Traditional AML/CFT runs on intermediaries. A bank on each end of a wire exchanges originator and beneficiary information, and the Travel Rule formalizes that exchange. It's a system built around two institutions that both know who their customer is.
Crypto breaks that assumption. The "intermediary" on one end of a transfer may be nothing more than a non-custodial wallet address. On-chain transfers can bypass every traditional financial intermediary entirely, and pseudonymous addresses plus mixers, cross-chain bridges, and instant swaps make identity attribution and fund tracing far harder than in traditional banking.
The pattern is consistent: you can't rely on inter-bank compliance flows alone. A crypto payment company needs on-chain-native compliance tools — KYA, KYT, continuous monitoring, and a working Travel Rule and SAR/STR process — plus a defense against a risk that has nothing to do with your own conduct: the stablecoin issuer freezing funds at the contract level. Below we cover both, then condense the whole thing into a seven-point self-check.
Why the Traditional AML Framework Falls Short in Crypto
The core problem isn't that crypto lacks rules — it's that the rules were written for a world where every counterparty is an identifiable institution. In crypto, that's often not true.
An on-chain transfer can move funds directly between wallets with no bank, no exchange, and no compliance officer on either end. Combine that with pseudonymous addresses and tools built specifically to obscure fund flow — mixers, cross-chain bridges, instant swaps — and identity attribution and fund tracing become far harder than in the traditional banking system.
That's why a crypto payment company can't treat AML as something handled entirely by counterparties. It has to deploy compliance tools that work directly on-chain, independent of whether the other side is a licensed, cooperative institution.
KYA: Know Your Address
KYA (Know Your Address) is the foundational capability of crypto AML. It uses an address-labeling system to identify the identity and risk attributes of on-chain addresses — the equivalent of knowing who you're dealing with, but built from blockchain data instead of a KYC form.
Address labels describe an address across three dimensions:
- Entity — which entity the address belongs to (for example, Binance, Tornado Cash).
- Attributes — the address's behavioral characteristics (for example, exchange, mixer, scam, sanctioned).
- Specific label — a fine-grained marker (for example, "OFAC SDN," "linked to Lazarus Group").
Those labels come from open-source intelligence (OSINT), an internal detection engine, and ecosystem partners, and they get expanded using patterns like exchange deposit-consolidation and factory-contract creation. The result is a live map of which addresses carry elevated risk — including sanctions exposure — before you ever process a transaction with them.
KYT: Know Your Transaction
KYA tells you about an address. KYT (Know Your Transaction) tells you about a specific transaction — the capability to assess the risk of each transaction in real time.
Four functions make up a working KYT system:
- Real-time transaction monitoring — every incoming or outgoing transaction automatically triggers a risk assessment.
- Multi-hop tracing — looking beyond the direct counterparty to trace the funds' historical path, typically 3–5 hops back. (The readiness checklist further down sets a higher bar for what you should require: at least 5 hops — see item 2.)
- Risk scoring — a composite score built from address labels, path analysis, and behavioral patterns.
- Alerting and interception — high-risk transactions get automatically flagged or blocked.
If you're evaluating a KYT setup, three things matter in practice: whether it can reach a risk decision before the transaction confirms, how many chains and tokens it covers, and how often its label database updates. It's worth pinning down all three before you rely on the system.
Continuous Monitoring: Address Risk Changes Over Time
Here's the point most compliance programs miss: KYA and KYT are both judgments made at a single point in time, but an address's risk isn't static. An address that looked clean when a transaction happened may later get added to the OFAC sanctions list, get attributed to a theft, or get flagged as mixer-linked.
If that risk shift happens on an address that has ever transacted with your company, is one of your customers, or is a fund source for one of your receiving addresses, you've silently taken on that risk without knowing it — until you go looking.
So technical compliance can't be a one-time screen. It needs three ongoing pieces:
- Periodic re-screening — regularly re-scan historical counterparties, customer-declared addresses, and active receiving addresses against the latest labels and sanctions data.
- Risk-change alerts — get notified the moment a previously low-risk address gets a new high-risk label, instead of waiting for the next transaction to find out.
- Post-trigger handling — once risk is confirmed, act on a plan: freeze or suspend the related funds, trace the affected transaction paths, file a SAR if necessary, and adjust your go-forward strategy for that counterparty.
This is the same underlying discipline as monitoring stablecoin freeze risk, covered further down: keep watching funds you've already received and addresses you've already dealt with, and act the moment the risk state changes — rather than discovering it at payout time or during an audit.
The Travel Rule and Its Real-World Limits
The FATF Travel Rule requires VASPs to exchange originator and beneficiary identity information on a transfer, and many jurisdictions have legislated it. You have to comply with it — but it's worth understanding where it actually reaches, and where it doesn't.
The rule assumes both sides of a transfer are licensed institutions holding their customers' identity information. The crypto reality is that the other end of a huge share of transfers is a non-custodial wallet, and who's behind that address is often unknowable. Even if your own side fully meets its obligations, an anonymous wallet on the other end means there's simply no identity information to exchange, and the rule falls away.
