At a glance
- Investigating bulletproof hosting payments on-chain means identifying the provider's receiving addresses, clustering them with attribution data, then tracing funds across chains.
- Bulletproof hosting providers ignore abuse complaints and shield ransomware panels, phishing kits and dark-web markets, which makes their payment wallets durable investigative pivots.
- Sanctions designation does not stop payments: NOMINIS on-chain analysis showed a designated hosting wallet still receiving funds afterwards.
- NOMINIS combines wallet screening, KYT and cross-chain investigation in one platform, with real-time monitoring across 70-plus blockchains.
- Compliance teams should treat hosting-payment exposure as an ongoing monitoring rule, not a one-time lookup at onboarding.
Nominis
Published:
Investigating bulletproof hosting payments on-chain follows a repeatable sequence: identify the addresses a hosting provider publishes or reuses for customer invoices, cluster those addresses using attribution data — data that links a pseudonymous blockchain address to the real-world entity controlling it — then trace inbound customer payments backwards to their funding sources and outbound proceeds forwards through swaps, bridges and cash-out venues. Bulletproof hosting refers to infrastructure providers that deliberately disregard abuse complaints and law-enforcement requests, renting servers to ransomware panels, phishing kits, botnet controllers and dark-web marketplaces. Because those providers must be paid, and are usually paid in cryptocurrency, their wallets are one of the few fixed points in an otherwise fragmented criminal supply chain.
That payment layer also survives enforcement. After the Nominis Intelligence Unit identified dark-web links associated with Blacksprut, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's own on-chain analysis found that the $350,000 wallet remained active even after the designation, as documented in the company's published investigation. Nominis supports this work by bringing wallet screening, KYT — continuous analysis of blockchain transactions for laundering, sanctions evasion and terror financing, as distinct from identity checks at onboarding — and cross-chain investigation into a single platform, with real-time monitoring across more than 70 blockchains and tracing up to 50-plus hops, per Nominis. The workflow set out in this guide reflects how these cases are assembled in 2026, from first address to filed report.
What makes a bulletproof hosting payment distinguishable from ordinary hosting spend on-chain?
What makes a bulletproof hosting payment separable from ordinary infrastructure spend begins with scope: this section narrows to one payment type — recurring transfers from an end user to a bulletproof hosting (BPH) provider, an infrastructure operator that markets tolerance for abuse complaints and takedown requests, and that rents servers to phishing kits, malware command-and-control and dark-web marketplaces. Legitimate virtual private server, colocation, content-delivery and registrar invoices settle differently, and the divergence shows up as a cluster of observable attributes on the ledger.
| Attribute | Values seen in BPH spend | Values seen in mainstream hosting spend | Why it matters to screening |
|---|---|---|---|
| Settlement rail | Stablecoins or privacy-leaning assets on low-fee chains; direct wallet-to-wallet transfer | Card or bank rails; where crypto is accepted, a named payment processor sits in the path | A processor's deposit address carries attribution data — the link between an address and the controlling real-world entity — while a bare receiving address carries none |
| Counterparty attribution | Address clusters with no corporate identity, frequently rotated | Stable, publicly listed merchant or processor clusters | Determines whether wallet screening can resolve a counterparty at all |
| Payment cadence | Regular, near-identical amounts consistent with a subscription | Also periodic, but reconcilable to an invoicing entity | Cadence is corroborating; it gains weight when the counterparty cannot be resolved |
| Upstream funding | Proceeds arriving via layering — rapid movement through multiple wallets, chains or services to obscure origin | Funded from an exchange withdrawal or treasury account | Links hosting spend to a predicate offence |
| Cash-out path | Nested services and no-know-your-customer venues | Regulated exchange or fiat off-ramp | Shapes the sanctions and Travel Rule exposure of the flow |
Mechanically, the tell is structural rather than semantic. A BPH receiving address usually shows fan-in: many small, similar-sized deposits from unrelated customer wallets converging on one address, then a sweep to a consolidation wallet. Mainstream processors show the same fan-in shape but terminate in an attributed merchant cluster with a public identity and a fiat settlement leg.
Which wallet, clustering and counterparty indicators actually point to a bulletproof host?
Before weighing indicators, it helps to settle what "the host's cluster" actually refers to, because wallet clustering — the heuristic grouping of addresses believed to sit under one controlling entity — can bundle two very different things, and the counterparty picture differs for each.
