How crypto sanctions compliance screening works across both layers: customer and entity screening, on-chain address and exposure screening, and the best providers for exchanges in 2026.

Last updated: 31 August 2026
Sanctions compliance has quietly become one of the highest-stakes obligations any crypto business can face. A single transaction with a sanctioned wallet can trigger regulatory penalties, frozen banking relationships, and reputational damage that outlasts any fine. That is why choosing the right sanctions screening software is now a board-level decision for exchanges, VASPs, and any platform that touches customer funds.
One thing to settle before comparing vendors: crypto sanctions compliance screening happens in two distinct layers, and most teams need both.
This guide is an educational overview, not legal advice. Always confirm your obligations with qualified compliance counsel in your jurisdiction.
Sanctions are legal restrictions that prohibit dealing with specific individuals, entities, countries, or, increasingly, specific blockchain addresses. In the United States, the Office of Foreign Assets Control (OFAC) maintains the Specially Designated Nationals (SDN) list, which since 2018 has included cryptocurrency wallet addresses. The European Union maintains its own consolidated list, and the UK and UN publish theirs.
Crucially, sanctions enforcement is generally strict liability: you can be held responsible for a prohibited transaction even if you did not intend to break the rules and did not know your counterparty was sanctioned.
For a crypto exchange the exposure is constant. Deposits arrive from wallets you did not create, withdrawals leave to addresses you cannot vet by name, and mixers, bridges and privacy tools obscure where value originated. Regulators from FinCEN and OFAC to national competent authorities under MiCA increasingly expect VASPs to demonstrate that they screen both customers and on-chain activity in real time. OFAC has issued multimillion-dollar settlements against crypto businesses that failed to implement adequate controls.
Traditional name-based screening, matching a customer's name and date of birth against a list, is only half the picture in crypto. The other half is on-chain analysis. A complete screening program combines five techniques.
The first control, and the one that runs before any money moves. When a user or a corporate client onboards, their identity is checked against sanctions lists, politically exposed person (PEP) lists, law-enforcement watchlists and adverse media. For business customers this is the same check applied to the company, its directors and its ultimate beneficial owners.
This is where an entity screening tool differs from a blockchain analytics tool: it answers "who is this counterparty" rather than "where did these coins come from." A crypto business needs both answers, and neither substitutes for the other. Because designations and media change constantly, the meaningful feature here is ongoing re-screening of your existing customer base, not just a one-off check at signup.
The most direct on-chain check: is this specific wallet address on a sanctions list, a law-enforcement blocklist, or otherwise flagged? Because OFAC and other bodies now publish designated addresses, a good tool checks every deposit and withdrawal address before funds move.
Most sanctioned funds never touch you directly. They arrive after passing through several hops, exchanges or mixers. Blockchain analytics traces the flow of funds to measure a wallet's indirect exposure to sanctioned entities, darknet markets, ransomware operators or high-risk services. Instead of a simple yes/no you get a risk score and an entity attribution: "these funds are two hops from a sanctioned exchange."
Screening cannot be a one-time event at onboarding. Wallets that were clean yesterday can receive tainted funds tomorrow, and new addresses are added to sanctions lists continuously. Real-time monitoring re-evaluates activity as it happens and alerts your compliance team the moment risk crosses a threshold, so you can freeze, review or file a report.
This is the single biggest differentiator between tools. A platform that refreshes its lists daily and screens in batch will, by definition, let some designated addresses through for hours. Ask any vendor two specific questions: how quickly does a newly designated OFAC address appear in your product, and is screening evaluated at transaction time or on a schedule?
When an alert fires, someone has to decide what to do. The best platforms include visual investigation tools, graphs of fund flows, entity labels and evidence trails, plus case management so analysts can document decisions and produce an audit trail for regulators.
| Criterion | What good looks like |
|---|---|
| Both layers covered | Customer/entity screening AND on-chain address screening, from one vendor or two |
| Blockchain coverage | Every chain your users touch, not just Bitcoin and Ethereum |
| Screening latency | Evaluated at transaction time, not in a nightly batch |
| List depth | OFAC SDN, EU consolidated, UN and UK, plus PEP and adverse media, updated within hours of designation |
| Ongoing re-screening | Existing customers re-checked as lists change, not just screened once at onboarding |
| Entity attribution | Deep, maintained intelligence so alerts are actionable and false positives are rare |
| Investigations | Graph tracing plus case management, not just a risk score |
| Integration | API that slots into onboarding and withdrawal flows |
| Audit trail | Logs of who screened what, when, and what they decided |
Sanctions screening also works best alongside strong identity controls and ongoing monitoring. Our guides to crypto KYC providers, KYB software and AML compliance for VASPs cover the surrounding program.
Partly, and it is worth being precise about where free stops working.
The sanctions lists themselves are public. OFAC publishes the SDN list, including designated crypto addresses, at no cost, and the EU consolidated list is freely downloadable. Several block explorers and open tools will tell you whether a single address appears on a published list. For a one-off check on one wallet, that is genuinely sufficient.
What free tools do not give you is everything that makes screening a compliance control rather than a lookup: indirect exposure through intermediate hops, real-time evaluation at production volume, entity attribution, ongoing re-screening as lists change, and an audit trail a regulator will accept.
We cover the free options and their limits in detail in free crypto sanctions screening: what it covers and where it fails. The short version: free list checks are a reasonable starting point for an individual or a very early-stage project, and are not a substitute for a screening program at any business holding customer funds.
