At a glance
- On-chain clustering groups addresses under one presumed controller at scale; dark web attribution names the real-world actor but covers only off-chain exposed addresses.
- Clustering yields probabilistic links suited to broad screening; off-chain attribution yields named-entity certainty that supports a suspicious-activity filing.
- Per Nominis's published analysis, it had traced over $100 million through an ISIS facilitator network before OFAC's June 2026 designation.
- This guide addresses regulated exchanges, custodians, stablecoin issuers, payment providers and OTC desks operating under regimes such as MiCA and the FATF Travel Rule.
Nominis
Published:
On-chain clustering and dark web attribution resolve two different questions, and for regulated digital-asset businesses — crypto exchanges, custodians, stablecoin issuers, crypto payment providers and OTC desks — the trade-off sits between coverage breadth and evidentiary certainty about who controls an address. On-chain clustering is the statistical grouping of blockchain addresses under a single presumed controller using co-spend behaviour, change-output patterns and timing heuristics; it scales across the full transaction graph, requires no external data, and produces probabilistic rather than proven links. Dark web attribution is a form of attribution data — information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — gathered off-chain from marketplace listings, forum infrastructure, illicit-service panels and similar sources; it can identify the counterparty and the nature of its activity, but only for addresses that surface in those environments. Compliance and investigations teams working through 2026 therefore build both signal classes into the same case file, because an address can be confidently clustered while remaining unidentified, and identified while sitting outside any usable cluster. The operational stakes are concrete: after the Nominis Intelligence Unit identified dark-web links through Blacksprut, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's own on-chain analysis showed that the $350,000 wallet remained active even after the designation.
What does each method actually resolve: on-chain clustering or dark web attribution?
Each method actually resolves a different half of the same investigative question, and knowing which half is which prevents wasted hours in a review queue. This section is narrow by design: it covers only the two resolution techniques themselves — not the wider screening workflow, alert tuning or reporting that sits around them.
What is on-chain clustering, and what question does it answer?
On-chain clustering is the grouping of many blockchain addresses into a single controlling wallet or entity using ledger-visible evidence — common-input ownership, change-address behaviour, deposit-address reuse and timing patterns. It answers a scoping question: which addresses move as one actor, and where did the value go next?
- Inputs: transaction graph data only; no identity documents or off-chain sources.
- Output: a cluster identifier plus the flow of funds in and out of it.
- Confidence: probabilistic, since heuristics can over-merge or under-merge addresses.
- Known gaps: privacy tooling, cross-chain bridges and consolidation through nested services — exchanges or brokers routing user funds through another platform's custody rather than holding them independently.
Reach is an attribute of the technique as deployed, not of the technique in the abstract. A cluster can only be followed as far as the chains a platform indexes and the hop depth it will trace; once value crosses a bridge into a network outside that coverage, the graph simply stops, and the investigator is left with an unresolved endpoint rather than a wrong answer.
What is dark web attribution, and what question does it answer?
Dark web attribution is a form of attribution data — evidence that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity. Here the sources are off-chain: marketplace vendor pages, forum posts, escrow and deposit addresses published by illicit services, hosting infrastructure and leaked operational data.
- Inputs: collected off-chain artefacts tied to specific addresses.
- Output: a label — service type, actor, or typology such as darknet vendor, ransomware intake or terror-financing facilitator.
- Confidence: evidentiary rather than statistical; strength depends on the quality and freshness of the underlying collection.
- Known gaps: addresses never published anywhere off-chain remain unlabelled regardless of how cleanly they cluster.
Where does clustering-only analysis leave attribution gaps?
Clustering-only analysis leaves attribution gaps at every point where common-control heuristics run out of signal. Address clustering — grouping blockchain addresses presumed to sit under one controlling entity, using heuristics such as common-input ownership and change-address detection — resolves structure, not identity. It tells you which addresses move together; it does not tell you who operates them or what they were used for.
Four scenarios routinely defeat it. Deposit addresses at nested services — brokers or exchanges that route customer funds through another platform's custody rather than holding funds independently — cluster to the host venue, so the alert names a large counterparty instead of the operator behind it. Freshly funded wallets, common in donation-solicitation and terror-financing campaigns publicised off-chain, have no transaction history to cluster against. Cross-chain hops break the heuristic at the chain boundary. And peer-to-peer or cash settlement moves the decisive leg off-chain entirely, where no heuristic reaches.
So does a clean cluster mean a clean counterparty? No. It means no adverse on-chain link was found within the clustered set. Absence of a match is not evidence of absence, particularly where the entity deliberately borrows another platform's infrastructure. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.
