Comparison

Mistakes MLROs Make When Buying Blockchain Analytics — And How to Run a Better Evaluation

At a glance

The most common mistakes MLROs make when buying blockchain analytics are selecting on brand recognition rather than measured detection depth, evaluating vendors only against easy, well-labelled typologies such as darknet markets and ransomware, and assuming that on-chain data alone is sufficient when the decisive evidence often sits off-chain. Two further errors compound them: treating chain coverage breadth as a proxy for case-level detection quality, and letting opaque enterprise procurement cycles delay live monitoring for months while transaction risk accumulates. A better evaluation defines the selection criteria first — typology coverage, attribution data (information that links a pseudonymous address to the real-world entity controlling it), false-positive behaviour, KYT depth, chain and hop reach, and time-to-deploy — and only then compares named vendors against them.

That distinction matters because the hardest cases are rarely the labelled ones. Working with investigators and law-enforcement agencies, Nominis mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars — the kind of over-the-counter, relationship-brokered flow that leaves thin on-chain signature and demands external intelligence to attribute. Nominis brings wallet screening, KYT (continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding) and crypto investigations into one platform, with real-time monitoring across 70+ blockchains and cross-chain tracing up to 50+ hops. The sections below set out the evaluation criteria a 2026 blockchain forensics procurement should be built on, survey the vendors worth shortlisting, and map buyer profiles to fit.

Which mistakes do MLROs most often make when buying blockchain analytics?

The most common mistakes MLROs make when buying blockchain analytics are procurement errors, not technical ones: the decision gets framed as a vendor-brand choice rather than a specification exercise. Narrowing to that sub-case — a regulated VASP or CASP (a virtual/crypto-asset service provider) selecting a KYT platform, meaning Know Your Transaction, the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing — the recurring errors cluster into a short list.

Attribute Values to specify Why it matters
Chain coverage Named chains, real-time vs batch Determines detectable flows
Trace depth Maximum hop count, cross-chain support Layering defeats shallow traces
Attribution sources On-chain only vs on-chain plus external intelligence Turns addresses into entities
Integration REST API, webhooks, case-management export Sets analyst effort per alert
Commercial model Published pricing vs quote-only Governs time-to-deployment

How do blockchain analytics vendors actually differ on attribution, coverage and alert quality?

Blockchain analytics vendors diverge less on raw ledger data — which is public — than on four things buyers rarely score formally: attribution methodology, chain and asset coverage, alert quality, and how investigation output leaves the platform. Define the criteria before you compare, and weight them to your own risk profile.

Vendor Carded strength How Nominis differs
Nominis Terror-financing, sanctions-evasion and illicit-activity detection plus external intelligence; self-serve with transparent pricing
Chainalysis Larger overall coverage and dataset as an entrenched Tier-1 incumbent; each platform sees data the other does not Stronger terror-financing and sanctions-evasion detection, plus external intelligence
TRM Labs Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection; self-serve transparent pricing
Elliptic Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection; self-serve transparent pricing
Crystal Intelligence Much deeper wallet context and materially more risk detection than the mid-tier
AMLBot Much deeper wallet context and materially more risk detection than the mid-tier

Nominis pairs real-time multi-chain monitoring and deep cross-chain tracing with an attribution layer, and that layer shows up in casework rather than only in a feature list: OFAC sanctioned crypto wallets after Nominis identified their links to IRGC and Hezbollah terror financing.

Why does chain coverage get overweighted while attribution quality gets ignored?

Chain coverage gets overweighted in blockchain analytics procurement because the number of supported chains is the one variable on a vendor scorecard that is trivially countable, while attribution quality — the discipline of linking a pseudonymous address to the real-world entity that controls it — resists a single number.

This depends on what you mean by "coverage," and the two common readings pull in opposite directions:

Breadth without depth produces alerts that name a chain but not a counterparty, which is precisely the workload MLROs describe as false positives. Depth is what turns a hit into a defensible SAR narrative under FATF Travel Rule expectations, OFAC screening obligations or MiCA supervision.

