suspicious transaction flows, risky counterparties, or identified illicit services. AML Verifier helps users check an Ethereum wallet and review its blockchain risk exposure before completing a transaction. Check an Ethereum wallet What Is an Ethereum Wallet? An Ethereum wallet is a tool that allows a user or business to store, manage, send, and receive assets on the Ethereum network. In practice, people often use the phrase “Ethereum wallet” to refer to a public wallet address. An Ethereum address is a public identifier used on the Ethereum blockchain. It usually begins with 0x and can receive: - ETH; - ERC-20 tokens; - other compatible on-chain assets. A wallet is not the same as: - a private key; - a seed phrase; - a password; - a wallet application. The wallet address is public and can be analyzed through blockchain data, while private credentials must never be shared. Why Check an Ethereum Wallet? Ethereum transactions are public, but blockchain risk is not obvious just by looking at a wallet address. An Ethereum wallet may have direct or indirect exposure to: - sanctioned entities; - stolen funds; - scams and fraudulent services; - phishing schemes; - mixer services; - darknet activity; - hacked funds; - ransomware-related transactions; - high-risk exchanges; - suspicious DeFi interactions; - fraudulent investment schemes; - suspicious OTC or P2P counterparties; - money laundering networks; - other high-risk services. Checking a wallet before sending or accepting ETH can help identify warning signs and provide additional risk context. When Should You Check an Ethereum Wallet? An Ethereum wallet AML check may be useful before: - accepting ETH from an unknown counterparty; - sending ETH to a new address; - completing a P2P trade; - paying a freelancer, vendor, or partner in ETH; - processing a customer withdrawal; - accepting a merchant payment; - completing an OTC transaction; - depositing ETH to a centralized exchange; - interacting with an unfamiliar service; - investigating a suspicious incoming transfer. A check may also be useful after receiving funds if an exchange, auditor, compliance team, or payment provider requests information about the source of the assets. How to Check an Ethereum Wallet The process is simple: 1. Copy the Ethereum wallet address you want to analyze. 2. Open AML Verifier. 3. Select the Ethereum network. 4. Paste the public wallet address. 5. Start the AML check. 6. Review the risk score and risk level. 7. Examine the detected exposure categories. 8. Save the report if needed. Make sure that you enter a wallet address rather than a transaction hash. Start an Ethereum wallet check Ethereum Wallet vs Transaction Hash A wallet check and a transaction check answer different questions. Ethereum wallet An Ethereum wallet address identifies a public destination on the Ethereum network. It usually begins with 0x. A wallet check helps analyze the broader blockchain activity and risk exposure associated with that wallet. Transaction hash A transaction hash identifies one specific Ethereum transaction. A transaction check focuses on: - the sending wallet; - the receiving wallet; - the transferred value; - token movements; - the time of the transfer; - transaction status; - risk connected to that specific transaction. For a more complete review, it may be useful to check both the wallet and the transaction. What Does an Ethereum Wallet Check Show? The available results may include: - overall risk score; - risk level; - identified entity information; - sanctions-related exposure; - scam or fraud exposure; - stolen-funds exposure; - hack-related exposure; - mixer exposure; - darknet-related connections; - high-risk exchange exposure; - suspicious service categories; - direct and indirect transaction relationships; - wallet activity information; - broader transaction-history context. This helps transform raw blockchain data into risk information that can be reviewed by users, businesses, and compliance teams. Ethereum Is an Account-Based Blockchain Ethereum uses an account-based model. This means a wallet address has a visible balance and transaction history associated with that address. This is different from Bitcoin’s UTXO model. When reviewing Ethereum activity, a checker may analyze: - outgoing transactions; - incoming transactions; - token transfers; - interactions with smart contracts; - repeated counterparties; - known service addresses; - identified wallet clusters. Because Ethereum is programmable, wallet activity may include not only simple transfers but also interactions with: - decentralized exchanges; - lending protocols; - bridges; - staking services; - token contracts; - DeFi protocols; - other smart contracts. That makes context especially important when interpreting Ethereum wallet risk. Externally Owned Accounts and Smart Contracts On Ethereum, there are different types of addresses. Externally owned account An externally owned account, often called an EOA, is controlled by a private key. This is the type of address most users think of when they talk about an Ethereum wallet. Smart contract A smart contract is an on-chain program deployed to the Ethereum network. Some contracts simply provide technical functionality, while others may act as: - token contracts; - DeFi applications; - liquidity pools; - swap routers; - custody systems; - payment processors; - risky or fraudulent services. Not every smart contract interaction is risky. However, when funds move through complex contract-based routes, it becomes even more important to understand the destination, counterparties, and transaction purpose. Direct and Indirect Exposure Ethereum AML analysis should consider both direct and indirect exposure. Direct exposure Direct exposure exists when the checked Ethereum wallet sends assets directly to or receives assets directly from an identified address, entity, or service. For example: Wallet A → Identified high-risk service There is no intermediary wallet or transaction path between the checked address and the identified entity. Direct exposure may be easier to interpret because the transaction relationship is immediate. Indirect exposure Indirect exposure exists when funds pass through one or more intermediary wallets or services before reaching or coming from a high-risk entity. For example: Wallet A → Intermediary wallet → High-risk service Indirect exposure does not automatically prove that the wallet owner knowingly interacted with the final high-risk entity. Its significance may depend on: - the number of transaction hops; - the amount involved; - the percentage of wallet activity involved; - how recently the exposure occurred; - whether the pattern is repeated; - whether an intermediary belongs to an identified cluster; - the type of high-risk service; - the context and purpose of the transfer. A distant historical connection may require a different response from a recent and repeated indirect flow involving substantial value. How to Understand the Ethereum Wallet Risk Score A risk score summarizes multiple blockchain risk signals into a single result. In general: - Low risk suggests that no significant high-risk exposure was detected in the available data. - Medium risk suggests that some exposure, uncertainty, or unusual activity requires additional review. - High risk suggests stronger connections to identified high-risk entities, services, or transaction patterns. The score should not be interpreted alone. It should be reviewed together with: - the detected categories; - whether the exposure is direct or indirect; - the amount involved; - the percentage of activity involved; - the timing of the activity; - how often the pattern appears; - whether an identified entity is involved; - the context of the current transaction. Learn how to understand a crypto wallet risk score Risk Score and Risk Categories Are Different The overall risk score provides a summary. The risk categories explain why the wallet received that score. Two Ethereum wallets may have the same risk level but very different underlying exposure. For example: - one wallet may have indirect exposure to a mixer; - another may have direct exposure to stolen funds; - another may repeatedly interact with a high-risk exchange; - another may have received assets from a scam-related cluster. The same score should not always lead to the same decision. The transaction paths and detected categories often provide more useful context than the headline score alone. Sanctions Exposure on Ethereum An Ethereum wallet may be associated with a person, organization, service, or cluster listed under sanctions. Sanctions-related exposure may be: - direct; - indirect; - historical; - recent; - limited; - substantial. A sanctions connection does not always have the same meaning in every jurisdiction. Businesses should consider: - applicable legal obligations; - internal compliance policies; - the transaction context; - the specific sanctions information detected. A sanctions-related match or exposure may require escalation or enhanced review. Stolen Funds and Hack-Related Exposure Ethereum wallets may be exposed to funds connected to: - exchange hacks; - protocol exploits; - phishing attacks; - wallet compromises; - smart-contract vulnerabilities; - malware; - fraudulent schemes; - unauthorized withdrawals. A wallet may receive stolen or hacked funds directly or indirectly through several intermediary transactions. Direct receipt of recently stolen assets may require more review than a limited and old indirect connection. However, the presence of exposure does not automatically prove who committed the theft or exploit. It is important to review: - the transaction path; - the amount involved; - the time of the activity; - the current transaction context; - the explanation from the counterparty, if available. Mixer Exposure Ethereum has been used with various privacy-enhancing services and transaction-obfuscation techniques. Mixer exposure may be relevant when reviewing the wallet’s risk. At the same time, exposure to a mixer does not automatically prove illegal activity. The interpretation depends on: - whether the exposure is direct or indirect; - the amount involved; - the timing; - the frequency; - other detected risk categories; - the context of the wallet activity. A single distant indirect connection may require a different