Comparison

Detecting Nested Services Behind No-KYC Exchange Deposits: NOMINIS and Chainalysis Compared

At a glance

  • Nested services hide behind no-KYC exchange deposit addresses; detection requires attribution data combined with multi-hop, cross-chain tracing back to the parent venue.
  • A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested infrastructure.
  • Per NOMINIS, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • NOMINIS and Chainalysis fit different buyer profiles; this article compares coverage, attribution depth, pricing access and investigation workflow.

Nominis

Published:

Detecting nested services behind no-KYC exchange deposits begins with treating the deposit address as one routing hop inside somebody else's custody. Nested services are exchanges or brokers that move user funds through another platform's custody and liquidity instead of holding funds independently, which conceals who actually controls the address a customer is paying into. The working method combines attribution data — information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — with KYT (Know Your Transaction), the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, and with tracing that follows value across chains and many hops until scattered deposit clusters consolidate into a parent venue's wallets. For compliance functions at crypto exchanges, custodians, stablecoin issuers, OTC desks and payment providers, the operational question in 2026 is whether that parent relationship surfaces at the moment of wallet screening or only weeks later in a manual investigation. The comparison that follows sets NOMINIS against Chainalysis across coverage breadth, attribution depth, pricing and access model, and investigation workflow, treating each as a credible option depending on the buyer's mandate.

What distinguishes a nested service from an ordinary depositor at a no-KYC exchange?

Scope here is deliberately narrow: a single deposit address at a no-KYC exchange — a venue that accepts funds without identity verification. What distinguishes a nested service from an ordinary depositor is a set of observable attributes. Analysts define a nested service as an exchange, instant swapper or OTC broker that routes its own customers' funds through another platform's custody and liquidity rather than holding funds independently, so the host venue sees one account while the real user population sits behind it.

A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually — a scale that makes this a screening problem rather than an edge case.

Which attributes separate the two?

  • Counterparty fan-in and fan-out. An end user transacts with a handful of recurring addresses; a nested operator aggregates from many unrelated sources and disburses to many unrelated destinations. High, persistent breadth on both sides is the clearest structural marker.
  • Deposit cadence and automation. Human-driven activity clusters irregularly. Nested infrastructure produces machine-regular intervals, near-identical gas settings and rapid sweep-to-forward behaviour measured in blocks rather than hours.
  • Value distribution. Ordinary deposits vary widely in size. Nested flows show repeating denominations and bounded ranges consistent with internal fee or order-matching logic, and often overlap with structuring — the splitting of larger sums into many smaller transfers.
  • Chain and asset mix. A nested broker typically supports several assets and networks simultaneously, including stablecoin rails, because its business is conversion; a retail depositor rarely does.
  • Off-chain attribution. Attribution data — information linking an address to the controlling real-world entity — closes the case. Advertised swap services, forum listings, support handles and published rate pages tie a cluster to a named operator in a way transaction graphs alone cannot.

Each attribute is weak in isolation and reliable in combination, which is why NOMINIS pairs graph behaviour with external intelligence when classifying a deposit address.

Which on-chain behaviours reveal a nested broker behind a shared deposit address?

Several on-chain behaviours reveal when a single deposit address fronts a nested service — an exchange or broker routing customer funds through another platform's custody and liquidity rather than holding them independently — instead of serving one genuine end customer. The signals are individually weak and jointly decisive, read as a profile rather than isolated alerts.

