At a glance
- Investigating an OTC broker network means clustering the desk's wallets, tracing counterparty flows across chains, then testing each hop for sanctions exposure.
- A Nominis study of 57 no-KYC exchanges found 45 route funds through nested services, spanning nearly 6,000 wallets and over $100 million annually.
- NOMINIS monitors in real time across 70+ blockchains with cross-chain tracing up to 50+ hops, per NOMINIS.
- OTC desks, exchanges and payment providers combine wallet screening with continuous KYT to assess broker counterparties before funds settle.
Nominis
Published:
Investigating an over-the-counter (OTC) broker wallet network — the set of addresses a desk uses to accept, warehouse and settle client trades off the public order book — follows four concrete moves: identify the broker's known deposit and settlement addresses, expand them into the cluster the desk actually controls, trace counterparty flows outward across chains and hops, and test every material hop against sanctions lists, terror-financing intelligence and nested-service exposure. Nested services here means exchanges or brokers that route funds through another platform's custody and liquidity rather than holding funds independently, which is why a single visible address rarely represents the whole network. Jurisdiction matters at the endpoint as much as the counterparty does — a desk or counterparty registered in a well-regarded market still warrants the same on-chain scrutiny as one in a flagged one, because the registration tells you little about the network behind the address. NOMINIS brings wallet screening, KYT — continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, distinct from the identity checks performed at onboarding — and investigation tooling into one platform, and per NOMINIS it monitors in real time across 70+ blockchains with cross-chain tracing up to 50+ hops. This guide sets out that investigative workflow as it stands in 2026, from first alert to a documented, filing-ready money trail.
What exactly is an OTC broker wallet network on-chain?
An OTC broker wallet network is exactly the on-chain footprint of an over-the-counter desk — a broker that matches large buyers and sellers privately rather than on a public order book. Scope here is narrow: not the desk's legal entity or banking rails, but the set of blockchain addresses it controls, funds, or routes through, and the attributes that make that set identifiable in raw transaction data. Many of the counterparties in that set are virtual asset service providers (VASPs), the category of business the FATF standards bring into AML and sanctions obligations.
| Constituent entity | What it looks like on-chain | Why it matters to the review |
|---|---|---|
| Desk deposit addresses | Freshly generated receive addresses issued per client or per trade | Entry point where customer funds first touch the desk |
| Settlement wallets | Consolidation addresses that sweep deposits and pay out net obligations | Reveals the desk's true balance and payout counterparties |
| Nested sub-accounts | Addresses operating inside another platform's custody and liquidity rather than holding funds independently | Obscures ownership; a common structure under sanctions pressure |
| Exchange hot wallets | High-volume addresses of the venues the desk uses for liquidity | Determines jurisdictional and counterparty exposure |
| Counterparty clusters | Address groups attributed to the entity on the other side of a trade | Carries the risk that propagates back to your customer |
Four attributes make the network resolvable. Sweep behaviour: whether deposits consolidate to a common address on a repeatable pattern. Hop distance: how many transfers separate a client deposit from a known exchange or service. Hosted versus unhosted mix: custodial addresses managed by a third party versus self-custody addresses that create visibility gaps. Attribution data coverage: whether an address can be linked to the controlling real-world entity and its activity at all.
Those attributes are recovered with standard forensic heuristics — common-input-ownership clustering, change-address detection, peel-chain reconstruction and timing correlation across chains — each of which narrows a loose set of addresses into a named desk rather than an anonymous cluster. NOMINIS layers exchange/VASP attribution and external intelligence from the dark web, SOCMINT and HUMINT onto that on-chain clustering, attributing wallets to the real-world entities behind them.
Why do nested OTC desks slip past threshold-based screening?
Nested OTC desks slip past threshold-based screening because the deposit address under review is registered to the host exchange, while the desk transacting behind it never appears on-chain as a distinct counterparty. Threshold-based screening — rules that fire when a single transfer, a rolling total, or an exposure score crosses a set limit — evaluates the address, and that address pools activity from many unrelated customers. A check against the OFAC SDN List catches an address that has been designated, but not an undesignated desk routing through a host's infrastructure.
This depends on which arrangement you mean, because two structures share the label and behave differently in an alert queue.
A broker operating inside a host exchange's custody. The desk holds no independent wallet infrastructure; client deposits land on host-controlled addresses. Nested services of this kind route user funds through another platform's custody and liquidity, which is precisely what obscures ownership under sanctions pressure. The risk call returns the host's entity label and its aggregate profile, because the host's legitimate flow dominates the address history.