response from repeated direct interaction. Scam and Fraud Exposure An Ethereum wallet may be connected to scam-related activity such as: - fraudulent investment schemes; - phishing operations; - impersonation scams; - fake airdrops; - fake token sales; - wallet-drainer schemes; - fraudulent OTC activity; - other deceptive services. Scam-related exposure is an important warning sign, but the details matter. Review whether the interaction was: - direct or indirect; - recent or historical; - large or small; - repeated or isolated. Darknet and Other High-Risk Services Ethereum wallets may also be associated with darknet-related activity or other high-risk services. The detected exposure may involve: - direct transfers; - indirect transaction paths; - small incidental amounts; - repeated patterns; - identified service clusters. A direct and repeated relationship may carry more significance than a minor historical indirect connection. Does a Low-Risk Ethereum Wallet Guarantee Safe Funds? No. A low-risk result means that no significant high-risk exposure was identified based on the information available at the time of the check. It does not guarantee that: - the counterparty is trustworthy; - the transaction is legitimate; - the assets were obtained legally; - every relevant address has been identified; - the wallet will remain low risk; - an exchange or service will accept the funds; - another analytics provider will reach the same result. Blockchain intelligence can change when: - new wallet clusters are identified; - stolen funds are traced; - hack investigations become public; - sanctions lists are updated; - scams are discovered; - historical transactions receive new attribution. For important transactions, it may be useful to save the report and repeat the check later if necessary. Can an Ethereum Transaction Be Reversed? Confirmed Ethereum transactions are generally irreversible. If ETH is sent to: - the wrong wallet; - a scammer; - a compromised address; - a high-risk counterparty; - an unsupported service; there may be no simple way to recover the assets. That is why checking the wallet before sending ETH is generally more useful than investigating it only after a problem occurs. Checking an Ethereum Wallet for P2P Transactions P2P transactions may involve counterparties whose identity or source of funds is not fully known. Before accepting ETH in a P2P deal, it may be useful to check the sender’s wallet for exposure to: - stolen funds; - scam-related clusters; - mixers; - sanctioned entities; - hack-related funds; - suspicious service categories; - other high-risk activity. A wallet check does not replace: - identity verification; - proof of payment; - source-of-funds review; - due diligence on the counterparty. It adds blockchain context to support a more informed decision. Checking an Ethereum Wallet for OTC Transactions OTC transactions may involve large values and additional settlement complexity. Before completing an OTC transaction, it may be useful to: 1. verify the counterparty; 2. confirm the Ethereum wallet address; 3. perform an AML wallet check; 4. review the risk score and categories; 5. analyze the transaction path; 6. request source-of-funds information if needed; 7. document the final decision; 8. save the report. The exact process depends on the transaction size, jurisdiction, counterparty profile, and applicable compliance obligations. Ethereum Wallet Checks for Businesses Businesses that send, receive, or process ETH may use wallet screening as part of a risk-based AML process. A possible workflow includes: 1. collecting the customer or counterparty wallet address; 2. confirming that the Ethereum network is correct; 3. performing an AML check; 4. reviewing the overall risk score; 5. reviewing the detected categories; 6. escalating medium- or high-risk results; 7. requesting additional information if necessary; 8. documenting the decision; 9. repeating the check if the wallet is used again. The appropriate response depends on: - the business model; - the transaction value; - the customer profile; - the jurisdiction; - applicable regulation; - internal risk appetite; - the detected risk category. Wallet screening should be treated as one component of a broader compliance process. What to Do If an Ethereum Wallet Has High Risk A high-risk result should not be ignored. Possible next steps include: - reviewing the detected categories; - checking whether the exposure is direct or indirect; - examining the amount and percentage involved; - analyzing the transaction path; - identifying the relevant entity or service; - requesting an explanation from the counterparty; - requesting source-of-funds documentation; - checking the specific transaction; - escalating the case to compliance; - delaying or rejecting the transaction where appropriate; - documenting the final decision. The appropriate response depends on the transaction context and applicable obligations. The score alone should not be treated as automatic proof of illegal activity. Example: Low-Risk Ethereum Wallet Imagine an Ethereum wallet that mainly interacts with ordinary services and identified exchanges and has no significant exposure to high-risk categories. The report may show: - a low overall risk score; - no sanctions exposure; - no direct stolen-funds exposure; - ordinary wallet activity; - limited unidentified counterparties. This result may support proceeding with the transaction, but the wallet address and counterparty should still be confirmed. Example: Medium-Risk Ethereum Wallet Imagine a wallet with mostly ordinary activity but some indirect exposure to a mixer through several intermediary transactions. The report may show: - a medium overall risk score; - indirect mixer exposure; - a limited amount involved; - no direct sanctions exposure; - an older transaction path. This result may require additional review rather than automatic rejection. The amount, timing, transaction purpose, and counterparty explanation should be considered. Example: High-Risk Ethereum Wallet Imagine a wallet that recently received a substantial amount directly from an identified cluster associated with stolen or hacked funds. The report may show: - a high overall risk score; - direct stolen-funds or hack-related exposure; - recent activity; - a significant percentage of wallet activity involved; - an identified high-risk counterparty. This result may require escalation, supporting documentation, or a decision not to proceed, depending on the applicable compliance process. Do You Need to Connect Your Ethereum Wallet? No. A public Ethereum wallet address can be analyzed without connecting the wallet. You do not need to provide: - a private key; - a seed phrase; - a wallet password; - access to the wallet application. Never share your seed phrase or private key with a screening service or counterparty. The public wallet address is sufficient for blockchain risk analysis. Ethereum Wallet Check vs General Crypto Wallet Check An Ethereum-specific guide focuses on the Ethereum network and its wallet activity. A general crypto wallet AML check explains broader principles that apply across multiple blockchains. These include: - risk scores; - risk categories; - direct and indirect exposure; - sanctions screening; - transaction context; - wallet and transaction checks; - business compliance workflows. Learn how to perform a general AML check on a crypto wallet AML Wallet Check Guides Use the relevant guide for the wallet or network you want to analyze: - Learn how to perform a general AML check on a crypto wallet - Check a USDT TRC20 wallet for AML risk - Understand a crypto wallet risk score - Check a Bitcoin address for AML risk - Check a TRON wallet for AML risk - Check a TON wallet for AML risk Check an Ethereum Wallet Before Sending or Accepting ETH Ethereum risk is not visible from the wallet address alone. An AML check can help identify exposure to sanctions, scams, stolen funds, hacks, mixers, darknet activity, high-risk services, and other suspicious transaction patterns. Review the risk score together with the detected categories, transaction paths, amounts, timing, entity information, and counterparty context. Check an Ethereum wallet now Frequently Asked Questions Can I check any Ethereum wallet? You can check a valid public Ethereum wallet address supported by the service. You do not need the private key or seed phrase. Does an Ethereum wallet address always start with 0x? Most standard Ethereum wallet addresses begin with 0x. Always confirm that you selected the Ethereum network before starting the check. Is an Ethereum wallet the same as a wallet application? No. A wallet application is a tool used to manage addresses and assets, while the wallet address is the public blockchain identifier used for receiving funds. Is a low-risk wallet automatically safe? No. Low risk only means that no significant high-risk exposure was detected in the available data at the time of the check. Does indirect exposure prove illegal activity? No. Indirect exposure is a risk indicator. It does not prove that the wallet owner knowingly interacted with the final high-risk entity or controls every address in the transaction path. Does mixer exposure automatically mean illicit activity? No. Mixer exposure can be relevant, but it must be interpreted in context, including the amount, timing, frequency, and other detected categories. Can the Ethereum wallet risk score change? Yes. The score may change because of new transactions, new attribution, sanctions updates, scam reports, hack investigations, or newly traced stolen funds. Can an AML report guarantee that an exchange will accept my ETH? No. Each exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds. Should I check the wallet or the transaction? They provide different information. A wallet check reviews broader wallet history, while a transaction check focuses on one specific transfer. For additional context, it may be useful to check both. Should I check the wallet before or after receiving ETH? Whenever possible, check it before completing the transaction. A post-transaction check may still help investigate the origin or destination of the assets and document a compliance decision. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that an Ethereum wallet is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