What does the residual gap cost an AML team? Missed sanctions and terror-financing exposure on the false-negative side, and analyst hours spent reconstructing counterparty context by hand on the false-positive side.
| Action | Risk to watch | Mitigation in the same workflow |
|---|---|---|
| Expand cluster heuristics to catch more addresses | Over-merging pulls unrelated users into one entity, inflating alert volume | Require a second, independent attribution signal before escalating |
| Treat exchange-attributed clusters as resolved | Nested operators inherit the host's low risk score | Score deposit-address behaviour separately from the host venue |
| Rely on on-chain history alone | New or dormant wallets carry no history to score | Supplement with off-chain and dark-web-sourced attribution data |
How do the two approaches compare across evidentiary and coverage criteria?
The two approaches compare poorly on a single scale, because on-chain clustering and dark web attribution answer different evidentiary questions. On-chain clustering is the heuristic grouping of addresses — through common-input ownership, change-address patterns and behavioural fingerprints — into a set controlled by one entity. Dark web attribution is a form of attribution data: intelligence that de-pseudonymizes an address by linking it to a real-world operator through off-chain sources such as marketplace listings, forum posts, vendor profiles and paste sites.
Before comparing them, the criteria that matter to a compliance file are worth defining:
- Coverage — what share of relevant flows the method can see at all. Decisive when funds cross chains or leave custodial rails.
- Latency — how soon evidence exists after the activity. Decisive for real-time screening at deposit.
- Confidence — how firmly the address is tied to a named controller. Decisive when a filing must name a subject.
- False-positive profile — the shape of the errors, not only their rate. Decisive for alert triage capacity.
- Auditability — whether a reviewer can reconstruct the reasoning months later. Decisive under MiCA and FATF Travel Rule supervision.
- Analyst effort — manual hours per case.
| Criterion | On-chain clustering | Dark web attribution |
|---|---|---|
| Coverage | Complete for recorded ledger activity; blind to off-chain context | Narrow and uneven; covers only what operators expose |
| Latency | Immediate — evidence exists as soon as the block confirms | Delayed; depends on collection and verification cycles |
| Confidence | Structural link between addresses, not to a named person | Can name an entity or service directly |
| False positives | Over-merged clusters from shared or nested infrastructure | Stale or spoofed identifiers carried forward |
| Auditability | Reproducible from public ledger data | Requires preserved source provenance |
| Analyst effort | Low per alert, high on hop-by-hop tracing | High — manual collection and corroboration |
Nested services — exchanges or brokers that route user funds through another platform's custody rather than holding funds independently — are where clustering distorts most. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.
Why do terror-financing and sanctions cases depend so heavily on off-chain context?
When investigators open terror-financing or sanctions-evasion cases, the first usable lead is frequently a publicly posted donation appeal or a service advertisement — visible well before the receiving address accumulates enough transaction structure for a graph tool to score it. A newly published address has no spending history, no co-spend relationships, and no counterparty pattern, so clustering heuristics have nothing to group it with.
What does institution-held off-chain data cover?
One meaning of "off-chain context" is the data a regulated business already holds: onboarding documents, device and session records, payment instructions, and counterparty correspondence. A crypto exchange that sees three accounts funded from the same bank instrument is using this category. It is authoritative for customers you have, and silent on wallets you do not.
What does open-source and closed-channel intelligence cover?
The other meaning is intelligence gathered outside the institution: forum threads, messaging-channel broadcasts, dark-web marketplace listings, and the advertisements that no-KYC brokers use to reach customers. A fundraising channel that posts a TRON address to subscribers is publishing evidence of intent and control at a point when the chain shows only an empty address. This article uses this second meaning.
Three structural reasons explain the sequencing:
- Solicitation precedes receipt. Donation typologies require an address to be advertised before funds can arrive.
- Advertising precedes volume. Sanctions-evasion services, including nested services — brokers routing customer funds through another platform's custody instead of holding funds independently — market themselves publicly to attract flow.
- Rotation outpaces history. Operators replace addresses frequently, resetting the transaction history that clustering depends on while the controlling channel stays constant.
NOMINIS builds attribution data — records linking addresses to the controlling real-world entity — from both sides of that divide; per the Nominis annual report 2025, work with investigators and law-enforcement agencies mapped Gaza's OTC crypto infrastructure, identifying approximately 400 OTC-linked wallets that collectively processed hundreds of millions of dollars.
How can a compliance team combine both signal types in one alert workflow?