Put plainly: the Travel Rule works in the closed VASP-to-VASP setting, but breaks the moment it meets an open on-chain address. (If you're mapping which license regime triggers which Travel Rule obligations in your target markets, our global crypto payment license map breaks that down by jurisdiction.)
What actually covers non-custodial wallets is KYA/KYT built on on-chain data. Address risk screening and transaction tracing don't depend on the counterparty volunteering an identity — they infer risk from on-chain behavior instead. The practical approach: exchange information as required for VASP-to-VASP transfers, and for transfers to non-custodial wallets, put the weight on the on-chain risk judgment of KYA/KYT.
Filing a SAR/STR When KYT Flags a Transaction
When your KYT system detects a suspicious transaction, you have a duty to file a suspicious activity report (SAR/STR) with the regulator. Getting there usually follows a consistent workflow:
- Define the investigation target — who you're looking at.
- Collect data using on-chain analysis tools.
- Analyze the fund flow, tracing funds through the addresses involved.
- Identify addresses, determining whether each one along the way is a key address.
- Build the evidence and the report.
- Continue monitoring the addresses involved, even after filing.
A compliance investigation is usually triggered by your internal KYA/KYT system. A criminal investigation, by contrast, is initiated by law enforcement, aiming to collect evidence, identify suspects, and trace illicit funds — a different starting point, but often the same on-chain trail.
Building that trail reliably — labeled addresses, transaction-level risk scores, and a documented investigation workflow — is what turns a suspicious-activity alert into a filing you can stand behind. For the screening layer underneath that, Phalcon Compliance brings wallet screening, KYT, and sanctions checks together in one place.
Stablecoin Freeze Risk: A Design Feature, Not an Edge Case
AML/CFT screening covers illicit activity. A separate risk sits on top of it: the stablecoin issuer itself can freeze funds at the contract level, regardless of whether you did anything wrong. Freezing by the issuer is one of the built-in design features of the centralized stablecoin system, not an occasional event, and the scale behind that statement is bigger than most finance and compliance teams assume.
As of April 2026, Tether had officially disclosed that it has supported law enforcement in freezing a cumulative total of over $4.4 billion in USDT, spanning 65 countries, more than 340 law-enforcement agencies, and over 2,300 cases — including more than 1,200 cases involving U.S. law enforcement.
BlockSec's data for the first half of 2026 shows 2,623 newly frozen addresses in just six months — 347 on Ethereum and 2,276 on Tron — for a frozen amount of $1.67 billion ($79 million on Ethereum, $1.59 billion on Tron).
Large freezes in 2026 further show how routine law-enforcement cooperation has become:
- Tether, coordinating with OFAC, froze $344 million in USDT in April 2026 — two addresses, linked to sanctioned entities or a criminal network.
- It helped Turkish authorities freeze $544 million in USDT in January 2026, targeting an illegal online-gambling and money-laundering network.
USDC, issued by Circle, is frozen on a relatively smaller scale and slower cadence, but its contract layer likewise has blacklister and pauser privileges, so the theoretical power is the same. Don't read the smaller USDC numbers as a reason to relax — the mechanism is built into the token, not into any one issuer's enforcement pace.
And a company cannot assume that "if I don't keep coins on an exchange, they can't be frozen." As long as it holds USDT or USDC, the issuer can restrict their circulation at the contract level. Continuous KYT monitoring, covered above, is one of the protections against this.
Building an Enterprise Protection System
The enterprise playbook lays out four protective measures a company can put in place before freeze risk materializes:
- Tiered wallets — manage receiving, consolidation, operations, and reserves separately, to keep risk from spreading from an edge address into the main fund pool.
- Diversified stablecoin holdings — don't concentrate critical operating liquidity in a single issuer or a single chain.
- Continuous KYT monitoring — deploy ongoing risk control at the incoming, consolidation, outgoing, and existing-holdings-review stages. You can use the free USDT Freeze & Blacklist Checker to quickly check a single address's USDT freeze and blacklist status on Ethereum/Tron.
- A freeze-event plan — define the escalation path, evidence preparation, and issuer communication channel before the risk materializes.
Responding When a Freeze Happens
If a freeze does hit, the response runs in three steps: identify the exposure in advance through Phalcon Compliance, run on-chain attribution with MetaSleuth to clarify the cause and scope once it lands, and assemble structured materials for the dialogue with the issuer.
The companies best positioned aren't the ones hoping to avoid a freeze; they're the ones with tiered wallets, diversified holdings, continuous KYT monitoring, and a plan already in place for when one happens.
The 7-Point Compliance Self-Check
If you've ever been asked "are we compliant?" and answered with "we did KYC at onboarding," you already know that's not the full question. Here is the compliance-readiness checklist from the playbook, grouped as it appears there. It's a starting point for a conversation with your compliance and security teams, not a substitute for one — treat it as a way to find the gaps, not a certificate that says you're covered.
AML/CFT technical compliance — three checks across the transaction lifecycle
- Customer onboarding. Is your KYC/KYB tied to on-chain KYA screening? Have you risk-screened every customer-declared address for mixer exposure, stolen funds, OFAC SDN listings, and interaction with sanctioned protocols?
