At a glance
- Hop depth should be set by risk type: sanctions and terror-financing exposure usually appears several hops out, not at hop one.
- Direct counterparty screening alone leaves gaps that mixers, nested services and cross-chain bridges are designed to exploit.
- Crypto exchanges and payment providers need depth calibrated per asset, corridor and customer segment, not one fixed hop limit.
- NOMINIS CEO Snir Levi told Swiss business newspaper Finanz und Wirtschaft that criminals increasingly use stablecoins.
Nominis
Published:
For regulated crypto exchanges and crypto payment providers, indirect exposure screening should extend well past a shallow default look at the immediate counterparty, because sanctions-evasion, terror-financing and proliferation-financing structures are built specifically to survive a shallow look. A hop is a single transfer between addresses; indirect exposure is the risk that reaches your customer through intermediaries rather than from a flagged counterparty directly. The practical answer in 2026 is that depth should be a policy variable set per risk type, asset and corridor — shallow for routine retail spot flows where attribution data is dense, and materially deeper for stablecoin corridors, over-the-counter desks, unhosted wallet withdrawals and jurisdictions where your own risk assessment already flags concentration. That framing matters for this segment in particular: exchanges and payment service providers carry Know Your Transaction obligations — the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from identity checks performed once at onboarding — and those obligations are judged on what the monitoring was capable of detecting. The stablecoin dimension is not incidental. Nominis CEO Snir Levi, interviewed by the Swiss business newspaper Finanz und Wirtschaft, described how criminals increasingly use stablecoins, which is precisely the flow class where value moves quickly across chains and bridges and where a two-hop screen loses the trail. Nominis is built for that problem: wallet screening, Know Your Transaction monitoring and crypto investigations in one platform, with published, self-serve pricing so a smaller VASP can configure depth without a long enterprise procurement cycle. The sections that follow map the decision — what depth buys you, what it costs in analyst time, how to tune it by segment, and how to document the choice for a supervisor who asks why you stopped where you stopped.
How many hops should indirect exposure screening actually cover?
How many hops an indirect exposure check should cover depends on what the check is for: automated deposit and withdrawal decisions are normally resolved within a shallow hop range, while investigative tracing of the same funds runs far deeper. A hop is a single transfer between two addresses; indirect exposure is risk inherited from an address your customer never dealt with directly but which sits a few transfers away on the funds' path. This section deals only with hop depth as a screening parameter for regulated digital-asset businesses — exchanges, custodians, payment providers and OTC desks — not with evidentiary tracing for law enforcement.
Each additional hop widens the reachable address set and spreads value attribution across more paths, so the share of a deposit traceable to any single upstream source falls. Signal does not decay uniformly: it holds where an intermediate address carries attribution data — information that links an address to the real-world entity controlling it — and thins where the path runs through unattributed pass-through wallets.
| Attribute | Range or values | Why it matters to the decision |
|---|---|---|
| Screening depth | Shallow, fixed hop count applied automatically | Keeps deposit decisioning deterministic and reviewable by an MLRO |
| Investigative depth | Extended multi-hop, cross-chain tracing triggered on escalation | Lets an analyst follow layering past the point where automated scoring stops |
| Intermediary type | Hosted wallet, unhosted wallet, nested service, mixer, bridge | A nested service — a broker routing funds through another platform's custody — can hide ownership one hop from your customer |
| Attribution coverage | Attributed entity vs unattributed address | Determines whether an extra hop adds a name or only another address |
| Direction | Inbound deposits, outbound withdrawals | Outbound paths carry different sanctions and terror-financing obligations |
Cross-chain bridges restart hop counting on the destination chain unless the tracing engine links both legs, so a depth policy documented in 2026 should state explicitly how bridged legs are counted and where escalation to manual review begins.
What exactly counts as a hop in a blockchain exposure trace?
This depends on what you mean by "hop" — the word carries two distinct meanings in exposure screening, and they produce different counts on the same money trail.
Transaction hop. One on-chain transfer from one address to the next. On UTXO chains such as Bitcoin, where value moves as discrete unspent outputs, a single transaction can consume many inputs and create many outputs, so one hop may fan value across several fresh addresses simultaneously. On account-based chains such as Ethereum or TRON, value moves between account balances, and a single smart-contract call can trigger internal transfers that a simplistic trace collapses into one hop. Example: a Bitcoin transaction paying a merchant and returning change to two new addresses is one hop that produces three downstream branches.
Entity hop. One movement between distinct real-world controllers, resolved through cluster attribution — the grouping of addresses under a single controlling entity using co-spend heuristics, deposit-address patterns and attribution data, meaning data that de-pseudonymizes blockchain addresses by linking them to the entity that controls them. Example: funds crossing five addresses that all belong to one exchange's deposit infrastructure register as five transaction hops and a single entity hop.
This article counts hops at the entity level, because that is the unit a risk score and a suspicious-activity narrative both rest on. Three related terms sit on top of that counting:
- Direct exposure — the counterparty sits one hop from the screened address.
- Indirect exposure — illicit or sanctioned value reaches the address through one or more intermediaries, so the counterparty appears at hop two or beyond.