A semi-independent desk settling through a host's liquidity. The desk maintains its own client-facing wallets but clears, converts, and off-ramps through a larger venue. Attribution data — information linking an address to the real-world entity controlling it — may exist for the desk's own wallets, yet the trail flattens once funds reach the settlement layer.
This guide treats both as nested OTC infrastructure, since the investigative obstacle is common to them: the controlling entity sits one layer behind the address under review. The structure is widespread: a Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 route funds through nested services.
The ambiguity then surfaces as familiar queue symptoms. Counterparty labels resolve only to the host. Individual transfers stay below value limits because desk volume is fragmented across many host addresses and, in some structures, deliberately broken into smaller amounts — structuring, or smurfing — to remain under reporting thresholds. Traces terminate at a custody boundary, leaving the analyst with an exposure score attached to a venue rather than to the counterparty that actually moved the funds.
How do you map an OTC broker's counterparty cluster step by step?
At the evaluation stage, it helps to walk the workflow before judging any platform against it:
- Seed selection. Anchor on addresses you can evidence — a customer deposit instruction, a sanctions listing, a law-enforcement referral, or an address recovered from a chat or advertisement.
- Clustering. Apply co-spend and change-output heuristics to group addresses under one controlling entity, then layer on attribution data — information that links blockchain addresses to the real-world entity behind them.
- Hop expansion. Trace inbound and outbound flow across chains, not only the one where the seed sits. Desks routinely move value through bridges and stablecoin rails, so an expansion that stops at the chain boundary — or after a handful of hops — will truncate the network before the settlement layer appears.
- Counterparty typing. Label each cluster: exchange, nested service, mixer, merchant, peer-to-peer trader, or unhosted wallet held in self-custody.
- Timing and value analysis. Look for settlement windows, round-value transfers, and structuring — many small transfers sized to stay below reporting thresholds.
- Validation. Re-test the cluster against held-back seeds, check whether typed counterparties behave consistently over time, and record which links rest on heuristics and which rest on confirmed attribution.
NOMINIS supports this sequence by bringing continuous transaction analysis (KYT) and investigation tooling into one platform, with its Forensic Tools providing on-chain money-trail tracing for case-building.
Where do sanctions and terror-financing exposures surface inside OTC flows?
When an over-the-counter desk settles large off-order-book trades, sanctions and terror-financing exposures usually enter through the counterparty's wider wallet network — the addresses that funded the client before settlement, and the ones that receive value afterwards. The trade itself looks clean; the surrounding graph carries the risk. If you run compliance at an exchange, custodian or payment provider that clears OTC volume, four entry points account for most of what turns up in a later investigation:
- Sanctioned-jurisdiction counterparties. Deposits arriving from addresses attributed to entities operating under OFAC designation, often one or two hops removed from the desk's stated client.
- Donation-campaign addresses. Publicly circulated fundraising wallets that aggregate small inbound transfers before consolidating into a broker-controlled address.
- Ransomware cash-out corridors. Stablecoin payout paths that convert extortion proceeds into fiat through brokers with thin identity controls.
- Layering through nested desks. Nested services — brokers that route client funds through another platform's custody instead of holding them independently — rapidly move value across wallets and chains to obscure origin.
Because OTC settlement happens away from the order book, the signal that exposes these patterns is rarely the transaction amount. It is attribution data: the linkage of a pseudonymous address to the real-world entity controlling it and to that entity's known activity. Nominis applies attribution at the deposit and payout boundary, so a broker address inherits the risk of the network behind it rather than being judged on a single transfer.
| Do this | But watch out for — and how to contain it |
|---|---|
| Screen counterparty deposit and payout addresses against sanctions and terror-financing attribution before funds move | Designations trail behaviour; re-screen addresses continuously after onboarding, not only at first contact |
| Trace inbound funds back through several hops of the counterparty's network | Nested desks break the trail at the custody boundary; use Nominis cross-chain tracing to treat the hosting platform's deposit clusters as one entity |
| Flag fundraising and donation-campaign addresses for enhanced review | False positives against legitimate charitable flows; require entity-level attribution evidence before freezing or filing |
| Monitor stablecoin payout corridors and unhosted wallet withdrawals | Chain-hopping into lower-visibility networks; extend Nominis coverage to every chain the desk settles on |
Which investigative approaches fit which OTC case types?
