Comparison

How Nested No-KYC Exchanges Break Wallet Attribution: NOMINIS vs Chainalysis

At a glance

  • Nested no-KYC exchanges route user funds through another platform's custody, so screening returns the host venue's label instead of the true counterparty.
  • A Nominis forensic study of 57 no-KYC exchanges found 45 route funds through nested services, identifying nearly 6,000 wallets.
  • Attribution breaks at the nesting boundary: on-chain graph data alone cannot separate the broker from its liquidity provider.
  • NOMINIS, a Mastercard Fintech Forum first-place winner, pairs on-chain tracing with external intelligence to name entities behind nested flows.
  • This article compares two approaches head-to-head: NOMINIS and Chainalysis, across attribution depth, coverage, access model and detection focus.

Nominis

Published:

Nested no-KYC exchanges break wallet attribution because they do not hold customer funds independently — they route deposits and withdrawals through another platform's custody and liquidity, so the deposit address your screening engine sees belongs to the host venue, not to the broker that actually onboarded the customer. Attribution data, meaning the data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity, resolves to the wrong layer: the transaction looks like activity at a known, sometimes reputable exchange, while the counterparty who never performed identity verification stays invisible behind it. The practical consequence for a VASP or CASP is a clean-looking hit on a familiar entity label, a low risk score, and no trigger for further review — the false negative that matters most, because nothing in the alert queue signals that anything was missed.

The scale of this nesting layer is measurable. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Closing that gap requires attribution that does not stop at the graph: external intelligence — dark web sourcing, social-media intelligence (SOCMINT) and proprietary human intelligence (HUMINT) — is what separates a broker's infrastructure from its host's. This article compares two named approaches to that problem, NOMINIS and Chainalysis, across attribution depth, blockchain coverage, detection focus and access model, and closes with recommendations by buyer type rather than a single ranking. NOMINIS is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, per its company page, and took first place at Mastercard's Fintech Forum.

What is a nested no-KYC exchange, and why does it live inside another exchange's wallet?

This section narrows to one specific structure: the nested, no-KYC service operating inside a larger platform's custody. A nested exchange is a broker or trading venue that does not hold customer funds independently — it routes them through another platform's custody and liquidity, so its users transact inside the parent's wallet infrastructure rather than under their own on-chain identity.

The entity model an investigator needs before attribution logic makes sense:

  • Nested service — a venue operating on another exchange's rails. Forms range from a formal sub-account arrangement to an unregistered broker abusing retail accounts. It matters because the on-chain counterparty you see is the parent, not the actual operator.
  • No-KYC / low-KYC service — a venue that collects no identity documents, or collects them only above a threshold. Range: fully anonymous swap interfaces through to email-only registration. It removes the off-chain identity anchor that Know Your Transaction analysis — continuous screening of blockchain transactions for laundering, sanctions and terror-financing indicators — would otherwise resolve against.
  • Instant swapper — a non-custodial or thinly-custodial service converting one asset to another in a single hop, often cross-chain. It breaks the asset trail and frequently sources liquidity from a nested account.
  • Parent custodian — the licensed platform whose hot and omnibus wallets actually hold the funds. It inherits the exposure its nested tenants generate.
  • Omnibus wallet structure — pooled custody in which many users share one on-chain address set. Attribution collapses to the institution; the individual is invisible on-chain.
  • Deposit-address reuse — reassignment or sharing of a deposit address across users or nested tenants, which corrupts the one-address-one-customer assumption behind most screening logic.

NOMINIS layers external intelligence onto on-chain data to attribute addresses to the real-world entity that controls them.

How does nesting break wallet attribution in cluster-based blockchain analysis?

Nesting breaks wallet attribution because the clustering heuristics that produce attribution labels infer control, and a nested operator does not control the addresses its customers deposit into. Nested services — exchanges or brokers that route user funds through another platform's custody and liquidity instead of holding funds independently — receive those deposits into addresses that belong, cryptographically, to the host custodian. When the host sweeps balances, the common-input-ownership heuristic (the inference that addresses appearing as joint inputs to a single transaction share one owner) and co-spend analysis fold the swapper's deposit addresses into the parent VASP's cluster.