Check a Bitcoin Address for AML Risk | AML Verifier
Jul 13, 2026

Check a Bitcoin Address for AML Risk | AML Verifier

Check a Bitcoin Address for AML Risk Before sending or accepting Bitcoin, it is important to understand whether the address may be connected to scams, stolen funds, sanctioned entities, darknet marketplaces, ransomware, mixers, or other high-risk activity. A Bitcoin address can appear normal while still having direct or indirect exposure to suspicious transaction flows. AML Verifier helps users check a Bitcoin address and review its blockchain risk exposure before completing a transaction. Check a Bitcoin address What Is a Bitcoin Address? A Bitcoin address is a public identifier used to receive BTC on the Bitcoin network. It is generated from cryptographic information associated with a wallet and can be shared publicly without revealing the wallet’s private key. Common Bitcoin address formats include: - legacy addresses beginning with 1; - script addresses beginning with 3; - SegWit addresses beginning with bc1q; - Taproot addresses beginning with bc1p. Different address formats may use different transaction scripts, but all valid Bitcoin addresses can be analyzed through public blockchain data. A Bitcoin address is not the same as a private key, seed phrase, or complete wallet. A wallet may generate and control many different Bitcoin addresses. Why Check a Bitcoin Address? Bitcoin transactions are public, but their risk is not immediately visible. An address may have direct or indirect exposure to: - sanctioned entities; - stolen Bitcoin; - scams and fraudulent services; - phishing operations; - darknet marketplaces; - ransomware; - mixers and privacy-enhancing services; - high-risk exchanges; - unlicensed gambling services; - fraudulent investment platforms; - suspicious P2P counterparties; - money laundering networks; - other high-risk services. Checking an address before sending or accepting BTC can help identify warning signs and provide additional context for the transaction. When Should You Check a Bitcoin Address? A Bitcoin AML check may be useful before: - accepting BTC from an unknown person; - completing a P2P trade; - sending Bitcoin to a new counterparty; - processing a customer withdrawal; - accepting a merchant payment; - working with an OTC counterparty; - depositing funds to a centralized exchange; - purchasing goods or services with Bitcoin; - transferring BTC to an unfamiliar platform; - investigating a suspicious incoming transaction. A check may also be useful after receiving Bitcoin if an exchange, payment provider, bank, auditor, or compliance team asks for information about the origin of the funds. How to Check a Bitcoin Address The process is straightforward: 1. Copy the Bitcoin address you want to analyze. 2. Open AML Verifier. 3. Select the Bitcoin network. 4. Paste the public address. 5. Start the AML check. 6. Review the risk score and risk level. 7. Examine the detected exposure categories. 8. Save the report if necessary. Make sure that you enter a Bitcoin address rather than a transaction ID. Start a Bitcoin address check Bitcoin Address vs Transaction ID A Bitcoin address and a transaction ID answer different questions. Bitcoin address An address identifies a public destination that can receive Bitcoin. Examples of address prefixes include: - 1; - 3; - bc1q; - bc1p. An address check helps analyze the broader blockchain history and risk exposure associated with that address. Transaction ID A transaction ID, also called a TXID, identifies one specific Bitcoin transaction. It is normally displayed as a long hexadecimal string. A transaction check focuses on a particular transfer, including: - transaction inputs; - transaction outputs; - transferred amounts; - confirmation information; - sending and receiving addresses; - risk connected to the specific transaction. For additional context, it may be useful to check both the address and the transaction. What Does a Bitcoin Address Check Show? The available results may include: - overall risk score; - risk level; - identified entity information; - sanctions-related exposure; - scam or fraud exposure; - stolen-funds exposure; - darknet-related activity; - ransomware connections; - mixer exposure; - high-risk exchange exposure; - gambling-related exposure; - suspicious service categories; - direct and indirect transaction relationships; - address activity information; - transaction history context. The report helps transform raw Bitcoin blockchain data into information that can be reviewed by an individual user, business, or compliance team. A Bitcoin Address Is Not Always the Entire Wallet Bitcoin wallets often generate multiple addresses. A person or business may use: - a new address for every payment; - separate addresses for deposits and withdrawals; - change addresses; - different address formats; - multiple wallets for different purposes. For this reason, checking one address does not always reveal the complete activity of the person or wallet behind it. Blockchain analytics may use address attribution and clustering techniques to identify relationships between addresses when sufficient evidence is available. However, address clustering is analytical attribution and should not automatically be treated as proof that one person controls every related address. How the Bitcoin UTXO Model Affects AML Analysis Bitcoin uses an unspent transaction output model, commonly called the UTXO model. Instead of updating a single account balance, Bitcoin transactions spend previous outputs and create new outputs. A transaction may include: - one or more input addresses; - one or more recipient outputs; - a change output returning unused Bitcoin; - multiple transaction participants. This structure can make Bitcoin transaction analysis different from account-based blockchains. For example, one transaction may combine several previous outputs and create both a payment output and a change output. Blockchain analytics helps interpret these transaction relationships, but the context still matters. An output appearing in the same transaction does not always mean that all participants are controlled by the same person. Direct and Indirect Exposure Bitcoin AML analysis should consider both direct and indirect exposure. Direct exposure Direct exposure exists when the checked address sends BTC directly to or receives BTC directly from an identified address or service. For example: Bitcoin address A → Identified high-risk service There is no intermediary transaction path between the checked address and the identified entity. Direct exposure may be easier to interpret because the transaction relationship is immediate. Indirect exposure Indirect exposure exists when Bitcoin moves through one or more intermediary addresses before reaching or coming from a high-risk entity. For example: Bitcoin address A → Intermediary address → High-risk service Indirect exposure does not automatically prove that the address owner knowingly interacted with the final high-risk entity. Its significance may depend on: - the number of transaction hops; - the value of the funds; - the percentage of activity involved; - how recently the exposure occurred; - whether the pattern is repeated; - whether an intermediary belongs to an identified cluster; - the type of high-risk entity; - the purpose of the transaction. A small historical connection several hops away may require a different response from a recent and repeated indirect flow involving significant value. How to Understand the Bitcoin Address Risk Score A risk score summarizes multiple blockchain risk signals into one result. In general: - Low risk indicates that no significant high-risk exposure was detected in the available data. - Medium risk indicates that some exposure, uncertainty, or unusual activity requires additional review. - High risk indicates stronger connections to identified high-risk entities, services, or transaction patterns. The score should not be interpreted in isolation. You should also review: - which categories were detected; - whether the exposure is direct or indirect; - the amount of Bitcoin involved; - the percentage of the address activity involved; - how recently the activity occurred; - how often the pattern appears; - whether an identified entity is involved; - the context of the current transaction. Learn how to understand a crypto wallet risk score Risk Score and Risk Categories Are Different The overall risk score provides a summary. The detected categories explain why the score was assigned. Two Bitcoin addresses may have the same risk level but very different underlying exposure. For example: - one address may have limited indirect mixer exposure; - another may have direct exposure to stolen Bitcoin; - another may interact repeatedly with a high-risk exchange; - another may have received funds from a scam-related cluster. The same score should not always lead to the same decision. The underlying categories and transaction paths often provide more useful context than the headline score alone. Bitcoin Mixers and Privacy-Enhancing Transactions Bitcoin users may use mixers, CoinJoin-style transactions, or other privacy-enhancing techniques to make transaction tracing more difficult. These techniques can increase analytical uncertainty because funds from multiple participants may be combined or redistributed. However, privacy-enhancing activity does not automatically prove illegal behavior. It may be used for: - financial privacy; - protection from public transaction tracking; - business confidentiality; - personal security; - reduced address linkage. At the same time, mixers and similar techniques may also be used to obscure stolen funds, ransomware payments, sanctions exposure, or other illicit flows. The correct interpretation depends on: - the type of service or transaction pattern; - direct or indirect exposure; - the amount involved; - the timing; - the frequency; - other detected risk categories; - the explanation provided by the counterparty. Stolen Bitcoin Exposure Stolen Bitcoin may originate from: - exchange hacks; - wallet compromises; - phishing attacks; - malware; - fraudulent investment schemes; - compromised private keys; - theft from individuals or businesses. An address may receive stolen funds directly or through several intermediary transactions. Direct receipt of recently stolen BTC may require more scrutiny than a distant historical connection. However, the presence of stolen-funds exposure does not automatically determine who committed the original theft. The transaction path, amount, timing, and counterparty context should all be reviewed. Darknet Exposure Bitcoin has historically been used by some darknet marketplaces and illicit online services. A Bitcoin address may have: - direct transactions with an identified darknet service; - indirect exposure through intermediary addresses; - historical exposure to a marketplace that has since closed; - small incidental exposure; - repeated or significant transaction flows. Darknet-related exposure is an important risk indicator, but the details still matter. A direct and repeated interaction may have a different meaning from a distant historical transaction several hops away. Ransomware Exposure Bitcoin has been used in some ransomware payment schemes. An address may be connected to: - a known ransomware payment address; - an intermediary laundering address; - an exchange used to cash out ransom