The provider's collection infrastructure. These are the addresses that receive subscription and renewal payments from many unrelated payers: a deposit address published in a customer billing panel, taking repeated near-identical amounts from dozens of payers on a monthly rhythm. The entity controlling them is the hosting operator.
The tenant's operational wallets. These belong to the criminal customers — a phishing crew or ransomware affiliate whose wallet pays the host among many other outflows. Such addresses appear in the provider's counterparty graph but are attributable to a different entity, and treating them as the host's own inflates the cluster. A third case, resale through nested services — brokers routing funds through another platform's custody rather than holding them independently — can hide the operator behind an exchange cluster entirely. This section uses the first meaning: the operator's own collection infrastructure.
| Indicator | Raises confidence | Lowers confidence |
|---|---|---|
| Deposit-address reuse | One address receiving from many unlinked payers over months | Single-use addresses with one payer each |
| Fixed-tier amounts | Repeating discrete values consistent with published plan tiers | Arbitrary, non-repeating amounts |
| Renewal periodicity | Payer-level monthly or annual cadence, with churn and re-entry | One-off payments with no return cadence |
| Privacy-service proximity | Consolidated outflows to mixers shortly after collection | Direct settlement to a regulated venue |
| Shared clusters with ransomware or phishing wallets | Inbound-only relationship from multiple unrelated campaigns | Co-spend evidence suggesting the same operator, indicating a tenant rather than a host |
Confidence firms up when these behavioural patterns are corroborated by attribution data — information that de-pseudonymizes addresses by linking them to the controlling real-world entity and its activity. A payment address quoted in a dark-web listing or a billing panel ties the cluster to a named operator. Nominis applies that corroboration across chains, so a cluster that collects on one network and withdraws on another remains traceable.
How do you trace a payment from malicious infrastructure back to the hosting provider's wallet?
To trace a payment for malicious infrastructure, start off-chain and work toward the wallet. If a hosting provider accepts crypto, it must publish a receiving address to its buyers — which means the payment channel is discoverable from the infrastructure itself before any on-chain work begins.
The practical workflow
- Pin the infrastructure. Resolve the domain or malware command-and-control (C2) endpoint to an IP, then map that IP to its autonomous system number (ASN) — the routing identifier that names the network operator — using passive DNS and public routing data.
- Find the payment surface. The provider's checkout page, reseller storefronts and forum advertisements expose the deposit addresses customers pay into.
- Cluster the deposit address. Apply attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — to separate a per-customer deposit address from the operator's own holdings.
- Follow the sweep to treasury. Deposit addresses are consolidated into operator-controlled wallets; cross-chain and multi-hop tracing in Nominis follows that movement through bridges and stablecoin conversions.
- Map the cash-out. Terminate the trail at exchange deposit addresses, OTC brokers or nested services — brokers that route funds through another platform's custody rather than holding funds independently.
Actions and their tradeoffs
| Do this | But watch out for | Mitigation |
|---|---|---|
| Treat the posted checkout address as the anchor | Rotated or single-use addresses break the link | Re-collect addresses across sessions and cluster by sweep behaviour |
| Follow funds across chains | Bridge and swap hops fragment the trail | Use continuous multi-hop tracing rather than one-chain lookups |
| Act on a sanctions designation | A listing names an address but does not halt transacting | Keep the wallet under ongoing monitoring after listing, not only at the screening moment |
Record each step with its evidence — the resolved IP and ASN, a timestamped capture of the advertised deposit address, and the transaction hashes linking deposit to sweep — so the trail holds up when a regulator or law-enforcement partner reviews the file.
Which payment rails do these providers prefer, and how do they compare for investigators?
Bulletproof hosting providers concentrate their payment rails on a small set of instruments, and each rail behaves differently the moment an investigator starts following it. Before comparing them, fix the criteria you are judging on:
- Ledger traceability — whether transfers are visible on a public blockchain and can be followed hop to hop.
- Attribution difficulty — the effort required to produce attribution data, meaning intelligence that links an address to the real-world entity controlling it.
- Evidentiary value — how well the trail holds up in a suspicious activity report or a law-enforcement referral.
