September 28, 2026
at
9:30 am
EST
MIN READ

Crypto transaction monitoring is the practice of scanning and analyzing blockchain transfers as they settle and measuring each one against a set of risk factors to determine the likelihood of the transaction involving illicit funds.
A single transfer, on its own, is rarely incriminating. However, what makes a transaction suspicious is context: where the funds came from, how many wallets they crossed, how fast, and their respective counterparties. Automated software purpose built for this function can assemble this context at a speed no analyst could match by hand. Most crypto transaction monitoring passes through five stages to turn raw transaction data into a conclusion.
Ingestion: Blockchain nodes index every block across every supported chain and normalize the results. Bitcoin UTXOs, EVM event logs and Solana instructions are converted into a unified data structure before they are all compared.
Clustering and attribution: Individual addresses are grouped into entities, and entities are labelled as far as possible. This is what separates blockchain explorers from blockchain intelligence platforms. Arkham's Ultra engine performs this attribution across a catalogue containing over 7.1 billion address tags and 837,000 entity profiles as of June 2026.
Risk scoring: Each address or entity is graded on its exposure to illicit activity. Arkham Risk Scores return a value between 0 and 100 alongside a Risk Briefing explaining the reasoning and the connected addresses that drove it.

Alerting: Anything crossing a predetermined threshold generates a notification, allowing compliance teams to make immediate judgment calls.
Human review: A human analyst reviews the alert to determine if it is a false positive or otherwise escalates it for further action.
Blockchains demand purpose-built tooling for four structural reasons. Firstly, blockchains are pseudonymous by default, so identity must be inferred from contextual clues rather than simply looked up. Additionally, bridges move value between chains in minutes, which bypasses any blockchain tooling that only covers a single chain. Blockchains also run 24/7, so crypto transaction monitoring needs to run 24/7 as well. Finally, once a customer withdraws to self-custody, there is no longer any intermediary subpoena to stop the funds from being transferred and laundered away. Crypto transaction monitoring must catch these illicit fund movements as they happen, in real time.
Know Your Transaction, usually shortened to KYT, is the discipline of assessing the transaction itself rather than the person holding it.
The contrast with Know Your Customer (KYC) is the easiest way to understand it. KYC is a background check done at onboarding, where key data such as the customer’s full legal name, supporting documents, registered address, and more, are verified once and then refreshed periodically. KYT, on the other hand, is an ongoing process, tracking every new transaction received or made by the customer, long after the initial KYC process is completed. A customer can pass every onboarding check honestly and subsequently get flagged three months later for receiving a deposit that traces back to a ransomware wallet. Such deposits are detected and flagged by ongoing KYT protocols.
Attribution links the two processes. Once a counterparty address resolves to a named exchange, mixer or sanctioned entity, KYT turns a single transaction from an anonymous string to additional evidence about your customer's behavior which may not have surfaced during KYC checks.
Although transaction monitoring and wallet screening are terms that are often used interchangeably, they are not the same thing.
Wallet screening is a point-in-time lookup: take an address, check it against sanctions lists and internal watchlists, and return with a decision. OFAC publishes digital currency addresses directly on the SDN List, and firms can query them by hash using the Sanctions List Search tool. Screening is fast, cheap, and easy to prove.

Monitoring measures behavior across time, such as asking whether a pattern makes sense for a specific customer given their past behavior. A wallet three hops from a sanctioned exchange may pass a screening check cleanly, because it is not itself on any list.
With the increasing adoption of cryptocurrencies over the past few years, the obligations across major jurisdictions regarding AML are now explicit.
The Financial Action Task Force (FATF) extended its AML/CFT standards to virtual assets through Recommendation 15, and added the Travel Rule under Recommendation 16. Its seventh Targeted Update, published 16 July 2026, found 83% of surveyed jurisdictions had passed Travel Rule legislation, up from 73% a year earlier. The same report noted that most identified on-chain illicit activity now involves stablecoins, and documented a Cambodia-based conglomerate that laundered at least $4 billion between 2021 and 2025.

In the EU, MiCA has applied to crypto-asset service providers since 30 December 2024, with the transitional deadline for pre-existing firms closing on 1 July 2026. The Transfer of Funds Regulation took effect the same day, extending originator and beneficiary data requirements to crypto transfers of any size. In the US, money services businesses must file Suspicious Activity Reports (SARs) under 31 CFR 1022.320 within 30 calendar days of detecting the facts behind them. OFAC sanctions carry strict liability, so intent is no defence.
Two recent enforcement actions in the U.S. show the cost of failure to implement a robust transaction monitoring program.
On 4 January 2023, the New York Department of Financial Services issued a $100 million consent order against Coinbase, relating to its compliance failure surrounding its KYC, transaction monitoring and AML processes. The settlement is to be split between a $50 million penalty and $50 million of mandated compliance investment over two years.
Ten months later, on 21 November 2023, FinCEN assessed a $3.4 billion civil money penalty against Binance, the largest in Treasury and FinCEN history, alongside a five-year monitorship, for violation of AML laws. A separate settlement of $968 million was also made with OFAC in relation to the case.
Suspicious activity on-chain often follows a few similar patterns, which allow regulators and on-chain investigators to filter out such transactions.
Peel chains move a large balance through a long sequence of wallets, “peeling” off small amounts at each hop while the bulk continues onward. The peeled-off amounts are then sent to various exchanges to be laundered away. Due to the size of each individual transfer, the amounts are also less likely to be flagged for AML concerns.