proceeds; - a wallet cluster identified in an investigation. Ransomware exposure may be especially important when it is: - direct; - recent; - repeated; - associated with a significant amount; - linked to an identified ransomware group or campaign. A high-risk result should still be reviewed together with the full transaction context. Sanctions Exposure A Bitcoin address may be associated with a person, organization, service, or cluster included in an official sanctions list. Sanctions-related exposure may be: - direct; - indirect; - historical; - recent; - limited; - substantial. A sanctions connection does not always have the same meaning in every jurisdiction. Businesses should consider their applicable legal obligations, internal policies, transaction context, and the specific sanctions information detected. Does a Low-Risk Bitcoin Address Guarantee Safe Funds? No. A low-risk result means that no significant high-risk exposure was identified based on the data and attribution available at the time of the check. It does not guarantee that: - the transaction is legitimate; - the counterparty is trustworthy; - the Bitcoin was obtained legally; - every relevant address has been identified; - the address will remain low risk; - an exchange will accept the funds; - another analytics provider will reach the same result. Blockchain intelligence can change as: - new wallet clusters are identified; - stolen funds are traced; - law-enforcement information becomes public; - sanctions lists are updated; - scams are discovered; - historical addresses receive new attribution. For important transactions, consider saving the report and repeating the check if new information becomes available. Can a Bitcoin Transaction Be Reversed? Confirmed Bitcoin transactions are generally irreversible. If BTC is sent to: - the wrong address; - a scammer; - a compromised wallet; - a high-risk counterparty; - an unsupported service; there may be no simple way to recover the funds. That is why checking the address before sending Bitcoin is usually more useful than investigating it only after a problem occurs. Checking a Bitcoin Address for P2P Transactions P2P transactions may involve counterparties whose identity or source of funds is not fully known. Before accepting Bitcoin through a P2P deal, consider checking the sender’s address for exposure to: - stolen BTC; - scams; - darknet services; - mixers; - sanctioned entities; - ransomware; - fraudulent payment schemes; - suspicious P2P clusters; - other high-risk activity. A Bitcoin address check cannot replace identity verification, proof of payment, or full due diligence. It adds blockchain context that may help the user make a more informed decision. Checking a Bitcoin Address for OTC Transactions OTC transactions may involve large values and complex settlement arrangements. Before completing an OTC deal, it may be useful to: 1. verify the counterparty; 2. confirm the Bitcoin address; 3. perform an AML address check; 4. review the risk score and categories; 5. analyze the transaction path; 6. request source-of-funds information; 7. document the final decision; 8. save the report. The appropriate procedure depends on the transaction size, jurisdiction, counterparty profile, and applicable compliance requirements. Bitcoin Address Checks for Businesses Businesses that accept or process Bitcoin may use address screening as part of a risk-based AML process. A possible workflow may include: 1. collecting the customer or counterparty address; 2. confirming that the Bitcoin network is correct; 3. performing an AML check; 4. reviewing the overall risk score; 5. reviewing the detected categories; 6. escalating medium- or high-risk results; 7. requesting additional information when necessary; 8. documenting the decision; 9. repeating the check when the address is used again. The appropriate response depends on: - the business model; - transaction size; - customer profile; - jurisdiction; - applicable regulation; - internal risk appetite; - the detected exposure category. Wallet screening should be treated as one component of a broader compliance process. What to Do If a Bitcoin Address Has High Risk A high-risk result should not be ignored. Possible next steps may include: - reviewing the detected categories; - checking whether the exposure is direct or indirect; - reviewing the amount and percentage involved; - examining the transaction path; - identifying the relevant entity; - asking the counterparty for an explanation; - requesting source-of-funds documentation; - checking the specific transaction; - escalating the case to compliance; - delaying or rejecting the transaction when appropriate; - documenting the decision. The correct action depends on the transaction context and applicable obligations. The score alone should not be treated as automatic proof of illegal activity. Example: Low-Risk Bitcoin Address Imagine a Bitcoin address that mainly interacts with identified exchanges and has no significant exposure to high-risk categories. The report may show: - a low overall risk score; - no sanctions exposure; - no direct stolen-funds exposure; - ordinary exchange activity; - limited unidentified counterparties. This result may support proceeding with the transaction, but the user should still confirm the address and evaluate the counterparty. Example: Medium-Risk Bitcoin Address Imagine an address with mostly ordinary activity but some indirect exposure to a mixer several transactions away. The report may show: - a medium overall risk score; - indirect mixer exposure; - a limited amount involved; - no direct sanctions exposure; - an older transaction path. This result may require additional review rather than automatic rejection. The user may consider the amount, timing, purpose of the transaction, and explanation from the counterparty. Example: High-Risk Bitcoin Address Imagine an address that recently received a significant amount directly from a cluster associated with stolen Bitcoin. The report may show: - a high overall risk score; - direct stolen-funds exposure; - recent activity; - a significant percentage of the address activity involved; - an identified high-risk counterparty. This result may require escalation, supporting documentation, or a decision not to proceed, depending on the applicable compliance process. Should You Check a New Bitcoin Address? Yes, when the transaction is important. A newly generated Bitcoin address may have little or no previous activity. However, the transaction funding that address may still be connected to other inputs or transaction paths that require analysis. A new address is not automatically low risk simply because it has no long history. The source of the incoming Bitcoin and the associated transaction may still be relevant. Should You Check an Address More Than Once? A Bitcoin address risk profile can change over time. A repeated check may be appropriate when: - the address is used again; - a new transaction occurs; - a large payment is expected; - new risk information becomes available; - the counterparty relationship continues; - a previous result was medium or high risk; - compliance procedures require periodic monitoring. Saving previous reports can help document how the address risk changed over time. Do You Need to Connect Your Bitcoin Wallet? No. A public Bitcoin address can be analyzed without connecting the wallet. You do not need to provide: - a private key; - a seed phrase; - a wallet password; - access to the wallet application. Never share your seed phrase or private key with an AML screening service or counterparty. The public address is sufficient for blockchain risk analysis. Bitcoin Address Check vs General Crypto Wallet Check A Bitcoin-specific guide focuses on the features and transaction structure of the Bitcoin network. A general crypto wallet AML check explains broader principles that apply across multiple blockchains. These include: - risk scores; - risk categories; - direct and indirect exposure; - sanctions screening; - transaction context; - wallet and transaction checks; - business compliance workflows. Learn how to perform a general AML check on a crypto wallet AML Wallet Check Guides Use the relevant guide for the wallet or network you want to analyze: - Learn how to perform a general AML check on a crypto wallet - Check a USDT TRC20 wallet for AML risk - Understand a crypto wallet risk score - Check an Ethereum wallet for AML risk - Check a TRON wallet for AML risk - Check a TON wallet for AML risk Check a Bitcoin Address Before Sending or Accepting BTC Bitcoin transactions are generally irreversible, and blockchain risk may not be visible from the address alone. An AML check can help identify exposure to sanctions, scams, stolen funds, mixers, darknet services, ransomware, high-risk exchanges, and other suspicious activity. Review the risk score together with the detected categories, transaction paths, amounts, timing, entity information, and counterparty context. Check a Bitcoin address now Frequently Asked Questions Can I check any Bitcoin address? You can check a valid public Bitcoin address supported by the service. You do not need access to the private key or seed phrase. Which Bitcoin address formats can be checked? Common formats include addresses beginning with: - 1; - 3; - bc1q; - bc1p. Always confirm that you selected the Bitcoin network before starting the check. Is a Bitcoin address the same as a wallet? Not always. A wallet may control many different Bitcoin addresses and generate new addresses for different transactions. Is a new Bitcoin address automatically safe? No. A new address may have little history, but the transaction funding it can still be connected to high-risk sources. What does a high-risk Bitcoin address mean? It may indicate stronger exposure to identified high-risk entities, services, or transaction patterns. Review the detected categories, transaction paths, amounts, timing, and counterparty context before making a decision. Does indirect exposure mean the owner committed a crime? No. Indirect exposure is a risk indicator. It does not prove that the owner knowingly interacted with the final high-risk entity or controls every address in the transaction path. Does mixer exposure prove illegal activity? No. Mixers and privacy-enhancing transactions may be used for legitimate privacy reasons as well as to obscure illicit funds. The amount, timing, frequency, transaction path, and other risk categories should be reviewed. Can a Bitcoin risk score change? Yes. The score may change because of new transactions, new entity attribution, sanctions updates, scam reports, law-enforcement information, or newly traced stolen funds. Can an AML report guarantee that an exchange will accept my Bitcoin? No. Each exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds. Should I check the Bitcoin address or the transaction? They provide different information. An address check reviews broader address history, while a transaction check focuses on one specific transfer. For additional context, it may be useful to check both. Should I check the address before or after receiving Bitcoin? Whenever possible, check it before completing the transaction. A post-transaction check can still help investigate the origin or destination of funds and document a compliance decision. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that a Bitcoin address is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

