For a regulated crypto exchange or crypto payment provider, adequate blockchain coverage means three things at once: every chain and token standard you actually support, the chains and bridges that funds realistically move to after they leave you, and enough tracing depth to follow those funds through the layering hops in between. A chain count on a vendor datasheet is not the measure — a monitoring stack that watches thirty networks but stops tracing after a handful of hops will lose a laundering trail faster than one with narrower breadth and deeper attribution data, meaning data that links a pseudonymous address to the real-world entity controlling it. That is why coverage in 2026 is best assessed on three axes: breadth (how many networks are screened), depth (how far cross-chain tracing follows a fund flow), and attribution quality (whether the flagged counterparty is identified as a nested service, an OTC broker, a mixer, or a sanctioned entity). NOMINIS states that its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, combining wallet screening, KYT — the continuous analysis of blockchain transactions for laundering, sanctions evasion and terror financing, as distinct from identity checks at onboarding — and investigations in one system. The sections below turn each axis into a concrete requirement you can test a vendor against.
What does blockchain coverage actually mean inside an AML program?
Blockchain coverage in financial-crime compliance comprises two distinct elements: the breadth of ledgers and assets a screening system can see, and the depth to which it can follow value once it moves. This section defines what an exchange or crypto payment provider should count when auditing coverage.
Transaction monitoring coverage describes rules, thresholds and typologies applied to activity you already observe. Blockchain coverage describes whether that activity is observable at all. A perfectly tuned rule set on an unsupported chain detects nothing.
The attributes below define the coverage surface a VASP or CASP should document:
| Attribute | Typical range or values | Why it matters |
|---|---|---|
| Supported chains | From a few major ledgers to dozens of networks | Unsupported chains are silent blind spots, not clean flows |
| Asset types | Native coins, ERC-20/TRC-20 tokens, stablecoins, NFTs | Stablecoins carry a growing share of illicit value movement |
| Bridges and cross-chain paths | None, single-bridge, or full cross-chain tracing | Layering — rapid movement through wallets, chains and services to obscure origin — defeats single-chain views |
| Screening depth (hops) | Direct counterparty only, or deep multi-hop tracing | Shallow depth misses funds routed through intermediary wallets |
| Attribution data | Data linking addresses to the controlling real-world entity and its activity | Converts a pseudonymous address into an entity you can risk-rate |
| Wallet type handling | Hosted (custodial) vs unhosted (self-custody) | Unhosted wallets create visibility gaps that Travel Rule workflows alone do not close |
| Refresh cadence | Batch lists to real-time KYT | KYT — continuous analysis of transactions for laundering, sanctions evasion and terror financing — needs live data, unlike KYC's one-time identity check |
Which chains, tokens, and bridges create the most AML exposure?
Coverage breadth is decided by a narrow set of exposure vectors: the chains that carry the highest illicit volume, the tokens criminals actually use to move value, and the bridges that move funds between networks. The scope is deliberately narrow — not typologies in general, but which specific assets and infrastructure a VASP or CASP must see before its screening scope can be called adequate.
Stablecoins sit at the centre. NOMINIS CEO Snir Levi, interviewed by Finanz und Wirtschaft, described how criminals increasingly use stablecoins — dollar-pegged tokens on high-throughput networks are the practical unit of laundering for many illicit flows.
| Exposure vector | What varies (the attribute range) | Why it dictates coverage |
|---|---|---|
| Chains | Single-network vs. multi-network support | Funds exit whichever network you cannot see |
| Tokens | Native assets, stablecoins, wrapped and bridged tokens | Screening must reach the token layer where the value actually sits |
| Bridges and swap services | Custodial bridges, decentralized bridges, cross-chain swap DEXs | A bridge hop breaks single-chain tracing; NOMINIS follows the trail across networks instead of stopping at the boundary |
| Mixers and privacy tools | Pool mixers, privacy chains, coin-swap intermediaries | Determines whether exposure is scored as direct or indirect |
| Nested services | Brokers routing funds through another platform's custody rather than holding funds independently | Ownership is obscured, so attribution data — the link between an address and the controlling real-world entity — becomes the reliable signal |
Nested infrastructure is measurable: a Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Screening that stops at the deposit address misses that layer entirely.