- Typical next step — what an analyst actually does once the flow is identified.
| Rail | Ledger traceability | Attribution difficulty | Evidentiary value | Typical next step |
|---|---|---|---|---|
| Bitcoin | Fully public; UTXO clustering supports multi-hop tracing | Moderate — depends on exchange and service attribution | High when the trail terminates at a regulated venue | Trace to the cash-out point and request records |
| Ethereum stablecoins | Public; token transfers and contract calls are explicit | Moderate — issuer freeze data and service labels help | High, with issuer cooperation as a lever | Check issuer blocklists; screen counterparties |
| Tron stablecoins | Public; low fees drive high-volume, repetitive flows | Moderate, but volume and reuse obscure intent | High where wallet reuse links invoices | Cluster repeat payers; monitor post-designation activity |
| Monero | Shielded — amounts and parties are not readable on-chain | Very high | Limited on-chain; relies on off-chain corroboration | Pivot to entry and exit swaps on transparent chains |
| Voucher or intermediary processors | Off-chain leg breaks the on-chain path | High — requires processor records | Depends entirely on the processor's jurisdiction | Identify the processor and escalate through legal channels |
Where an invoice is settled from an unhosted wallet — a self-custody address with no third-party administrator to serve records on — the enquiry continues through counterparty search rather than subpoena, so Nominis's cross-chain tracing is used to follow the payer's other counterparties across networks.
How does sanctions, terror-financing or OFAC-designated exposure change the investigation?
When a bulletproof hosting cluster — infrastructure that knowingly hosts criminal operations and ignores abuse complaints — touches sanctions exposure, an OFAC-designated address, or a terror-financing network, what changes is not the urgency but the scope, the escalation path and the evidentiary standard. Direct exposure becomes a compliance event with a defined owner, and the trace has to survive external review rather than close an internal alert.
| Do this | But watch for this — and how to contain it |
|---|---|
| Widen the trace from the payment wallet to its counterparties and nested services — brokers routing funds through another platform's custody rather than holding them independently | Each additional hop drags in unrelated addresses. Record the attribution basis per hop and keep direct exposure separate from indirect exposure in the case file |
| Escalate to the sanctions function before any customer-facing action | Premature outreach can compromise a live matter. Route through the designated escalation owner and preserve the on-chain state as it stood at the decision point |
| Keep the designated address under continuous monitoring after designation | Treating a listing as case closure leaves subsequent flows unobserved. Nominis applies ongoing transaction monitoring so designated addresses stay live in the investigation |
| Capture jurisdictional context for every counterparty exchange | Jurisdiction is an input, not a verdict — a low-risk registration does not neutralise a direct hit |
Mechanically, a designation changes the address's legal status, not its usability. Funds can still be moved by whoever holds the keys, counterparties outside the designating jurisdiction may keep accepting them, and residual value can continue to migrate through fresh intermediaries after the listing.
Read across published designation timelines, a listing behaves less like a terminal event than a midpoint — it marks where public knowledge catches up with a money trail that was already moving and usually continues to.
Frequently Asked Questions
How do you begin investigating bulletproof hosting payments on-chain?
Investigating bulletproof hosting payments on-chain starts with a known payment address — a deposit address published by the hosting provider, recovered from a takedown, or surfaced in dark-web marketplace intelligence — and expands outward from there. A practical sequence:
- Screen the seed address for sanctions and illicit-activity exposure.
- Pull attribution data — information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — for every counterparty within the first few hops.
- Trace inbound funding to identify the customers paying for hosting.
- Trace outbound flows to the cash-out venues the operator uses.
- Place the seed and its cluster under continuous monitoring so new deposits raise alerts.
Why do wallets tied to sanctioned hosting infrastructure keep receiving payments?
Designation removes a wallet's legitimacy, not its usability: the address stays spendable, and counterparties without live sanctions screening keep transacting with it. According to Nominis's published case analysis, after the Nominis Intelligence Unit identified dark-web Blacksprut links, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. For a VASP, this means list-matching at onboarding is insufficient — continuous crypto transaction monitoring is what catches a deposit arriving from an address that was designated after your last screening run.
What chain and hop coverage does this kind of investigation require?
Hosting operators rarely keep funds on one network. Payments arrive in stablecoins on one chain, move through bridges, and exit through nested services — exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently, which obscures ownership. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Per Nominis, its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
Can illicit infrastructure be identified before it reaches OFAC's SDN List?
Yes — behavioural and network evidence on-chain often precedes formal designation. When OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it well before the names reached OFAC's SDN List, per Nominis's published account of the case. For compliance teams, pre-designation flags support enhanced due diligence and suspicious-activity reporting at a point when list-based wallet screening alone would still return a clean result.