Crypto Wallet Risk Score: How to Read AML Results | AML Verifier
Jul 7, 2026

Crypto Wallet Risk Score: How to Read AML Results | AML Verifier

Crypto Wallet Risk Score: How to Understand AML Results A crypto wallet risk score helps summarize the potential AML risk associated with a public blockchain address. Instead of reviewing every transaction manually, users and compliance teams can use the score as a starting point for understanding whether a wallet has exposure to sanctions, scams, stolen funds, mixers, darknet services, ransomware, high-risk exchanges, or other suspicious activity. However, a risk score should never be treated as a simple guarantee that a wallet is safe or unsafe. The score must be reviewed together with the detected risk categories, transaction paths, amounts, timing, entity attribution, and the overall context of the transaction. AML Verifier helps users screen crypto wallets and review their blockchain risk exposure before sending, accepting, or processing cryptocurrency. Check a crypto wallet risk score What Is a Crypto Wallet Risk Score? A crypto wallet risk score is a numerical or categorized assessment of the potential risk associated with a blockchain address. The score is based on blockchain analytics data and may reflect the wallet’s direct or indirect relationships with identified services, entities, and transaction clusters. Depending on the available data, an AML analysis may consider exposure to: - sanctioned entities; - scams and fraudulent platforms; - stolen cryptocurrency; - phishing operations; - crypto mixers; - darknet marketplaces; - ransomware; - high-risk exchanges; - unlicensed gambling services; - suspicious P2P activity; - fraudulent investment services; - money laundering networks; - other high-risk counterparties. The purpose of the score is to make complex blockchain activity easier to review. It does not determine whether the wallet owner committed a crime, knowingly interacted with a suspicious service, or controls every connected address. How Is a Crypto Wallet Risk Score Calculated? Blockchain analytics systems analyze transaction histories and relationships between addresses, services, and identified entities. The exact methodology may vary between analytics providers, but a risk assessment commonly considers factors such as: - which entities the wallet interacted with; - whether the exposure is direct or indirect; - the value of the related funds; - the percentage of activity associated with each category; - how recently the activity occurred; - how frequently the interaction appears; - the number of transaction hops involved; - whether the counterparty belongs to an identified cluster; - whether the address is associated with a known service; - the severity of the detected risk category. For example, a recent direct transfer from a sanctioned entity may be treated differently from an old indirect connection through several intermediary wallets. The score therefore represents a combination of risk signals rather than one isolated transaction. What Do Low, Medium, and High Risk Mean? Risk levels help organize the result into a form that is easier to review. Low risk A low-risk result generally means that no significant high-risk exposure was identified in the available blockchain analytics data. This may indicate that: - most detected activity involves lower-risk counterparties; - no major direct exposure was identified; - suspicious categories represent only a limited part of the wallet’s activity; - available attribution does not show strong links to known high-risk services. Low risk does not guarantee that the wallet is completely safe. It also does not guarantee that: - the wallet owner is trustworthy; - the current transaction is legitimate; - every counterparty has been identified; - the risk score will remain unchanged; - an exchange will accept the funds. Medium risk A medium-risk result generally means that some exposure, uncertainty, or unusual activity requires additional review. This may include: - indirect exposure to high-risk services; - limited direct exposure to a concerning category; - activity involving unidentified or high-risk counterparties; - a mixture of low-risk and higher-risk transactions; - an older connection that may still be relevant; - insufficient context to make an immediate decision. A medium-risk result should not automatically lead to rejection. The reviewer should examine the categories, transaction paths, dates, amounts, and counterparty explanation. High risk A high-risk result may indicate stronger exposure to identified high-risk entities, services, or transaction patterns. Examples may include: - direct exposure to sanctioned entities; - significant interaction with scams or stolen funds; - repeated transfers involving mixers; - connections to darknet marketplaces; - ransomware-related exposure; - substantial activity involving high-risk services; - recent or repeated suspicious transaction patterns. A high-risk score is an important warning signal, but it still requires contextual review. The score alone does not prove criminal activity or determine the legal status of the wallet owner. Risk Score and Risk Categories Are Not the Same The overall risk score provides a summary, while the risk categories explain why the score was assigned. Two wallets may have a similar score but very different underlying risks. For example: - one wallet may have limited indirect exposure to a mixer; - another may have direct exposure to a scam; - another may interact frequently with a high-risk exchange; - another may have received a small amount of stolen funds. The same overall score should not always lead to the same decision. When reviewing an AML report, identify: 1. which categories were detected; 2. whether each connection is direct or indirect; 3. how much value is associated with the exposure; 4. when the activity occurred; 5. how frequently the pattern appears; 6. whether an identified entity is involved; 7. whether the transaction has a reasonable explanation. The category details often provide more useful context than the headline score alone. Direct and Indirect Exposure The difference between direct and indirect exposure is one of the most important concepts in wallet risk analysis. Direct exposure Direct exposure exists when a wallet sends funds directly to or receives funds directly from an identified address or service. For example: Wallet A → Identified high-risk service There is no intermediary wallet between the address being checked and the identified entity. Direct exposure is usually easier to interpret because the transaction relationship is visible and immediate. Indirect exposure Indirect exposure exists when funds move through one or more intermediary addresses. For example: Wallet A → Intermediary wallet → High-risk service The relationship may become more complex when several wallets, exchanges, smart contracts, or services are involved. Indirect exposure does not automatically mean that the wallet owner knowingly interacted with the final high-risk entity. Its significance may depend on: - the number of transaction hops; - the amount of funds involved; - how recently the transaction occurred; - whether the pattern is repeated; - whether the intermediary belongs to an identified cluster; - the type of high-risk entity involved; - the economic purpose of the transaction. A distant, small, historical connection may require a different response from a recent and repeated indirect flow involving substantial value. Why the Amount of Exposure Matters The amount associated with a risk category can affect how the result should be interpreted. Consider the difference between: - a very small payment received once from an unknown address; - repeated incoming transfers from the same suspicious cluster; - a large percentage of the wallet’s total activity involving high-risk services; - a single high-value direct transfer from a sanctioned entity. The significance of exposure may depend on both the absolute value and its share of the wallet’s overall activity. A small exposure should not always be ignored, but it may have a different risk meaning from repeated or substantial exposure. Why Timing Matters Recent activity may be more relevant than an old historical connection. When reviewing a wallet, consider: - when the high-risk exposure occurred; - whether the activity happened before or after an entity was identified; - whether the relationship is ongoing; - whether the wallet continues to interact with similar counterparties; - whether the activity was isolated or repeated. An old transaction does not automatically become irrelevant. However, its significance may be different from a direct transfer that occurred immediately before the current transaction. Why Frequency Matters Repeated exposure can indicate a stronger relationship than a one-time transaction. For example, a wallet that repeatedly sends funds to the same high-risk cluster may require more scrutiny than a wallet that received one small unsolicited transfer. Frequency can help distinguish: - accidental or incidental exposure; - recurring business activity; - repeated P2P transactions; - ongoing interaction with a service; - structured transaction patterns; - potentially coordinated behavior. The correct interpretation still depends on the transaction context. Can a Risk Score Prove That a Wallet Is “Dirty”? No. The informal expressions “clean wallet” and “dirty wallet” can be misleading because blockchain risk is not always binary. A wallet may have: - mostly lower-risk activity with a small indirect exposure; - an old connection that is no longer representative; - incoming funds from an unknown third party; - a mixture of unrelated risk categories; - a high-risk association discovered only after the transaction occurred; - activity involving a service whose classification later changed. It is more accurate to describe: - the detected risk category; - the source of the exposure; - whether it is direct or indirect; - the value involved; - the date of the activity; - the significance of the relationship. A risk score is an assessment based on the data available at the time of the check. It is not a permanent moral or legal label attached to a wallet. Does a Low-Risk Score Mean the Funds Are Safe? No. A low-risk score means that no significant high-risk exposure was detected using the available blockchain analytics data and attribution at that time. It does not guarantee that: - the current transaction is not fraudulent; - the wallet owner is the person they claim to be; - the cryptocurrency was obtained legally; - the address has never interacted with an unidentified suspicious service; - the score will remain low; - another company will reach the same decision. Wallet screening should be combined with the broader transaction context. For businesses, this may include identity verification, source-of-funds information, customer history, jurisdiction, payment purpose, and internal compliance policies. Why Can a Crypto Wallet Risk Score Change? A wallet’s score may change over time. This can happen when: - the wallet performs new transactions; - new address clusters are identified; - an exchange or service receives new attribution; - a scam report is confirmed; - stolen cryptocurrency is traced; - law-enforcement investigations become public; - an entity is added to a sanctions list; - historical transactions are linked to newly identified services; - the analytics methodology or available data changes. A wallet that appears low risk today may receive new high-risk exposure tomorrow. A wallet’s historical transactions may also be reassessed when new attribution becomes available. For important or recurring counterparties, periodic rechecking may be appropriate. How to Review a Crypto Wallet Risk Score A structured review can help prevent decisions based only on the headline number. 