How much coverage does a risk-based AML program really need?
A risk-based program needs blockchain coverage matching its exposure profile — the chains, assets and counterparties its customers actually touch. "Risk-based" means calibrating controls to measured exposure rather than applying uniform effort everywhere.
What does "coverage" actually mean?
Two different things travel under the same word:
- Breadth (chain and asset coverage). How many networks, tokens and bridges a screening tool can see. A stablecoin issuer settling on several networks has a breadth problem when a customer withdraws to an unsupported chain.
- Depth (tracing and attribution coverage). How far a transaction can be followed — hop count across chains, plus attribution data linking pseudonymous addresses to controlling real-world entities. A platform can support a chain and still stop tracing two hops from a nested service.
Which inputs should size the requirement?
| Sizing input | Question to answer | Effect on coverage |
|---|---|---|
| Customer base | Retail, institutional, or high-risk corridors? | Drives attribution and jurisdiction depth |
| Product mix | Custody, payments, OTC, staking? | Determines which chains are in scope |
| Jurisdictions | Which regimes — MiCA, FATF Travel Rule, OFAC? | Sets reporting and sanctions-screening obligations |
| Volume thresholds | Where do structuring patterns hide? | Sets alert sensitivity and review capacity |
Jurisdiction is easy to underweight: Nominis research found illicit actors are 12x more likely to use crypto exchanges in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Low-risk domicile is not a reason to narrow coverage.
Full-chain coverage suits businesses with open deposit rails and unpredictable inflows. Targeted coverage — a defined chain set with deeper tracing — suits single-network payment providers. Capability classes follow: wallet screening, continuous transaction monitoring, cross-chain tracing and attribution.
How do blockchain analytics coverage models compare?
Blockchain analytics coverage is an architecture choice; four models trade off predictably. Fix criteria and weighting before comparing. Chain breadth determines whether assets are screened at all; weight it highest—an unmonitored chain is a blind spot no tuning can fix. Attribution quality—linking pseudonymous addresses to real-world entities—decides whether alerts are actionable or noise. Latency matters for pre-transaction wallet screening at deposit and withdrawal. Cost and audit defensibility (can you show supervisors a reproducible trail?) determine whether the model survives examination.
| Coverage model | Chain breadth | Attribution quality | Latency | Cost profile | Audit defensibility |
|---|---|---|---|---|---|
| Single-vendor analytics | Limited to vendor's supported chains | Consistent, but inherits one vendor's blind spots | Low | Predictable, often enterprise-tier | Strong — one evidence chain |
| Multi-vendor stacking | Widest, via union of catalogues | Highest — cross-checks contradictory verdicts | Low, but reconciliation adds work | Highest; duplicated licences | Strong if arbitration logic is documented |
| In-house node indexing | Whatever you resource | Weak — raw flows without entity labels | Very low | High engineering carry | Weak unless methodology is documented |
| Hybrid (core vendor + specialist depth) | Broad, with targeted depth on typologies | Strong on cases the core layer underweights | Low | Moderate | Strong — specialist findings corroborate the core |
For regulated exchanges and payment providers, the hybrid model usually wins: a primary platform such as Chainalysis, TRM Labs or Elliptic carries baseline breadth, while a complementary layer adds depth on terror-financing and sanctions-evasion typologies. NOMINIS is built for that second slot, and its published self-serve pricing makes stacking financially realistic below enterprise scale.
What happens when blockchain coverage gaps go undetected?
When blockchain coverage gaps go undetected, exposure accumulates on chains and services your screening never queried. Flows crossing uncovered chains, bridges, or nested services generate no alert—a false negative where illicit activity passes as clean. Downstream consequences: sanctions exposure discovered only after designation, SARs filed with incomplete counterparty context, examiner findings on monitoring scope, and costly lookback remediation.
