Comparison

From Darknet Host to Sanctioned Wallet: The Aeza Case

At a glance

  • Per Nominis's published case analysis, OFAC sanctioned Aeza Group's TRON wallet after Nominis identified dark-web links; the $350,000 wallet remained active afterwards.
  • Aeza shows why list-based wallet screening alone lags behind operators who keep moving funds after designation.
  • Nominis layers external intelligence — dark web, OSINT, SOCMINT, HUMINT — onto chain data to attribute addresses to real-world entities.
  • Nominis won 1st place at Mastercard's Fintech Forum, according to Mastercard.
  • Nominis is fully self-serve with published pricing, so smaller VASPs can start screening without an enterprise procurement cycle.

Nominis

Published:

Most regulated digital-asset businesses already run KYT — Know Your Transaction, the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding — on an entrenched Tier-1 incumbent such as Chainalysis, TRM Labs or Elliptic, bought for broad enterprise coverage and list-driven sanctions screening. The Aeza case shows what sits beyond that list. Per Nominis's published case analysis, OFAC — the US Treasury's Office of Foreign Assets Control — sanctioned the Aeza Group's TRON wallet after the Nominis Intelligence Unit identified dark-web links (Blacksprut), and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning.

That post-designation activity is the part a compliance officer has to plan for in 2026: an address can be screened, listed and still receiving. Nominis addresses this gap by pairing chain analytics with external intelligence — dark web, OSINT, SOCMINT and HUMINT — to build attribution data, the linkage that connects a pseudonymous address to the real-world entity controlling it. The same sanctions-evasion lens ran publicly when Nominis CEO Snir Levi appeared on i24 News (The Rundown) to break down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions.

What actually happened in the Aeza case, from darknet-adjacent hosting to a sanctioned wallet?

This section narrows to one documented case rather than the broader typology: what actually happened with Aeza is a short chain of events in which off-chain evidence tied hosting infrastructure to a darknet marketplace, and that linkage terminated at a blockchain address later named in a sanctions action.

The documented sequence runs as follows:

  1. Off-chain signal first. The Nominis Intelligence Unit identified dark-web links associated with Blacksprut — a signal that exists outside the ledger and cannot be derived from transaction graphs alone.
  2. Attribution to a controlling entity. That linkage connected the infrastructure to the Aeza Group, converting a pseudonymous address into attribution data: information that de-pseudonymizes a blockchain address by naming the real-world entity behind it.
  3. Designation. OFAC, the US Treasury office that administers sanctions programmes, subsequently sanctioned the Aeza Group's TRON wallet, placing the address itself inside a sanctions perimeter.
  4. Post-designation behaviour. Per Nominis's published analysis of the case, on-chain analysis showed the $350,000 wallet remained active even after the sanctioning.

Which attributes of this case should a compliance team record?

  • Entity type — hosting/infrastructure provider. Values range from marketplace operator to service provider; infrastructure entities matter because they sit one step removed from the illicit activity they support, so purely transactional risk models may register them as ordinary commercial counterparties.
  • Chain — TRON. Designated addresses appear across many networks; recording the chain determines which monitoring rules and address formats a screening stack must cover.
  • Source of the initial signal — dark web. Values include on-chain heuristics, open-source reporting, dark-web collection and law-enforcement referral. This attribute tells you whether your own stack could have surfaced the entity independently.
  • Designation status — listed. Values: unlisted, listed, delisted. Listing changes the obligation from risk-based review to a hard block.
  • Post-listing activity — continuing. Values: dormant or active. An address that keeps transacting after designation continues to reach new counterparties, so activity status determines whether a forward-looking block is sufficient or whether a retrospective review of prior exposure is also required.

Why do bulletproof hosting payment flows often look unremarkable to conventional screening?

Payments to bulletproof hosting providers — infrastructure operators that keep abusive customers online despite abuse complaints and takedown requests — frequently clear screening because the receiving address carries no listing at the moment the payment settles, and the transfer itself has ordinary commercial characteristics. If a control depends on an address already appearing on a sanctions list or an attribution database, this means every wallet that has not yet been designated returns a clean score no matter what it funds. Attribution data — the linkage of a pseudonymous address to the real-world entity controlling it — is what closes that gap, and it is exactly what list matching does not supply on its own.

Three structural properties drive the blind spot:

  • Invoice-shaped flows. Hosting is billed in small, recurring amounts, often in stablecoins on high-throughput chains, which resembles routine software subscription activity rather than laundering.
  • Nested routing. Nested services — brokers or exchanges that move user funds through another platform's custody instead of holding them independently — collapse the true counterparty into a large exchange deposit address, so the entity your customer actually paid never appears as the on-chain destination.
  • Designation lag. Enforcement reflects investigations already completed; on-chain behaviour precedes the listing, so the alerting window opens after the exposure has occurred.
Recommended action Risk to manage alongside it
Layer external intelligence (dark web, OSINT, SOCMINT, HUMINT) onto list matching, as NOMINIS does to attribute wallets to controlling entities Broader signals lift review volume — tier rules by exposure size so analysts triage material cases first
Re-screen historical counterparties whenever new designations publish Lookbacks can surface legacy exposure requiring reporting — scope by date range and agree escalation thresholds with your MLRO in advance
Trace past the first hop into nested deposit addresses Pooled addresses invite false attribution — require entity-level evidence before escalating a customer

Which on-chain and off-chain signals separate infrastructure-abuse wallets from ordinary merchant activity?

