September 28, 2026

at

9:30 am

EST

(Updated:

)

MIN READ

Crypto Transaction Monitoring Explained

Crypto transaction monitoring, or Know Your Transaction (KYT), is the continuous analysis of blockchain data to flag illicit activity and meet AML obligations
No items found.
Arkham Intelligence logo white
0xKira
Arkham
Article
Guides
News
Insights
Reports
Trading

Contents

    ‍

    Summary

    • Crypto transaction monitoring is the ongoing review of blockchain activity against a firm's own risk rules, flagging transfers that resemble money laundering, sanctions evasion or fraud so that an analyst can investigate and report them.
    • It is designed to catch suspicious on-chain activity including mixer exposure, sanctioned counterparties, peel chains, chain-hopping, deposits deliberately structured to sit under a reporting threshold, among others.
    • Exchanges, VASPs, custodians, stablecoin issuers and crypto payment processors are legally required to run it under rules put in place by regulatory bodies such as FATF and the EU.
    • Crypto transaction monitoring is often automated. APIs like Arkham API expose transfer feeds, entity attribution and Risk Scores as endpoints which can be integrated into an organisation’s systems and polled at regular intervals.

    What Is Crypto Transaction Monitoring?

    Crypto transaction monitoring is the practice of scanning and analyzing blockchain transfers as they settle and measuring each one against a set of risk factors to determine the likelihood of the transaction involving illicit funds.

    A single transfer, on its own, is rarely incriminating. However, what makes a transaction suspicious is context: where the funds came from, how many wallets they crossed, how fast, and their respective counterparties. Automated software purpose built for this function can assemble this context at a speed no analyst could match by hand. Most crypto transaction monitoring passes through five stages to turn raw transaction data into a conclusion.

    Ingestion: Blockchain nodes index every block across every supported chain and normalize the results. Bitcoin UTXOs, EVM event logs and Solana instructions are converted into a unified data structure before they are all compared.

    Clustering and attribution: Individual addresses are grouped into entities, and entities are labelled as far as possible. This is what separates blockchain explorers from blockchain intelligence platforms. Arkham's Ultra engine performs this attribution across a catalogue containing over 7.1 billion address tags and 837,000 entity profiles as of June 2026.

    Risk scoring: Each address or entity is graded on its exposure to illicit activity. Arkham Risk Scores return a value between 0 and 100 alongside a Risk Briefing explaining the reasoning and the connected addresses that drove it.

    ‍

    Arkham’s Risk Score and Risk Briefing covering reasons for the score, and risk factors - Arkham

    ‍

    Alerting: Anything crossing a predetermined threshold generates a notification, allowing compliance teams to make immediate judgment calls.

    Human review: A human analyst reviews the alert to determine if it is a false positive or otherwise escalates it for further action.

    Blockchains demand purpose-built tooling for four structural reasons. Firstly, blockchains are pseudonymous by default, so identity must be inferred from contextual clues rather than simply looked up. Additionally, bridges move value between chains in minutes, which bypasses any blockchain tooling that only covers a single chain. Blockchains also run 24/7, so crypto transaction monitoring needs to run 24/7 as well. Finally, once a customer withdraws to self-custody, there is no longer any intermediary subpoena to stop the funds from being transferred and laundered away. Crypto transaction monitoring must catch these illicit fund movements as they happen, in real time.

    What Is KYT?

    Know Your Transaction, usually shortened to KYT, is the discipline of assessing the transaction itself rather than the person holding it.

    The contrast with Know Your Customer (KYC) is the easiest way to understand it. KYC is a background check done at onboarding, where key data such as the customer’s full legal name, supporting documents, registered address, and more, are verified once and then refreshed periodically. KYT, on the other hand, is an ongoing process, tracking every new transaction received or made by the customer, long after the initial KYC process is completed. A customer can pass every onboarding check honestly and subsequently get flagged three months later for receiving a deposit that traces back to a ransomware wallet. Such deposits are detected and flagged by ongoing KYT protocols.

    Attribution links the two processes. Once a counterparty address resolves to a named exchange, mixer or sanctioned entity, KYT turns a single transaction from an anonymous string to additional evidence about your customer's behavior which may not have surfaced during KYC checks.

    Transaction Monitoring vs Wallet Screening

    Although transaction monitoring and wallet screening are terms that are often used interchangeably, they are not the same thing.

    Wallet screening is a point-in-time lookup: take an address, check it against sanctions lists and internal watchlists, and return with a decision. OFAC publishes digital currency addresses directly on the SDN List, and firms can query them by hash using the Sanctions List Search tool. Screening is fast, cheap, and easy to prove.

