VaultNow Blog
Try free
Guides

Cryptocurrency Address Screening: How to Check a Wallet Before You Send Money to It

Send a wire and correspondent banks screen the beneficiary for you. Send USDT from your own wallet and nobody does. What address screening actually checks, what OFAC strict liability costs, and the decision tree for when a screen comes back bad.

By Dmitrii Borisov 19 min read
Cryptocurrency Address Screening: How to Check a Wallet Before You Send Money to It
Aug 2026
On this page
  1. What cryptocurrency address screening actually checks
  2. Why this stopped being optional
  3. The two cases that should change your process
  4. Issuer freezes: the risk that isn’t about you at all
  5. What tainted money does to your own wallet
  6. The Travel Rule changes who does the work
  7. A working screening process
  8. When your own address is the one that gets flagged
  9. Where this fits in the payment flow
  10. Frequently Asked Questions

In August 2026, thousands of wallets received unsolicited USDT deposits of between 7.5 and 12 dollars, sent from addresses tagged as connected to HTX. The recipients did nothing. They didn’t ask for the money, didn’t touch it, didn’t move it. Automated compliance systems at several major exchanges picked up the tagged inflow anyway, and accounts were frozen — belonging to people whose only action was existing at a public address.

That’s the shape of the problem. Dust costs a few cents to send. A single flagged deposit can lock an account for weeks.

When you send a wire, the correspondent banks in the middle screen the beneficiary for you. It’s slow and it costs somewhere between $25 and $50 depending on your bank, and part of what you’re buying is somebody else’s compliance department. Send USDT from your own wallet and that layer is gone. The screening either happens because you did it, or it doesn’t happen at all — and the liability doesn’t disappear along with the intermediary.

What cryptocurrency address screening actually checks

It isn’t a list lookup. That’s the first thing to understand, because “is this address on the SDN List” is a five-second check that catches a small fraction of the risk.

A real screen evaluates several dimensions at once:

Direct exposure. The address’s immediate counterparties — identified services or entities it transacted with one hop away. Direct exposure to a sanctioned entity, a darknet market, a ransomware wallet or a mixer normally triggers immediate action.

Indirect exposure. Services reached through intermediary addresses that aren’t themselves attributed to any service. Chainalysis traces through these hops until an attributed entity is reached, however many hops intervene, precisely because deliberate buffer wallets and peel chains are the standard way to defeat direct-only screening. If you screen only one hop, you’re screening for carelessness rather than for intent.

Cluster attribution. Addresses get grouped into clusters controlled by the same entity. A wallet inside a cluster associated with a designated entity carries real risk even when that specific address appears on no list. TRM Labs exposes 155-plus configurable risk combinations across direct sanctions ownership, indirect exposure, counterparty risk, mixer and bridge exposure, darknet activity and fraud.

Taint methodology. The common approach is the haircut method: one dirty coin mixed with nine clean ones leaves all outputs carrying 10% taint.

Here’s the part vendors don’t advertise. There is no industry standard for any of this. No consensus on how many hops to trace, what taint percentage is disqualifying, or which tainting method to use. The direct operational consequence is that one exchange accepts a deposit another rejects, from the same address, on the same day. Risk scores are configurable by the customer, not published as a fixed scale — so be suspicious of anyone who tells you there’s a universal threshold above which an address is “bad.”

Practically, what you get back is a severity tier and a set of reasons. What you do with it is a policy decision your business has to make and write down.

Why this stopped being optional

Three things converged.

Stablecoins became the dominant medium for illicit flows. Chainalysis’s 2026 Crypto Crime Report puts illicit addresses as receiving at least $154 billion in 2025, up 162% year over year, with stablecoins accounting for 84% of all illicit transaction volume. Bitcoin and everything else make up the remaining sixth. That’s a complete inversion of the picture from a decade ago, and it means the asset you’re most likely to pay a contractor in is the asset most likely to carry history.

Context matters here: illicit activity remains below 1% of all attributed crypto volume. This isn’t an argument that crypto is criminal. It’s an argument that the specific asset you’re handling has a screening requirement attached to it.

Sanctions volume exploded. Sanctioned entities received $104 billion in 2025, up 694% year over year. Russia’s A7A5 ruble stablecoin alone moved $93.3 billion in under a year. Garantex’s successor Grinex processed at least $4.76 billion in 2025 before OFAC designated it on 14 August 2025 along with seven Tron addresses.