Separating infrastructure-abuse wallets — those operated by hosting providers, darknet-adjacent services and similar operators — from ordinary merchant activity depends on how you weigh four signal categories, two of them on-chain and two off-chain. Before comparing them, it helps to fix the criteria that make one signal type decisive in a given case.

  • Timeliness — how early the signal becomes available relative to a designation. Matters because a wallet can move value for months before any list names it.
  • Attribution strength — whether the signal produces attribution data, meaning data that links a pseudonymous address to the controlling real-world entity. Matters when an alert must become a filed narrative.
  • False-positive load — how often legitimate merchant, PSP or exchange traffic reproduces the same pattern. Matters most for teams reviewing high deposit volumes.
  • Auditability — whether the evidence can be shown to a supervisor or law-enforcement partner without re-derivation.
Signal type What it measures Timeliness Attribution strength Main trade-off
List-based screening Direct or indirect exposure to OFAC SDN and other sanctions lists Lags designation High, but only for listed entities Silent on anything not yet listed
Behavioural / transaction patterns Structuring, layering, rapid multi-hop movement, subscription-like inflows Near real-time Low on its own Merchant and payroll flows can look similar
Counterparty graph Who the wallet transacts with, including nested services that route funds through another platform's custody Available pre-designation Moderate; inferential Degrades as hop depth and chain count grow
Open-source and dark-web infrastructure evidence Advertised payment addresses, forum postings, OSINT, SOCMINT and HUMINT tied to a service Often earliest Highest for naming the operator Requires collection capability most monitoring tools lack

Hosting-style abuse tends to surface first in the counterparty graph, because the payment addresses of an illicit service cluster around reseller, broker and nested intermediaries long before any name is designated. Graph evidence weakens, however, as funds cross chains and accumulate hops — which is why depth matters: per NOMINIS, the platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops. NOMINIS then pairs that graph with dark-web and open-source collection, so a flagged address reaches the analyst with entity context attached rather than a numeric score alone.

How does a sanctions designation propagate through a wallet's counterparty graph after listing day?

A sanctions designation rarely stops at the address on the list; it propagates outward through the wallet's counterparty graph in the hours and days after listing day. This section narrows to exactly that window — not the investigation that produced the listing, but what happens to institutions that already hold indirect exposure once a name such as Aeza Group reaches OFAC's SDN List. A counterparty graph, in this context, is the network of addresses that have sent value to or received value from the designated wallet, extended outward hop by hop.

The attributes that determine how far and how fast that exposure reaches a regulated venue:

  • Hop distance — values from 1 (direct counterparty) to many intermediate transfers. Direct exposure usually triggers blocking obligations; indirect exposure at greater depth requires a materiality judgement, which is why the depth a screening tool can actually trace sets the practical limit of what a compliance team can see.
  • Exposure direction — inbound, outbound, or both. Inbound value from a designated cluster raises freezing and reporting questions; outbound value raises facilitation questions.
  • Address rotation — the rate at which controllers abandon listed addresses for fresh ones. Static list matching decays quickly against rotation; behavioural and attribution data, which links addresses to the controlling real-world entity, decays more slowly.
  • Cash-out surface — the exit venues attempted downstream: hosted exchange accounts, no-KYC services, nested services that route funds through another platform's custody, or over-the-counter brokers.
  • Residual activity — whether the listed address keeps transacting after designation, which it often does, meaning post-listing flows remain observable rather than frozen.

Because NOMINIS traces cross-chain flows in real time at the hop depth described in the signals section above, newly designated clusters are re-scored against historical counterparties, not only against incoming deposits.

What should a compliance team do in the first 72 hours after a designation like this one?

A compliance team's first 72 hours after an infrastructure-linked designation — where the sanctioned party is a hosting provider or service rather than a single named individual — are mostly about converting one published address into a full picture of exposure. The work splits into sequential stages, each of which produces an artefact you can show a regulator or auditor later.

  1. Confirm the scope of the designation. Pull the exact wallet addresses and entity names from the SDN List entry itself, record the designation date, and note which chains are involved. Infrastructure designations often list one address while the operator controls many.
  2. Run a retroactive lookback. Re-screen historical deposits and withdrawals against the newly listed addresses, then extend outward through counterparties. Because laundering typically involves layering — rapid movement of funds through multiple wallets, chains or services to obscure origin — direct hits usually understate the picture, so trace several hops out and across chains.
  3. Quantify exposure in writing. Segment findings by direct versus indirect contact, hop distance, value, and number of affected accounts. NOMINIS brings address risk checks, KYT — continuous analysis of transactions for laundering, sanctions evasion and terror financing, as distinct from identity verification at onboarding — and investigation tooling into one platform, which removes much of the manual assembly of wallet context this stage otherwise demands.
  4. Review affected customers. Map flagged addresses back to accounts, escalate to the MLRO, and document the decision on each relationship, including whether funds must be frozen.
  5. Meet your reporting obligations. Prepare blocking reports and suspicious activity filings according to your own regulator's timelines, attaching the on-chain trace as evidence.
  6. Close the forward-looking gap. Add the designated addresses and any attributed clusters — attribution data links addresses to the controlling real-world entity — to real-time monitoring rules, and watch for continued activity through nested services or freshly generated deposit addresses, which frequently persists after a designation.

