Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should crypto firms screen wallets and transactions…
Governance, Ownership & Risk

How should crypto firms screen wallets and transactions to reduce fraud and money laundering risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Crypto firms should combine wallet screening, transaction monitoring, and risk-based investigation in one workflow. The goal is to identify high-risk wallets, trace transaction patterns, and escalate suspicious activity quickly enough to support compliance and fraud response. A unified view helps teams avoid fragmented reviews, reduce manual handoffs, and keep controls aligned with travel rule and AML requirements.

Why This Matters for Security Teams

crypto fraud and money laundering reviews fail when wallet screening is treated as a one-time identity check instead of a continuously changing risk decision. A wallet can be clean at onboarding, then receive tainted funds, interact with sanctioned exposure, or pivot through layered hops minutes later. That is why risk-based monitoring needs to sit alongside customer due diligence and transaction review, not after them. Guidance from FATF Recommendations and control mapping in NIST Cybersecurity Framework 2.0 both support an ongoing, risk-based approach.

For NHI Management Group, the key issue is visibility across the full transaction path: wallet origin, counterparty exposure, velocity, clustering, and links to known illicit infrastructure. That same visibility gap shows up in broader identity operations too, where Ultimate Guide to NHIs — Key Challenges and Risks notes that only 5.7% of organisations have full visibility into service accounts, and the pattern is similar here when firms cannot see the full chain of custody for funds. Teams often over-rely on static labels and miss how quickly exposure changes after first contact with a risky address. In practice, many security teams encounter laundering patterns only after funds have already been fragmented across multiple hops, rather than through intentional pre-transaction prevention.

How It Works in Practice

Effective screening combines three checks in one workflow: wallet screening before acceptance, transaction monitoring during movement, and case investigation after an alert. The first step is to score the wallet and its counterparties against sanctions, darknet, mixer, scam, theft, and fraud typologies. The second step is to inspect transaction behaviour for structuring, rapid peeling, chain hopping, bridge usage, and unusual velocity. The third step is to document why an alert was opened, whether funds were frozen, and what remediation or reporting followed. This is aligned with Top 10 NHI Issues, which emphasises that visibility and lifecycle control are only useful when they drive action.

  • Use risk scoring at onboarding and update it each time the wallet touches a new high-risk cluster.
  • Apply rules for sanctions, fraud typologies, travel rule thresholds, and pattern-based anomaly detection.
  • Link alerts to case management so investigators can see graph history, not just the latest transaction.
  • Separate low-risk retail flow from higher-risk cases, but keep the same evidence standard for escalation.

Practitioners should also treat data quality as a control. False positives rise when source data is stale, labels are poorly maintained, or entity resolution is weak across exchanges, custodians, and self-hosted wallets. Current guidance suggests the best programs combine deterministic rules with behavioural analytics, then add human review for ambiguous cases. The control objective is not to block every suspicious wallet immediately, but to make it difficult for bad actors to move value unnoticed. These controls tend to break down when firms cannot resolve ownership across nested wallet structures because attribution becomes too uncertain for confident escalation.

Common Variations and Edge Cases

Tighter screening often increases operational friction, requiring organisations to balance faster customer access against more conservative fraud controls. That tradeoff is most visible when a firm supports both retail trading and institutional settlement, because the acceptable false-positive rate is rarely the same across segments. For that reason, current guidance suggests different thresholds for onboarding, ongoing monitoring, and enhanced due diligence, rather than one universal rule set for every wallet type.

Edge cases usually appear in cross-chain bridges, privacy-enhancing tools, and self-custody wallets. A wallet may look clean on one chain while its funds are already linked to a compromised cluster on another. Similarly, high-activity market makers can resemble layering behaviour unless the firm understands expected volume and counterparties. The Ultimate Guide to NHIs — Why NHI Security Matters Now makes the broader point that privileged assets become dangerous when they remain valid longer than expected, and the same logic applies to wallets and transaction permissions. There is no universal standard for this yet, so firms should document risk thresholds, escalation triggers, and review exceptions in policy-as-code where possible. That approach makes audit trails clearer and helps explain why one wallet is approved while another is frozen.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Wallets and keys need continuous visibility and inventory, not one-time checks.
CSA MAESTROGOV-2Agentic governance maps to risk-based review and escalation workflows.
NIST AI RMFAI risk management supports continuous monitoring and human oversight of fraud models.
NIST CSF 2.0DE.CM-1Continuous monitoring is central to detecting suspicious wallet and transaction patterns.
NIST SP 800-63IAL2Identity assurance matters when linking wallets to customers and beneficial owners.

Maintain an always-current inventory of wallets, keys, and counterparties with automated risk reclassification.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org