Sanctuary Research

Crypto wallet screening is checking a blockchain address against known entities and risk categories before you transact with it or onboard the person behind it. Venues do it because the money arrives first and the questions arrive later — a deposit that came out of a sanctioned entity or a seized marketplace becomes your problem the moment you credit it. Screening moves that discovery to before the credit, while refusing still costs nothing. Try it on any address right now in the Sanctuary bot — 3 free checks a day, an answer in about 60 seconds, no signup.
Crypto wallet screening is the check that maps a blockchain address to what is publicly known about it — which entity it belongs to, which risk categories its transaction history touches, and in which direction that exposure runs — and returns a risk level, with the attribution behind it, that a business can act on and file. It runs on the address rather than on the person. It runs before value moves rather than after. And it produces a dated record of the basis on which a transfer was accepted, refused or escalated.
That definition is narrow on purpose. Screening the money and verifying the customer are two different controls: one reads a public ledger, the other reads a passport, and a policy that quietly merges them tends to leave a hole on both sides. KYT vs KYC sets out where the line sits.
The phrase people type into a search box is wallet screening aml, and the intent is operational rather than academic: there is an address on the screen, a decision attached to it, and someone who will ask about that decision later.
Four things, read together rather than in sequence.
A risk level. A number on a 0-100 scale, grouped into five bands. Act on the band — the distance between 41 and 44 is noise, the distance between 41 and 84 is your decision.
| Score | Level | What it means for the decision |
|---|---|---|
| 0-9 | Clean | Nothing found against the address or its counterparties. Proceed. |
| 10-33 | Low | Weak or distant signals only. Proceed and file the result. |
| 34-66 | Medium | Something real surfaced that the check cannot resolve on its own. Ask before you move. |
| 67-89 | High | Direct or close links to named criminal activity. Hold and request an explanation. |
| 90-100 | Critical | Sanctions exposure or confirmed criminal attribution. Do not complete the transaction. |
Medium is the band that gets misread: it does not mean probably fine, it means the check surfaced something it cannot settle alone. What a crypto risk score means walks the scale band by band.
Named-entity attribution. The field that changes decisions most often. An address that resolves to a deposit address at a named exchange is a person with an account, a customer file behind it and a venue that answers lawful requests. An address that resolves to nothing is silence — not clean, not dirty, just unattributed, which is the ordinary state of most addresses on any chain. Two addresses with the same level and different attribution are two different decisions.
Risk categories. Sanctions, scam, stolen funds, mixer, darknet. The category, not the number, sets the response. Sanctions is a legal exposure rather than a matter of appetite, and it does not fade with time. Stolen funds means somebody is already looking for that coin, often with a case number attached. A mixer in the history is a question; a darknet cluster one hop away rarely is.
Exposure direction. Incoming and outgoing are separate readings. On a deposit you care about what reached the address and where it came from. On a payout you care about where your money is going: a destination that forwards straight into a sanctioned entity turns your transfer into a line in someone else's case file. The same address can be quiet on one side and loud on the other.
What a result does not contain is the machinery underneath it. We publish what a check shows; the weighting stays unpublished, here and at every serious vendor, for the same plain reason a bank does not publish its fraud rules.
The mechanics of crypto wallet screening are dull, and that is the point — a control you can run under pressure is a control that actually gets run.
Screening is not an event, it is a set of triggers. Each screens a different address and drives a different decision, and writing them down in this shape is most of what a screening policy is.
| Trigger | What you screen | What the result drives |
|---|---|---|
| Incoming deposit | the sending address and the history behind it | credit, hold pending source of funds, or freeze |
| Withdrawal or payout | the destination address | release the transfer or block it before it signs |
| Customer onboarding | the wallets the customer declares, plus the first deposit | accept, accept with limits, or decline |
| OTC quote or P2P trade | the counterparty's settlement address | quote the deal or walk away |
| Scheduled monitoring | saved addresses that were cleared earlier | alert, review, offboard |
| Case or file review | historic addresses attached to an old decision | reopen the case or close it with evidence attached |
Two of these get skipped in practice. Payout screening is the one firms discover late, usually when a withdrawal lands somewhere that makes the transfer their problem. Scheduled monitoring is the other: an address cleared in January is a statement about January. Onboarding is where the wallet check meets customer due diligence — related controls, different evidence, and neither substitutes for the other.
