Sanctuary Research

KYC tells you who your customer is. KYT tells you what their money has touched. That is the whole of kyt vs kyc in one line: identity verification runs once at the door, transaction screening runs on every payment that walks through it — and no passport scan has ever flagged a deposit that came out of a sanctioned wallet. See what KYT returns on any address in the Sanctuary bot — three free checks a day, about sixty seconds.
KYC — know your customer — is identity verification. You collect a document, a selfie, an address and a date of birth, run the name against sanctions and PEP lists, decide whether this person may hold an account, and file the evidence you relied on. It runs at onboarding and refreshes periodically, and it answers one question: is this person who they say they are, and are they someone we are allowed to serve?
KYT — know your transaction — is money verification. The know your transaction meaning is literal: you stop screening the customer and start screening the movement. Every deposit address, every withdrawal destination, every counterparty is checked against what is known about that address and what it has transacted with — sanctioned entities, darknet markets, ransomware wallets, scam clusters, mixers, exchangers with fraud records. It runs on every transaction rather than once at signup, and it answers a different question: where has this money been, and do we want it on our books?
So what is kyt in crypto, said plainly: KYC screens the person, KYT screens the money. The two controls never read the same data, and neither one covers for the other.
The difference between KYC and KYT holds in six dimensions. If you read nothing else on this page, read the table.
| Dimension | KYC | KYT |
|---|---|---|
| What it verifies | The person or company behind the account | The address and the funds moving through it |
| When it runs | Once at onboarding, then on periodic refresh | On every deposit, withdrawal and counterparty, as it happens |
| What data it reads | Documents, selfies, company filings, sanctions and PEP name lists | Blockchain history, address labels, counterparty attribution, sanctions listings on wallets |
| What it catches | False identities, an undisclosed beneficial owner, a name on a sanctions list | Funds from scams, stolen coin, darknet withdrawals, mixers, wallets tied to sanctioned entities |
| What regulators expect it for | Customer due diligence and record-keeping at account opening | Ongoing transaction monitoring and detection of suspicious activity |
| What happens when it trips | Application refused, account restricted, customer offboarded | Deposit held, withdrawal blocked, source-of-funds request, internal report filed |
Row two is where programs fail. A customer who cleared KYC in March is still cleared in September, and the deposit they send in September is a fact the identity file was never built to see. KYC is a snapshot of a person. KYT is a live read on money that keeps moving long after the snapshot was taken.
A KYC file contains what the customer declared and what a document bureau confirmed. It contains nothing whatsoever about the blockchain. As of August 2026 our label set holds 14,488,795 entity labels — the attribution surface a KYC file returns none of — drawn from 20+ intelligence sources across 10 chains at full AML depth.
Run an address through transaction screening and what comes back is:
Here is the case that makes the argument concrete. A customer clears KYC with a valid passport, a clean name check and a real residential address. Six weeks later they deposit USDT that left a scam cluster two hops earlier. Nothing about the customer changed, nothing in the file is out of date, and the identity control has no mechanism to notice — because the problem is not the person, it is the coin. That deposit is either caught at the transaction layer or it is not caught at all. What wallet screening covers walks through what a full address check reads.
One boundary worth stating plainly: we publish what a check shows, not how the level is assembled. That is standard at every serious vendor, for an obvious reason — a published formula is a map for the people the lists exist to catch. What you should demand from any tool is the evidence: which source named the address, as what, and how close the link is. A number with no reason attached is not usable in an argument with a customer and not defensible in a conversation with an auditor. How to read a risk level covers what the bands mean for a decision.
Framing kyt vs kyc as a choice is the mistake. Both controls exist because each one is blind exactly where the other sees.
KYC without KYT is a filing cabinet. You know precisely who your customers are, in fine detail, and nothing at all about what they are moving. KYT without KYC is the mirror failure: you see a deposit sitting one hop from a ransomware wallet and have no person to attach it to — no account to restrict, no file to report, nobody to ask. Each control is what makes the other actionable.
In a working program they sit at different points in the flow:
What the rules require varies by jurisdiction, but the shape is the same everywhere: verify the customer once, then keep watching the money. Transaction monitoring is treated as a standing obligation rather than a box ticked at signup, which is why a strong KYC programme is never an answer to the question of how you monitor transactions.
Most small venues run KYC and skip KYT for one reason, and it is not disagreement with the argument. It is that transaction screening has traditionally been sold as an annual enterprise contract with a procurement cycle attached. KYT crypto compliance does not have to start there, and it does not have to start with an integration.
Three ways in, in the order venues usually take them:
All three run on the same data: the same labels, the same bands, 10 chains at full AML depth. If you want to see what a single check reads before you commit to anything, checking a Bitcoin address for AML walks through one from the address going in to the verdict coming out.
Do not take anyone's word for what transaction screening returns, ours included — run one. Paste an address you are about to credit into the Sanctuary bot and read what comes back: three free checks a day, a verdict in about sixty seconds, sources attached. If it changes a single decision, put it on every deposit — that is what the API is for, and plans start at $199 a month. That is where kyt vs kyc lands in practice: KYC gets you the customer, KYT keeps the customer's money from becoming your problem.
Know your transaction. Where KYC verifies the customer at onboarding, KYT screens the transactions that customer sends and receives — the deposit address, the withdrawal destination, the counterparty — against what is known about those addresses on-chain. It runs continuously rather than once, and it catches problems that surface long after an identity file was signed off.
In substance, yes. Regulators expect licensed crypto businesses to monitor transactions on an ongoing basis, not only to identify customers at signup — and on a public ledger, monitoring means screening addresses. Unlicensed venues meet the same pressure commercially: banks, exchanges and payment partners downstream will ask what you screen before they take your flow.
No, and the reverse is equally false. KYT tells you a deposit sits one hop from a ransomware wallet, but without KYC there is no person to attach that to, no account to restrict and no file to report. KYC tells you who the customer is, but without KYT you never learn what they are moving. The two answer different questions.
It can start at nothing. The Sanctuary Telegram bot gives three free checks a day with a verdict in about sixty seconds, which is enough to screen incoming addresses by hand at a small desk. A team panel with bulk screening, PDF reports and monitoring starts at $199 a month, and the API puts the same check inside your deposit flow.