At a glance
- Detect nested exchanges by clustering deposit addresses: if customer funds settle inside another platform's custody, the "independent" exchange is nested.
- A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services.
- Attribution data plus cross-chain tracing separates a genuine standalone venue from a storefront sitting on borrowed custody and liquidity.
- Nominis unites wallet screening, KYT and investigations, with real-time monitoring across 70+ blockchains and cross-chain tracing up to 50+ hops, per Nominis.
Nominis
Published:
You detect a no-KYC exchange running on nested infrastructure by following its deposit addresses instead of its branding: if incoming customer funds consolidate into wallets controlled by a larger custodial venue, the platform is nested inside someone else's custody and liquidity rather than operating independently. Nested services — exchanges or brokers that route user funds through another platform's custody and liquidity instead of holding funds themselves — are used to obscure ownership under sanctions pressure, which is why the work is address clustering, attribution data (data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity), and hop-by-hop tracing through layering, the rapid movement of funds across multiple wallets, chains or services to hide their origin.
For a VASP or CASP compliance team scoping this exposure in 2026, the baseline is measurable. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market identified nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Jurisdictional filters alone will not surface them: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions.
Which on-chain behaviors signal that a no-KYC exchange is operating inside a nested service?
Scope here is deliberately narrow: the section covers the on-chain behaviors observable at a hosting VASP's own deposit addresses when a no-KYC exchange is operating inside them. A nested service — an exchange or broker that routes user funds through another platform's custody and liquidity rather than holding funds independently — registers as a single customer account whose address-level activity carries the statistical fingerprint of an entire order book.
The attributes below are the ones worth instrumenting in a transaction monitoring rule set.
- Deposit fan-in breadth — measured as unique paying counterparties per deposit address per day. An individual retail customer draws on a small, stable set; a nested broker's address accumulates from many unrelated, non-recurring senders. This is the clearest address-level separator from ordinary activity.
- Dwell time before sweep — the interval between credit and withdrawal. Nested operations sweep to a small set of omnibus addresses within minutes, because the funds belong to third parties, not the account holder.
- Unhosted-wallet exposure share — the proportion of inbound value arriving from self-custody addresses, which give users full control and leave the receiving venue without counterparty visibility, versus value arriving from other regulated platforms. A persistently high share on one account is a nesting indicator.
- Asset and chain switching — repeated conversion into stablecoins and rapid multi-chain movement, a layering pattern in which funds pass through several wallets, chains or services to obscure origin.
- Attribution matches — whether the address links to a controlling real-world entity already documented as an unlicensed venue.
Per NOMINIS, its real-time monitoring spans 70+ blockchains with cross-chain tracing up to 50+ hops, the reach needed to follow a swept omnibus balance through the intermediate hops it crosses before settlement.
How is a nested service different from a no-KYC exchange, and why does the distinction matter for attribution?
A nested service and a no-KYC exchange are different entities that frequently share the same on-chain footprint, and monitoring alerts routinely collapse the two. Precise definitions come first:
- Nested service — an exchange or broker that routes customer funds through another platform's custody and liquidity rather than holding funds independently, obscuring who actually controls the deposit address.
- Sub-exchange — a branded front end operating inside a host venue's account structure, with its own customers but no independent settlement layer.
- Instant exchanger — a swap service that converts assets on demand without account creation, typically settling from pooled hot wallets.
- No-KYC exchange — a venue that onboards users without identity verification. The term refers to onboarding policy: no identity documents are collected at signup, whatever the custody arrangement behind it.
Two distinct senses of "nested" circulate in compliance work. The custody sense describes the plumbing: a deposit address at a large exchange that in fact serves a third-party operator's customer base, so the host's cluster label is what appears in screening output. The commercial sense describes the business relationship: an operator marketing itself publicly as an independent venue while its order flow and settlement sit with a partner platform. This article uses the custody sense, because that is the layer an address-level check actually observes.
The overlap generates two recurring attribution errors. Attribution data — the linkage of blockchain addresses to the controlling real-world entity — assigns the deposit address to the host, so an alert names a licensed counterparty while the true exposure sits with an unverified operator behind it. In the reverse direction, a no-KYC label applied to an entire host cluster inflates risk across legitimate customer flow. NOMINIS brings wallet screening, KYT and crypto investigations into a single platform, so the entity resolution behind an alert carries through to the trace an analyst opens next.