Blockchain address screening is not one check repeated ten times. The formats differ — bech32 on Bitcoin, 0x on account chains, a T prefix on TRON — and a checker that accepts anything shaped like a string will happily screen a typo. The history underneath differs more. On UTXO chains an address is one window onto a wallet that may hold thousands of them, so the check has to read the cluster around it. On account chains the address is the account, and the token contract that moved is what matters: USDT on TRON and USDT on Ethereum are the same brand and two different screening problems.
Depth differs by chain, which is why coverage claims are worth reading closely. Ours: 14,488,795 entity labels across 10 chains with full AML coverage, as of August 2026. Those are label rows rather than distinct addresses — one address can carry several labels, and a label can describe an entity rather than a single wallet.
The chain-specific mechanics are worth knowing before you screen at volume: checking a Bitcoin address covers clustering and change addresses, and checking a USDT TRC-20 address covers the contract question and the trap of screening the wrong network.
The same data sits behind all three. The difference is who is holding the address and what they have to do next.
Telegram bot — one address, right now. Open @sanctuaryapp_bot, press the check button, paste the address. The verdict comes back in about 60 seconds with the attribution and categories behind it: 3 free checks a day, no signup, nothing to install. This is the surface for a trader before a P2P transfer, or an officer sanity-checking one address on a Sunday. Start in the bot.
Web panel — for a team that has to show its work. Checks land in a shared history with timestamps, export as PDF reports for a case file, run in bulk across a counterparty list, and stay under monitoring, so a saved address that picks up a new label reaches you without a manual re-run. Plans start at $199 a month. See plans.
API — screening inside your own flow. Deposits and withdrawals screened at the moment they happen, with the decision written into your own system instead of a browser tab. This is how an exchange, a payment processor or an iGaming platform screens at volume. Read the API docs.
Screening manages risk. It does not remove it, and a tool sold as though it does is being sold dishonestly.
If you are about to send or accept a transfer, screen the address first. Paste it into the Sanctuary bot, read the level and the attribution behind it, keep the result: 3 free checks a day, about 60 seconds, no signup.
If screening is part of somebody's job at your company — deposits to clear, payouts to release, an audit trail someone will read back to you — put the team on a plan. History, PDF reports, bulk checks and monitoring start at $199 a month on the pricing page, and the API puts the same check inside your deposit flow. The check that costs a minute today is the case file you do not have to open next quarter.
It is checking a blockchain address against known entities and risk categories — sanctions, scam, stolen funds, mixer, darknet — before you transact with it. The result gives a risk level on a 0-100 scale, the entity the address is attributed to, and the direction of the exposure, so a business can accept, refuse or escalate a transfer and keep a dated record of why.
For regulated venues, yes. Transaction monitoring comes with the licence: an exchange, payment processor or OTC desk has to know where incoming funds came from and be able to show the basis on which each deposit was accepted or refused. Screening is what makes that basis writable — a level, an attribution and a timestamp attached to a specific transaction.
About 60 seconds for a single address in the Telegram bot: paste it, read the level and the attribution behind it. Through the API the check runs inside your deposit or withdrawal flow, so the decision arrives with the transaction rather than after it. Bulk checks in the web panel run a whole counterparty list in one pass.
It means nothing has been reported against that address or its counterparties across the data checked, at the moment the check ran. That is a point-in-time verdict, not a permanent state: addresses get designated and marketplaces get seized after the fact, so coin that looked quiet in March can read differently in September. Re-screen on new activity and monitor addresses you use repeatedly.