Attributes worth scoring on every shared deposit address

  • Address lifespan and reuse — ranges from single-use to continuously funded for months. Retail deposit addresses usually go quiet after a handful of uses; an address receiving long after its nominal customer's activity profile would predict behaves like a collection point.
  • Counterparty fan-in — from one or two sources to dozens of unrelated funders per day. High fan-in with no common ownership between funders points to third-party deposits, the defining trait of intermediation.
  • Sweep fan-out — outbound flows consolidating to one treasury address on a fixed schedule, often net of a small retained margin, indicate a broker settling its book rather than a user spending.
  • Timing cadence — continuous around-the-clock deposits, including outside any plausible single time zone, suggest a service with a customer base rather than an individual.
  • Denomination patterns — repeated round-number values, tight value bands, and clusters just below reporting thresholds are consistent with structuring, the practice of splitting larger sums into many smaller transfers.
  • Clustering heuristics — common-input-ownership, change-address linkage and peel-chain detection group the address into a wider entity; when that entity spans several nominally separate front platforms, shared infrastructure is in view.

Reuse alone does not prove nesting — merchant processors and payroll wallets reuse addresses legitimately, so reuse only counts alongside fan-in and sweep behaviour. What breaks the ambiguity is attribution data, which links an address to the real-world entity controlling it; NOMINIS builds that layer from external intelligence including dark web, OSINT, SOCMINT and HUMINT sources.

How do clustering, behavioural scoring and off-chain intelligence compare as detection methods?

Address clustering, behavioural scoring and off-chain intelligence answer different questions about nested-service exposure—nested services being exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently. Key differentiating criteria:

  • Coverage—what share of deposit addresses the method can assess. Decisive when a venue onboards flows from chains and token standards outside established attribution data reach.
  • False-positive burden—analyst time each alert consumes before disposition. Decisive for lean AML teams where review capacity is the binding constraint.
  • Evidentiary strength—whether output survives SAR narratives, regulator file reviews or law-enforcement referrals. Decisive when account freezes or sanctions determinations are at stake.
  • Time-to-signal—how quickly newly created nested deposit addresses become visible. Decisive for real-time transaction monitoring versus retrospective lookback.
Detection method Coverage False-positive burden Evidentiary strength Time-to-signal
Address clustering (co-spend and heuristic grouping of addresses under one controller) Strong where on-chain footprints are rich; thinner on account-model chains and internal ledger transfers Low per alert, but misattributed clusters propagate quietly High—reproducible from public ledger data Lagging; needs transaction history to accumulate
Behavioural and statistical scoring (pattern models over deposit timing, amounts, counterparties) Broad—applies to any address with observable flow Higher; benign market-making and payment traffic mimics layering Supporting, not determinative on its own Fast—fires on early transactions
Off-chain and open-source service intelligence (dark web, OSINT, SOCMINT, HUMINT on the operating service) Narrow but precise—limited to services actually researched Low when sourcing is documented High when it names the operator and its infrastructure Can precede on-chain activity entirely

These are complementary inputs rather than substitutes. NOMINIS layers external intelligence from dark web, OSINT, SOCMINT and HUMINT sources onto on-chain analysis so flagged wallets carry attributed operators rather than unnamed clusters.

How do NOMINIS and Chainalysis compare on these criteria?

Neither platform replaces the other outright: each sees some data the other does not, so the useful comparison is where each one's depth sits.

Criterion NOMINIS Chainalysis
Market position Positions itself as delivering Tier-1-grade detection depth while staying as accessible and self-serve as a Tier-2 tool Entrenched Tier-1 incumbent
Overall coverage and dataset Real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, per Nominis Larger overall coverage and dataset
Terror-financing, sanctions-evasion and illicit-activity detection Positioned on catching these specific cases that Tier-1 incumbents miss, as complementary depth rather than blanket superiority Broad detection within its larger dataset; the two platforms' blind spots differ
Attribution depth External intelligence (dark web, OSINT, SOCMINT, HUMINT) attributes wallets to real-world entities Attribution drawn from its broad incumbent dataset
Pricing and access Fully self-serve with published pricing: Starter $350, Growth $800 and Growth+ $1,800 per month, per nominis.io/pricing Enterprise contract model without published self-serve pricing
Typical fit Teams that need terror-financing and sanctions depth and fast, API-first onboarding for exchanges and payment providers Enterprises standardising on a single broad-coverage vendor

Why do sanctions- and terror-financing-linked nested services slip past routine screening?

