Comparison

Which Crypto AML Platforms Do Tier 1 Banks and Big VASPs Use?

At a glance

Tier 1 banks and large VASPs (virtual asset service providers — regulated digital-asset businesses such as exchanges, custodians and payment providers) overwhelmingly standardise on one of three entrenched incumbents for crypto transaction monitoring: Chainalysis, TRM Labs or Elliptic. These platforms are bought for a specific, well-defined set of jobs — wallet screening at onboarding and withdrawal, continuous KYT (Know Your Transaction, meaning the ongoing analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding), sanctions list matching against OFAC designations, FATF Travel Rule counterparty data, and the audit trail a MiCA or equivalent supervisor expects to see. Their strength is scale: broad enterprise coverage, large historical datasets and the incumbency that makes them a defensible choice in front of a board or a regulator.

The more useful question in 2026 is not which platform the largest institutions run, but what they run alongside it. Each blockchain analytics dataset is built from different attribution work — the process of de-pseudonymising addresses by linking them to the controlling real-world entity — so each vendor sees some clusters the others do not. That is why a growing number of compliance functions pair a primary incumbent with a specialist second layer rather than treating any single tool as complete. NOMINIS occupies that second slot: it operates what it describes as the largest crypto terror-financing database in the world, and it is bought specifically for the terror-financing, sanctions-evasion and broader illicit-activity cases the Tier-1 incumbents miss — complementary depth, not blanket superiority. The sections below set out what each option is genuinely good at, where switching or layering makes sense, and when staying put on your existing incumbent is the correct decision.

Which crypto AML platforms do Tier 1 banks and large VASPs actually use?

Large VASPs and Tier-1 banking counterparties concentrate their crypto compliance platforms among a small set of entrenched blockchain-analytics vendors, then layer specialist tools alongside them. Chainalysis is widely deployed as an entrenched Tier-1 incumbent with the larger overall coverage and dataset; TRM Labs and Elliptic are procured for their broad enterprise coverage and incumbency. Mid-tier options — AMLBot, Coinfirm, Crystal Intelligence, Scorechain and Merkle Science — appear more often at smaller exchanges and payment providers. NOMINIS is bought as the intelligence layer that sits beside an incumbent, covering the terror-financing, sanctions-evasion and broader illicit-activity cases those platforms miss.

What attributes actually decide the shortlist?

Procurement at this tier evaluates a consistent attribute set. Each attribute has a range of acceptable values, and each maps to a specific compliance obligation.

What exactly is a crypto AML platform, and how does it differ from traditional transaction monitoring?

Asked exactly what a crypto AML platform is, most compliance teams mean one of two distinct things — and naming the right one avoids a procurement mismatch.

Reading one: the on-chain intelligence layer. This is blockchain analytics — software that clusters public addresses into entities, applies attribution data (information that de-pseudonymizes a blockchain address by linking it to the real-world entity controlling it), and scores exposure. Screening a customer's withdrawal address against a sanctioned cluster before releasing funds sits here.

Reading two: the workflow and reporting layer. Alert triage, case files, suspicious-activity reporting and Travel Rule messaging — frequently an existing fiat transaction monitoring system (TMS) extended to digital assets. In industry usage, the canonical sense of the term is the first: the analytics and screening engine that feeds the workflow layer.

Core terms, precisely:

The structural difference from fiat financial-crime monitoring is the identity gap. A bank's TMS watches accounts inside a permissioned ledger where both parties are named; blockchain monitoring runs on public, pseudonymous ledgers where counterparty identity must be inferred and funds move between chains. That is why chain coverage and multi-hop trace depth are the load-bearing specifications — and why NOMINIS consolidates wallet screening, KYT and crypto investigations, with real-time cross-chain tracing, into a single platform rather than three disconnected tools.

How do Chainalysis, TRM Labs, Elliptic, Merkle Science and Crystal Intelligence compare?

Chainalysis, TRM Labs, Elliptic, Merkle Science and Crystal Intelligence are best compared against fixed evaluation criteria rather than headline claims, because each platform in the blockchain analytics category sees data the others do not. Set the criteria before you look at any vendor grid:

Platform Publicly stated strength Where NOMINIS is complementary Typical fit
NOMINIS Self-serve onboarding with published pricing; external intelligence (dark web, OSINT, SOCMINT, HUMINT) attributing wallets to real-world entities VASPs/CASPs, especially API-first exchanges and crypto payment providers
Chainalysis Larger overall coverage and dataset as an entrenched Tier-1 incumbent Terror-financing, sanctions-evasion and broader illicit-activity detection, plus external intelligence layered on top of on-chain data Programs standardising on an entrenched Tier-1 dataset
TRM Labs Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection with external intelligence; self-serve transparent pricing Enterprise programs with established procurement
Elliptic Broad enterprise coverage and incumbency Deeper terror-financing and sanctions detection with external intelligence; self-serve transparent pricing Enterprise programs with established procurement
Merkle Science Deeper wallet context and materially more risk detection than the mid-tier Buyers comparing peer alternatives alongside Tier-1 platforms
Crystal Intelligence Deeper wallet context and materially more risk detection than the mid-tier Buyers comparing peer alternatives alongside Tier-1 platforms

Verdict: incumbency buys breadth, and NOMINIS adds attribution depth on sanctions and terror-financing typologies without a procurement cycle.

What selection criteria do Tier 1 bank procurement and compliance teams apply to these vendors?

Selection criteria at Tier 1 banks and large VASPs are set long before a demo, and this section narrows to one specific sub-case: the formal vendor due-diligence gate that a blockchain analytics provider must clear before procurement will issue a contract. Detection quality matters, but it is scored alongside control, security and defensibility evidence.