1. Review the overall score Identify whether the wallet is categorized as low, medium, or high risk. Use this as the beginning of the analysis rather than the final conclusion. 2. Identify the detected categories Determine whether the exposure relates to: - sanctions; - scams; - stolen funds; - mixers; - darknet services; - ransomware; - gambling; - high-risk exchanges; - another category. Different categories may require different responses. 3. Check whether exposure is direct or indirect A direct transfer generally has a different risk meaning from an indirect connection through several intermediary wallets. 4. Review the value involved Consider both: - the absolute amount; - the percentage of the wallet’s total activity. 5. Review the timing Determine when the exposure occurred and whether it is still ongoing. 6. Review the frequency Check whether the exposure is isolated, occasional, or repeated. 7. Review entity attribution Determine whether the wallet or counterparty is linked to an identified exchange, service, platform, or organization. 8. Consider the transaction context Review: - who the counterparty is; - why the transaction is taking place; - whether the amount is expected; - whether the activity matches the customer profile; - whether the explanation is reasonable; - whether supporting documents are available. 9. Document the decision Businesses may need to record: - the report result; - the categories reviewed; - the transaction paths; - the amounts and dates; - the customer’s explanation; - supporting documents; - the final decision; - any monitoring or follow-up actions. Example: Low-Risk Wallet Imagine a wallet that mainly interacts with identified exchanges and has no significant direct exposure to high-risk services. The report may show: - a low overall score; - no sanctions exposure; - no direct scam or stolen-funds connections; - ordinary exchange activity; - limited unidentified counterparties. This result may support proceeding with the transaction, but the user should still confirm the wallet address and evaluate the counterparty. Example: Medium-Risk Wallet Imagine a wallet with mostly ordinary activity but some indirect exposure to a mixer through an intermediary address. The report may show: - a medium overall score; - indirect mixer exposure; - a limited amount involved; - no direct sanctions exposure; - an older transaction path. This result may require additional review rather than automatic rejection. The user may consider the amount, timing, purpose of the transaction, and explanation from the counterparty. Example: High-Risk Wallet Imagine a wallet that recently received a significant amount directly from an address linked to stolen funds. The report may show: - a high overall score; - direct stolen-funds exposure; - recent activity; - a substantial percentage of wallet activity involved; - an identified high-risk counterparty. This result may require escalation, additional documentation, or a decision not to proceed, depending on the applicable compliance procedure. Risk Scores for P2P Transactions P2P transactions may involve counterparties whose identity and source of funds are not fully known. Before accepting cryptocurrency through a P2P deal, a wallet risk score can help identify exposure to: - scams; - stolen assets; - mixers; - darknet services; - sanctioned entities; - fraudulent payment schemes; - suspicious P2P clusters; - other high-risk activity. A risk score cannot replace identity verification, proof of payment, or proper counterparty checks. It provides additional blockchain context that may help the user make a more informed decision. Risk Scores for Businesses Businesses that accept, send, or process cryptocurrency may include wallet scoring in a risk-based AML workflow. A possible process may include: 1. collecting the wallet address; 2. confirming the correct blockchain network; 3. performing the AML check; 4. reviewing the overall risk score; 5. reviewing the underlying risk categories; 6. escalating medium- or high-risk results; 7. requesting additional source-of-funds information; 8. documenting the final decision; 9. rechecking the wallet when it is used again. The appropriate response depends on: - the business model; - transaction size; - customer profile; - jurisdiction; - applicable regulation; - internal risk appetite; - the detected exposure category. A wallet score should be treated as one component of a broader compliance process. Risk Score vs Identity Verification A wallet risk score and identity verification serve different purposes. Wallet risk score A wallet score analyzes the blockchain address and its transaction exposure. It may reveal: - transaction relationships; - entity attribution; - risk categories; - direct and indirect exposure; - historical blockchain activity. Identity verification Identity verification confirms information about the individual or company involved. It may include: - legal name; - identity documents; - company registration information; - address; - beneficial ownership; - sanctions or PEP screening. A complete compliance review may require both blockchain screening and identity verification. Risk Score vs Transaction Risk A wallet score evaluates the broader activity of an address, while a transaction check focuses on one specific transfer. A wallet may have a generally low-risk history while one incoming transaction has suspicious exposure. The opposite can also occur: a specific transaction may look ordinary, but one of the associated wallets may have a broader high-risk history. For additional context, it may be useful to check: - the sending wallet; - the receiving wallet; - the specific transaction. How to Check a Crypto Wallet Risk Score To check a wallet: 1. Copy the public blockchain address. 2. Open AML Verifier. 3. Select the correct network. 4. Paste the wallet address. 5. Start the check. 6. Review the score and risk level. 7. Examine the detected categories and transaction relationships. 8. Save the report if necessary. Never share a private key or seed phrase. A public wallet address is sufficient for blockchain risk screening. Check a crypto wallet risk score AML Wallet Check Guides Use the relevant guide for the wallet or network you want to analyze: - Learn how to perform a general AML check on a crypto wallet - Check a USDT TRC20 wallet for AML risk - Check a Bitcoin address for AML risk - Check an Ethereum wallet for AML risk - Check a TRON wallet for AML risk - Check a TON wallet for AML risk Check the Risk Score Before Completing a Transaction Blockchain transactions are generally irreversible. A wallet risk score can help identify warning signs before funds are sent, accepted, or processed. The result should be reviewed together with the detected categories, transaction paths, amounts, dates, entity information, and counterparty context. Use AML Verifier to check a crypto wallet for sanctions exposure, scams, stolen funds, mixers, darknet activity, ransomware, and other high-risk connections. Check a crypto wallet now Frequently Asked Questions What is a good crypto wallet risk score? A lower-risk result generally indicates that no significant high-risk exposure was identified in the available data. However, the score should always be reviewed together with the detected categories and transaction context. What does a high wallet risk score mean? A high-risk result may indicate stronger exposure to identified high-risk entities, services, or transaction patterns. It does not automatically prove illegal activity, but it may require additional review or escalation. Can a low-risk wallet still be involved in fraud? Yes. A low-risk result does not confirm the identity or intentions of the wallet owner and does not guarantee that the current transaction is legitimate. Does indirect exposure mean the wallet owner committed a crime? No. Indirect exposure is a risk indicator. It does not by itself prove that the wallet owner knowingly interacted with an illicit service or controls another address. Why did my wallet risk score change? The score may change because of new transactions, new entity attribution, sanctions updates, scam reports, law-enforcement information, or newly traced stolen funds. Can I improve a wallet’s risk score? A blockchain transaction history cannot simply be deleted. Future activity may affect the wallet’s overall risk profile, but there is no guaranteed method for changing how an analytics provider assesses an address. Can an AML report guarantee that an exchange will accept my funds? No. Every exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds. Do I need to connect my wallet? No. You only need the public wallet address and the correct blockchain network. Never provide your seed phrase or private key. Should I check the wallet before or after receiving funds? Whenever possible, check the wallet before completing the transaction. A post-transaction check can still help investigate the origin or destination of funds and document a compliance decision. Is the risk score permanent? No. Risk scores may change as the wallet performs new transactions or new blockchain intelligence becomes available. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that a wallet is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

