An AML wallet check is fundamentally a blockchain analysis problem. The engine takes a wallet address or transaction hash as input and performs several parallel operations: (1) it traces fund flow backwards up to 5 hops on the blockchain to identify the source of incoming funds, (2) it screens each counterparty address against curated compliance databases, and (3) it calculates a weighted risk score from 0% to 100% based on severity and directness of exposure.
The compliance databases powering this come from specialized blockchain analytics firms — Chainalysis, Elliptic, TRM Labs, Crystal Blockchain, Scorechain, and Merkle Science — which spend millions annually cataloging suspicious addresses. Their classifications include mixer services, darknet markets, sanctioned entities, ransomware wallets, exchange hack proceeds, phishing drainers, fraudulent ICOs, and high-risk gambling platforms.
When you screen a wallet on AMLGuard, our engine performs on-chain forensics across 9 parallel analyzers: sanctions list screening (OFAC, EU, UN, UK), mixer and tumbler detection, darknet market exposure, FATF jurisdiction compliance, FinCEN SDN matching, phishing and scam database lookup, 5-hop fund flow tracing, counterparty risk analysis, and finally risk score calculation. The full pipeline completes in under 20 seconds.
The final report shows three category tiers — Danger (direct exposure to stolen funds, darknet, sanctions), Suspicious (mixer touches, risky exchanges, unknown P2P), and Trusted (regulated exchanges, institutional custody) — with each contributing a percentage to the overall risk score.
Under the hood, AMLGuard's AML API runs cross-chain checks — a single USDT wallet that moves between Tron, Ethereum and BNB Smart Chain is tracked as one identity, not three. This matters because scammers deliberately bridge funds across chains to obscure their trail. Our crypto AML check catches these bridge patterns the same way binance AML compliance teams do internally — and returns a unified verdict in seconds.