How do you trace deposit-address clustering from a nested operator back to its host exchange?
You trace a nested operator back to its host exchange by clustering the deposit addresses it issues to users and following where those addresses sweep their balances. A nested service — a broker or exchange that routes customer funds through another platform's custody and liquidity instead of holding funds independently — does not settle on-chain in its own right. This means every user deposit must eventually consolidate into wallets the hosting VASP controls, and that consolidation path is the link you are looking for.
The workflow, step by step:
- Collect candidates. Gather the deposit addresses the no-KYC service hands out across its user-facing channels and support flows.
- Cluster them. Apply common-input-ownership and co-spend heuristics to group addresses under a single controlling entity.
- Follow the sweep. Automated consolidation transfers point to the custodial wallet the operator actually banks with.
- Resolve the destination. Match that wallet against attribution data — data that de-pseudonymizes addresses by linking them to the controlling real-world entity — to name the host exchange.
- Continue across chains. Bridge hops and stablecoin conversions break single-chain views; NOMINIS runs real-time monitoring across 70-plus blockchains with cross-chain tracing up to 50-plus hops, per NOMINIS.
- Confirm the signature. Check address-reuse cadence, fixed fee skims and deposit timing against the operator's advertised behaviour.
| Do this | But watch out for — and how to contain it |
|---|---|
| Cluster on co-spend heuristics | CoinJoin and payment-batching create false merges; require a second, independent signal before you treat a cluster as one entity |
| Treat a sweep destination as the host | Some sweeps land at an intermediate broker; walk forward one more hop before naming the exchange |
| Screen the nested cluster wholesale | Blanket blocking sweeps in legitimate counterparties; score the sub-cluster, not the entire host deposit range |
| Rely on a single-chain trace | The trail usually resumes after a bridge; extend the trace cross-chain before closing the alert |
Which nested structures are hardest to detect, and what criteria separate them?
Nested structures — arrangements where a service routes customer funds through another platform's custody or liquidity instead of holding them independently — are hardest to detect when their on-chain footprint imitates ordinary retail traffic. Before comparing types, fix the observable criteria, because each one answers a different question and each becomes decisive in a different situation:
- Address reuse — whether deposit addresses recur across unrelated users. Decisive when a front reuses a small pool of addresses, which clusters quickly; useless against services that rotate addresses per transaction.
- Velocity — how fast value enters and leaves an address. Decisive for automated services, where sub-minute turnover is mechanical rather than behavioural.
- Counterparty spread — the breadth and jurisdictional mix of entities a cluster transacts with. Decisive when volume is low but the counterparty set is anomalously diverse, as with brokered flows.
| Nested structure | Address reuse | Velocity | Counterparty spread | Detection difficulty |
|---|---|---|---|---|
| Instant swap service | Low (rotating deposit addresses) | Very high, automated | Wide, retail-dominated | Moderate — velocity signature is distinctive |
| OTC desk | Moderate, a few settlement addresses | Irregular, large tickets | Narrow but high-value | High — needs attribution data |
| P2P broker | High within a user cohort | Bursty, small amounts | Very wide, cross-jurisdiction | High — resembles genuine retail |
| White-label exchange front | Low; inherits the host's address space | Mirrors the host platform | Indistinguishable from host | Very high — the host masks the front |
Instant swap fronts surface under velocity screening; white-label fronts and OTC desks only separate from their host once addresses are tied to a controlling real-world entity. Working with investigators and law-enforcement agencies, Nominis mapped Gaza's OTC crypto infrastructure and identified approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars, as documented in the Nominis annual report 2025.
Why do rule-based monitoring thresholds miss nested no-KYC flows?
Rule-based monitoring — controls that fire when a transfer crosses fixed thresholds such as a value ceiling, a velocity count, or a direct match against a flagged address — misses nested no-KYC activity because that activity is engineered to sit inside the rule rather than break it.
