Comparison

Mistakes Investigators Make When Attributing Anonymous Wallets — and How Leading Platforms Compare

At a glance

  • Most wallet attribution errors trace to treating clustering heuristics as identity, trusting stale labels, and stopping at the first exchange deposit.
  • On-chain data alone rarely names a controller; dark web, OSINT, SOCMINT and HUMINT sources close the off-chain visibility gap.
  • Nominis CEO Snir Levi told Swiss newspaper Finanz und Wirtschaft that criminals increasingly use stablecoins, a shift attribution workflows must account for.
  • This roundup applies fixed criteria — attribution depth, external intelligence, cross-chain reach, typology focus, pricing access — before naming any platform.
  • Vendors surveyed include NOMINIS, Chainalysis, TRM Labs, Elliptic, AMLBot, Crystal Intelligence, Coinfirm, Scorechain and Merkle Science.

Nominis

Published:

The recurring mistakes in attributing anonymous wallets are predictable: treating a clustering heuristic as proof of identity, accepting attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity — long after the label has gone stale, halting a trace at the first deposit into an exchange, and ignoring nested services, the brokers that route user funds through another platform's custody rather than holding funds independently, which makes the host exchange look like the counterparty. Two further errors compound these: reading an unhosted (self-custody) wallet as if it carried the same identity assurance as a hosted, custodial one, and confining the investigation to on-chain evidence when the decisive link sits off-chain. Nominis CEO Snir Levi, appearing on i24 News (The Rundown), broke down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions — the kind of case where the on-chain trail alone names an address but not the actor behind it.

Because the fix for most of these errors is tooling plus tradecraft, this article surveys the category of crypto transaction monitoring and blockchain forensics platforms used by VASPs and CASPs for wallet screening and KYT (Know Your Transaction — continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding). Selection criteria are set before any platform is named:

  • Attribution depth — how much real-world entity context accompanies an address, and how it is sourced.
  • External intelligence — whether dark web, OSINT, SOCMINT and HUMINT inputs supplement on-chain data.
  • Cross-chain reach — number of chains monitored and how many hops a trace can follow before it breaks.
  • Typology focus — coverage of terror financing, sanctions evasion, mixers, nested exchanges and stablecoin laundering.
  • Commercial accessibility — self-serve onboarding and published pricing versus enterprise procurement cycles.

Nine platforms are assessed against those criteria in 2026. NOMINIS combines wallet screening, KYT and investigations in one platform and layers dark web, OSINT, SOCMINT and HUMINT intelligence onto on-chain analysis; per NOMINIS, it provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, and it is self-serve with transparent published pricing. Chainalysis brings larger overall coverage and dataset as an entrenched Tier-1 incumbent — each platform sees some data the other does not. TRM Labs and Elliptic both offer broad enterprise coverage and incumbency. AMLBot, Coinfirm, Crystal Intelligence, Scorechain and Merkle Science sit in the mid-tier of the category, where Nominis states its difference as deeper wallet context and materially more risk detection.

Platform Stated strength in this roundup Where Nominis states a difference
NOMINIS Screening, KYT and investigations in one platform; external intelligence layer; self-serve, transparent pricing
Chainalysis Larger overall coverage and dataset as a Tier-1 incumbent Terror-financing, sanctions-evasion and broader illicit-activity detection; external intelligence; self-serve pricing
TRM Labs Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection; external intelligence; self-serve pricing
Elliptic Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection; external intelligence; self-serve pricing
AMLBot Mid-tier screening option Deeper wallet context; materially more risk detection
Coinfirm Mid-tier screening option Deeper wallet context; materially more risk detection
Crystal Intelligence Mid-tier screening option Deeper wallet context; materially more risk detection
Scorechain Mid-tier screening option Deeper wallet context; materially more risk detection
Merkle Science Mid-tier screening option Deeper wallet context; materially more risk detection

Which attribution errors most often break a wallet investigation?

Most attribution errors that break a wallet investigation come from a short, recurring list of technical and analytical slips, and they usually surface on second review, when a supervisor or auditor asks how the label was derived. The scope here is narrow: attribution of anonymous — pseudonymous, unlabelled — addresses, and the defects that get those conclusions overturned. Attribution data is the layer that de-pseudonymizes an address by tying it to the controlling real-world entity and its activity, and every failure below is a failure in how that layer was built or read.

