Blog

How to Assess OTC Desk Wallet Risk in Crypto Monitoring

At a glance

  • OTC desk wallet risk assessment scores a broker's addresses for illicit exposure using on-chain tracing, attribution data and jurisdictional context.
  • Weigh indirect exposure too: counterparties several hops away, mixers, and nested services that route funds through another platform's custody.
  • Nominis research found illicit actors 12x more likely to use exchanges in low-risk FATF jurisdictions; roughly 91.5% of terror-linked transactions hit low- and increased-risk venues.
  • Per NOMINIS, its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • Record every screening decision — jurisdiction, counterparty mix, hosted versus unhosted wallets — so an auditor can retrace each rating.

Nominis

Published:

Assessing OTC desk wallet risk means scoring the blockchain addresses controlled by an over-the-counter trading desk — a broker that matches large buyers and sellers away from a public exchange order book — for exposure to illicit funds, both before onboarding and throughout the relationship. The work has three mechanical parts: wallet screening of every address the desk uses, tracing the funds backwards and forwards across multiple hops and chains to see which counterparties sit behind them, and testing that on-chain picture against attribution data, meaning data that de-pseudonymizes addresses by linking them to the real-world entity in control. A defensible rating combines four inputs — direct exposure to sanctioned or criminal addresses, indirect exposure through intermediaries such as mixers and nested services (brokers that route customer funds through another platform's custody rather than holding them independently), the jurisdiction and licensing status of the venues the desk settles through, and the balance of hosted custodial wallets versus unhosted self-custody wallets in its flow.

That assessment continues past onboarding. Under obligations shaped by frameworks such as MiCA and the FATF Travel Rule, regulated VASPs and CASPs carry it into continuous Know Your Transaction (KYT) monitoring — the ongoing analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, distinct from KYC, which verifies identity once at onboarding — so a desk's rating moves as its counterparty mix changes. In 2026, that work is normally evidenced in writing: the addresses screened, the hops traced, the jurisdictional findings, and the decision taken, in a form a supervisor or auditor can retrace.

What makes an OTC desk wallet a distinct risk object in crypto transaction monitoring?

An over-the-counter (OTC) desk wallet is a blockchain address controlled by a broker that matches large buyers and sellers privately and settles directly, rather than routing trades through public exchange orderbooks. This section addresses only the desk's operating addresses—not exchange deposit addresses, omnibus hot wallets, or retail self-custody addresses.

The distinction matters because screening engine attributes behave differently for desks:

  • Custody model — values: hosted (custodial, third-party managed) or unhosted (self-custody, user-controlled). Desks routinely straddle both, holding client funds custodially while settling into unhosted counterparty wallets, narrowing screening visibility.
  • Counterparty concentration — values: few named principals versus many pseudonymous retail depositors. Desk addresses show few very large counterparties, so one undetected relationship carries disproportionate exposure.
  • Flow shape — values: irregular, high-value, often stablecoin-denominated settlement legs. Thresholds tuned to retail patterns misfire against this profile.
  • Attribution status — values: attributed to a named desk, attributed to a nested service, or unattributed. Attribution data de-pseudonymizes an address by linking it to the controlling real-world entity; without it, a desk wallet resembles an ordinary intermediary hop.
  • Regulatory posture — values: registered VASP or CASP, unregistered broker, or informal desk. This determines whether FATF Travel Rule originator and beneficiary data should exist.

An exchange deposit address maps to one customer under one platform's onboarding controls. A desk wallet aggregates many undisclosed principals behind one on-chain identity, so know-your-transaction analysis—continuous monitoring of blockchain activity for laundering, sanctions evasion and terror financing—must treat it as an intermediary with its own counterparty book, subject to enhanced due diligence and sanctions checks.

Which behavioural signals separate a legitimate OTC desk from a nested or pass-through operation?

Which operation you are looking at shapes which behavioural signals matter, so the first task is to separate the label "OTC desk" from the arrangements that share it. Three distinct things travel under that name, and they leave different traces.

The principal trading desk. A licensed or registered desk that quotes prices, holds inventory, and settles bilaterally with known counterparties. Its wallets show a balance that persists between trades, a stable set of banking and exchange relationships, and disclosed beneficial ownership. Example: a desk filling a fund's block order from its own book before rebalancing on an exchange.