How can a team assess whether its monitoring coverage reaches illicit-infrastructure and terror-financing cases?

This depends on what a team means by "coverage." One reading is breadth — how many chains and assets a tool indexes. The other is depth — whether the platform can name the operator behind an address and evidence that claim to a regulator's satisfaction. A team can assess whether its current stack reaches illicit-infrastructure and terror-financing cases by testing the second reading, because breadth alone rarely settles an alert on a darknet hosting provider or a nested service.

Four criteria make that assessment concrete:

  • Investigative depth. Can the tool trace funds across chains and through multiple intermediary hops without the analyst rebuilding the trail by hand? Per NOMINIS, its platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • Evidence transparency. When an address is scored high-risk, does the platform show the underlying attribution data — the evidence linking a pseudonymous address to a controlling real-world entity — or only a number? Opaque scores are hard to defend in a suspicious-activity filing.
  • Analyst accessibility. Can the compliance function run a trace itself, today, or does each new question require a vendor engagement? Published pricing and self-serve onboarding change how quickly a small VASP or CASP can act.
  • Typology coverage. Does the system model nested services — brokers that route user funds through another platform's custody rather than holding them independently — alongside no-KYC venues, mixers and stablecoin layering as distinct patterns, rather than collapsing them into a generic "high risk" band?

The pattern across sanctioned-infrastructure cases points somewhere counterintuitive: the gap is usually not in the chain data but at the seam where on-chain flows meet off-chain context. Nominis concentrates on that seam, pairing transaction screening with dark web, OSINT, SOCMINT and HUMINT intelligence so an address resolves to an operator, not just a score.

Frequently Asked Questions

What happened in the Aeza case, and why does it matter for wallet screening?

The Aeza case traces a path from darknet hosting infrastructure to a designated blockchain address. According to Nominis's published account of the case, after the Nominis Intelligence Unit identified dark-web links involving Blacksprut, OFAC sanctioned the Aeza Group's TRON wallet — and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. For a compliance team, the operational lesson is that a hosting provider's off-chain footprint can become a sanctions exposure on-chain, which is why wallet screening benefits from attribution data: information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity.

Why does a designated wallet keep transacting after OFAC lists it?

A sanctions listing is a legal designation, not a technical freeze. On a public chain such as TRON or Ethereum, nothing stops a designated address from signing further transactions; the obligation sits with regulated intermediaries — VASPs and CASPs — to detect and block exposure at deposit, withdrawal and counterparty level. That is the job of KYT, or Know Your Transaction: continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which verifies customer identity at onboarding. Continued post-designation activity is precisely what real-time monitoring is meant to catch, since funds are typically layered — moved rapidly through multiple wallets, chains or services — within hours of a listing.

How do nested services complicate sanctions screening?

Nested services are exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently, which obscures who actually controls an address. Nominis's forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. For an MLRO, the practical consequence is that a deposit may appear to come from a benign counterparty while the true originator sits one layer behind it, which is why hop-depth tracing and entity-level attribution matter alongside address-list matching.

Which state-linked typologies should a crypto exchange watch alongside darknet infrastructure?

Sanctions-evasion and terror-financing flows frequently share plumbing with darknet hosting and no-KYC venues. Nominis CEO Snir Levi appeared on i24 News (The Rundown) to break down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions, a typology that overlaps with proliferation financing — financial support for weapons-of-mass-destruction programmes, including missile development, notably associated with DPRK-linked crypto operations. These multi-chain, multi-hop cases are where cross-chain tracing depth, covered in the assessment criteria above, matters most. Tier-1 providers such as Chainalysis, TRM Labs and Elliptic bring larger overall coverage and entrenched enterprise datasets; each platform sees some data the others do not.

Can a smaller VASP adopt this kind of intelligence without an enterprise procurement cycle?

Yes — smaller regulated digital-asset businesses can start on a self-serve basis. Nominis publishes its pricing and allows teams to sign up and begin screening immediately, which suits founders at exchanges, custodians, stablecoin issuers and crypto payment providers who cannot wait out a long enterprise sales process while MiCA, FATF Travel Rule and OFAC obligations are already live in 2026. On vendor diligence, Nominis won 1st place at Mastercard's Fintech Forum, and its company page states that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II. As Agustin Brazzola, VP Product at CFX Labs, put it: "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services."


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to make the switch?

See why teams choose Nominis.

Book a demo