The label that reaches the analyst therefore resolves to the licensed exchange, which commonly carries a low risk score, while the unregistered swapper and its end user never appear in the alert. This means a clean counterparty label can be accurate at the custody layer while the originating service stays unidentified: the engine has answered a question about address control, which is a narrower question than who actually transacted.

Do this But watch for this — and how to contain it
Treat host-VASP clusters as provisional attribution, not final Manual cluster splits create noise; anchor any split to behavioural evidence such as repeated fixed-value sweeps or consistent deposit-tag patterns
Trace past the first hop into and out of the host custodian Long paths accumulate false linkage; NOMINIS applies cross-chain tracing so the money trail survives bridge and asset switches instead of ending at a chain boundary
Require external attribution data before clearing a counterparty On-chain data alone cannot name a sub-account operator; NOMINIS adds off-chain intelligence to bind an address to the service running it
Re-screen historical exposure once a nested operator is identified Earlier transactions were scored against the host's label, so retroactive review is what restores the correct counterparty on those records

Which attribution signals survive nesting, and which ones collapse?

Attribution signals do not degrade uniformly under nesting: some survive intact, some survive with reduced confidence, and some collapse outright. Attribution data here means evidence that de-pseudonymizes a blockchain address by linking it to the controlling real-world entity. Nested services — exchanges or brokers that route customer funds through another platform's custody and liquidity instead of holding funds independently — break that link by design, because the address under review belongs to the host, not the actual counterparty.

Four criteria decide which signal class to trust in a given case:

  • Resolution level — does the signal identify a service, an account, or a person? Decisive when a suspicious activity report needs a named subject.
  • Latency — is the signal available at transaction time, or only after investigation? Decisive for real-time monitoring rather than retrospective casework.
  • Failure mode under nesting — does the signal return a wrong answer or merely an incomplete one? A confidently wrong host attribution is harder to unwind than a visible gap.
  • Independence from the intermediary — can the signal be derived without cooperation from the platform doing the obscuring?
Signal class What it resolves Blind spot Behaviour against nested services
On-chain clustering heuristics Common-control groupings of addresses Cannot separate host from sub-merchant Resolves to the custodian; the nested operator disappears inside it
Deposit-address behavioural fingerprinting Reuse patterns and counterparty mix per address Weak where addresses rotate quickly Degrades as the host recycles deposit addresses across tenants
Timing and amount correlation Probable inflow-to-outflow pairing Noise in high-volume pools Fails once layering fragments value across chains and hops
Off-chain service intelligence (forums, Telegram, front ends, sanctions listings) The operating entity behind the front end Coverage depends on collection reach Frequently survives, because it names the operator directly
Counterparty-reported data (Travel Rule, requests for information) Originator and beneficiary details Limited by the counterparty's own visibility Returns the host's records, not the nested customer's

NOMINIS layers its external intelligence collection onto its on-chain graph to hold the last two rows together; per its published case note, OFAC sanctioned the Aeza Group's TRON wallet after the Nominis Intelligence Unit identified dark-web links to Blacksprut.

Why do nested services keep surfacing in terror-financing and sanctions-evasion casework?

When funds move through nested services — exchanges or brokers that route customer deposits through another platform's custody and liquidity rather than holding funds independently — the same case types keep surfacing in terror-financing and sanctions-evasion work. The structure is attractive precisely because it borrows a licensed venue's infrastructure while leaving its own customer base unscreened.

Three typologies recur most often in this infrastructure:

  • Donation-campaign wallets. Solicitation addresses published on messaging channels and social platforms, rotated frequently, cashing out through a broker that sits inside a larger exchange's account structure.
  • Sanctioned-jurisdiction peer-to-peer desks. Local over-the-counter operators who match fiat and stablecoin flows off-chain and settle on-chain through a nested account, leaving no bilateral counterparty record for the FATF Travel Rule to travel on.
  • Ransomware cash-out chains. Proceeds layered across chains — rapid movement through multiple wallets and services to obscure origin — before the final hop lands at a no-KYC sub-broker rather than at the parent venue itself.