- Counterparty — the attributed entity controlling the address at a given hop, rather than the raw address string.
Nested services complicate both counts: a broker operating inside another platform's custody can present as a single attributed counterparty while several different controllers sit behind it.
Which factors should determine hop depth for a given asset, chain, or case type?
Several factors determine how deep a hop trace should run, and defining them before any comparison keeps the calibration auditable. A hop is one transfer between two addresses; indirect exposure is risk that reaches your customer through intermediaries rather than through the counterparty they transacted with directly.
The criteria worth fixing in policy first:
- Chain type — account-based chains, UTXO chains with change outputs, and bridge or wrapped-asset routes consume hop budget at very different rates, so an identical depth setting yields unequal reach.
- Transaction value and volume — high-frequency retail deposits and low-value flows cannot absorb deep manual review; large or irregular transfers justify it.
- Counterparty category — a hosted (custodial) wallet run by a licensed venue resolves quickly; unhosted (self-custody) wallets and nested services, which route funds through another platform's custody and liquidity rather than holding them independently, hide ownership behind additional hops.
- Case trigger — routine onboarding screening, a monitoring alert, and a sanctions or law-enforcement request carry different evidentiary expectations.
- Risk appetite — documented tolerance, approved at board level, is what makes any chosen depth explainable to a supervisor.
- Jurisdiction — jurisdictional risk rating cuts against intuition here: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions.
| Criterion | Shallow trace (1–2 hops) | Deeper multi-hop trace |
|---|---|---|
| Chain type | Adequate on a single chain, no bridging | Needed where funds cross chains or wrapped assets |
| Value and volume | Sustainable at retail volumes | Reserved for material or irregular flows |
| Counterparty | Works for hosted venues | Required for unhosted wallets and nested services |
| Case trigger | Routine screening | Alerts, sanctions and terror-financing enquiries |
| Jurisdiction | Weak where low-risk venues are misused | Surfaces layering behind nominally low-risk venues |
| Analyst cost | Low, high false-positive sensitivity | Higher, offset by automation |
According to Nominis, its platform performs real-time monitoring and multi-hop cross-chain tracing with automated wallet screening, so the deeper traces these case types call for do not have to be assembled by hand.
Why do terror-financing and sanctions-evasion patterns tend to surface beyond the first hop?
Terror-financing and sanctions-evasion patterns tend to surface beyond the first hop because the actors behind them deliberately insert intermediaries between a monitored deposit and the wallet that originally controlled the funds. If those intermediaries are placed on purpose, then a screen that inspects only the immediate sending address will return a clean result for funds that are not clean.
As of 2026, the documented typologies that place illicit counterparties two or more hops away from a monitored wallet include:
- Layering — the rapid movement of funds through multiple wallets, chains or services to obscure their origin.
- Fresh wallets — newly created addresses with no transaction history, so attribution data (information linking an address to the real-world entity controlling it) has nothing yet to attach to.
- Cross-chain bridges — value leaves one chain and reappears on another, interrupting a single-chain trace.
- Mixers and privacy pools — pooled deposits and withdrawals designed to break the link between sender and recipient.
- Donation collection addresses — publicly solicited addresses that are swept into intermediary wallets before funds reach a cash-out venue.
- Nested services — exchanges or brokers that route customer funds through another platform's custody and liquidity rather than holding funds independently, so the deposit a monitored venue sees belongs to the host platform, not to the underlying user.
| Do this | But watch out for | Mitigation |
|---|---|---|
| Extend indirect exposure screening past the immediate counterparty | Each extra hop enlarges the candidate set and the review queue | Weight each hop by the entity type at that node, so ordinary pass-through addresses carry less alert weight than sanctioned or terror-linked clusters |
| Trace across chains, not only within one | Bridge outputs can be joined to the wrong recipient | Require attribution evidence before treating a cross-chain match as the same actor |
| Record the hop depth applied to each alert | Undocumented depth is hard to defend in examination | Log the configured depth and the reason for it alongside the disposition |
How can teams add hop depth without drowning analysts in false positives?
Teams can add hop depth without drowning analysts by controlling what travels along each hop rather than simply how far the trace runs. Depth becomes usable when every additional hop is filtered through value, attribution quality and counterparty type before it ever produces an alert.
| Do this | But watch out for — and how to contain it |
|---|---|
| Value-weighted tracing — follow the share of funds along each path instead of every branch equally | Structuring (splitting large sums into many small transfers) dilutes weight per path; aggregate by destination cluster, not per transaction |
| Attribution quality thresholds — escalate only where attribution data (information linking an address to the controlling real-world entity) meets a set confidence bar | Unattributed addresses can read as clean; route unknown clusters to a review queue rather than auto-clearing them |
| Counterparty typing — score by service category (mixer, no-KYC venue, nested service) rather than by distance | Nested services route funds through another platform's custody, inheriting the host's reputation; type the underlying operator, not the front end |
| Materiality floors — suppress exposure below a documented monetary or percentage floor | Floors that never change become predictable; review and record them on a fixed governance cycle |
| Alert triage tiers — separate auto-clear, analyst review and investigation escalation | Tiering can bury genuine cases; sample-test auto-cleared alerts periodically |
Does deeper screening automatically mean more alerts? Not necessarily. The pattern across published on-chain casework suggests alert volume is governed less by hop count than by how many counterparty types the screening model can actually name: depth without typing multiplies noise, while depth with typing concentrates it into a smaller, better-evidenced queue.