Enforcement arrived. OFAC has been adding digital-currency addresses to the SDN List since 2018, roughly a thousand are listed today across BTC, TRX, ETH, USDT and other tickers, and the list changes weekly. FinCEN issued a final rule on 14 October 2025 severing Huione Group from the US financial system under Section 311; FinCEN found Huione had received at least $4 billion in illicit proceeds between August 2021 and January 2025; Elliptic puts the group’s total inbound crypto flows since 2021 at around $98 billion.

And OFAC started fining companies for not screening.

The two cases that should change your process

ShapeShift AG, September 2025, $750,000. Seventeen thousand one hundred and eighty-three apparent violations, involving over $12.5 million in transactions for users in Cuba, Iran, Sudan and Syria between December 2016 and October 2018. OFAC’s finding rested on the absence of any sanctions compliance program at all: no transaction screening, no wallet-address screening, despite the company holding IP data that indicated sanctioned-jurisdiction users. OFAC asserted jurisdiction over the Swiss-incorporated company because its leadership and operations sat in Denver.

Exodus Movement, December 2025, $3.1 million (against a base penalty of $4,774,400). Two hundred and fifty-four violations of the Iranian Transactions and Sanctions Regulations, twelve deemed egregious. The important part: Exodus is a non-custodial wallet provider. OFAC held it had exported prohibited services to Iran anyway, and treated customer support staff recommending VPNs to circumvent IP controls as an aggravating factor.

Non-custody was not a defence. Neither was not knowing.

That’s because OFAC civil enforcement is strict liability: a US person may be held liable for sanctions violations “even without having knowledge or reason to know” that a violation occurred. The IEEPA civil maximum was $377,700 per violation or twice the transaction value, whichever is greater, as of the January 2025 inflation adjustment. Each payment is a separate violation. A payment run of 40 contractors, one of whom has an address in a designated cluster, is not one exposure.

Issuer freezes: the risk that isn’t about you at all

The sanctions angle is about money you send. The freeze angle is about money you receive, and it’s the one that catches legitimate businesses.

Tether can freeze any USDT address, and does, constantly. The contract exposes three owner-only functions: addBlackList(address), which sets isBlackListed to true and reverts every subsequent transfer; removeBlackList(address); and destroyBlackFunds(address), which permanently burns the balance and reduces total supply. Anyone can query isBlackListed on the contract for free.

Tether’s own disclosure, in its April 2026 statement on a $344 million freeze of Tron addresses linked to the Central Bank of Iran, put the cumulative total at more than $4.4 billion frozen across more than 2,300 cases globally, working with over 340 law enforcement agencies in 65 countries. Independent on-chain trackers count higher: BlockSec’s tracker showed 9,597 blacklisted addresses and $5.69 billion frozen as of 26 July 2026, running at roughly ten new freezes a day. The figures measure different things, Tether counts case value, the trackers count balances sitting at blacklisted addresses, so cite one and say which.

The rate is what matters operationally. In the thirty days to the end of June 2026, BlockSec’s tracker recorded 364 addresses blacklisted holding $185.48 million, with Tron accounting for 97.4% of it.

Freezes are hard to reverse. Only 3.6% of blacklisted USDT addresses were unfrozen in 2025, with a median release time of 18.2 days. Over the same year the volume destroyed via destroyBlackFunds ran at 55.6% of the volume newly frozen, $698 million against roughly $1.26 billion, a comparison of two flows rather than the fate of one cohort. Destruction is usually paired with a burn-and-reissue to a victim or a court-designated wallet.

USDC works differently. Circle’s contract uses a separate Blacklistable module with a dedicated blacklister role; transfers revert with a clear error. There’s no burn equivalent, so USDC freezes are reversible where USDT freezes can escalate to permanent confiscation. Circle’s cumulative numbers are much smaller, around 370 to 500 addresses and roughly $109 million through 2025, about twenty times fewer addresses than Tether and thirty times less value.

That’s not automatically reassuring. On 23 March 2026 Circle froze 16 unrelated business hot wallets under a sealed civil order from a New York federal court. The affected addresses belonged to exchanges, casinos, forex platforms and payment processors, and included the ckETH Minter bridge contract run by the DFINITY Foundation; withdrawals, payments and settlements stopped. Three days later Circle unfroze one of them, and left the rest. Circle gave no public explanation, citing the sealed proceedings. Days later it failed to block over $230 million in stolen USDC moving during the Drift Protocol exploit. Whichever token you use, the issuer holds a switch you don’t control.