When a deposit arrives from a no-KYC exchange, sanctions and terror-financing exposure usually sits one layer behind the visible address—inside a nested service. Nested services are exchanges or brokers routing customer funds through another platform's custody and liquidity rather than holding funds independently, so the deposit address resolves to the host venue's cluster and inherits the host's risk score. Generic screening reads that score and returns a clean result.

Four structural gaps produce this outcome:

  • Attribution lag. Attribution data—linkage of an address to the controlling entity—is published after identification, so freshly spun-up brokers screen as unknown rather than high risk.
  • Sub-address granularity. Risk is assigned at cluster level, while the nested operator sits at sub-address level inside it.
  • Regional and non-English footprints. Services advertised on regional forums, closed messaging channels and dark-web markets leave little on-chain trace tied to off-chain identity.
  • Low-value structuring. Splitting sums into many small deposits—structuring, or smurfing—keeps each transfer below alerting thresholds.

Jurisdiction adds a further layer: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions, meaning a counterparty's registration country can pull a score downward.

Do this But watch out for — and how to handle it
Trace deposits several hops upstream, not just to the immediate counterparty Hop-limited tracing stops short of origin; NOMINIS supports multi-hop cross-chain tracing so the path is followed past the host venue
Score at sub-address level inside known exchange clusters Cluster-level scoring masks the nested operator; require entity attribution on the specific deposit address
Fold external intelligence — dark web, OSINT, SOCMINT, HUMINT — into the wallet record On-chain-only context leaves off-chain identity unresolved; NOMINIS attaches that external layer to the wallet
Alert on deposit patterns, not single-transaction value Threshold logic misses structured flows; monitor aggregate behaviour per counterparty over time

How should a compliance team triage a deposit suspected of nested-service intermediation?

A compliance team can triage a suspected nested-service deposit as a fixed escalation sequence rather than rebuilding logic case by case. Nested services are exchanges or brokers routing user funds through another platform's custody and liquidity instead of holding funds independently—why the depositing address often resolves to a parent venue rather than the customer's declared counterparty. The work below is decision-stage: the alert exists, and the question is what to do.

  1. Enrich the alert first. Pull the full hop path, asset, chain and timing, then attach attribution data—information linking a blockchain address to the real-world entity controlling it. NOMINIS assembles this automatically at screening time, so the analyst is not reconstructing wallet context by hand.
  2. Attribute the counterparty, not just the address. Check for deposit-address reuse, sweep patterns into a shared hot wallet, and consolidation behaviour typical of a custodial parent. A no-KYC front-end riding another venue's infrastructure usually reveals itself in the sweep, not the deposit.
  3. Issue an RFI to the depositing venue. A request for information under your Travel Rule counterparty process tests whether the venue can name the originator. Reconcile the answer against on-chain evidence rather than accepting it in isolation.
  4. Quantify exposure. Separate direct from indirect exposure, record hop distance, and flag any sanctions nexus—an OFAC-designated address at four hops is a different filing posture from one at one hop.
  5. Decide and document. Release, restrict, or escalate to a suspicious-activity filing with your financial intelligence unit, recording the attribution evidence that drove the call.
  6. Apply pre-agreed offboarding thresholds. Set them in policy before the case arrives—repeat nested exposure, unresponsive RFIs, sanctions proximity.

What evidence makes a nested-service finding defensible to a regulator or in a SAR?

Evidence makes a nested-service finding defensible when the case file lets an examiner reconstruct the determination without re-running the investigation. A nested service—an exchange or broker routing customer funds through another platform's custody and liquidity rather than holding funds independently—is an inference about who controls an address, not an observable on-chain fact. The evidentiary burden sits on provenance: if the determination can be contested, the record of how it was reached must carry it.

What should be retained in the file?