What if the compliance team is only two or three people? Automate the deterministic layer. Nominis cuts manual compliance effort through automated wallet screening and continuous monitoring, so a small team entering its 2026 review cycle spends its hours on typed, material, well-attributed exposure rather than assembling wallet context by hand.
Frequently Asked Questions
How many hops should indirect exposure screening cover?
Hop depth in indirect exposure screening should be set by risk rather than by a single fixed number, and a tiered policy is the defensible design: a shallow look for routine retail flows and a much deeper trace for counterparties tied to sanctions, terror financing or high-risk jurisdictions. Indirect exposure means value that reached your customer's wallet through intermediaries rather than straight from the risky source. The practical constraint is tooling: your policy can only be as deep as your platform traces. According to Nominis, its platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which lets a compliance team set depth by typology instead of by technical ceiling.
What exactly counts as a hop, and where should the count begin?
A hop is one transfer of value between two addresses, so a five-hop trace follows funds through five sequential on-chain movements away from the address you are screening. Counting normally begins at the deposit address your customer used, then walks backwards along the inbound path or forwards along the outbound path. Two details decide whether hop counts are comparable across vendors: whether internal transfers inside a single service are counted as hops, and whether consolidation into a pooled exchange wallet terminates the trace. Document both choices in your KYT policy — KYT, or Know Your Transaction, being the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as opposed to identity checks performed once at onboarding.
Why do nested services force deeper hop coverage?
Nested services — exchanges or brokers that route customer funds through another platform's custody and liquidity instead of holding funds independently — absorb hops without showing ownership, which is why shallow screening frequently returns a clean result on funds that are anything but. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 of them route funds through nested infrastructure, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Against that structure, a two-hop or three-hop limit often stops at the nesting layer itself. Deeper tracing paired with attribution data — data that links an address to the real-world entity controlling it — is what turns an anonymous intermediate address into a named counterparty.
How do stablecoins and cross-chain movement change the calculation?
Stablecoins and cross-chain movement stretch the effective distance between illicit origin and customer deposit, because each bridge, swap or chain change can add hops that a single-chain tool simply does not follow. Nominis CEO Snir Levi was interviewed by the Swiss business newspaper Finanz und Wirtschaft on how criminals increasingly use stablecoins, a pattern that matters directly for depth policy: dollar-denominated tokens move across multiple networks without the price friction that used to slow layering. For exchanges, custodians, stablecoin issuers and crypto payment providers, the operational requirement is that hop counting survives a chain transition — otherwise the trace resets at every bridge and the reported depth overstates real coverage.
Does deeper tracing automatically mean more false positives?
Deeper tracing does not have to mean more false positives, provided exposure is weighted rather than treated as binary. Sound practice applies value-share weighting (how much of the received amount actually originates from the flagged source), decay by distance, and entity type — a pass through a large custodial exchange carries different meaning from a pass through a mixer. Jurisdictional context matters too: Nominis research found that illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions, so a low-risk domicile alone is a weak reason to shorten a trace.
How should sanctions and terror-financing typologies shape hop policy?
Sanctions-evasion and terror-financing typologies usually justify the deepest hop settings a VASP or CASP operates, because these networks deliberately insert intermediaries between designated entities and the regulated on-ramp. On i24 News (The Rundown), Nominis CEO Snir Levi broke down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions — flows that reach a licensed platform several transfers removed from any listed address. Nominis is built for exactly these cases: it surfaces terror-financing, sanctions-evasion and broader illicit-activity cases that larger Tier-1 platforms can miss — complementary depth rather than blanket superiority, since each platform sees some data the others do not — as shown in its published work on Herzallah/Hamas, IRGC/Hezbollah, and an ISIS network whose $100M-plus flows Nominis traced before the names reached OFAC's SDN List. Firms should encode that asymmetry in policy: named-risk typologies get maximum depth, routine retail flows get a proportionate look.
How quickly can a smaller VASP start screening counterparties?
Nominis is fully self-serve with published pricing: a compliance team can sign up and begin wallet screening immediately, without an enterprise procurement cycle. That matters where monitoring obligations arrive before a dedicated procurement function exists. Screening, KYT and investigation tooling sit in the same platform, so a smaller exchange or payment provider can start with address screening and extend into continuous monitoring and money-trail tracing without re-tooling or a second vendor onboarding.
When does staying on your current monitoring platform make sense?
If your existing Tier-1 deployment is embedded in case management, alerting and regulatory reporting workflows, and your risk appetite centres on general laundering typologies already well covered, a migration in 2026 may create more operational disruption than it resolves. One option in this position is to run a second layer for specific exposures — sanctions, terror financing, nested counterparties — rather than replacing the incumbent. Contract timing, API rework, historical case continuity and retraining of analysts all belong in that calculation.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24