And in the 2023 pig-butchering freeze that hit 37 wallets holding $225 million, many of the frozen wallets belonged not to the principals but to grey-market OTC brokers, small exchanges, and merchants who had unknowingly accepted the payments.

That’s the whole argument for screening incoming addresses as well as outgoing ones.

What tainted money does to your own wallet

The asymmetry is the point. Flagging is one automatic operation that takes milliseconds. Clearing a flag takes weeks of correspondence, statements and source-of-funds documentation.

In practice a tainted inbound transfer produces some combination of: exchange deposit rejection, account freeze pending review, withdrawal suspension, and correspondent banking problems if you bank with anyone who cares. If the taint traces to an SDN, the funds are blocked property and you have a reporting obligation, not a customer service problem.

For a business paying contractors, the practical exposure runs both ways. You screen the contractor’s address before you send, because sending to a designated address is a prohibited dealing. And you screen the addresses that pay you, because a client settling an invoice from a wallet with mixer history can contaminate the wallet you then pay your team from.

The Travel Rule changes who does the work

One more date to put in the calendar before the numbers: the EU’s AMLR (Regulation 2024/1624) applies from 10 July 2027, banning anonymous crypto accounts and privacy coins for obliged entities and capping cash at EUR 10,000, which will change what an EU counterparty is allowed to accept from you. FATF’s Seventh Targeted Update, published 16 July 2026, reports that 83% of surveyed jurisdictions have passed Travel Rule legislation, up from 73% a year earlier. But only around 40% of jurisdictions with legislation have taken any supervisory or enforcement action, the headline finding is the gap between adoption and enforcement. FATF also confirmed that most identified on-chain illicit activity now involves stablecoins.

Thresholds vary more than the FATF baseline suggests:

Jurisdiction

Threshold

FATF baseline

USD/EUR 1,000 (reduced data set below)

EU (Reg. 2023/1113)

Zero for full originator/beneficiary data

UK

EUR 1,000 equivalent (in force since 1 Sep 2023)

Singapore

S$1,500 for the full data set; basic originator and beneficiary data at any value (MAS Notice PSN02)

Australia

No threshold (from 1 Jul 2026)

Philippines

PHP 50,000

US

No crypto-specific rule; 31 CFR 1010.410(f) $3,000 wire analogue

What this means for a company paying contractors:

Sending through a VASP, an exchange or regulated payment provider, means that provider collects and transmits your identity and the beneficiary’s, screens the destination, and in many jurisdictions must verify whether a self-hosted destination address is actually controlled by the named counterparty. Expect held or blocked transfers when an address screens badly. Expect the data to be retained.

Sending from self-custody to self-custody carries no Travel Rule obligation for you as a non-VASP. It also means nobody screens on your behalf, while OFAC strict liability applies in full. The burden moves; it doesn’t vanish.

A working screening process

Six steps, in order.

1. Screen at onboarding, and screen again at payment time. This is the single most common failure. An address that was clean when you onboarded a contractor in February may be in a designated cluster by August, OFAC updates weekly, Tether blacklists daily. Screening at onboarding only tells you about the past.

2. Screen the whole counterparty, not just the string. Name and country against the SDN List and other applicable lists, plus the destination address. A contractor whose address is clean but who is personally designated is still a prohibited dealing.

3. Set a written policy for what each severity tier triggers. Since there’s no industry standard, yours is the only standard that applies. Decide in advance: what score or reason set means proceed, what means escalate, what means stop. Write it down before you need it, not during an incident.

4. When an address returns high risk, don’t send. Ask for a different settlement address and screen that one. Most of the time a contractor using a personal wallet that touched a mixer two years ago can simply give you a fresh address from a regulated exchange account. That conversation is awkward for ninety seconds and cheap. Address screening is one layer inside payment fraud controls generally.

5. Log everything. The screening result, the timestamp, the decision, and who made it. OFAC’s Enforcement Guidelines treat a documented, risk-based compliance program as a mitigating factor, the ShapeShift finding turned on the absence of one. A screen you ran but didn’t record is, for enforcement purposes, close to a screen you didn’t run.

6. If you hit an actual SDN match, block, don’t reject. A US person must block the property and report to OFAC within 10 business days under 31 CFR 501.603, and file an annual report by 30 September covering property still blocked as at 30 June. Returning the funds to the sender is itself a prohibited dealing.