- Transaction stage. Do you run real-time KYT on every incoming and outgoing transaction, with multi-hop tracing (at least 5 hops) to catch indirect exposure to high-risk entities? Does that coverage extend to every chain you operate on, not just your primary one?
- Emergency stage. Do you have on-chain fund-tracing capability to support SAR/STR filing and asset recovery?
None of these three checks is a one-time project. An address that looked clean during onboarding can later be added to a sanctions list or attributed to a theft — which is exactly why the transaction-stage and emergency-stage checks exist alongside onboarding, not instead of it.
Stablecoin freeze risk — two checks before it happens
- Screen and monitor continuously. Are incoming funds screened before they flow into your main pool — including a re-screen at the sweep step of the pay-in flow, where isolated funds get consolidated? Are all your wallet addresses continuously monitored for changes in freeze or blacklist status — not just checked once when a deposit lands? A single point-in-time check misses the case where a previously clean address gets flagged after the fact.
- Write down your freeze-event plan. Do you have a written freeze-event contingency plan that covers your escalation path, evidence preparation, and issuer communication channel? Freezing happens at real operational scale, so the question isn't whether it can happen to you — it's whether your team has a documented plan the moment it does, rather than improvising one during an active incident.
Continuous improvement — two checks that never finish
The last group isn't a technical control at all — it's a discipline for keeping the first five from going stale.
- Training and drills. Have all relevant staff completed onboarding security training? Are you regularly running social-engineering defense exercises, new-threat briefings, and incident-response drills — not just a one-time session at hire? Payment systems move money, which makes the people who operate them as much a part of the attack surface as the code.
- Learning from industry incidents. Are post-mortems of major industry incidents systematically absorbed into your own controls, rather than treated as news about someone else's problem? An incident at another crypto payment company is a free lesson about a control gap you may share — the checklist only pays off if that lesson actually changes something in your stack.
Where This Fits in the Bigger Picture
This seven-item checklist covers technical AML/CFT compliance, freeze-risk management, and continuous improvement — but it deliberately leaves out one entire compliance track: whether you're licensed to operate in a given jurisdiction in the first place. That's a separate question with its own regime per country, which we map out in our global crypto payment license map.
Running through all seven checks won't make you compliant by itself — compliance depends on how well each control is actually implemented and maintained, not just whether the item is checked. But it's a fast way to find out where your gaps are before an auditor, a regulator, or an incident finds them for you.
For how KYA, KYT, SAR/STR duties, and freeze-risk defense fit into a payment system's wider security and compliance program, download our crypto payment security and compliance playbook (PDF).
FAQ
What's the difference between KYA and KYT? KYA (Know Your Address) assesses the risk of the address itself, using labels for entity, attributes, and specific markers like "OFAC SDN." KYT (Know Your Transaction) assesses the risk of a specific transaction in real time, using multi-hop tracing and risk scoring.
Why doesn't the FATF Travel Rule cover transfers to non-custodial wallets? The Travel Rule assumes both sides of a transfer are licensed VASPs holding customer identity data. When the other end of a transfer is a non-custodial wallet, there's no identity information to exchange, so the rule falls away — which is why KYA/KYT on-chain risk judgment has to carry that weight instead.
Why does an address need to be re-screened after the initial transaction? Because address risk isn't static. An address that was clean at transaction time can later be added to the OFAC sanctions list, attributed to a theft, or flagged as mixer-linked — and if you've ever dealt with it, you've silently taken on that risk without knowing.
How many hops should KYT multi-hop tracing cover? Typical KYT implementations trace 3–5 hops back. The compliance-readiness checklist sets the bar at a minimum of 5 hops, to catch indirect exposure to high-risk entities that wouldn't show up if you only checked the direct counterparty.
What triggers a SAR/STR filing? A SAR/STR filing duty is triggered when your KYT system detects a suspicious transaction, kicking off an investigation workflow: define the target, collect on-chain data, trace the fund flow, identify key addresses, build the evidence, and keep monitoring afterward.
How much USDT has Tether frozen in total? As of April 2026, Tether had officially disclosed a cumulative total of over $4.4 billion in USDT frozen in coordination with law enforcement, spanning 65 countries, more than 340 agencies, and over 2,300 cases (including more than 1,200 U.S. cases).
Can USDC be frozen the same way as USDT?
Yes. USDC, issued by Circle, is frozen on a relatively smaller scale and slower cadence, but its contract layer has the same blacklister and pauser privileges, so the theoretical freeze power is the same.
Does keeping stablecoins off an exchange protect against freezing? No. A company cannot assume that keeping coins off an exchange means they can't be frozen. As long as it holds USDT or USDC, the issuer can restrict their circulation at the contract level.
Does passing this checklist mean we're fully compliant? No. It's a self-check to help you find gaps against BlockSec's compliance-readiness checklist — actual compliance depends on how well each control is implemented, documented, and maintained, and on requirements (like licensing) outside this checklist's scope.