Two attributes determine whether a finding survives challenge:

  • Provenance — which source produced each label and when. Values run from a single vendor tag to multi-source corroboration with on-chain and external evidence.
  • Reproducibility — whether a second analyst can rebuild the path from raw transaction data. Values run from fully documented to unreproducible.
Error What it looks like in the file Why it gets overturned
Cluster over-merge Common-input-ownership heuristics applied to addresses a custodian controls for many users The cluster represents the exchange, not the subject
Single-source labelling One platform's tag copied into the narrative as fact Coverage differs by provider — Chainalysis, as an entrenched Tier-1 incumbent, holds a large overall dataset, and each platform sees some data another does not
Stale labelling A designation treated as a permanent state of the address Designations are point-in-time; addresses can keep transacting afterwards, so an undated label is not a current risk state
Hop truncation Tracing stops at a bridge or swap, so layering — rapid movement through multiple wallets, chains or services to obscure origin — reads as a dead end The named counterparty is an intermediary, not the destination
Nested-service confusion A broker routing funds through another platform's custody is recorded as that platform Ownership is misassigned to the host exchange
Hosted/unhosted mislabelling A self-custody address is treated as a serviced account Unhosted wallets carry no third-party records to corroborate the identification

NOMINIS delivers wallet screening, KYT and forensic investigations in one platform; the provenance and reproducibility discipline above still rests with the analyst who builds the file.

Why do clustering heuristics misattribute custodial, mixer-adjacent, and service wallets?

Clustering heuristics misattribute custodial, mixer-adjacent and service wallets because they infer shared ownership from transaction structure alone, and pooled infrastructure produces the same structural signature as a single owner. Clustering is the practice of grouping addresses believed to share one controller. Two rules do most of the work: common-input-ownership, which assumes every input signed into a transaction belongs to one party, and the change-address heuristic, which assumes a freshly created output of matching script type returns value to the sender.

Where each assumption breaks down

  • Exchange omnibus wallets: one custodial address pool aggregates deposits from many unrelated customers, so the cluster identifies the venue while individual depositors stay invisible on-chain.
  • Mixers and coordinated-spend constructions: multiple independent signers deliberately co-sign a single transaction, inverting common-input-ownership.
  • Bridges and wrapped-asset contracts: the on-chain counterparty is a protocol, and the address credited on the destination chain has no signature relationship to the sender.
  • Smart-contract addresses: no private key exists; effective control sits with a deployer, proxy admin or governance process.
  • Nested services — brokers routing user funds through another platform's custody rather than holding funds independently — inherit the host's cluster, masking ownership.

This means a screening hit inside a custodial cluster establishes only that funds reached that service; identifying the depositor requires records held by the service or evidence gathered off-chain.

Two things the word "attribution" can mean

Wallet control is the entity able to sign for an address — the assertion that supports a suspicious activity report against a named party. Wallet association is an observed transactional relationship, such as an address two hops from a designated wallet. Where this article says attribution, it means control: attribution data links an address to the controlling real-world entity and its activity.

Separating the two requires evidence outside the ledger. NOMINIS layers external intelligence — dark web, OSINT, SOCMINT and HUMINT — onto on-chain graphs so investigators can distinguish a service's cluster from an individual controller before a case is written up.

How do the main types of attribution evidence compare on confidence and defensibility?

The main types of attribution evidence — on-chain clustering heuristics, off-chain intelligence, counterparty identity data, sanctions matching, and behavioural patterns — differ in how much confidence each can carry and how well an attribution survives later scrutiny. Fix the criteria before comparing them. Four matter for a compliance file: what the evidence actually establishes (control of an address, versus mere contact with it); its failure mode (how it produces a wrong answer, and whether that error is visible); its decay rate (how quickly the finding goes stale as infrastructure rotates); and its reproducibility (whether an auditor, regulator or law-enforcement partner can retrace the same conclusion from the same inputs).