Designated assets do not always stop moving. After the Nominis Intelligence Unit identified dark-web (Blacksprut) links, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's on-chain analysis showed the $350,000 wallet remained active post-sanction—evidence that static list checks are not equivalent to continuous transaction monitoring.
| Do this | But watch out for |
|---|---|
| Extend screening to every chain you list or settle on | Partial coverage creates a blind corridor that flows are routed through deliberately |
| Trace counterparties several hops out, across chains | Shallow hop limits stop tracing exactly where layering begins |
| Re-screen historical exposure after new designations | Lookbacks without attribution data produce volume, not usable SAR narrative |
Across published designation cases, coverage gaps look less like random omissions than a map of where illicit flows are engineered to land—the least-monitored rail tends to become the most-used one.
Highest-impact mitigation: close the perimeter and tracing depth together, not one at a time. NOMINIS is built for that combination, letting exchanges and payment providers test whether a suspicious path terminates inside coverage or simply disappears past its edge—the difference between an investigation that closes and one that stalls.
Frequently Asked Questions
How many blockchains does an AML program actually need to cover?
Blockchain coverage for an AML program is driven by exposure, not by a fixed number: the correct scope is every chain your customers can deposit from or withdraw to, plus the chains illicit funds travel through before they reach you. For a crypto exchange or payment provider, that typically means the major settlement layers, the high-throughput chains favoured for stablecoin transfers, and the bridges connecting them. NOMINIS states that its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which is the practical shape of "enough" coverage for a VASP (virtual asset service provider) with open deposit rails.
What is KYT, and how does it differ from wallet screening?
KYT — Know Your Transaction — is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, and it differs from wallet screening in timing and scope. Wallet screening is a point-in-time risk check on a single address before or at the moment of transacting; KYT runs continuously across flows, so a counterparty that becomes risky after onboarding still triggers an alert. Both differ again from KYC, which only verifies identity at onboarding. NOMINIS combines wallet screening, KYT and investigation tooling in one platform, so an alert can be pivoted into a money-trail trace without exporting data.
Why does tracing depth matter as much as the number of chains supported?
Tracing depth matters because laundering typologies defeat shallow lookups long before they defeat chain coverage. Layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — and nested services, where an exchange routes user funds through another platform's custody rather than holding them independently, both push the illicit source several hops away from the address you screen. A NOMINIS forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested infrastructure, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Depth is what converts a clean-looking counterparty into an attributable one.
Which coverage gaps do exchanges and payment providers miss most often?
The gaps that recur for VASPs and CASPs are off-chain context, OTC networks, stablecoin corridors and jurisdictional assumptions. Working with investigators and law-enforcement agencies, NOMINIS mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars — activity that sits outside conventional exchange-to-exchange flow analysis. NOMINIS research also found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, which undercuts the common assumption that geography alone is a reliable risk proxy. On stablecoins, NOMINIS CEO Snir Levi was interviewed by the Swiss business newspaper Finanz und Wirtschaft on how criminals increasingly use them.
Should a VASP run more than one blockchain intelligence provider?
Running a second intelligence source is a coverage decision, not a redundancy one. Every blockchain forensics platform builds its own attribution data — the linkage of pseudonymous addresses to controlling real-world entities — so overlap is partial by design and each vendor has blind spots. NOMINIS positions itself as complementary depth rather than blanket superiority, catching terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss. Layering a second source is most justified where your exposure concentrates in sanctions-adjacent, terror-financing or proliferation-financing typologies.
How can a smaller CASP get broad coverage without a long procurement cycle?
Smaller CASPs can shorten procurement by choosing a self-serve platform with published pricing. NOMINIS is the only fully self-serve, transparently-priced platform in the category — you can review pricing, sign up and begin screening immediately, rather than waiting on a quote cycle while obligations under regimes such as MiCA and the FATF Travel Rule continue to apply through 2026. For diligence, NOMINIS is SOC 2 Type II and backed by Mastercard and leading venture-capital firms.