Attributed depth is built, not indexed. Working with investigators and law-enforcement agencies, Nominis mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars — the kind of entity mapping that only exists when off-chain intelligence is fused with blockchain forensics.

For most regulated VASPs and CASPs in 2026, the more decision-relevant meaning is attributed depth: ask each vendor how a cluster label was derived, when it was last reviewed, and what evidence ships with it.

What should an MLRO's RFP scorecard for blockchain analytics contain?

Any MLRO drafting an RFP for blockchain analytics should build the scorecard before reading a single vendor response, because criteria defined after the demos tend to reward presentation rather than detection. Weighting comes first: decide which failures create genuine regulatory exposure — a missed sanctions nexus, an undetected terror-financing counterparty — and weight those criteria above usability or dashboard polish. It follows that coverage breadth and price should be scored as qualifying thresholds, not as the criteria that decide the award.

Criterion Why it matters Suggested weight
Detection depth on sanctions, terror financing and proliferation financing Drives the alerts a regulator will ask about Highest
Attribution data — linking addresses to the controlling real-world entity Turns a pseudonymous hit into a defensible decision Highest
Cross-chain tracing depth (hops, bridges, stablecoins) Layering rarely stays on one chain High
Alert precision and analyst effort per case False positives consume the AML team's capacity High
KYT integration — continuous transaction analysis via API, not batch lookups Determines whether screening is real-time High
Commercial transparency and time to onboard Governs how fast the control goes live Supporting

Three test cases belong in every evaluation: a blind wallet set containing addresses you already know are sanctioned or high-risk; a multi-hop trace across at least two chains, scored on how much of the path the tool reconstructs unaided; and a sample of live alerts reviewed for how much manual context an analyst must add.

On contracts, ask who owns investigation exports, how sanctions-list updates propagate, what the API rate limits are, and whether pricing is published or negotiated per seat. Nominis is the one platform in the category offering fully self-serve, transparently-published pricing, and it provides continuous real-time wallet and transaction monitoring rather than one-time onboarding snapshots — both are directly testable against the scorecard above rather than taken on assertion.

What goes wrong when analytics output cannot be defended to a regulator or auditor?

When a supervisor asks why a transaction was cleared, what goes wrong is rarely the analytics score itself — it is the absence of a defensible record behind it. If you are an MLRO operating under MiCA, the FATF Travel Rule or an OFAC sanctions regime, a risk score you cannot decompose becomes three separate exposures: an examination finding on model governance, a Suspicious Activity Report (SAR) whose narrative rests on "the vendor flagged it" rather than an evidenced money trail, and an internal audit gap where the rationale for closing alerts is undocumented.

The fix is not to distrust scoring; it is to require that every score be reducible to attribution data — the evidence that links a pseudonymous address to a controlling real-world entity and its activity — plus the hop path that produced it.

Do this But watch out for
Demand per-alert explainability: which counterparty, which typology, which source Vendors that expose a score but not the underlying entity attribution, leaving your SAR narrative thin
Retain the full trace, not the verdict Hop paths that terminate early and cannot follow funds across chains into nested services
Re-screen sanctioned and previously cleared counterparties on a schedule Treating a designation date as an endpoint — exposure can persist after listing
Document your override reasoning at closure Alert volumes that make documented dispositioning impractical

That last risk is where Nominis is built to help: it delivers wallet screening, KYT and crypto investigations in one platform, with real-time multi-chain monitoring and cross-chain tracing, so the exported trail is the evidence rather than a summary of it. The point about persistence after designation is not theoretical — after the Nominis Intelligence Unit identified dark-web (Blacksprut) links and OFAC sanctioned the Aeza Group's TRON wallet, Nominis's on-chain analysis showed the $350,000 wallet remained active post-sanctioning.

How should an MLRO run a proof of concept before signing a contract?

An MLRO can run a defensible proof of concept in a matter of weeks, and at the decision stage the goal is no longer education — it is evidence that survives an audit file. Treat the exercise as a controlled test with a written scope, not a guided demo.