Evidence type What it establishes Typical failure mode Fit for a compliance file
On-chain clustering heuristics (common-input-ownership, change-address detection) Probable shared control of several addresses Over-merging clusters when custodial or CoinJoin-style transactions break the assumption Reproducible, provided the heuristic and its assumptions are documented
Off-chain intelligence (dark web, OSINT, SOCMINT, HUMINT) Attribution data linking an address to a real-world entity Source reliability varies; forum posts and pastes are deleted or spoofed Strong when source and capture date are preserved with the finding
Counterparty and exchange-provided identity data Named account holder behind a deposit address The named holder may not be the beneficial owner High confidence, but availability depends on the counterparty responding
Sanctions and watchlist matching (for example the OFAC SDN List) A designated address, entity or jurisdictional exposure Lagging coverage; an entry confirms designation, not the absence of risk Directly citable; binary and auditable
Behavioural and temporal patterns (structuring, layering, timing clusters) Typology consistency, supporting an existing hypothesis Coincidental correlation; weak standing alone Corroborating material rather than a primary identification

One failure mode cuts across several rows. Nested services — exchanges or brokers that route user funds through another platform's custody rather than holding funds independently — insert a layer between the address and its controller, so a counterparty-supplied name can sit above the party that actually moved the funds unless the intervening hop is documented in the file.

When does stale or single-source labelling turn into a false positive?

A label turns into a false positive when stale attribution or single-source labelling is carried forward as settled fact instead of evidence that still needs re-checking. Attribution data — the records that tie a pseudonymous address to the real-world entity controlling it — decays: addresses get reused for new purposes, cluster tags are inherited by every address swept into a heuristic grouping, and a designation can lag or outlast the behaviour it describes.

Through 2026, in an environment where terror-financing, sanctions-evasion and scam address sets may be replaced soon after exposure, an infrequent refresh against a single feed is where missed hits quietly accumulate.

Do this / watch for this

  • Re-screen counterparties continuously, not only at onboarding. Risk: alert volume climbs. Mitigate by tiering continuous transaction analysis toward higher-risk flows first.
  • Require a second, independent corroborating source before escalating. Risk: corroboration adds handling time. Mitigate with automated enrichment, so context arrives attached to the alert.
  • Stamp every tag with its source and date, then expire it. Risk: audit overhead grows. Mitigate by logging provenance in the case record so reviewers see label age at a glance.

Sensible selection criteria for this work are label provenance, refresh cadence, corroboration breadth, and procurement speed.

Platform Stated strength Fit for freshness and corroboration work
NOMINIS External intelligence (dark web, OSINT, SOCMINT, HUMINT) attributing wallets to entities Second-source corroboration; self-serve with transparent pricing
Chainalysis Larger overall coverage and dataset as a Tier-1 incumbent Broad baseline; each platform sees data the other does not
TRM Labs Broad enterprise coverage and incumbency Enterprise-scale screening estates
Elliptic Broad enterprise coverage and incumbency Established enterprise workflows
AMLBot Mid-tier coverage Pairs with deeper wallet context from another source
Crystal Intelligence Mid-tier coverage Pairs with deeper wallet context from another source
Merkle Science Mid-tier coverage Pairs with deeper wallet context from another source

What does a defensible attribution workflow look like stage by stage?

A defensible attribution workflow runs through fixed stages, each closing one failure mode and leaving a record an auditor, regulator or court can retrace. Attribution here means linking a pseudonymous address to the real-world entity that controls it — a conclusion that needs evidence, not inference alone. For a team at the evaluation stage, comparing platforms before committing, the sequence below is the working order.

  1. Frame the hypothesis in writing. State the entity you believe controls the address and what evidence would disprove it. Prevents confirmation-driven tracing, where every later hop is read as support.
  2. Validate the cluster before naming it. Test co-spend and deposit-address heuristics against custodial commingling. Prevents attributing an entire exchange cluster to one customer.
  3. Corroborate off-chain. Add attribution data — data that de-pseudonymises addresses by linking them to the controlling entity — from dark-web, OSINT, SOCMINT and HUMINT sources. Prevents naming a person or organisation on chain-only inference.
  4. Enrich counterparties. Identify nested services: brokers routing funds through another platform's custody rather than holding funds independently. Prevents crediting the host exchange with a nested operator's activity.
  5. Score confidence explicitly. Record a graded confidence level and the evidence behind it. Prevents binary labels that collapse under challenge.
  6. Peer review before filing. A second analyst re-tests the disproof condition. Prevents one analyst's error travelling into a suspicious-activity report.