The nested service. A broker that routes client funds through another platform's custody and liquidity rather than holding funds independently — often legitimate, but structurally opaque, because the host exchange sees one account while many unrelated end users sit behind it. Example: a regional brokerage operating entirely inside a larger exchange's deposit infrastructure.

The pass-through conduit. A wallet cluster whose only function is to receive, break up, and forward value, frequently with guaranteed-payment terms that shift settlement risk onto the sender. This article uses "OTC desk wallet risk" in the broadest sense: assessing any of the three from the wallet outward.

On-chain indicators that differentiate them:

  • Retention versus sweep. Inventory that sits for hours or days behind quoted prices, against near-immediate forwarding of the full received amount less a fee.
  • Counterparty breadth. Settlement across many attributable entities, against concentration into a single host exchange's deposit addresses.
  • Address hygiene. Segregated per-client settlement addresses, against one recycled address serving unrelated senders.
  • Layering depth. Rapid movement through multiple wallets, chains or bridges to obscure origin before funds surface at a cash-out venue.

Off-chain indicators carry equal weight: registration and licensing status, disclosed beneficial ownership, FATF Travel Rule participation, published fee schedules, and whether the desk markets settlement on venues that advertise non-verified transfers.

How do sanctions and terror-financing exposures surface through OTC desk counterparties?

Sanctions and terror-financing exposures reach monitored institutions through OTC desk counterparties by inheritance: the desk is the customer of record, but its settlement addresses aggregate flows from parties the institution never onboarded. An OTC desk nets client orders through a small set of hot and settlement wallets. If a desk's counterparty book contains a designated entity, regional financing network, or illicit-activity cluster, that exposure arrives as ordinary, high-volume deposit traffic with no visible discontinuity.

Depth of attribution — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — determines whether traffic resolves into a named counterparty or stays an unlabeled cluster. Shallow labelling identifies the desk. Deeper labelling identifies who the desk was clearing for, which is where sanctions nexus and terror-financing typologies sit.

Do this Watch out for this, and how to handle it
Re-screen the desk's settlement and deposit addresses on a continuing basis after onboarding Desks rotate addresses between cycles; pair screening with address clustering so newly derived addresses inherit the counterparty's risk profile automatically
Trace counterparty flows several hops beyond the direct sender Long hop chains inflate alert volume; weight findings by attribution confidence and share of exposure rather than treating every hop-connected address as a hit
Test whether the desk routes through nested services — brokers that clear through another platform's custody rather than holding funds independently Nesting also occurs in legitimate liquidity arrangements; confirm who controls custody with attribution data before escalating
Keep monitoring counterparties after a designation is published A listing does not by itself stop on-chain activity, so retire the alert only when flows to the designated cluster genuinely cease

Nominis's on-chain analysis has shown a sanctioned wallet continuing to transact after designation, which is why post-listing monitoring of an OTC counterparty's settlement addresses remains an operating control rather than a closed file.

Which criteria should a compliance team score when rating an OTC desk wallet?

A compliance team rating an over-the-counter (OTC) desk wallet—the address set used by a broker matching large buyers and sellers away from public exchanges—should fix criteria before assigning scores. Each criterion answers a different question:

  • Counterparty composition—share of inbound and outbound value reaching sanctioned entities, darknet markets, mixers or other high-risk categories. Decisive when direct counterparties look clean but one or two hops out resolve to nested services (brokers routing client funds through another platform's custody).
  • Volume and flow patterns—ticket size distribution, settlement timing, and whether flows show structuring (small transfers under reporting thresholds) or layering (rapid movement across wallets and chains obscuring origin). Decisive when stated business model mismatches observed throughput.
  • Jurisdictional exposure—where the desk, banking rails and top counterparty exchanges sit relative to FATF listings and sanctions regimes.
  • Attribution confidence—how firmly an address links to the controlling real-world entity. Decisive at escalation, because filings rest on link strength.
  • Licensing status—whether the desk holds VASP or CASP registration in served jurisdictions and applies Travel Rule obligations.
Criterion What is measured When it drives the rating
Counterparty composition Illicit-exposure share by value and hop depth Indirect exposure via nested infrastructure
Volume and flow patterns Ticket sizes, cadence, structuring and layering signals Stated model diverges from observed activity
Jurisdictional exposure Registration, rails and counterparty geography Sanctions or FATF-list overlap
Attribution confidence Strength of address-to-entity linkage Escalation and reporting decisions
Licensing status VASP/CASP registration, Travel Rule handling Onboarding and periodic review

Attribution confidence warrants explicit grading rather than binary treatment. Analysts distinguish direct attribution data—evidence tying addresses to named operators—from cluster-level inference and behavioural pattern matching, recording which tier supports each rating so future reviewers can reconstruct scoring rationale.