The decision tree, written down

Every vendor explainer stops at “trigger a compliance workflow.” Nobody says what the workflow is, because saying it edges into legal advice. Here is the version a business paying contractors actually needs, and the version you should adapt into your own written policy.

What the screen returns

What it means

What you do

Direct match to an SDN-listed address

Prohibited dealing

Do not send. Block, don’t reject. Report to OFAC within 10 business days. Escalate to counsel before any communication with the counterparty

Direct exposure to a sanctioned entity, darknet market or ransomware wallet

One hop from designated activity

Do not send. Request an alternative address. Document. Consider EDD on the counterparty, not just the address

Direct exposure to a mixer

Not per se illegal, high risk

Do not send to that address. Ask why. A contractor with a good answer will have one

Indirect exposure at several hops, small proportion

Common and often meaningless

Proceed under your policy threshold, log the result and the reason

Counterparty risk only, no sanctions nexus

Their exchange has a reputation

Usually proceed; note it and re-screen next run

Clean

Clean today

Proceed, and screen again next run

Two rules that hold across every row. Block, don’t reject, on an actual SDN hit. Returning the funds to the sender is itself a prohibited dealing, and the property is blocked property with a reporting obligation attached. And log the negative results too. A screen that returned clean and was recorded is evidence of a functioning program; a screen that returned clean and vanished is nothing. OFAC’s enforcement guidelines treat a documented, risk-based compliance program as a mitigating factor, and the ShapeShift finding turned on the absence of one.

When your own address is the one that gets flagged

Every page written on this subject assumes you are the exchange doing the screening. Most readers are on the other side of it: a business, a freelancer, a DAO treasury, someone who accepted a payment and now can’t move it.

The mechanics are unforgiving because they’re automated. Your exchange screens inbound deposits. A deposit arrives carrying exposure you had no way to see and no part in creating. The account is restricted while a review runs. Flagging took milliseconds; clearing takes weeks of correspondence, statements and source-of-funds paperwork, and the burden of proof sits with you.

What actually helps, in order of how much:

Segregate wallets by purpose. The wallet that receives payments from counterparties you haven’t vetted should not be the wallet that pays your contractors, and neither should be your treasury. This is the single most useful control you can put in place, it costs nothing, and it means one contaminated inflow can’t freeze your payroll. Our guide to choosing business crypto wallets covers the structure.

Screen inbound before you accept, where you can. For invoices, that means asking which address will pay and screening it before the client sends, not after. It feels awkward the first time and then becomes normal, in the same way asking for bank details became normal.

Keep the provenance file. Invoice, contract, transaction hash, and the screening result you ran at the time. When an exchange asks for source of funds, the difference between a two-day review and a two-month one is whether you can answer in one email.

Don’t touch dust. Unsolicited small deposits from tagged addresses are a known pattern, and the August 2026 HTX wave froze accounts belonging to recipients who did nothing at all. Moving or consolidating dust attaches it to your other funds. Leave it.

Where this fits in the payment flow

The design question is whether screening happens before the money moves or after.

Bolt-on screening, export addresses, run them through a separate tool, import results, then pay, works at ten contractors and falls apart at a hundred. It fails in the specific way that matters: under time pressure, someone skips the export step for the one urgent payment, and that’s the payment that turns out to matter.

Screening built into the send path doesn’t have that failure mode. VaultNow scores addresses for AML risk before a transfer goes out, on both incoming and outgoing sides, so the check runs as part of the payment rather than as a separate discipline someone has to remember. Bulk payouts run up to 100 transactions from a CSV or address book at $0.50 per transaction plus gas, with per-user permissions so the person who builds a payment run isn’t necessarily the person who approves it. The screening record and the payment record end up in the same place, which is the part that matters when someone asks you to reconstruct a decision from eight months ago.

There’s an unresolved question worth watching. On 15 May 2026 a lawyer filed in the Southern District of New York on behalf of holders of unpaid US terrorism judgments against Iran, seeking to compel Tether to reissue the 344,149,759 USDT it froze at two OFAC-designated Tron addresses to a wallet controlled by plaintiffs’ counsel. The outcome is pending, and it goes directly to who has a claim on frozen issuer-controlled balances. Nobody currently knows the answer.

Frequently Asked Questions

What is cryptocurrency address screening (AML Check)?

It’s the process of assessing a wallet address for links to sanctions, criminal activity or high-risk services before transacting with it. It goes well beyond checking a sanctions list: providers evaluate direct exposure to identified entities, indirect exposure through intermediary hops, cluster attribution, and exposure to mixers, darknet markets and designated services, and return a risk assessment rather than a yes/no answer.

