Crypto AML Address Screening: Where to Deploy Screening Across the Transaction Lifecycle

AMLComplianceAddress Screening
July 27, 2026
4 min read

Crypto AML address screening checks a blockchain address against risk intelligence before a transaction clears. For VASPs, exchanges, and payment processors, the hard question is not what screening does but where to run it. A program that screens once at onboarding leaves most of the transaction lifecycle uncovered. This page is part of the AML Compliance Hub and focuses on the deployment framework: how to filter illicit funds at the source, at each control point, and after the fact. It does not cover how risk scores are calculated or how addresses are classified; those belong to their own dedicated pages.

AML Address Screening, What It Catches and Why

Address screening targets illicit crypto at its source: phishing drainers, pig-butchering scam clusters, hacker-controlled wallets, and sanctioned entities. These are the fund categories that trigger Suspicious Transaction Report (STR) obligations. They live on-chain, in the wallet's history rather than the customer's paperwork. That is exactly the gap between identity verification and address-level screening that the Know Your Address (KYA) page unpacks in full.

FATF's 2025 targeted update on virtual assets sets the baseline: VASPs must apply a risk-based approach across the full transaction lifecycle, not only at account opening (FATF Recommendations). That is the regulatory reason a single onboarding gate is insufficient, and the operational reason address screening has to be positioned at multiple points. This is one control layer within a full crypto AML compliance program.

Stablecoins now carry the majority of illicit on-chain transaction volume, so any platform with meaningful stablecoin flow will encounter tainted addresses. The only open question is whether the architecture catches them before or after funds clear.

The Four AML Control Points for Address Screening

Effective screening is deployed at four distinct moments in the transaction lifecycle. This four-point framework is the deployment standard BlockSec documents for enterprise stablecoin risk management. For the concept of address-level risk itself, see What Is KYA (Know Your Address).

Infographic showing AML address screening control points
  • Pre-deposit: screen the source address before crediting an incoming transfer. This is the most critical gate: it stops contaminated funds from ever entering custody. The Tornado Cash case, in which MetaSleuth traced roughly 7,400 ETH of illicit flow back out through exchange deposits, shows the cost of skipping it (full breakdown on the Money Laundering Examples page); pre-deposit screening at the receiving venues would have caught those addresses at the gate.

  • Pre-sweep: re-screen source addresses before consolidating wallets into treasury. Risk status changes between deposit and sweep; a counterparty flagged after the deposit cleared would otherwise merge into the treasury unnoticed.

  • Pre-withdrawal: screen the destination before releasing any outbound transfer. Sending to a sanctioned address is a violation regardless of intent, so this is the last point to intervene before the platform becomes the transmitting party.

  • Portfolio review: periodically re-screen the existing address inventory against current intelligence, surfacing addresses whose status changed after onboarding.

Because these points interlock, each catches what the previous one cannot. (For the risk-scoring thresholds behind a screening decision, see the Address Risk Scoring page; this page stays on deployment.)

Real-Time Screening vs Batch Review, Trade-offs for Compliance Teams

The first three control points are time-sensitive; portfolio review is not. That difference decides the screening mode.

Phalcon Compliance address screening lifecycle interface

The LI.FI incident shows why speed matters: stolen funds were moved within roughly 2 hours across a 20-hop path before portions reached a mixer (full breakdown on the Money Laundering Examples page). A daily batch scan is blind to that. Only a real-time check, fired before the first outbound transfer, could have intervened in time. Regulatory guidance such as FinCEN's suspicious-activity rules presumes controls proportionate to that speed of movement.

Screening mode Latency Best-fit control points Failure mode if used alone
Real-time API (synchronous) <200 ms, blocks settlement Pre-deposit, pre-sweep, pre-withdrawal None (this is the correct mode for time-sensitive points)
Real-time API (asynchronous) <200 ms, flags post-settlement Documented low-risk transaction types Brief live window before the hold triggers
Scheduled batch Per cycle (hourly–daily) Portfolio review Newly flagged addresses sit undetected until the next run

Batch-only architectures cannot satisfy the timing of pre-deposit and pre-withdrawal screening; real-time-only architectures miss the retrospective status changes that portfolio review is built to catch.

How Phalcon Compliance AML Screening Performs at VASP Scale

Crypto AML address screening deployment workflow

A deployment framework is only usable if it runs at production throughput. Phalcon Compliance processes screening at 500+ transactions per second with millisecond-level response, which is fast enough to screen every transaction without delays.

The operational payoff shows up in deployment results. Interlace, a licensed crypto payment processor, reported a 99.9% high-risk withdrawal interception rate and zero security incidents after wiring screening into these control points. This is a brief illustration here; the full cost-and-ROI breakdown lives on the AML Check for Crypto page.

Start AML Address Screening with Phalcon Compliance

Address screening stops illicit funds only when it runs at every control point where they move. Map your deposit, sweep, withdrawal, and review flows to the four points above, then wire real-time screening into the three time-sensitive gates.

Frequently Asked Questions

Upgrade Your Crypto Compliance Architecture

Transition from traditional identity verification to proactive address-based risk management; master the core strategies and technologies for crypto AML.