AML Check for Crypto Wallets: Risk Screening Guide | AML Verifier
Jul 6, 2026

AML Check for Crypto Wallets: Risk Screening Guide | AML Verifier

AML Check for a Crypto Wallet Before sending, accepting, or processing cryptocurrency, it is important to understand the potential risk associated with the wallet involved. A crypto wallet may appear ordinary while having direct or indirect connections to scams, stolen funds, sanctioned entities, mixers, darknet marketplaces, ransomware, or other high-risk services. An AML check helps analyze blockchain activity and convert transaction data into a structured risk assessment. AML Verifier allows individuals, businesses, and compliance teams to screen crypto wallets, review their risk exposure, and make more informed decisions before completing a transaction. Check a crypto wallet What Is a Crypto Wallet AML Check? A crypto wallet AML check is an analysis of a public blockchain address for potential exposure to high-risk or illicit activity. The check uses blockchain analytics data to examine how the address has interacted with other wallets, services, exchanges, and identified entities. Depending on the available data, an AML check may reveal connections to: - sanctioned entities; - scams and fraudulent services; - stolen cryptocurrency; - phishing operations; - darknet marketplaces; - ransomware; - crypto mixers; - high-risk exchanges; - unlicensed gambling services; - fraudulent investment platforms; - suspicious P2P activity; - money laundering networks; - other high-risk counterparties. The purpose of the check is not to determine guilt or prove ownership of every connected address. It is to identify risk indicators that may require further review. Why Can a Crypto Wallet Carry AML Risk? Blockchain transactions are public, but the risk behind them is not always obvious. A wallet address does not display a warning when it has received funds from a scam, interacted with a mixer, or transferred assets through a high-risk service. Risk may arise from: - the original source of the funds; - previous counterparties; - repeated transfers through suspicious clusters; - interactions with identified services; - indirect exposure through intermediary wallets; - recent law-enforcement or sanctions activity; - transaction patterns associated with known typologies. A wallet may also receive high-risk funds without the owner immediately recognizing the source. For this reason, AML screening should consider the wallet’s transaction history and relationships rather than only its current balance. When Should You Check a Crypto Wallet? A crypto wallet check may be useful before: - sending cryptocurrency to a new counterparty; - receiving funds from an unknown person; - completing a P2P transaction; - processing a customer deposit or withdrawal; - accepting a crypto payment; - working with an OTC counterparty; - interacting with an unfamiliar service; - depositing cryptocurrency to a centralized exchange; - returning funds to a customer; - investigating a suspicious transaction; - onboarding a customer who uses cryptocurrency; - approving a high-value transfer. A check may also be performed after a transaction if an exchange, payment provider, bank, auditor, or compliance team requests information about the origin of the funds. How to Perform an AML Check on a Crypto Wallet The process is straightforward: 1. Copy the public wallet address you want to check. 2. Open AML Verifier. 3. Select the relevant blockchain network. 4. Paste the wallet address. 5. Start the AML check. 6. Review the risk score and exposure categories. 7. Save the report if you need to document your decision. Make sure you select the correct blockchain. Some address formats may look similar across different networks, while others are network-specific. Entering an address under the wrong network can produce an error or an irrelevant result. Start an AML wallet check What Can an AML Wallet Report Show? The available results may include: - overall risk score; - risk level; - identified entity information; - sanctions-related exposure; - scam and fraud exposure; - connections to crypto mixers; - exposure to stolen funds; - darknet-related activity; - ransomware connections; - gambling exposure; - exchange exposure; - suspicious service categories; - direct transaction relationships; - indirect transaction relationships; - wallet activity information; - transaction history context; - known cluster or entity attribution. The exact information available depends on the blockchain, the address, its transaction history, and the available attribution data. What Is a Crypto Wallet Risk Score? A crypto wallet risk score summarizes multiple blockchain risk indicators into a single result. In general: - Low risk means that no significant high-risk exposure was detected in the available data. - Medium risk means that some exposure, uncertainty, or unusual activity requires further review. - High risk means that stronger connections to high-risk entities, services, or transaction patterns were identified. The score is a starting point, not the final decision. A proper review should also consider: - the detected risk categories; - whether exposure is direct or indirect; - the value of the associated funds; - how recently the activity occurred; - how frequently the connection appears; - the percentage of activity associated with each category; - whether the wallet is linked to an identified entity; - the purpose of the transaction; - the customer or counterparty context. A medium-risk wallet is not automatically unsafe, and a low-risk wallet is not guaranteed to be safe. Direct and Indirect Exposure One of the most important parts of blockchain risk analysis is the difference between direct and indirect exposure. Direct exposure Direct exposure exists when the wallet sends funds directly to or receives funds directly from an identified entity or high-risk address. For example: Wallet A → Identified high-risk service This relationship is generally easier to understand because there is no intermediary address between the wallet and the identified entity. Indirect exposure Indirect exposure exists when funds pass through one or more intermediary addresses. For example: Wallet A → Intermediary wallet → High-risk service The connection may be more complex when several wallets or services are involved. Indirect exposure does not automatically mean that the wallet owner knowingly interacted with an illicit service. However, it may become more important when: - the exposure is recent; - the same pattern appears repeatedly; - the value of the funds is significant; - several high-risk categories are involved; - the intermediary wallet belongs to an identified cluster; - the transaction has no clear economic explanation. Wallet Address Check vs Transaction Check A wallet address check and a transaction check answer different questions. Wallet address check A wallet check evaluates the broader history and exposure of a blockchain address. It may help identify: - overall address risk; - historical counterparties; - entity attribution; - repeated exposure patterns; - connections to high-risk services; - the address’s general blockchain activity. Transaction check A transaction check focuses on one specific transfer. It may help identify: - sender and recipient; - transferred asset; - transferred amount; - transaction time; - blockchain confirmation details; - risk associated with the particular transfer. A transaction may appear ordinary when viewed alone while being connected to a wallet with a broader high-risk history. For additional context, it may be useful to check both the transaction and the associated wallet addresses. Supported Blockchain Networks Crypto assets operate across different blockchains, and each network has its own address formats, tokens, transaction structure, and risk environment. AML Verifier supports wallet screening across multiple blockchain networks, including major networks such as: - Bitcoin; - Ethereum; - TRON; - TON; - BNB Smart Chain; - Polygon; - Solana; - Litecoin; - XRP Ledger; - other supported networks available in the application. When performing a check, always select the network on which the transaction actually occurred. AML Wallet Check Guides by Network Different blockchains use different address formats, assets, transaction structures, and risk environments. Use the appropriate guide for the network you want to check: - Check a USDT TRC20 wallet for AML risk - Check a Bitcoin address for AML risk - Check an Ethereum wallet for AML risk - Check a TRON wallet for AML risk - Check a TON wallet for AML risk - Understand a crypto wallet risk score AML Checks for P2P Transactions P2P transactions often involve counterparties whose source of funds is not fully known. A person may receive cryptocurrency directly from another user without the screening controls normally applied by a centralized exchange. Before completing a P2P transaction, consider checking the counterparty’s wallet