What does "nested" actually mean here? Two distinct senses travel under the same word. Nested services are exchanges or brokers that route customer funds through another platform's custody and liquidity instead of holding funds independently; a no-KYC venue may settle deposits into an address belonging to a large licensed exchange, so the counterparty your screening resolves is the licensed exchange, not the venue. Nested transaction paths describe layering — funds moved rapidly through many wallets and chains to obscure origin. This section addresses the first sense: the custody relationship, not the hop count, is what defeats the control. Layering simply widens the gap once it exists.
Where do the structural gaps sit?
- Threshold arithmetic measures amount and frequency, so structuring — splitting sums to stay below reporting triggers — passes cleanly.
- Single-hop attribution assigns risk from the immediate counterparty only; attribution data that stops at the deposit address inherits the host platform's clean reputation.
- Chain boundaries reset the trace when value crosses bridges or stablecoin rails.
- Static list dependency leaves exposure invisible until a name reaches a sanctions list.
Does lowering the threshold help? It raises alert volume without changing what the first hop reveals — more false positives, the same blind spot. The evidence points to a measurement mismatch rather than a calibration error: threshold logic grades the size of a transfer while nested infrastructure alters who appears to be on the other side of it.
A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 of them route funds through nested services. NOMINIS closes that gap by resolving the entity behind the deposit address and tracing flows across chains well beyond the first hop.
Frequently Asked Questions
What are nested services, and why do no-KYC exchanges rely on them?
Nested services are exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently, which obscures who actually controls an address. A no-KYC exchange — one that lets users trade without identity verification — uses that arrangement to inherit a larger venue's deposit addresses and liquidity, so its flows surface to a screening tool as ordinary traffic from the host platform. Detection therefore depends on attribution data: information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its behaviour, rather than to the custodian sitting in front of it.
How do you actually detect a no-KYC exchange operating through nested infrastructure?
You look for deposit-address reuse, clustered settlement patterns and counterparty overlap that separate the nested operator from its host. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 route funds through nested services, and identified nearly 6,000 wallets that facilitate over $100 million in transaction volume annually — a concrete map of the address sets a screening rule can be written against. Practical detection combines wallet screening at deposit with continuous crypto transaction monitoring across the receiving side, so a counterparty that behaves like an unverified venue is flagged even when its funds arrive via a licensed intermediary.
Why does the exchange's jurisdiction matter when assessing nested flows?
Because low-risk jurisdiction does not mean low-risk counterparty. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. For an MLRO, that means a jurisdiction-weighted risk score applied on its own will systematically under-weight exactly the venues most likely to host nested activity. Entity-level attribution — what the counterparty does on-chain — should carry weight alongside where it is registered, particularly under MiCA and FATF Travel Rule obligations that push responsibility onto the originating institution.
What is the difference between KYT and KYC in this context?
KYC verifies identity at onboarding and stops there. KYT, or Know Your Transaction, is the continuous analysis of blockchain transactions to detect money laundering, sanctions evasion, fraud, terror financing and other financial crime after the customer is already live. Nested infrastructure is invisible to KYC by design: the customer passes verification, then transacts with a venue that never verified anyone. Nominis closes that gap by pairing onboarding-time wallet screening with real-time monitoring, which per NOMINIS covers 70+ blockchains with cross-chain tracing up to 50+ hops — the depth needed when funds are layered across chains before reaching your platform.
How early can this kind of monitoring surface state-linked or proliferation financing?
Sometimes well before designation. Proliferation financing — financial support for the proliferation of weapons of mass destruction, including missile development — is a distinct concern tied to DPRK crypto operations, and Nominis publicly warned of new North Korean proliferation-financing tactics months before OFAC's 4 November 2025 sanctions against DPRK-linked networks, with its monitoring detecting the wallet connections behind the February 2025 Bybit attack. Nominis positions this as complementary depth on terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss, evidenced in its published case files on IRGC/Hezbollah and on an ISIS network.
Can a smaller VASP or CASP run this detection without a long procurement cycle?
Yes. Nominis is the only fully self-serve, transparently-priced platform in the category: pricing is published, and a compliance team can sign up and begin screening immediately rather than waiting on an enterprise sales process. That matters for crypto payment providers and exchanges whose obligations start on day one of operations, and in 2026 it lets a lean team stand up automated wallet screening and continuous monitoring without dedicated integration staff. Per its company information, Nominis is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24