Do I legally have to screen wallet addresses before paying someone?

There’s no statute that says “screen wallet addresses” in those words. But OFAC sanctions compliance is strict liability, so sending funds to a designated address is a violation regardless of intent, and OFAC’s own virtual currency guidance calls for screening physical, digital wallet and IP addresses. The ShapeShift settlement in September 2025 rested substantially on the absence of wallet-address screening. Treat it as mandatory in effect.

How often does OFAC add crypto addresses to the SDN List?

Regularly, and unpredictably. Roughly a thousand digital-currency addresses are currently listed across BTC, TRX, ETH, USDT and other tickers, and the list is updated week to week. Recent additions include Cryptex (September 2024), Aeza Group (July 2025) and Grinex with seven Tron addresses (August 2025). This is why point-in-time screening at onboarding isn’t sufficient.

How much USDT has Tether frozen?

Tether’s own figure, published April 2026, is more than $4.4 billion across more than 2,300 cases, working with over 340 law enforcement agencies in 65 countries. On-chain trackers count differently: BlockSec showed 9,597 blacklisted addresses holding $5.69 billion as of July 2026. The freeze rate is roughly ten addresses per day, heavily concentrated on Tron.

Can frozen USDT be recovered?

Rarely. Only 3.6% of blacklisted USDT addresses were unfrozen in 2025, with a median release time of 18.2 days. More than half of the value frozen that year was subsequently destroyed with destroyBlackFunds and reissued to victims or court-designated wallets. USDC is different, Circle’s contract has no burn function, so its freezes are reversible in principle.

What should I do if a contractor’s wallet address returns a high risk score?

Don’t send. Ask for an alternative settlement address, ideally from a regulated exchange account, and screen that one. Document the original result, the decision, and the reason. Escalate to compliance or legal where the exposure is direct rather than several hops out. If the hit is an actual SDN match, block the funds rather than returning them, and report to OFAC within 10 business days.

Does screening protect me if the money I receive is tainted?

It reduces the exposure rather than eliminating it. Screening inbound addresses lets you decline a payment before it lands, which is far cheaper than explaining it afterwards. What you cannot control is unsolicited dust, the August 2026 HTX wave froze accounts belonging to recipients who took no action at all. Segregating wallets by purpose helps: an operating wallet that pays contractors shouldn’t be the same wallet that receives client payments from counterparties you haven’t vetted. Our guide to choosing business crypto wallets covers that structure.

Is address screening different for USDT on Tron versus Ethereum?

The analysis is the same, but the risk concentration isn’t. Tron accounted for 97.4% of USDT freeze value in the thirty days to the end of June 2026, which reflects where the volume is rather than anything about the chain itself. Screen the same way on both. The network choice affects your costs and settlement, which we cover in ERC-20 vs TRC-20.


The uncomfortable thing about this subject is that doing it properly doesn’t feel like it’s doing anything. You screen fifty addresses, they all come back clean, and the process looks like overhead. Then one comes back with direct exposure to a designated cluster, you don’t send, and nothing happens, which is the entire point, and which is invisible.

The businesses that got fined weren’t reckless. ShapeShift and Exodus were operating companies with lawyers. They just didn’t have a screening step, and strict liability doesn’t care why.

So build three things this week. Write the policy: what each severity tier triggers, who decides, and what gets logged, on one page, because yours is the only standard that applies to you. Split your wallets so the one receiving from unvetted counterparties is not the one paying your team. Then put the screen inside the payment path instead of beside it, because a check that lives in a separate tool is a check somebody skips on the urgent payment, and that is always the one that matters. VaultNow scores addresses for AML risk on both the incoming and outgoing side before a transfer goes out, with batch payouts of up to 100 recipients at $0.50 per transaction plus gas, so the screening record and the payment record are the same record eight months later when someone asks. The surrounding pieces: paying international contractors on choosing a rail, paying employees in cryptocurrency on the legality, the crypto contractor agreement on the clause that lets you refuse a risky address, cross-border crypto payments on the wider picture, and how to send USDT on the transfer itself.

General information on how these rules work, not legal or tax advice. Positions are stated as at 26 August 2026; rates, thresholds and filing dates change, and the right answer turns on facts specific to you. Check the current text of anything cited here with your own adviser before acting on it.

Read next