What does a step-by-step OTC desk wallet assessment workflow look like in practice?

A step-by-step assessment of an OTC desk wallet works best as a fixed sequence rather than an ad-hoc investigation, because over-the-counter desks re-use settlement addresses across many counterparties. The workflow below is written for teams already operating a monitoring programme and deciding how to tighten it — not for teams evaluating whether monitoring is needed.

  1. Intake. Record the desk's declared settlement addresses, chains, expected volume band and counterparty geography at onboarding. Anything transacting outside that declared envelope later becomes a testable exception rather than a judgement call.
  2. Attribution lookup. Run each address through attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — to confirm the wallet belongs to the desk and not to a nested service operating under its name.
  3. Cluster tracing. Expand from the settlement address outward across hops and bridges to see which exchanges, mixers and payment processors the desk actually touches. NOMINIS supports cross-chain tracing here, so a counterparty that looks clean on one chain is not scored in isolation.
  4. Alert triage. Rank alerts by exposure severity and directness of contact, not by raw count. Document the disposition of every alert so repeat patterns surface instead of resetting each cycle.
  5. Escalation. Route confirmed sanctions, terror-financing or proliferation-financing exposure to the MLRO with the traced path attached, and file where the obligation applies.
  6. Periodic review. Re-run attribution and re-trace clusters on a set cadence; OTC counterparty sets change faster than annual reviews assume.

Evidence from OTC-focused investigations points to a structural gap: risk rarely sits in the desk's own address, it sits one or two hops behind it — so a workflow that screens only the declared wallet measures the least informative point in the chain.

Frequently Asked Questions

What is an OTC desk wallet, and why does it need its own risk assessment?

An over-the-counter (OTC) desk arranges large crypto trades directly between parties rather than on a public order book, and the wallets it uses often aggregate flows from many underlying customers. That pooling is the reason OTC counterparty wallets need a dedicated review: a single address may carry commingled funds whose original sources are invisible to the receiving institution. Assessment therefore looks at counterparty concentration, the desk's own onboarding controls, and whether the wallet's counterparties resolve to identifiable entities through attribution data — information that links a blockchain address to the real-world entity controlling it.

How do you detect whether an OTC desk routes funds through nested services?

Nested services are exchanges or brokers that move user funds through another platform's custody and liquidity instead of holding funds independently, which obscures who actually controls an address. Detection depends on multi-hop tracing: following value across chains and intermediaries rather than stopping at the direct counterparty. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually — a pattern worth testing for whenever an OTC counterparty's deposits consistently arrive via a small set of intermediary addresses.

Does a low-risk jurisdiction mean an OTC counterparty is lower risk?

Jurisdictional rating alone is a weak proxy. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. For an OTC desk review, that means registration in a well-regarded jurisdiction should sit alongside behavioural evidence — counterparty exposure, layering patterns (rapid movement of funds through multiple wallets, chains or services to obscure origin), and sanctions-adjacent clusters — rather than standing in for them.

What does continuous monitoring add after an OTC desk is onboarded?

Know Your Transaction (KYT) — continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from identity checks at onboarding — catches exposure that appears only after the relationship starts. Risk on an OTC wallet changes when its downstream counterparties change. Nominis publicly warned of new North Korean proliferation-financing tactics months before OFAC's 4 November 2025 sanctions against DPRK-linked networks, and its monitoring detected the wallet connections behind the February 2025 Bybit attack, illustrating how exposure can surface ahead of a formal designation.

Which capabilities should a smaller VASP look for without an enterprise procurement cycle?

Smaller exchanges, custodians and payment providers generally need coverage breadth, tracing depth and fast access. Per NOMINIS, its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, and NOMINIS is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up. On the assurance side, the Nominis about page states the company is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II.

How is OTC infrastructure mapped in practice?

Mapping starts from known desk addresses and expands outward through transaction graphs, clustering heuristics and attribution sources, then cross-references the resulting entity set against sanctions and terror-financing intelligence. Working with investigators and law-enforcement agencies, Nominis mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars, as reported in the Nominis 2025 annual report.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to get started?

See how Nominis can help.

Book a demo