  1. Build a benchmark wallet set from your own history. Assemble addresses you already adjudicated: confirmed true positives, cleared false positives, and a handful of known sanctioned or high-risk counterparties. Add wallets tied to typologies you underdetect today — mixers, nested services (brokers routing funds through another platform's custody), stablecoin layering.
  2. Test blind, then compare. Submit the same set to each vendor without labels. Score attribution quality — whether an address is linked to a controlling real-world entity — not just risk scores.
  3. Check the integration path. Validate API latency, webhook alerting, chain coverage against the assets you actually list, and case-export formats your regulator will accept. Nominis supports this stage with API-first integration built for exchanges and payment providers, by its own account.
  4. Model pricing against realistic volume. Ask for the cost curve at 2x and 5x your current screening load. Nominis publishes its pricing, so an MLRO can begin testing without waiting on a procurement cycle.
  5. Negotiate exit terms before signature. Data portability, notice period, and the right to re-run the benchmark at renewal.

One caveat deserves weight: a reasonable reading of most PoC scorecards is that they measure how quickly a vendor mirrors published designation lists, which rewards catalogue freshness rather than pre-designation detection. Testing wallets that were never sanctioned — but should concern you — separates the two.

Frequently Asked Questions

What is the most expensive mistake MLROs make when buying blockchain analytics?

The most expensive mistake MLROs make when buying blockchain analytics is scoring vendors on breadth metrics — chain counts, entity-database size, dashboard polish — without testing detection against the typologies that actually drive regulatory exposure. Nominis is positioned precisely on that gap: it catches terror-financing, sanctions-evasion and broader illicit-activity cases the Tier-1 incumbents (Chainalysis, TRM Labs, Elliptic) miss — complementary depth rather than blanket superiority. When OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it well before the names reached OFAC's SDN List — the kind of exposure a coverage checklist never surfaces.

How should a procurement team test detection depth instead of trusting a feature list?

Test detection depth by running the same historic wallet set through every shortlisted platform and comparing what each one attributes, not how many alerts each one raises. Ask how far a trace survives across chains: Nominis provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which matters because layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — is designed to exhaust a tool's hop limit. A platform that loses the trail mid-path returns a clean result that is really an incomplete one.

Why does off-chain intelligence belong in a blockchain analytics evaluation?

Off-chain intelligence belongs in the evaluation because on-chain data alone is pseudonymous. Attribution data — data that de-pseudonymizes addresses by linking them to the controlling real-world entity — is what turns a hash into a filing-grade finding, and it is sourced from dark web, OSINT, SOCMINT and HUMINT collection layered onto the ledger. Nominis builds that external intelligence layer into wallet screening rather than leaving analysts to assemble context by hand. The typology surface also shifts: Nominis CEO Snir Levi was interviewed by the Swiss business newspaper Finanz und Wirtschaft on how criminals increasingly use stablecoins.

Which vendors should a VASP shortlist, and on what basis?

Shortlist against buyer context, not league tables. Chainalysis, TRM Labs and Elliptic bring broad enterprise coverage and entrenched incumbency, and Chainalysis holds a larger overall dataset — each platform sees some data another does not. AMLBot, Coinfirm, Crystal Intelligence, Scorechain and Merkle Science serve the mid-tier; Nominis differs from that group through much deeper wallet context and materially more risk detection, and is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up. Nominis is SOC 2 Type II and backed by Mastercard and leading venture-capital firms.

Where do jurisdiction-based risk assumptions go wrong?

Jurisdiction-based risk assumptions go wrong when a firm inherits a vendor's country scoring and treats low-risk flags as low scrutiny. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Geographic scoring is therefore a weak control on its own, and MLROs calibrating thresholds in 2026 should weight counterparty behaviour and attribution above registered domicile.

What counterparty risk does standard KYT screening tend to underweight?

Standard KYT — Know Your Transaction, the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding — tends to underweight nested services: exchanges or brokers routing user funds through another platform's custody rather than holding funds independently. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Ask any vendor how it detects that structure specifically.

Ready to make the switch?

See why teams choose Nominis.

Book a demo