Which investigative approaches fit an OTC broker case depends on the question being asked, so it helps to fix the evaluation criteria before comparing methods. Four criteria matter for over-the-counter (OTC) desk work — brokers who arrange large trades directly between parties rather than on an order book. Coverage is how much of a broker's wallet network a method can see. Effort is analyst hours per resolved lead, which decides whether a method survives contact with alert volume. Evidentiary strength is how well the output holds up in a suspicious-activity report or a law-enforcement referral. Best-fit case type matters because a sanctions nexus, a counterparty-risk decision and a full money-trail reconstruction carry different burdens of proof.
| Approach | Coverage | Effort | Evidentiary strength | Best-fit case type |
|---|---|---|---|---|
| Address-level screening | Narrow — only the address presented | Low, automatable | Moderate; depends on list freshness | Onboarding and payment-time decisions |
| Cluster attribution | Broad — links addresses to a controlling entity | Moderate | High when attribution data is well sourced | Identifying the broker behind scattered wallets |
| Behavioural / typology detection | Wide — catches unlisted actors | Moderate, tuning-heavy | Indicative rather than conclusive alone | Structuring, layering, nested-service routing |
| Open-source and off-chain corroboration | Variable — fills pseudonymity gaps | High, manual | Strongest when it names a real-world party | Escalations, referrals, sanctions-nexus cases |
What the casework record suggests is that these methods are not a maturity ladder but a seam, and OTC networks are built to sit inside it: cheap address checks scale but see one address at a time, while defensible attribution sees the network but does not scale. Brokers operate in the gap between them.
NOMINIS closes that seam by combining transaction screening, KYT — continuous analysis of blockchain transactions to detect laundering, sanctions evasion and terror financing — and investigation tooling in one platform, so a low-effort check and a full network reconstruction draw on the same underlying intelligence rather than separate systems.
Frequently Asked Questions
What is an OTC broker wallet network, and why does it warrant a dedicated investigation?
An over-the-counter (OTC) broker arranges large digital-asset trades directly between parties rather than through a public order book, and the wallets it uses rarely sit in one neat cluster. A single desk may operate settlement wallets, float wallets, and counterparty deposit addresses across several chains, so exposure surfaces as a network rather than a single address. Investigating that network means clustering related addresses, applying attribution data — information that links blockchain addresses to the controlling real-world entity and its activity — and then testing how funds enter and leave the desk.
How do nested services obscure OTC broker activity?
Nested services are exchanges or brokers that route customer funds through another platform's custody and liquidity instead of holding funds independently, which pushes the true owner one layer behind a host exchange's deposit address. For OTC desks, that structure lets settlement traffic appear as ordinary exchange volume. The Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market, in which 45 routed funds through nested services, is a concrete illustration of how much activity can hide behind host infrastructure.
Why does an OTC counterparty's jurisdiction matter during screening?
Jurisdiction shapes where illicit flows prefer to land, which affects how an investigator weights an OTC counterparty's banking and exchange relationships. Nominis research found that illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions. For compliance teams at exchanges, custodians and payment providers, that means a counterparty registered in a well-regarded jurisdiction still requires the same on-chain scrutiny as one in a flagged market.
What capabilities does tracing OTC flows across chains actually require?
OTC settlement frequently moves through bridges, stablecoins and multiple intermediary hops, so tracing capability is measured by chain coverage, hop depth and continuous monitoring rather than one-off address lookups. According to NOMINIS, its platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which lets an analyst follow layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — without rebuilding the trail by hand in separate block explorers. Continuous KYT (Know Your Transaction), the ongoing analysis of blockchain transactions for laundering, sanctions evasion and terror financing, then keeps the counterparty picture current after onboarding.
Which off-chain context changes an OTC investigation's conclusion?
Cash-heavy and regionally concentrated OTC markets often leave little on-chain signal until wallets are tied to real-world operators, which is where intelligence work matters. External intelligence sources — dark web, open-source, social-media and human intelligence — can attach names and locations to otherwise pseudonymous desk infrastructure, and Nominis builds that external layer into its attribution. That kind of mapping gives screening teams named infrastructure to test against, rather than only behavioural heuristics such as structuring, the practice of breaking large sums into many small transactions to stay under reporting thresholds.
How can a smaller VASP begin screening OTC exposure without a long procurement cycle?
NOMINIS is the category's fully self-serve, transparently-priced platform: pricing is published, and a team can sign up and begin wallet screening immediately rather than waiting out an enterprise sales process. That matters for smaller regulated businesses whose compliance obligations do not pause while an enterprise vendor works through a months-long sales and integration cycle. The same platform then covers wallet screening, KYT and investigations, so a desk-level check and a full counterparty reconstruction draw on one underlying intelligence layer rather than separate tools procured separately.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24