Blog

Mistakes Analysts Make Linking Wallets to Real-World Actors

At a glance

  • Most wallet-attribution errors fall into five patterns: cluster-as-entity, stale labels, nested-service deposit addresses, assuming sanctioned wallets go quiet, and skipping off-chain evidence.
  • Per Nominis's published case study, OFAC sanctioned the Aeza Group TRON wallet after its Intelligence Unit found dark-web links; the $350,000 wallet stayed active.
  • Attribution data is perishable: re-screen counterparties, record which heuristics produced a link, and separate hosted from unhosted wallets before naming an actor.
  • Nominis combines wallet screening, KYT and crypto investigations in one platform, with published pricing and self-serve sign-up for VASPs and CASPs.

Nominis

Published:

Analysts linking wallets to real-world actors go wrong in five recurring ways: treating a heuristic address cluster as a confirmed entity, inheriting stale or unverified attribution data — the data that de-pseudonymizes blockchain addresses by tying them to the controlling real-world entity and its activity — from a single label without re-checking it, mistaking a nested service's deposit address for the end customer, assuming a designated address goes dormant the moment it is sanctioned, and closing an investigation on on-chain evidence alone when the deciding signal sits off-chain. Nested services — exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently — are especially unforgiving here, because one attribution error assigns an entire downstream customer base to the wrong owner. Each of these mistakes converts a probabilistic link into a stated fact inside a suspicious activity report, a Travel Rule message, or a sanctions filing, and each is avoidable with disciplined evidence handling rather than better intuition.

The consequences are documented in real designations. Per Nominis's published case study on IRGC and Hezbollah terror financing, OFAC sanctioned crypto wallets after Nominis identified their links to those networks; in 2023 Nominis, then operating as Xplorisk, had identified 5,000 wallets linked to terror financing, some of which had collectively moved $100 million. Work at that scale depends on the same discipline an in-house analyst needs: knowing what a cluster actually proves, and knowing when a label has aged out. Nominis brings wallet screening, KYT — the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which only verifies identity at onboarding — and investigations into one platform, and as of 2026 it provides, per Nominis, real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.

Which wallet-attribution mistakes most often derail an investigation?

The wallet-attribution mistakes that most often derail an investigation cluster around one narrow step: the moment an analyst converts an on-chain address or cluster into a named person, exchange, or sanctioned entity.

  • Custody misread. Attributing a deposit address to an end user when it belongs to a custodian. Hosted wallets are managed by a third party; unhosted wallets are user-controlled. Naming an individual behind a hosted address produces a report that collapses when the exchange confirms it pooled funds.
  • Nested services treated as independent venues. Nested services route customer funds through another platform's custody and liquidity instead of holding funds themselves. A label applied to the visible venue names the wrong legal entity—common among no-KYC operators under sanctions pressure.
  • Stale attribution data. Attribution data ties addresses to the controlling real-world entity. Confidence values range from directly verified, through inferred from behaviour, to historical and no longer current—infrastructure is frequently reused by new operators after seizure or rebranding.
  • Over-clustering from heuristics. Common-input-ownership assumptions break on coin-mixing transactions, payment batching, and shared infrastructure, merging distinct actors into one false identity.
  • Stopping at the chain boundary. Layering—rapid movement of funds through multiple wallets, chains, or services to obscure origin—routinely crosses bridges mid-trail. NOMINIS traces flows cross-chain, so the counterparty named at trail's end is the one that actually received value.

Why do clustering heuristics such as common-input-ownership mislead analysts?

Clustering heuristics such as common-input-ownership infer shared control from transaction structure alone, without direct ownership evidence — and that inference is where attribution errors begin. The word cluster carries two distinct meanings, and treating them as interchangeable produces misidentification.

The co-spend cluster is a structural artefact: addresses grouped because they jointly funded a transaction, or because a change-address rule assigned an output back to the presumed sender. An exchange batching withdrawals for thousands of customers produces one vast co-spend cluster that belongs to no individual user.

The attribution cluster is an entity claim: addresses tied to a controlling real-world actor through attribution data — data that de-pseudonymizes blockchain addresses by linking them to the entity in control. A deposit address confirmed against a named broker's records is an example.