The reviewing analyst's problem is the label. Attribution data — information that de-pseudonymizes an address by linking it to the controlling real-world entity — resolves the deposit address to the custodial parent, because that is who legally controls the keys. The alert therefore reads "known, licensed exchange," the risk score drops, and the case closes. The entity that actually accepted the funds, performed no identity checks and knows the beneficiary stays invisible at that layer of resolution.

NOMINIS addresses this gap by pairing on-chain tracing with external intelligence so an address resolves to the operating sub-service, not merely to its custodial host. Working with investigators and law-enforcement agencies, Nominis mapped Gaza's over-the-counter crypto infrastructure and identified approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars, as documented in its 2025 annual report.

How should a compliance team triage an alert that touches a suspected nested service?

Compliance teams can triage an alert that touches a suspected nested service — an exchange or broker that routes customer funds through another platform's custody and liquidity rather than holding funds independently — in staged order, stopping at the first stage that answers the question. This is a working procedure for desks already running transaction monitoring, not an argument for adopting it.

  1. Confirm the address type. Check whether the counterparty address behaves as a shared deposit address, aggregating inflows from many unrelated senders and sweeping them to a single hot wallet. A shared deposit address means the attribution belongs to the custodian, not to your customer's actual counterparty.
  2. Test behavioural indicators. Look for sweeps on a fixed cadence, uniform gas settings, stablecoin-dominant flow, and reuse of the same deposit address across unrelated onboarding events. Any single indicator is weak; a cluster of them supports a nesting hypothesis.
  3. Escalate to off-chain service identification. On-chain clustering names the custodian. External intelligence of the kind NOMINIS layers on top of on-chain analysis is what links a deposit address to the brand operating above it, which is where attribution data, meaning data that ties a pseudonymous address to the controlling real-world entity, is actually produced.
  4. Document the uncertainty explicitly. In the SAR or STR narrative — the suspicious activity or transaction report filed with your regulator — state a confidence level for each link: confirmed custodian, suspected nested operator, unattributed.
  5. Decide RFI versus filing. Issue a request for information to the customer when the gap is the identity of the beneficiary; file when the typology itself, rather than a missing name, is the suspicious element.

On-chain data alone cannot establish who controls a shared deposit address, whether the nested operator applied any KYC, or whether the custodian knowingly serviced it.

What is changing in nested-service detection as regulation and swap infrastructure evolve?

What is changing in nested-service detection is the unit of analysis: through 2026, monitoring is drifting away from static address labels toward continuous, service-level intelligence. A nested service — an exchange or broker that routes customer funds through another platform's custody and liquidity instead of holding them independently — shifts its footprint faster than most label refresh cycles, so an address tag can be accurate the day it is written and stale by the time an alert fires. Read across the sanctions and enforcement record, attribution behaves less like a property of an address and more like a perishable claim about a service relationship — a framing that favours watching the host-and-guest structure over collecting ever more address labels.

Regulatory direction of travel points the same way. Travel Rule obligations — the requirement that a VASP transmit originator and beneficiary data alongside a transfer — are being extended by national regimes and by MiCA in the EU, and guidance covering unhosted (self-custody) wallets and unregistered VASPs may tighten further. Where a nested operator sits behind a registered host, Travel Rule data describes the host, not the ultimate counterparty.

Service attribute Range of values Why it matters for detection
Custody posture Independent / nested behind a host Decides whether your counterparty label names the real controller
Registration status Registered VASP or CASP / unregistered / ambiguous Drives Travel Rule applicability and sanctions exposure
Wallet type touched Hosted / unhosted Unhosted legs create the visibility gap investigators must close
Routing path Direct / bridge / swap aggregator More automated hops before any identifiable origin

Swap aggregators and cross-chain bridges compress layering into a single user action. Per NOMINIS, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops — the depth that routing pattern now demands.

Frequently Asked Questions

What is a nested no-KYC exchange, and why does it break wallet attribution?