Mixer exposure is another clear signal for suspicious on-chain activity. Funds entering or leaving a service like Tornado Cash exist to break traceability, and that intent is hard to explain away. That said, the use of a mixer service does not always point to illicit activity and is sometimes used purely for privacy purposes too.
Post-theft chain-hopping follows a distinctive pattern. Generally, it begins with a large exploit, followed by rapid bridging across several chains within hours, then a pause where the funds lay dormant for a period. Arkham's research on the Lazarus Group maps this behaviour across multiple incidents.
Dormancy breaks happen when an address untouched for years suddenly transfers everything at once. While this pattern is usually observed with dormant Bitcoin wallets, illicit funds from exploits often also lay dormant for prolonged periods before being transferred and laundered.
Structuring splits one deposit into many smaller ones, sitting just below a reporting threshold to prevent triggering any alerts. This is often used in peel chains to minimize detection risks.
Arkham's Visualizer allows users to easily render these transactions as network graphs, while the Tracer follows funds hop by hop through intermediate wallets, making suspicious transactions easier to spot.

For beginners, starting manually is much simpler than jumping straight into the deep end with automating transaction monitoring. Manual transaction monitoring also enables better understanding of each genuine alert, rather than fighting against possibly hundreds of alerts on an automated setup. Manual monitoring can be encompassed in a few simple steps:
1. Look up the address: Search the address at intel.arkm.com. If Arkham already labeled the individual or entity, you can navigate to its respective entity page, which covers every address that entity controls, not just the one you searched.

2. Read the Profiler: The Profiler splits into Portfolio, Historical Performance, Transactions, Counterparties, and Borrows & Loans. The Transactions unit applies a $1 minimum value filter by default, stripping out spam and spoofed tokens.

3. Review counterparties: Open the Counterparties unit and sort by volume. Filter by time period, token, network, and inflow versus outflow. Under this tab, any large transactions or frequent small transactions to suspicious addresses should be highlighted and flagged for further investigation.

4. Trace anything unclear. Push suspicious flows into Tracer or the Visualizer and follow them until they reach an exchange, a mixer, or a dead end.

5. Set an alert: For addresses deemed to be suspicious that you would like to monitor further, create a new Alert, with your own conditions using Arkham filters such as entity or address involved, sending and receiving entity, token, token amount, USD value, and chain. Delivery runs through email, Telegram or webhook.

Manual review stops scaling around a few hundred addresses. At that point, the same workflow no longer becomes scalable without automation. One prime example for ongoing crypto transaction monitoring would be to leverage Arkham Intelligence’s API.
Start with requesting access at arkm.com/api. Every request to the root URL https://api.arkm.com naturally requires a valid API key in its header. Store the key in an environment variable or secrets manager, never directly in the repository.
The core polling loop looks like this:
curl -s "https://api.arkm.com/transfers?base=<address_or_entity>&flow=all
\&timeLast=1h&usdGte=10000&sortKey=time&sortDir=desc&limit=100" \
-H "API-Key: $ARKHAM_API_KEY"Run that on a schedule against each entity on your watchlist. usdGte sets your materiality floor, timeLast accepts shorthand durations, and flow narrows to incoming, outgoing or self-transfers. To prevent a restart from replaying past alerts, deduplicate the results based on their transaction hash.
For each counterparty returned, call the intelligence endpoint (/intelligence/address/{address}/all) to resolve labels and entity attribution. If you have the paid Risk Scores add-on enabled, you may also request a score and read the accompanying Risk Briefing, which returns the reasoning behind the number and the risky connected addresses that produced it.
For any responses above your threshold, the data can be routed into a case queue with its respective evidence attached: transfer details, counterparty labels, score, and briefing. This evidence can be reviewed by an analyst later or requested by an examiner.
When building, do note that API rate limits are tiered, with different endpoints requiring facing different throttle limits. Users can also paginate with offset rather than requesting all transaction data at once to avoid timeouts on high-volume addresses. Finally, all users should check parameters against the API reference and integration guide before building, since endpoints can change over time.
Crypto transaction monitoring works by continuously screening blockchain activity against risk rules, flagging patterns like peel chains, mixer exposure, and structuring so an analyst can review and act on them. It exists because blockchains are pseudonymous, cross-chain, and running 24/7, which puts them beyond the reach of one-time checks like KYC or simple wallet screening. Whether done manually through a tool like Arkham's Profiler or automated through API integrations, the underlying goal stays the same: to catch and stop illicit fund movement in time to act on it.






.jpeg)
.jpeg)














.png)
.png)




























.jpg)
.jpg)


















.png)
.png)
.png)
.png)










.png)
.png)




.png)
.png)


.png)
.png)


.png)
.png)


.png)
.png)
.png)
.png)


















.png)
.png)


.png)
.png)
.png)
.png)


.png)
.png)








.png)
.png)