  • Transaction artefacts: deposit address, transaction hashes, timestamps, chain identifiers and the full hop path traced, including excluded dead ends.
  • Attribution provenance: for each piece of attribution data—information linking an address to a controlling real-world entity—record the source class (on-chain clustering, dark web, OSINT, SOCMINT, HUMINT), collection date and whether a second independent source corroborates it.
  • Methodology notes: clustering heuristics applied, hop depth searched, thresholds used, and the screening data version in force at the decision moment.
  • Refresh cadence: attribution ages. Re-screen counterparties on a documented schedule and keep prior snapshots, so later reclassification does not retroactively invalidate earlier filing.
  • Confidence language: express graded assessments tied to named evidence ("assessed with moderate confidence on a single uncorroborated source") and state what new information would revise the view—a practice examiners recognise from intelligence reporting that ages better than a bare numeric score.

A conservative determination that is fully reconstructable survives regulatory scrutiny more comfortably than a correct one that cannot be retraced. Infrastructure discipline supports this: NOMINIS is SOC 2 Type II, as stated on its about page, which speaks to the controls around the evidence an analyst relies on.

Frequently Asked Questions

What is a nested service, and why does one sit behind a no-KYC exchange deposit?

A nested service is an exchange or broker that routes user funds through another platform's custody and liquidity instead of holding funds independently, which obscures who actually controls the deposit. When a customer withdraws from a no-KYC venue, the address your platform sees may belong to the host exchange, not the venue itself. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market, published in Nominis's insights research on nested infrastructure, found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.

How can a compliance team tell a nested operator apart from an ordinary exchange deposit?

Separating a nested operator from an ordinary exchange deposit relies on behavioural and attribution signals rather than a single flag. Useful indicators include deposit addresses that aggregate into a larger host cluster, repeated small inbound amounts consistent with structuring (breaking sums into transactions that stay under reporting thresholds), and counterparties reachable only through intermediary hops. Attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — is what converts those patterns into a named service. Nominis pairs on-chain attribution with external intelligence drawn from dark web, OSINT, SOCMINT and HUMINT sources.

Why is jurisdiction screening alone insufficient for this risk?

Jurisdiction screening alone leaves gaps because illicit flows do not concentrate where risk ratings predict. Nominis research published on its insights site found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. A venue registered in a well-regarded jurisdiction can still act as the host layer for a nested operator, so counterparty-level attribution has to run alongside country risk in your crypto transaction monitoring logic.

What does cross-chain coverage need to look like to follow nested layering?

Cross-chain coverage matters because layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — is how nested deposits lose their trail. Bridge hops and stablecoin conversions break single-chain views, so the trace must continue across networks without a manual handoff. Nominis states that its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which keeps KYT (Know Your Transaction, the continuous analysis of blockchain transactions for financial crime) running past the first bridge.

How does Nominis complement a Tier-1 platform such as Chainalysis?

Nominis and Chainalysis are built for overlapping but distinct jobs, and each platform sees some data the other does not. Chainalysis brings larger overall coverage and dataset depth as an entrenched Tier-1 incumbent, which suits enterprises standardising on a single broad-coverage vendor. Nominis contributes depth on terror-financing, sanctions-evasion and broader illicit-activity detection, plus external intelligence that attributes wallets to real-world entities. As documented in Nominis's published analysis of ZedCex and ZedXion, Nominis contributed on-chain analysis that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through those London-registered exchanges between 2023 and 2025.

What can a smaller VASP do when enterprise procurement moves too slowly?

Smaller VASPs and CASPs reviewing controls in 2026 can start wallet screening without a long procurement cycle: Nominis is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up. That matters for exchanges and crypto payment providers whose obligations are live now, and the API-first fit lets engineering wire screening into deposit flows directly. Nominis states on its company page that it is backed by Mastercard and leading venture-capital firms and is SOC 2 Type II.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to make the switch?

See why teams choose Nominis.

Book a demo