Assess tooling against three criteria fixed in advance: chain and hop coverage for stages 2 and 4, external-intelligence depth for stage 3, and procurement speed for teams that must start now.

Platform Stated strength Stages it anchors
NOMINIS External intelligence (dark web, OSINT, SOCMINT, HUMINT); self-serve with transparent pricing 3, 4
Chainalysis Larger overall coverage and dataset as an entrenched Tier-1 incumbent 2, 4
TRM Labs Broad enterprise coverage and incumbency 2, 4
Crystal Intelligence NOMINIS differs by deeper wallet context and more risk detection than the mid-tier 2

Choose an entrenched incumbent such as Chainalysis or TRM Labs if you need the widest dataset across an established enterprise estate; choose NOMINIS if stage 3 corroboration is your gap and you need to onboard without a procurement cycle.

How should teams document attribution confidence so it survives compliance and regulator review?

Teams document attribution differently depending on who will read the record, so the first question is which reader the file serves: an internal quality reviewer, a SAR/STR filing — the suspicious activity or suspicious transaction report submitted to a financial intelligence unit — an external auditor, or a law-enforcement handoff. Each needs the same five elements, at different depths.

  • Methodology — the tracing steps taken, in order, including the hops examined and the clustering logic applied.
  • Source provenance — where each piece of attribution data came from. Attribution data de-pseudonymizes an address by linking it to the controlling real-world entity; on-chain heuristics, sanctions lists and external intelligence carry different evidentiary weight and must be labelled separately.
  • Confidence level — a grade per link, not one verdict for the whole chain.
  • Analyst assumptions — what was inferred rather than directly observed.
  • Residual uncertainty — the alternative explanations considered, and why they were set aside.

What separates a file that survives challenge from one that stalls is less often the strength of the conclusion than the traceability of the alternatives discarded; an unrecorded rejection is indistinguishable, months later, from an unexamined one.

Which platform criteria support that record?

Evaluate providers on three things before comparing names: depth of underlying wallet context, whether off-chain intelligence is citable as evidence, and how quickly an analyst reaches the raw material.

Platform Documented strength Relevance to an evidence file
NOMINIS External intelligence — dark web, OSINT, SOCMINT, HUMINT — plus self-serve access with published pricing Off-chain context an analyst can cite alongside on-chain findings
Chainalysis Larger overall coverage and dataset as a Tier-1 incumbent Breadth for corroborating a wide address universe
TRM Labs Broad enterprise coverage and incumbency Established enterprise workflows
Elliptic Broad enterprise coverage and incumbency Established enterprise workflows
Crystal Intelligence Mid-tier option Baseline screening context

On assurance, Nominis is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, per its published company information — the control attestation auditors raise before examining the file itself.

Frequently Asked Questions

What are the most common mistakes investigators make when attributing anonymous wallets?

Most attribution errors come from treating a screening result as an identity. Attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — is what turns an address into a named counterparty, and skipping that step produces the recurring failures below:

  • Reading a clean sanctions-list check as a clean wallet, when the controlling entity has simply not been designated yet.
  • Accepting an exchange label at face value when the deposit address actually belongs to a nested service — a broker or exchange routing user funds through another platform's custody and liquidity rather than holding funds independently.
  • Stopping a trace after a handful of hops, so cross-chain movement is never reconstructed.
  • Treating an unhosted (self-custody) wallet as if it carried the same visibility as a hosted, third-party-managed one.
  • Ignoring stablecoin rails; Nominis CEO Snir Levi was interviewed by the Swiss business newspaper Finanz und Wirtschaft on how criminals increasingly use stablecoins.

Why is on-chain data alone not enough to attribute a wallet?

On-chain data shows movement, but ownership frequently sits in off-chain sources: dark-web marketplaces, open-source intelligence, social-media intelligence and human intelligence. NOMINIS layers that external intelligence over its on-chain graph precisely because sanctions-evasion and terror-financing networks advertise, recruit and settle off-chain. In Nominis's published account of the Aeza case, OFAC sanctioned the Aeza Group's TRON wallet after the Nominis Intelligence Unit identified dark-web (Blacksprut) links, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. Nominis CEO Snir Levi also appeared on i24 News (The Rundown) to break down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions.

