Back to Blog

What Is Illicit Crypto and How Is It Flagged: A Compliance Primer

Phalcon Compliance
July 27, 2026
6 min read

A deposit lands from a wallet that touched a mixer two hops upstream. The customer passed identity checks at onboarding. The question is not who the customer is, but what the money carries. Illicit crypto is cryptocurrency tied to criminal activity or held by sanctioned and high-risk entities. Knowing how it is flagged is the difference between catching contaminated funds and pooling them with clean assets.

What Is Illicit Crypto: Definition and Two Categories

Illicit crypto is cryptocurrency tied to crime or held by sanctioned and high-risk entities. It splits into two categories: proceeds or tools of crime, and funds linked to sanctioned or high-risk actors. A clean identity at onboarding does not make the funds clean.

Infographic defining illicit crypto categories
Infographic defining illicit crypto categories

Category one is crime-related. These are proceeds of crime or the tools used to commit it. The funds connect to scams, hacker attacks, ransomware, mixing services, darknet markets, terrorist financing, human trafficking, drug trafficking, money laundering, and child abuse material. Each is a distinct criminal typology, but all share one trait. The asset itself is contaminated at the source.

Category two is sanctioned and high-risk entities. These are addresses on OFAC or other sanctions lists, or tied to FATF high-risk and grey-list jurisdictions. The transaction may look ordinary, but the holder carries a compliance status that turns any interaction into a risk event. A transfer from a sanctioned address is illicit regardless of its size.

Phalcon Compliance maps these two categories to seventeen risk indicators. The crime-related set includes Sanctioned, Attack, Scam, Ransomware, Child Abuse Material, Laundering, Mixing, Dark Market, Darkweb Business, Terrorist Financing, Human Trafficking, and Drug Trafficking. The high-risk entity set includes Blocked, Gambling, No KYC Exchange, FATF Grey List Jurisdiction, and FATF High Risk Jurisdiction. This two-category frame is the cognitive entry point. For the government assessment of illicit finance in crypto, see the U.S. Treasury's illicit finance risk assessment of decentralized finance.

How Illicit Crypto Is Flagged: Labels, Linkage, and Behavior

Flagging illicit crypto is not one signal. It is three layers stacked. A compliance system reads who the address is, who it interacts with, and how the money moves.

Phalcon Compliance flags illicit crypto risk signals
Phalcon Compliance flags illicit crypto risk signals

The first layer is the address label. The system checks whether the address itself carries an illicit risk indicator such as Sanctioned, Mixing, Scam, Ransomware, Dark Market, or Laundering. System Tags like sanctioned and mixer are immutable. They come from a verified address database maintained by Phalcon Compliance, not from user input, so a counterparty cannot relabel a sanctioned wallet away from risk.

The second layer is linkage interaction. The system traces fund flow across multiple hops and asks whether the address connects, directly or indirectly, to a known risk entity. A deposit that looks clean at the target wallet may carry funds that passed through a mixer three hops upstream. Exposure Value quantifies the total dollar amount sourced from risk origins. Exposure Percentage quantifies the share of contaminated assets against total inflow or outflow. An address that directly interacts with a blacklisted address is auto-flagged for immediate review under the default Risk Engine configuration. The specific risk level assigned depends on the organization's compliance policy—Phalcon Compliance offers six configurable tiers from Critical down to No Risk.

The third layer is behavioral pattern. The system reads how the money moves. Large-value transfers above typical thresholds, high-frequency small payments that stay under alert limits, and rapid transit through intermediary addresses all signal layering. These patterns catch funds that carry no address label but still move like illicit money.

The two-category frame breaks into a seven-type operational classification in the deeper read. Phalcon Compliance runs all three layers through its risk engines. The Exposure Risk Engine applies Entity Risk, Interaction Risk, and Blacklist Interaction rules across the seventeen indicators. The Behavioral Risk Engine flags Large-Value Transfers, High-Frequency Transfers, and Transit Address patterns. Each screened target lands in one of six risk levels, from Critical down to No Risk. The full seven-type classification and detection methods are covered in the illicit crypto address detection deep read.

Why Platforms Must Flag Illicit Crypto: Regulation and Risk

Under the FATF risk-based approach, a platform must identify illicit funds, apply risk-based disposition, and keep auditable records. Failing to flag illicit crypto is a compliance failure, not a missed optimization. The obligation runs continuously, because an address clean today can be sanctioned tomorrow.

Continuous monitoring workflow for illicit crypto detection
Continuous monitoring workflow for illicit crypto detection

Regulation sets the floor. The FATF risk-based approach requires virtual asset service providers to identify and disrupt illicit flows. OFAC sanctions lists make any transfer involving a listed address a prohibited transaction. A platform that processes sanctioned funds without flagging them has failed its compliance duty, regardless of intent.

Risk contagion is the operational reason. Illicit funds that enter a main asset pool do not stay quarantined. They raise the Exposure Percentage of the entire batch. They trigger cascading alerts on outbound transfers and counterparty screens. One contaminated deposit can taint balances that were clean minutes earlier. The damage spreads faster than a manual review can contain.

Phalcon Compliance's Monitor module addresses the continuous obligation. It re-runs risk analysis on a dynamic schedule, without manual re-screening. Four event types fire alerts when risk changes. Risk Level Increased and Risk Level Decreased track overall shifts. Alert Triggered and Alert Expired track individual rule hits. An address cleared on Monday can be linked to a sanctions designation by Thursday, and the team is notified the moment the risk state flips.

This is why flagging is not a one-time gate. It is a continuous read on the risk state of every address a platform touches.

Take Illicit Crypto Detection From Awareness to Action

Awareness is the entry point, not the destination. Once a compliance team can name what illicit crypto is and how the three layers flag it, the next step is operational depth. The full seven-type classification, the detection methods, and label freshness live in the illicit crypto address detection deep read. The complete framework across nine chains and seventeen indicators lives on the AML compliance for crypto hub. That is where KYA and KYT move from definition to deployment.

→ Book a Phalcon Compliance demo and flag illicit crypto across your wallet exposure: Book a demo

Frequently Asked Questions

What is illicit crypto?

Illicit crypto is cryptocurrency tied to crime or held by sanctioned and high-risk entities. The two categories are crime-related proceeds or tools, and funds linked to sanctioned or high-risk actors.

How is illicit crypto flagged?

Through three layers: address labels, linkage interaction, and behavioral pattern. Address labels check whether the wallet carries a risk indicator. Linkage traces multi-hop fund flow to known risk entities. Behavior reads how the money moves for layering signals.

What are the two categories of illicit crypto?

Category one is crime-related: scams, attacks, ransomware, mixing, darknet markets, terrorist financing, human trafficking, drug trafficking, laundering, and child abuse material. Category two is sanctioned and high-risk entities: sanctions list addresses and FATF high-risk or grey-list jurisdictions.

Does a clean identity check at onboarding make the funds clean?

No. Identity verification confirms who the customer is. It does not see what the transaction carries. Funds can be clean at the source of identity and contaminated at the source of money.

Why must flagging be continuous?

Risk state changes over time. An address cleared today can be linked to a sanctions designation tomorrow. Continuous monitoring re-runs risk analysis on a dynamic schedule and alerts the team when the risk level changes.

Start Real-Time AML with Phalcon Compliance

Turn Phalcon Network alerts into actions with Phalcon Compliance. Use verified blockchain intelligence to screen wallets, monitor transactions and investigate risks. This helps you respond quickly and stay compliant in the digital assets ecosystem.

Phalcon Compliance