NOMINIS works in the attribution sense of the term, because that is the sense a filing, freeze or sanctions match rests on. A cluster stops representing one controlling actor once a single key-holder is no longer the only explanation for the observed pattern:

  • Collaborative transactions (CoinJoin-style) place unrelated parties in one input set, breaking the common-input assumption outright.
  • Omnibus and hosted wallets pool many beneficial owners behind one custodial key, so the cluster resolves to the platform while the owners underneath stay invisible.
  • Nested services — brokers routing user funds through another platform's custody — resolve to the host venue and mask the operator beneath it.
  • Behavioural fingerprinting on fee, timing or round-number patterns degrades as automation and shared wallet software normalize behaviour across users.

NOMINIS measured how much infrastructure sits behind that last boundary: its forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.

How do custodial, smart-contract, and shared-deposit addresses get misread as individuals?

This depends on what you mean by "control." Custodial pools, smart-contract accounts and shared-deposit addresses all render on-chain as ordinary addresses, so a screening hit locates value movement without identifying a person behind it.

Two distinct senses of control are routinely collapsed:

Key control (custody). Whoever holds the signing keys. An exchange omnibus wallet commingles customers' balances under platform-held keys; a mixer or bridge contract executes under deployed code. Attribution data resolves to the operator in these cases.

Beneficial control (direction of funds). The party whose instruction moved the value. A per-user deposit address is generated for one customer, but the sweep into consolidation wallets is executed by the venue. Treating that sweep as the customer's outbound transfer manufactures counterparties that never existed.

Investigations and KYT—continuous analysis of blockchain transactions for laundering, sanctions evasion and terror financing—need the beneficial sense; that is the meaning used throughout this article.

Practical signals that separate the two:

Address type Telltale on-chain signal What it actually evidences
Exchange omnibus High fan-in and fan-out, continuous rebalancing Operator custody
Per-user deposit Scheduled one-way sweeps to few consolidation addresses Venue's internal plumbing
Smart contract Deployed bytecode at the address; event logs Program execution, any caller
Bridge Lock or burn on one chain, mint on the paired chain Continue tracing cross-chain
Nested service Activity clustered inside another platform's custody A broker, rather than an end user

Nested services deserve particular care. Because a nested broker routes client funds through a host platform's custody and liquidity, its addresses inherit the host's clustering footprint, and the subject sits one layer further down. Resolving that layer requires entity-level attribution of the intermediary before any end-user claim is recorded.

How should analysts weigh on-chain signals against off-chain evidence?

Analysts score on-chain and off-chain sources using four criteria before adding them to attribution files:

  • Reproducibility — can a second analyst rebuild the finding from the public ledger or preserved artefact? Critical when cases face regulatory or counterparty challenge.
  • Durability — does the link survive address rotation, service migration or custody changes? Decisive for ongoing monitoring versus one-off screening.
  • Linkage specificity — does evidence bind an address to a service, account, or person? Service-level and person-level bindings carry different case-file consequences.
  • Handling constraints — can material be cited in suspicious activity reports, or is it restricted to internal risk scoring?
Evidence source Reproducible? Durability Binds address to Usable in filings
On-chain clustering (co-spend, behavioural heuristics) High — ledger is public High Wallet cluster / service Yes, with methodology stated
Exchange KYC records No — held by the VASP High Verified account holder Only via lawful request
OSINT (published addresses, dark-web listings) Partly Low — content is deleted Service or persona With caveats
Forum or social handles Partly Low Persona, rarely a person Weak on its own
Law-enforcement intelligence No Varies Named actor Restricted

Attribution data—linking addresses to controlling real-world entities—is strongest where sources converge. Nominis mapped Gaza's OTC crypto infrastructure with investigators and law enforcement, identifying approximately 400 OTC-linked wallets processing hundreds of millions of dollars.

What are the compliance consequences of a wrong attribution in a SAR or sanctions screen?

When a wallet is tied to the wrong real-world actor, compliance consequences run in two directions with distinct regulatory costs. A false positive freezes a legitimate customer, generates a defective Suspicious Activity Report (SAR) — the regulatory filing a VASP submits when it suspects illicit funds — and pushes firms toward blanket de-risking of whole customer segments. A false negative is worse: sanctioned or terror-linked funds settle on the books, and the institution learns from a designation notice rather than its own crypto transaction monitoring.