    ‍

    OFAC’s Sanction List Search - OFAC

    ‍

    Monitoring measures behavior across time, such as asking whether a pattern makes sense for a specific customer given their past behavior. A wallet three hops from a sanctioned exchange may pass a screening check cleanly, because it is not itself on any list.

    Why Is Transaction Monitoring Necessary for AML?

    With the increasing adoption of cryptocurrencies over the past few years, the obligations across major jurisdictions regarding AML are now explicit.

    The Financial Action Task Force (FATF) extended its AML/CFT standards to virtual assets through Recommendation 15, and added the Travel Rule under Recommendation 16. Its seventh Targeted Update, published 16 July 2026, found 83% of surveyed jurisdictions had passed Travel Rule legislation, up from 73% a year earlier. The same report noted that most identified on-chain illicit activity now involves stablecoins, and documented a Cambodia-based conglomerate that laundered at least $4 billion between 2021 and 2025.

    ‍

    Jurisdictions which have implemented FATF’s Travel Rule - FATF

    ‍

    In the EU, MiCA has applied to crypto-asset service providers since 30 December 2024, with the transitional deadline for pre-existing firms closing on 1 July 2026. The Transfer of Funds Regulation took effect the same day, extending originator and beneficiary data requirements to crypto transfers of any size. In the US, money services businesses must file Suspicious Activity Reports (SARs) under 31 CFR 1022.320 within 30 calendar days of detecting the facts behind them. OFAC sanctions carry strict liability, so intent is no defence.

    Two recent enforcement actions in the U.S. show the cost of failure to implement a robust transaction monitoring program.

    On 4 January 2023, the New York Department of Financial Services issued a $100 million consent order against Coinbase, relating to its compliance failure surrounding its KYC, transaction monitoring and AML processes. The settlement is to be split between a $50 million penalty and $50 million of mandated compliance investment over two years.

    Ten months later, on 21 November 2023, FinCEN assessed a $3.4 billion civil money penalty against Binance, the largest in Treasury and FinCEN history, alongside a five-year monitorship, for violation of AML laws. A separate settlement of $968 million was also made with OFAC in relation to the case.

    What Suspicious Activity Looks Like On-Chain

    Suspicious activity on-chain often follows a few similar patterns, which allow regulators and on-chain investigators to filter out such transactions.

    Peel chains move a large balance through a long sequence of wallets, “peeling” off small amounts at each hop while the bulk continues onward. The peeled-off amounts are then sent to various exchanges to be laundered away. Due to the size of each individual transfer, the amounts are also less likely to be flagged for AML concerns.

    ‍

    How a peel chain works - Maltego

    ‍

    Mixer exposure is another clear signal for suspicious on-chain activity. Funds entering or leaving a service like Tornado Cash exist to break traceability, and that intent is hard to explain away. That said, the use of a mixer service does not always point to illicit activity and is sometimes used purely for privacy purposes too.

    Post-theft chain-hopping follows a distinctive pattern. Generally, it begins with a large exploit, followed by rapid bridging across several chains within hours, then a pause where the funds lay dormant for a period. Arkham's research on the Lazarus Group maps this behaviour across multiple incidents.

    Dormancy breaks happen when an address untouched for years suddenly transfers everything at once. While this pattern is usually observed with dormant Bitcoin wallets, illicit funds from exploits often also lay dormant for prolonged periods before being transferred and laundered.

    Structuring splits one deposit into many smaller ones, sitting just below a reporting threshold to prevent triggering any alerts. This is often used in peel chains to minimize detection risks.

    Arkham's Visualizer allows users to easily render these transactions as network graphs, while the Tracer follows funds hop by hop through intermediate wallets, making suspicious transactions easier to spot.

    ‍

    Arkham’s Tracer tracks funds from the Bybit exploit to bridges like THORChain, LiFi and OKX’s Dex Router - Arkham

    ‍

    Crypto Transaction Monitoring for Beginners

    For beginners, starting manually is much simpler than jumping straight into the deep end with automating transaction monitoring. Manual transaction monitoring also enables better understanding of each genuine alert, rather than fighting against possibly hundreds of alerts on an automated setup. Manual monitoring can be encompassed in a few simple steps:

    1. Look up the address: Search the address at intel.arkm.com. If Arkham already labeled the individual or entity, you can navigate to its respective entity page, which covers every address that entity controls, not just the one you searched.

    ‍

    Searching for a labelled address will surface its named entity

    ‍

    2. Read the Profiler: The Profiler splits into Portfolio, Historical Performance, Transactions, Counterparties, and Borrows & Loans. The Transactions unit applies a $1 minimum value filter by default, stripping out spam and spoofed tokens.