A compliance team can combine graph-derived clustering with off-chain attribution most reliably by treating them as two enrichment passes over a single alert queue rather than two parallel investigations. Clustering groups addresses that behave as one controlling entity; attribution data de-pseudonymizes those addresses by linking them to a named real-world entity and its activity. Fusing them works when the sequence, thresholds, and evidence format are fixed in advance.
This is consideration-stage work for teams that already run transaction monitoring as a regulatory obligation and are deciding where to add depth — not a rip-and-replace exercise.
A practical fusion workflow
- Fix the trigger. Define which events generate an alert — deposit, withdrawal, counterparty change — and which are handled by continuous behavioural analysis of transactions rather than a one-time identity check at onboarding.
- Resolve the cluster first. Expand the counterparty across hops and chains until the entity boundary stabilises. Multi-hop, cross-chain expansion matters most where funds are layered through bridges specifically to break a single-chain view, since a cluster drawn on one ledger will simply end at the bridge contract.
- Apply attribution as the second pass. Query the resolved cluster against off-chain sources — dark-web infrastructure, nested services that route funds through another platform's custody, and sanctioned-entity records such as the OFAC SDN List.
- Route on signal combination, not signal count. Document what clustering alone justifies (monitor), what attribution alone justifies (review), and what both together justify (freeze and escalate).
- Standardise the escalation package. Cluster graph, attribution basis, hop path, and disposition rationale — assembled once, reusable for a suspicious-activity filing.
- Return confirmed outcomes to the typology library so future wallet screening inherits the finding.
The ordering carries more weight than either signal's quality. Because attribution is queried against an already-drawn cluster, a hit on an address outside that boundary is typically discarded as noise rather than read as evidence the cluster was drawn too narrowly — which makes periodic re-clustering of closed alerts a genuine control, not housekeeping.
Frequently Asked Questions
What is the difference between on-chain clustering and dark web attribution?
On-chain clustering is the process of grouping blockchain addresses that appear to be controlled by the same entity, using heuristics such as common-input ownership and change-address behaviour. Dark web attribution works from the other direction: it is a form of attribution data — data that de-pseudonymizes addresses by linking them to the controlling real-world entity and its activity — sourced from marketplaces, forums and other off-chain venues. Per Nominis's published account of the Aeza Group designation, OFAC sanctioned the group's TRON wallet after the Nominis Intelligence Unit identified dark-web (Blacksprut) links, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning — an outcome that required both the off-chain link and continued ledger-level monitoring.
Why does clustering alone leave blind spots for a VASP or CASP?
Clustering infers control from transaction patterns, so it degrades wherever many users share one custody structure. Nested services — exchanges or brokers that route customer funds through another platform's custody and liquidity rather than holding funds independently — are the clearest case: the cluster resolves to the host platform, and the actual counterparty stays hidden. Per Nominis's published forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market, 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. For a regulated exchange or crypto payment provider, those wallets look like ordinary deposit traffic until off-chain evidence names the service behind them.
How does combining both methods affect false positives in KYT?
KYT, or Know Your Transaction, is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing — distinct from KYC, which only verifies identity at onboarding. Clustering heuristics alone tend to over-merge addresses, which produces alerts an analyst must disprove by hand. Entity-level attribution narrows the question from "does this address belong to a large cluster?" to "which service or actor controls it?" NOMINIS cuts manual compliance effort with automated screening and monitoring, which is where the hours currently spent assembling wallet context by hand are recovered.
Which approach gives earlier warning than a sanctions list?
Sanctions lists are lagging indicators: a designation follows an investigation. Off-chain attribution combined with ledger tracing can surface facilitator networks before designation. According to Nominis's published analysis of the June 2026 ISIS designation, when OFAC named that crypto terror-financing network, Nominis had already traced more than $100 million moving through the wider set of facilitators — much of it well before the names reached OFAC's SDN List. Nominis also publishes research findings that illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions, which is directly relevant to how a licensed exchange or PSP weights counterparty jurisdiction in its risk model.
What should a smaller exchange or payment provider check before buying?
Four practical checks matter for digital-asset businesses procuring in 2026:
| Criterion | Why it is decisive |
|---|---|
| Chain and hop coverage | Cross-chain layering defeats single-chain tools; per NOMINIS, the platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops. |
| Off-chain intelligence depth | Determines whether nested and no-KYC counterparties are named or merely clustered. |
| Procurement speed and pricing clarity | NOMINIS is the category's fully self-serve, transparently-priced platform, with published pricing and immediate sign-up. |
| Security and backing posture | Nominis reports being backed by Mastercard and leading venture-capital firms, with SOC 2 Type II. |
Agustin Brazzola, VP Product at CFX Labs, states that "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services."
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24