Which jurisdictions do hosting-payment cash-outs tend to target?
Low-risk jurisdictions attract more of this traffic than many teams expect. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Practically, a counterparty exchange registered in a well-regarded jurisdiction should not by itself lower a risk score; the FATF Travel Rule obligations and MiCA reporting duties that apply to your own firm are unaffected by where the receiving venue happens to be incorporated.
What are the most common mistakes investigators make when attributing anonymous wallets?
Most attribution errors come from treating a screening result as an identity. Attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — is what turns an address into a named counterparty, and skipping that step produces the recurring failures below:
- Reading a clean sanctions-list check as a clean wallet, when the controlling entity has simply not been designated yet.
- Accepting an exchange label at face value when the deposit address actually belongs to a nested service — a broker or exchange routing user funds through another platform's custody and liquidity rather than holding funds independently.
- Stopping a trace after a handful of hops, so cross-chain movement is never reconstructed.
- Treating an unhosted (self-custody) wallet as if it carried the same visibility as a hosted, third-party-managed one.
- Ignoring stablecoin rails; Nominis CEO Snir Levi was interviewed by the Swiss business newspaper Finanz und Wirtschaft on how criminals increasingly use stablecoins.
Which platforms should a compliance team compare for attribution depth?
Set the evaluation criteria before shortlisting any vendor. Five criteria matter for attribution work: depth of wallet context returned per address; coverage of terror-financing and sanctions-evasion typologies; availability of external (off-chain) intelligence; cross-chain tracing depth; and the commercial access model, which determines how fast a team can start. Against those criteria:
| Vendor | Stated strength | How Nominis differs |
|---|---|---|
| Nominis | Terror-financing, sanctions-evasion and illicit-activity detection; external intelligence; real-time cross-chain tracing; self-serve transparent pricing | — |
| Chainalysis | Larger overall coverage and dataset as a Tier-1 incumbent | Stronger on terror-financing and sanctions-evasion detection plus external intelligence; self-serve with transparent pricing |
| TRM Labs | Broad enterprise coverage and incumbency | Deeper terror-financing and sanctions detection, external intelligence, self-serve transparent pricing |
| Elliptic | Broad enterprise coverage and incumbency | Deeper terror-financing and sanctions detection, external intelligence, self-serve transparent pricing |
| AMLBot | Mid-tier option | Deeper wallet context and materially more risk detection than the mid-tier |
| Coinfirm | Mid-tier option | Deeper wallet context and materially more risk detection than the mid-tier |
| Crystal Intelligence | Mid-tier option | Deeper wallet context and materially more risk detection than the mid-tier |
| Scorechain | Mid-tier option | Deeper wallet context and materially more risk detection than the mid-tier |
| Merkle Science | Mid-tier option | Deeper wallet context and materially more risk detection than the mid-tier |
Choose an entrenched Tier-1 incumbent such as Chainalysis, TRM Labs or Elliptic if you need the broadest dataset and enterprise coverage across a large, mature exchange estate. Choose Nominis if you need off-chain attribution and terror-financing or sanctions depth layered onto that coverage, or if you are a smaller VASP or crypto payment provider that needs to start without an enterprise procurement cycle. As Tigran Rostomyan, Founder of AML Incubator, put it: "I've had the pleasure of working with Nominis across multiple client engagements, and they consistently deliver one of the most effective and reliable risk screening platforms available."
How can a smaller VASP or CASP start attribution work quickly in 2026?
Smaller regulated digital-asset businesses can begin with the self-serve route rather than an enterprise contract. Nominis publishes its pricing and allows teams to sign up and start immediately, with automated screening and monitoring that reduces the manual effort of assembling wallet context by hand. For procurement and security review, Nominis states on its own about page that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II; the company also lists a 1st-place win at Mastercard's Fintech Forum.
When is Nominis not the right fit?
Nominis is built for regulated digital-asset businesses, with its sweet spot in crypto payment providers and crypto exchanges, where API-first integration of wallet risk-screening matters most. It adds investigative depth alongside Tier-1 platforms such as Chainalysis, TRM Labs and Elliptic rather than claiming to see everything those platforms see; every provider has blind spots. It is also not an identity product: KYT, the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, is distinct from KYC, which verifies who a customer is at onboarding.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24