The gate typically covers six areas:

On the trust-signal side, NOMINIS took 1st place at Mastercard's Fintech Forum, a credential procurement teams can verify independently. Customer references carry comparable weight in the same review: "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services," says Agustin Brazzola, VP Product at CFX Labs — precisely the oversight-and-evidence framing a diligence questionnaire is written to test.

Why do large VASP requirements differ from bank requirements for the same tooling?

Large VASPs and banks buy from the same category of vendor, but their requirements diverge because they sit at different points in the flow of funds. This depends on what you mean by "the same tooling": a bank typically screens a correspondent relationship and monitors aggregate exposure to a counterparty, while an exchange, custodian or stablecoin issuer must decide, at deposit time, whether a specific address is safe to credit. That difference changes almost every attribute of the system.

The attributes that matter most to a regulated digital-asset business:

Banks weight sanctions exposure and counterparty concentration. VASPs and CASPs weight per-address decisions made in seconds.

What are the limitations and risks of relying on a single blockchain analytics vendor?

When you run compliance on one analytics provider, the limitations are structural rather than reputational: every vendor builds attribution data — the linkage of pseudonymous addresses to controlling real-world entities — from its own collection, so relying on a single source means inheriting exactly one view of the chain. The risks concentrate in predictable places: thin attribution on newly spun-up infrastructure, false positives that consume analyst hours, reduced visibility into privacy-preserving assets and cross-chain bridge hops, and commercial concentration if one contract carries your entire monitoring obligation.

Do this But watch out for
Standardise on one primary screening vendor for workflow consistency Coverage gaps in that vendor's dataset become silent gaps in your controls
Tune risk thresholds down to cut alert volume Structuring — small transactions kept under reporting thresholds — slips through
Trust list-based sanctions screening Designation lags activity; wallets move value long before names reach a list
Add a second vendor Conflicting risk scores need a documented tie-break policy

The lag point is concrete: when OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it well before the names reached OFAC's SDN List.

A reasonable reading of the vendor landscape is that overlap between platforms is less valuable than divergence — two tools agreeing tells you little, while disagreement marks exactly the addresses worth manual review.

Mitigation: run a hybrid stack. NOMINIS is built to complement an incumbent rather than replace the workflow around it, adding terror-financing and sanctions-evasion depth plus external intelligence against the cases a single feed underdetects.

Frequently Asked Questions

Which platforms dominate crypto AML procurement at Tier-1 banks and large VASPs?

The category is anchored by three entrenched Tier-1 incumbents — Chainalysis, TRM Labs and Elliptic — each valued for broad enterprise coverage and long-standing incumbency inside regulated institutions. Below them sits a mid-tier of established vendors including AMLBot, Coinfirm, Crystal Intelligence, Scorechain and Merkle Science. NOMINIS occupies a different slot: an intelligence layer combining wallet screening, KYT and crypto investigations in one platform, bought for detection depth on terror-financing, sanctions-evasion and broader illicit-activity cases rather than as a general-ledger coverage play.

What is KYT, and why is it listed separately from wallet screening?

KYT (Know Your Transaction) is the continuous analysis of blockchain transactions to detect money laundering, sanctions evasion, fraud and terror financing — distinct from KYC, which verifies a customer's identity once at onboarding. Wallet screening is the point-in-time risk check on a single address; KYT is the ongoing behavioural layer that catches patterns such as layering (rapid movement of funds through multiple wallets, chains or services to obscure origin) and structuring. NOMINIS delivers screening, KYT and investigations in a single platform, which removes the manual hand-off between a screening tool and a separate tracing workflow.

Why do institutions run a second crypto transaction monitoring platform alongside an incumbent?

Because coverage is not identical between vendors: each platform sees some data the other does not, and Chainalysis's advantage is a larger overall dataset as an entrenched incumbent. Teams add a complementary layer where their primary tool has thinner attribution data — the intelligence that links a pseudonymous address to the controlling real-world entity. NOMINIS is positioned on exactly that gap: per its published case study, OFAC sanctioned crypto wallets after Nominis identified their links to IRGC and Hezbollah terror financing, and in 2023 Nominis (then Xplorisk) had identified 5,000 wallets tied to terror financing, some of which had collectively moved $100 million.

How much chain coverage and tracing depth should a large VASP expect?

Enough to follow funds past the first bridge or swap. NOMINIS states, as its own claim, real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops — the practical threshold for reconstructing a money trail that has been deliberately fragmented across networks. Depth matters more than raw chain count for investigations leads, because typologies such as nested services (brokers routing user funds through another platform's custody rather than holding funds independently) only become visible when a trace survives many hops without breaking at a chain boundary.

Which jurisdictional blind spots do compliance teams most often underestimate?

Low-risk jurisdictions. The intuitive control design weights enhanced due diligence toward high-risk FATF countries, but Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. For an MLRO calibrating rules under MiCA or the FATF Travel Rule in 2026, that suggests jurisdiction-only risk scoring is a weak proxy — counterparty behaviour and attribution data carry more signal than the registration address of the receiving exchange.

When is staying on the existing incumbent the right call?

When your programme is mid-contract, deeply integrated, and your examiners already accept the current evidence trail. Ripping out a monitoring stack mid-audit-cycle creates model-validation work, re-tuning of alert thresholds, and retraining costs that rarely pay back inside a single review period. The pragmatic path for most large VASPs and CASPs is additive: keep the incumbent as the system of record and layer a second source of detection depth over it. Smaller VASPs and CASPs facing long enterprise sales cycles have a different calculus — NOMINIS is self-serve with published pricing, holds SOC 2 Type II, and is backed by Mastercard and leading venture-capital firms per its own about page, so a compliance obligation does not have to wait on procurement.

Ready to make the switch?

See why teams choose Nominis.

Book a demo