    ‍

    Searching up a labelled entity shows you their respective profiler page - Arkham

    ‍

    3. Review counterparties: Open the Counterparties unit and sort by volume. Filter by time period, token, network, and inflow versus outflow. Under this tab, any large transactions or frequent small transactions to suspicious addresses should be highlighted and flagged for further investigation.

    ‍

    Filter and sort between counterparties, by time period, volume and token. - Arkham

    ‍

    4. Trace anything unclear. Push suspicious flows into Tracer or the Visualizer and follow them until they reach an exchange, a mixer, or a dead end.

    ‍

    Trace specific flows that seem suspicious with Tracer - Arkham

    ‍

    5. Set an alert: For addresses deemed to be suspicious that you would like to monitor further, create a new Alert, with your own conditions using Arkham filters such as entity or address involved, sending and receiving entity, token, token amount, USD value, and chain. Delivery runs through email, Telegram or webhook.

    ‍

    An alert notifying for Bitcoin transfers from BlackRock addresses above $10K USD - Arkham

    ‍

    How to Automate Crypto Transaction Monitoring

    Manual review stops scaling around a few hundred addresses. At that point, the same workflow no longer becomes scalable without automation. One prime example for ongoing crypto transaction monitoring would be to leverage Arkham Intelligence’s API.

    Start with requesting access at arkm.com/api. Every request to the root URL https://api.arkm.com naturally requires a valid API key in its header. Store the key in an environment variable or secrets manager, never directly in the repository.

    The core polling loop looks like this:

    curl -s "https://api.arkm.com/transfers?base=<address_or_entity>&flow=all
      \&timeLast=1h&usdGte=10000&sortKey=time&sortDir=desc&limit=100" \  
      -H "API-Key: $ARKHAM_API_KEY"

    Run that on a schedule against each entity on your watchlist. usdGte sets your materiality floor, timeLast accepts shorthand durations, and flow narrows to incoming, outgoing or self-transfers. To prevent a restart from replaying past alerts, deduplicate the results based on their transaction hash.

    For each counterparty returned, call the intelligence endpoint (/intelligence/address/{address}/all) to resolve labels and entity attribution. If you have the paid Risk Scores add-on enabled, you may also request a score and read the accompanying Risk Briefing, which returns the reasoning behind the number and the risky connected addresses that produced it.

    For any responses above your threshold, the data can be routed into a case queue with its respective evidence attached: transfer details, counterparty labels, score, and briefing. This evidence can be reviewed by an analyst later or requested by an examiner.

    When building, do note that API rate limits are tiered, with different endpoints requiring facing different throttle limits. Users can also paginate with offset rather than requesting all transaction data at once to avoid timeouts on high-volume addresses. Finally, all users should check parameters against the API reference and integration guide before building, since endpoints can change over time.

    Conclusion

    Crypto transaction monitoring works by continuously screening blockchain activity against risk rules, flagging patterns like peel chains, mixer exposure, and structuring so an analyst can review and act on them. It exists because blockchains are pseudonymous, cross-chain, and running 24/7, which puts them beyond the reach of one-time checks like KYC or simple wallet screening. Whether done manually through a tool like Arkham's Profiler or automated through API integrations, the underlying goal stays the same: to catch and stop illicit fund movement in time to act on it. 

    0xKira is a crypto writer with roots in venture capital, having previously worked at Spartan Labs. An active DeFi user for the past five years, he has spent the last three years writing for industry publications like CoinMarketCap, as well as for a variety of DeFi protocols. 0xKira is known for his in-depth Twitter threads about the latest crypto trends - follow him on Twitter @0xKira_

    Arkham Intelligence logo white
    Arkham
    The Arkham Research Team comprises analysts and engineers who worked at Tesla, Meta, and Apple, alongside alumni from the University of Cambridge, Imperial College London, UC Berkeley, and other institutions.
    No items found.
    Information provided herein is for general educational purposes only and is not intended to constitute investment or other advice on financial products. Such information is not, and should not be read as, an offer or recommendation to buy or sell or a solicitation of an offer or recommendation to buy or sell any particular digital asset or to use any particular investment strategy. Arkham makes no representations as to the accuracy, completeness, timeliness, suitability, or validity of any information on this website and will not be liable for any errors, omissions, or delays in this information or any losses, injuries, or damages arising from its display or use. Digital assets, including stablecoins and NFTs, are subject to market volatility, involve a high degree of risk, can lose value, and can even become worthless; additionally, digital assets are not covered by insurance against potential losses and are not subject to FDIC or SIPC protections. Historical returns are not indicative of future returns.