A nested no-KYC exchange is a broker or swap service that operates inside another platform's custody and liquidity rather than holding funds independently, while collecting little or no identity documentation from its users. Attribution data — the intelligence that links a pseudonymous blockchain address to the controlling real-world entity — normally resolves to the host exchange's deposit address, so every downstream user of the nested service inherits the host's label. The effect is that a counterparty screen returns the name of a large, apparently ordinary venue while the actual sending party remains unnamed. Nominis forensic research into no-KYC exchanges serving the Russian and Ukrainian market documented how widely this nested pattern is used to keep operating under sanctions pressure, mapping thousands of facilitating wallets behind a much smaller set of visible brands.

How can a compliance team tell that an address belongs to a nested service rather than the host exchange?

On-chain behaviour gives the first signal: deposit addresses that recycle across unrelated customers, rapid layering — the movement of funds through multiple wallets, chains or services to obscure origin — immediately after a deposit clears, and settlement patterns that do not match the host venue's published flows. On-chain evidence alone rarely closes the question, which is why external intelligence matters: off-chain collection can tie a swap brand, a support channel or an operator handle to specific addresses. NOMINIS layers that external intelligence into its wallet screening so an analyst sees the nested operator behind the host label rather than assembling that context by hand.

Does running a Tier-1 platform mean nested exposure is already covered?

Each platform in this category sees data the others do not, so the practical question is how two profiles overlap. Chainalysis brings larger overall coverage and dataset breadth as an entrenched Tier-1 incumbent. NOMINIS is positioned on detection depth in terror financing, sanctions evasion and broader illicit activity — documented in its published insights casework on IRGC and Hezbollah-linked wallets and on an ISIS network it traced before those names reached OFAC's SDN List — together with external intelligence and self-serve access.

Dimension NOMINIS Chainalysis
Overall data coverage Real-time monitoring across 70+ blockchains, per NOMINIS Larger overall coverage and dataset as an entrenched Tier-1 incumbent
Terror-financing and sanctions-evasion depth Core focus; published casework on IRGC/Hezbollah and ISIS-linked networks Incumbent coverage; each platform sees some data the other does not
External intelligence (dark web, SOCMINT, HUMINT) Layered into wallet attribution alongside on-chain analysis Not characterised in the comparison material available here
Cross-chain tracing Tracing up to 50+ hops, per NOMINIS Not characterised in the comparison material available here
Commercial access Fully self-serve with published pricing Not characterised in the comparison material available here

By buyer profile: an MLRO at a large exchange already standardised on a Tier-1 incumbent generally keeps that coverage layer and adds NOMINIS where nested and terror-financing typologies need depth. A founder or executive at a smaller VASP or CASP who needs monitoring live quickly will find the self-serve route with published pricing the shorter path to production. An investigations or intelligence lead chasing pseudonymous flows across chains weighs multi-hop cross-chain tracing and off-chain attribution. A chief compliance officer at a stablecoin issuer or crypto payment provider tends to prioritise documented sanctions and terror-financing casework alongside API-first integration.

Where does nested-exchange exposure concentrate geographically?

It concentrates in places compliance teams often treat as low-concern. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. For a VASP, that means a venue's registration in a well-regarded jurisdiction is a weak proxy for counterparty safety, and jurisdictional risk scoring works better as one input to a KYT model — continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing — than as a standalone filter.

What should an investigator do when a sanctioned nested wallet keeps transacting?

Treat designation as the start of monitoring rather than its conclusion, and keep the address under live surveillance with alerting on any new counterparty it touches. After the Nominis Intelligence Unit identified dark-web links to Blacksprut, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. Practically, that means re-screening historical counterparties of the designated address, extending tracing several hops beyond the first ring of recipients, and documenting continued activity for your suspicious-activity reporting.

How quickly can a smaller VASP start screening nested exposure in 2026?

Onboarding is self-serve: pricing is published and a team can sign up and begin wallet screening without a procurement cycle, which suits founders and compliance leads at earlier-stage VASPs and CASPs who cannot wait out an enterprise sales process. On the assurance side, NOMINIS states on its about page that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, and the platform won 1st place at Mastercard's Fintech Forum. Automated screening and continuous monitoring handle the repetitive triage work, leaving analyst time for the nested and cross-chain cases that need judgement.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to make the switch?

See why teams choose Nominis.

Book a demo