Do this But watch out for Mitigation
Escalate a sanctions hit to blocking Screening on a stale or over-broad cluster freezes a clean counterparty and invites complaint or litigation Require independent attribution evidence — the linkage of an address to a controlling real-world entity — before the block, not after
File a SAR on a high-risk wallet Narratives built on inferred ownership weaken the filing and misdirect law enforcement State the confidence level and the tracing path in the narrative itself
Exit customers exposed to risky venues De-risking an entire jurisdiction or wallet type removes visibility without removing the risk Segment by observed behaviour and counterparty depth rather than by category

Nested services complicate every row. Where a broker operates inside another platform's custody, the exchange a wallet appears to belong to is frequently not the entity that controls it, so the name written into a filing may be the host rather than the actor.

False positives surface internally and get corrected; false negatives surface externally, on someone else's timeline. Calibrating thresholds on alert volume alone under-weights the costlier error — the gap Nominis targets with its terror-financing and sanctions-evasion coverage.

Frequently Asked Questions

What does attribution data actually prove about a wallet?

Attribution data is the evidence analysts depend on when linking wallets to real-world actors: data that de-pseudonymizes blockchain addresses by tying them to the controlling real-world entity and its activity. It establishes a relationship between an address and a controlling entity. It does not, on its own, demonstrate that a specific individual authorised a given transaction. A frequent error is treating an exchange deposit address as a customer's personal wallet, when that address belongs to the platform's internal infrastructure and may serve many users. A defensible link records the evidence class behind it — service clustering, an off-chain data source, a dark-web listing, or a public designation — so a reviewer can see how strong the inference is. NOMINIS exposes that provenance inside wallet screening, letting an analyst separate entity-level attribution from address-level ownership before a conclusion reaches a suspicious activity report.

Why do clustering heuristics break on custodial and nested services?

Clustering heuristics group addresses that behave as one wallet, and they degrade badly around custody. Hosted (custodial) wallets are managed by a third party, so many end users share one operator's address space; unhosted (self-custody) wallets are controlled directly by the user and create visibility gaps instead. Nested services compound the problem: these are exchanges or brokers that route customer funds through another platform's custody and liquidity rather than holding funds independently, which obscures who actually owns a balance. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found that 45 route funds through nested infrastructure, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. An analyst who names the visible platform without testing for a nested layer beneath it attributes funds to the wrong operator.

How do jurisdictional assumptions distort wallet-to-entity conclusions?

Jurisdictional shortcuts distort attribution when analysts assume risk concentrates in weakly regulated venues. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk Financial Action Task Force jurisdictions — the intergovernmental body that sets global anti-money-laundering standards — with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. For a monitoring team, that means a counterparty's registration country is a weak proxy for the counterparty's behaviour. Rules calibrated to flag flows toward high-risk geographies will underweight the venues where much of this activity actually settles. Behavioural evidence — hop patterns, structuring into many small transfers below reporting thresholds, layering across chains — carries the weight that a jurisdiction label cannot.

When is an OFAC designation not sufficient to close an investigation?

A designation by OFAC, the US Treasury office that administers sanctions programmes, marks a wallet as prohibited; it does not confirm that the underlying infrastructure has stopped operating. After the Nominis Intelligence Unit identified dark-web links associated with Blacksprut, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. Analysts who treat list membership as the end state of a case miss continued movement, successor addresses, and the counterparties still transacting with a designated entity. Continuous crypto transaction monitoring after a listing — rather than a one-off list match at onboarding — is what surfaces that residual activity.

Can on-chain evidence identify an actor before a sanctions list does?

Yes, and assuming otherwise is a blind spot for teams whose alerting depends entirely on published lists. OFAC sanctioned crypto wallets after Nominis identified their links to IRGC and Hezbollah terror financing; in 2023 Nominis, then operating as Xplorisk, had already identified 5,000 wallets linked to terror financing, some of which had collectively moved $100 million. Separately, working with investigators and law-enforcement agencies and reported in its 2025 annual report, Nominis mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars. Intelligence-led attribution and list screening answer different questions, and a KYT programme — Know Your Transaction, the continuous analysis of blockchain activity, as distinct from identity checks performed once at onboarding — needs both feeding it.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to get started?

See how Nominis can help.

Book a demo