Crypto sanctions screening, without the fog
Sanctions screening is the one part of crypto compliance where the answer can be a plain fact: either an address appears on an official list or it does not. Everything a vendor adds on top — clusters, exposure percentages, "indirect" risk — is inference. Useful, but not the same thing. This page explains what the official sources actually publish, what an exact match does and does not mean, and what a regulator will ask you to prove afterwards.
Who publishes crypto addresses
OFAC (United States) adds digital-currency addresses to SDN entries as identifiers — Ethereum, Bitcoin, Tron, Solana and others — and its own FAQ states the list is not exhaustive: a designated person can control addresses that were never published. UK OFSI includes crypto addresses in the UK Sanctions List for some designations. The EU consolidated listpublishes them for a smaller set. Other regimes (UN, national lists) mostly designate persons, not addresses. KYTGate fetches OFAC, UK and EU daily, records the address count and a content hash of each snapshot, and keeps every snapshot so you can show which version applied to a decision.
Exact match is a fact; a risk score is an opinion
An address that equals a listed address is a match — there is no probability to discuss. That certainty is why an exact match drives a BLOCK_PENDING_MLRO decision in KYTGate's baseline policy and never a mere score. Two consequences follow. First, the match must be case-normalised and chain-aware (an EVM address is the same on Ethereum, BSC, Base and Arbitrum; a Tron address is not). Second, "no match" has to be worded honestly: NO_KNOWN_MATCH, never "clean" — the list is incomplete by its publisher's own admission.
What "indirect exposure" adds — and costs
Commercial analytics providers trace funds a few hops back and report that a deposit is "12% exposed to a sanctioned entity". That is genuinely useful for source-of-funds review and for catching money that moved through a mixer after a designation. It is also an inference with parameters (hops, thresholds, attribution quality) that you cannot verify and that changes between vendors. KYTGate's coverage matrix keeps the two apart: sanctions is the exact-match dimension, sourceOfFundsExposure is the inference dimension, and a decision records which of them actually ran. You can add a commercial provider later without pretending it was there before.
Re-screening is not optional
Designations happen after onboarding. A counterparty that was clean in March may be listed in August, and the regulator's question will be "when did you find out?". KYTGate re-screens every address it has seen against each fresh snapshot every morning; a new match opens a case automatically and fires a webhook. The evidence pack shows the snapshot that first matched and the one that did not — the timeline a supervisor wants.
Stablecoin freezes are the other hard signal
Tether and Circle can and do freeze addresses at the contract level, often at law-enforcement request and often before any list is updated. KYTGate reads isBlackListed / isBlacklisted live from the official contracts on six networks. A frozen address is treated like a sanctions match: hard signal, block, human decision. More on this in stablecoin compliance.
What you will be asked to prove
Not "did you screen?" but: which list version, at what time, against which address, with what result, and who decided what next. Every KYTGate screening answers those five with a signed Decision Receipt that carries the snapshot hashes, the policy version and the human actions; anyone can verify the signature in a browser without trusting us. That is the difference between a screenshot and evidence.
Try it
The free wallet sanctions check runs the exact-match and issuer-freeze checks on any address and shows the list versions it used. Leave an e-mail and we re-check the address daily and tell you only when its status changes.