for exposure to: - stolen assets; - scams; - phishing; - mixers; - darknet services; - sanctioned entities; - fraudulent payment schemes; - high-risk exchanges; - suspicious P2P clusters. A wallet check cannot replace identity verification, proof of payment, or full customer due diligence. It provides an additional layer of blockchain risk information. AML Wallet Screening for Businesses Businesses that accept, send, or process cryptocurrency may include wallet screening in their risk-based AML procedures. A possible workflow may include: 1. collecting the customer or counterparty wallet address; 2. confirming the correct blockchain network; 3. performing an AML wallet check; 4. reviewing the risk score and detected categories; 5. escalating medium- and high-risk results; 6. requesting source-of-funds or source-of-wealth information when appropriate; 7. documenting the review and final decision; 8. monitoring or rechecking the address when it is used again. The appropriate procedure depends on factors such as: - the business model; - transaction size; - customer profile; - jurisdiction; - regulatory obligations; - internal risk appetite; - the products or services being provided. AML screening should be treated as one component of a broader compliance process rather than a complete replacement for customer due diligence. How Compliance Teams Can Review an AML Alert An alert should not be accepted or rejected based only on its headline score. A structured review may include the following steps. 1. Identify the risk category Determine whether the alert relates to sanctions, scams, stolen funds, mixers, darknet activity, ransomware, gambling, or another category. Different risk categories may require different escalation procedures. 2. Review the connection type Check whether the exposure is direct or indirect. A direct recent transfer may require a different response from a distant indirect connection through several intermediaries. 3. Review the amount and timing Consider: - the value of the associated funds; - the percentage of the wallet’s activity involved; - when the exposure occurred; - whether it was a one-time event or a repeated pattern. 4. Review the counterparty context Consider what you know about the customer or counterparty: - identity; - occupation or business activity; - expected transaction behavior; - country of residence; - source of funds; - explanation for the transfer. 5. Document the decision Record: - the report result; - the relevant exposure categories; - supporting documents; - the customer’s explanation; - the reviewer’s analysis; - the final decision; - any monitoring or follow-up actions. Documented decisions are especially important when a transaction is approved despite a medium- or high-risk alert. Can a Crypto Wallet Be Considered “Clean”? The terms “clean wallet” and “dirty wallet” are commonly used informally, but they can be misleading. Blockchain risk is not always binary. A wallet may have: - mostly low-risk activity and a small indirect exposure; - an old connection that is no longer representative; - incoming funds from an unknown counterparty; - several unrelated categories of exposure; - a high-risk connection that appeared only after new attribution data became available. It is more accurate to describe the detected risk, its source, and its significance than to label an address permanently clean or dirty. An AML report is a risk assessment based on the available information at the time of the check. Does a Low-Risk Result Guarantee Safety? No. A low-risk result means that no significant high-risk exposure was detected using the available data and attribution at that time. It does not guarantee that: - the wallet owner is trustworthy; - the transaction cannot be fraudulent; - the address has never been involved in suspicious activity; - the address will remain low risk; - every counterparty has already been identified; - an exchange will accept the funds. Blockchain analytics data can change as new information becomes available. Why Can a Wallet’s AML Risk Change? A wallet’s result may change when: - new address clusters are identified; - law-enforcement investigations become public; - new entities are added to sanctions lists; - exchanges or services receive new attribution; - scam reports are confirmed; - stolen funds are traced; - historical transactions are connected to new entities; - the wallet performs additional transactions. For important or recurring relationships, a wallet may need to be checked more than once. A previous report shows the information available at the time it was generated. It should not always be treated as a permanent assessment. Should You Save the AML Report? Saving the report can be useful when you need to: - document a compliance decision; - explain the source of a risk score; - respond to an exchange or payment provider; - maintain an audit trail; - compare the result with a future check; - demonstrate that screening occurred before a transaction; - investigate the source of received funds. Businesses should define how long reports and supporting records are retained based on their internal policies and applicable legal requirements. Check a Crypto Wallet Before Completing a Transaction Blockchain transactions are generally irreversible. If cryptocurrency is sent to the wrong address, a scammer, or an unacceptable counterparty, recovering the funds may be difficult or impossible. An AML check can help identify warning signs before the transaction becomes a financial, operational, or compliance problem. Use AML Verifier to review a crypto wallet for sanctions exposure, scams, stolen funds, mixers, darknet activity, ransomware, and other high-risk connections. Check a crypto wallet now Frequently Asked Questions Can I check any cryptocurrency wallet? You can check a valid public address on a blockchain supported by AML Verifier. The correct network must be selected before starting the analysis. Do I need to connect my wallet? No. Wallet screening uses the public blockchain address. You do not need to connect the wallet or provide access to it. Never share your seed phrase or private key. Does an AML check require the wallet owner’s permission? Public blockchain addresses and their transaction histories can generally be analyzed without access to the wallet. However, businesses should process customer information in accordance with applicable privacy and data-protection requirements. What information do I need to check a wallet? You normally need: - the public wallet address; - the correct blockchain network. For a transaction-specific review, you may instead need the transaction hash. Is an AML check the same as identity verification? No. Wallet screening analyzes blockchain activity and address exposure. Identity verification confirms information about a person or company. A complete compliance procedure may require both. What does a high-risk wallet result mean? A high-risk result may indicate significant exposure to identified high-risk entities, services, or transaction patterns. Review the specific categories, transaction paths, amounts, timing, and counterparty context before deciding how to proceed. Does indirect exposure prove illegal activity? No. Indirect exposure is a risk indicator. It does not by itself prove that the wallet owner committed a crime, controlled another address, or knowingly interacted with an illicit service. Can an AML score change over time? Yes. Scores and classifications may change as new transactions occur or new blockchain attribution, sanctions information, scam reports, or law-enforcement data becomes available. Should I check a wallet before or after a transaction? Whenever possible, perform the check before completing the transaction. A post-transaction check can still help investigate the origin or destination of funds and document a compliance decision. Can AML Verifier guarantee that an exchange will accept my cryptocurrency? No. Every exchange, payment provider, and financial institution applies its own compliance rules and risk thresholds. An AML report cannot guarantee that another organization will accept or reject particular funds. --- AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that an address is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.

Browse All Articles

Frequently asked questions

Find answers to common questions about our AML verification service.

AML Verifier supports address and transaction checks across popular blockchain networks, including major ecosystems, L2 networks, stablecoin networks, DeFi, and everyday crypto transfers. Supported networks: Arbitrum One, Avalanche, Base, Bitcoin, Bitcoin Cash, Blast, BNB Smart Chain, Cardano, Dash, Dogecoin, Ethereum, Ink, Litecoin, Mantle, Optimism, Polygon, Ripple, Solana, Stellar, Tezos, TON, TRON. We regularly expand our coverage so users can check crypto activity across the most in-demand networks.

Scan. Detect. Stay safe.

Check crypto wallets and transactions for risks — fast and easy.