The platforms below handle the on-chain layer: address screening, exposure scoring and investigation. The customer-screening layer is covered separately after them, because it is a different product category rather than a competing option.
Crystal Intelligence is our top recommendation for crypto businesses that need serious, defensible sanctions screening. It is a blockchain analytics and compliance platform built for banks, exchanges, VASPs and law enforcement, and its suite maps cleanly onto the workflow above:
Best for: exchanges and VASPs wanting broad multi-chain coverage, combined real-time monitoring and sanctions screening, and mature investigation tooling in one platform. Trade-off: a full analytics-plus-compliance suite is a bigger commitment than a lightweight list-check API, so smaller teams should scope which modules they need. Explore it at crystalintelligence.com.
Best for: large enterprises and public-sector teams that want a widely adopted brand and an extensive investigation ecosystem. Trade-off: premium pricing and a breadth of tooling that can exceed what a mid-size exchange needs. Chainalysis
Best for: firms wanting strong wallet and transaction screening with a research-driven approach to entity intelligence. Trade-off: coverage and labelling depth vary by chain, so validate support for the networks your users actually transact on. Elliptic
Best for: teams prioritising real-time monitoring and a modern API-first integration experience. Trade-off: as with any provider, alert value depends on entity-attribution quality, so run a proof-of-concept against your own transaction data first. TRM Labs
Whichever you shortlist, insist on a trial against your real deposit and withdrawal traffic. Screening quality is measured not by feature lists but by how few false positives it generates and how quickly it surfaces genuine risk.
None of the platforms above screen your customers — they screen the chain. If you need that half of the programme, iDenfy's AML screening is a viable option and a common pairing, particularly for teams that already run identity verification and want screening to fire automatically once KYC completes.
It screens against sanctions lists (UN and EU consolidated, World Bank, OICV-IOSCO), PEP lists covering four levels including relatives and close associates, law-enforcement watchlists, and adverse media indexed from over 20 million news sources. Ongoing daily screening re-checks your existing customer base and notifies you on a new hit, and it covers businesses as well as individuals, so the same tool serves a KYB process. Integration is by API with webhooks, or a dashboard for manual checks.
Worth knowing: this is identity-based screening. It does not analyse blockchain addresses or trace on-chain fund flows, so it complements rather than replaces an analytics provider. Details at idenfy.com/aml-screening.
If you are scoping this for the first time, the practical shape is:
Steps 1 and 2 come from the customer layer, steps 3 and 4 from the on-chain layer. A programme missing either half has a gap a regulator can point at.
JewelSwap is a non-custodial DeFi protocol operating on MultiversX, Sui and Radix. Because it does not custody user funds, users interact directly with smart contracts for NFT lending, liquid staking, yield farming and money markets, its risk profile differs from a centralized exchange. There is no central book of customer accounts a sanctioned party could deposit into and withdraw from.
The wider ecosystem JewelSwap connects with is nonetheless full of exchanges, VASPs and on- and off-ramps that absolutely do need robust screening. Anyone bridging between fiat and crypto, or operating a custodial venue, should treat sanctions compliance screening as foundational infrastructure.
It is technology that checks people, entities and, in crypto, wallet addresses and transactions against sanctions lists such as the OFAC SDN list and the EU consolidated list, plus PEP lists, watchlists and blocklists of known illicit actors. In crypto it also traces fund flows on-chain to measure indirect exposure to sanctioned sources.
One that screens the counterparty rather than the coins: checking an individual or business against sanctions, PEP, law-enforcement and adverse-media sources at onboarding and on an ongoing basis. It answers "who is this", where blockchain analytics answers "where did this value come from". Most crypto businesses need both, and they are usually separate products.
Yes. On-chain analytics platforms evaluate deposit and withdrawal addresses at transaction time against current designations and risk data, and can block or hold a transfer before it settles. The practical test when comparing them is how quickly a newly designated OFAC address appears in the product, and whether evaluation happens per transaction or on a schedule.
Both layers matter here. Customer-screening tools re-check your existing user base as designations change and notify you on a new hit. On-chain tools ingest newly designated addresses into their screening data. Ask each vendor for its stated update interval, and treat anything slower than daily as a gap you have to document.
The underlying lists are free: OFAC publishes designated crypto addresses and the EU consolidated list is downloadable. Free tools can tell you whether one address is listed. They cannot measure indirect exposure through intermediate hops, screen at production volume in real time, attribute entities, re-screen your customer base, or produce the audit trail a regulator expects. See our full breakdown of free crypto sanctions screening.
In most regulated jurisdictions, yes. Exchanges and VASPs are generally expected to implement sanctions controls, and liability is often strict, meaning a violation can occur without intent. Confirm your specific obligations with counsel, as requirements vary by country.
Traditional screening matches names and identity data against lists. Crypto screening keeps that layer and adds on-chain analysis: checking wallet addresses directly, tracing fund flows across hops and mixers, and scoring a wallet's exposure to sanctioned entities in real time.
Coverage of both layers, broad multi-chain support, real-time monitoring and alerts, promptly updated sanctions, PEP and adverse-media data, ongoing re-screening of existing customers, high-quality entity attribution to minimise false positives, strong investigation tooling, and clean API integration with an auditable trail.
JewelSwap is non-custodial and does not hold user funds, so its needs differ from a custodial exchange. Centralized exchanges, VASPs and fiat on-ramps in the wider ecosystem do need robust screening. This article is educational and not legal advice.
This article is for educational purposes only and does not constitute legal or compliance advice. Regulatory obligations vary by jurisdiction; consult qualified counsel before making compliance decisions.