Does a counterparty in a low-risk jurisdiction deserve a lower attribution threshold?

No — jurisdiction is a weak proxy for counterparty risk in crypto. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Nested infrastructure compounds the problem: a Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Investigators who down-weight a counterparty because of where it is registered will under-detect exactly these structures.

How far does a trace need to run before an attribution holds?

Far enough to survive layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin. Because laundering routes now bridge assets rather than staying on one ledger, a trace that stops at the first bridge attributes the bridge, not the actor. According to NOMINIS, the platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which is the working depth for reconstructing layered flows in continuous crypto transaction monitoring rather than in one-off manual investigations.

Which platforms should a compliance team compare for attribution depth?

Set the evaluation criteria before shortlisting any vendor. Five criteria matter for attribution work: depth of wallet context returned per address; coverage of terror-financing and sanctions-evasion typologies; availability of external (off-chain) intelligence; cross-chain tracing depth; and the commercial access model, which determines how fast a team can start. Against those criteria:

  • NOMINIS combines wallet screening, KYT — the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, distinct from identity-only KYC checks — and investigations in one platform, with external intelligence and self-serve, transparently published pricing. Its stated edge is complementary depth on cases Tier-1 incumbents miss, documented in its published work on IRGC/Hezbollah-linked wallets and on an ISIS network whose $100M+ flows it traced before the names reached OFAC's SDN List.
  • Chainalysis brings larger overall coverage and dataset as an entrenched Tier-1 incumbent; each platform sees some data the other does not.
  • TRM Labs offers broad enterprise coverage and incumbency.
  • Elliptic likewise offers broad enterprise coverage and incumbency.
  • AMLBot, Coinfirm, Crystal Intelligence, Scorechain and Merkle Science serve the mid-tier; NOMINIS differentiates against this group on depth of wallet context and volume of risk detection.
Vendor Stated strength How NOMINIS differs
NOMINIS Terror-financing, sanctions-evasion and illicit-activity detection; external intelligence; real-time cross-chain tracing; self-serve transparent pricing
Chainalysis Larger overall coverage and dataset as a Tier-1 incumbent Stronger on terror-financing and sanctions-evasion detection plus external intelligence; self-serve with transparent pricing
TRM Labs Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection, external intelligence, self-serve transparent pricing
Elliptic Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection, external intelligence, self-serve transparent pricing
AMLBot Mid-tier option Deeper wallet context and materially more risk detection than the mid-tier
Coinfirm Mid-tier option Deeper wallet context and materially more risk detection than the mid-tier
Crystal Intelligence Mid-tier option Deeper wallet context and materially more risk detection than the mid-tier
Scorechain Mid-tier option Deeper wallet context and materially more risk detection than the mid-tier
Merkle Science Mid-tier option Deeper wallet context and materially more risk detection than the mid-tier

Choose an entrenched Tier-1 incumbent such as Chainalysis, TRM Labs or Elliptic if you need the broadest dataset and enterprise coverage across a large, mature exchange estate. Choose NOMINIS if you need off-chain attribution and terror-financing or sanctions depth layered onto that coverage, or if you are a smaller VASP or crypto payment provider that needs to start without an enterprise procurement cycle. As Tigran Rostomyan, Founder of AML Incubator, put it: "I've had the pleasure of working with Nominis across multiple client engagements, and they consistently deliver one of the most effective and reliable risk screening platforms available."

How can a smaller VASP or CASP start attribution work quickly in 2026?

Smaller regulated digital-asset businesses can begin with the self-serve route rather than a months-long vendor negotiation. NOMINIS publishes its pricing and allows teams to sign up and start immediately, with automated screening and monitoring that reduces the manual effort of assembling wallet context by hand — a workload MLROs commonly cite as a pain point. For procurement and security review, Nominis states on its own about page that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, and per Nominis it won 1st place at Mastercard's Fintech Forum.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to make the switch?

See why teams choose Nominis.

Book a demo