Join our Newsletter — 33% off our NHI Course

Crypto Monitoring

Crypto monitoring is the ongoing review of wallets, transactions, and customer activity to identify fraud, sanctions exposure, and other financial crime risk. It combines screening, scoring, and alerting so compliance teams can act before or during a transaction rather than after funds have moved.

Expanded Definition

Crypto monitoring is more than blockchain analytics. In NHI and financial crime operations, it is the continuous detection layer that watches wallets, counterparties, and transaction paths for patterns linked to sanctions exposure, fraud, money laundering, and account takeover. The term is used differently across vendors, so definitions vary across vendors, but the practical core is consistent: detect risk early enough to block, review, or escalate before value is irreversibly transferred. This aligns closely with the risk-based control philosophy in the NIST Cybersecurity Framework 2.0, especially where monitoring supports timely response.

For NHI governance, crypto monitoring becomes relevant when automated agents, exchange APIs, treasury bots, or custody services can move assets without a human in the loop. It must therefore cover identity-linked activity, not just the transaction itself, including API key use, wallet clustering, and suspicious timing patterns. The most common misapplication is treating crypto monitoring as a post-transaction reporting tool, which occurs when teams rely on delayed batch review instead of real-time screening at execution.

Examples and Use Cases

Implementing crypto monitoring rigorously often introduces friction between transaction speed and review depth, requiring organisations to weigh operational throughput against the risk of blocking legitimate activity.

  • Screening outbound transfers against sanctions lists and high-risk wallet intelligence before settlement, then holding only the transactions that trigger material risk indicators.
  • Monitoring treasury bots or exchange-integrated agents for unusual destination changes, rapid value movement, or behavior inconsistent with the approved workflow.
  • Combining wallet scoring with NHI lifecycle controls so a compromised API key can be correlated with anomalous transfers, not just treated as an isolated credential issue. See the NHI Lifecycle Management Guide.
  • Investigating counterparties that appear benign on first contact but later connect to exposed infrastructure, mixer exposure, or previously flagged addresses, consistent with the risk themes in Top 10 NHI Issues.
  • Using rule-based alerting for known bad patterns and anomaly detection for novel behavior, which is consistent with the broader monitoring and logging guidance in NIST Cybersecurity Framework 2.0.

Why It Matters in NHI Security

Crypto monitoring matters because NHI compromise often turns into asset movement before a human notices the breach. In practice, identity controls, wallet controls, and transaction controls have to work together. NHI Management Group research shows that inadequate monitoring and logging is cited by 37% of organisations as a top cause of NHI-related attacks, which is a useful reminder that visibility failures are not theoretical. The broader Ultimate Guide to NHIs also highlights how weak visibility and excessive privilege combine to make detection harder once credentials are exposed.

For security and governance teams, the main issue is not only false positives. It is the operational gap created when an organisation cannot connect a wallet event to a specific service account, API key, or automated workflow quickly enough to intervene. Crypto monitoring supports sanctions compliance, fraud detection, and incident response, but only if it is paired with identity context and alert ownership. Organisations typically encounter the full cost of crypto monitoring only after a suspicious transfer has already been initiated, at which point transaction visibility becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-08 Monitoring and detection are core to identifying anomalous NHI behavior and misuse.
NIST CSF 2.0 DE.CM Continuous monitoring maps directly to detecting cybersecurity events and anomalies.
NIST AI RMF Risk monitoring is central when AI or automated agents can move value or trigger transfers.
NIST Zero Trust (SP 800-207) SC-7 Zero Trust requires continuous verification rather than trusting a transaction source once.
OWASP Agentic AI Top 10 AGENT-05 Agentic systems need guardrails and monitoring when they can execute financial actions.

Govern agent-driven transaction monitoring with defined escalation, oversight, and review thresholds.