Why Crypto Wallets Get Flagged — and What to Do about It
A joint guide by AMLBot × SimpleSwap
A swap goes under review when transaction screening surfaces risk indicators in the history of the funds involved, either in the deposit you sent, or in the address the swap is due to pay out to. The review is about the history those funds carry with them, not about the person initiating the swap.
Timing is what confuses people. The deposit is assessed only after it confirms on-chain, which is why a swap can enter review when you have already sent funds and nothing has come back. The payout address is assessed separately, before anything leaves. Either check can hold a swap.
If that is happening to you right now, the emotional read (that you have done something wrong) is almost always incorrect. Exposure is something funds carry, and it can reach an ordinary wallet through entirely ordinary means.
This guide is the product of a year of work between SimpleSwap and AMLBot. SimpleSwap organises the swap itself: crypto moves between wallets through multiple liquidity providers, non-custodially, without the platform taking control of user funds. AMLBot provides the screening layer, having analysed wallets and transactions for risk exposure since 2019.
TL;DR
- Screening does not mark individual coins. It analyses relationships between addresses.
- A swap is screened at two points: the deposit, after on-chain confirmation, and the payout address, before funds leave.
- Risk is assessed from where funds came from, which addresses appear to share an owner, and what those counterparties have been identified as.
- Exposure is often indirect, several transfers removed from the original source, and it still registers.
- A high score means elevated probability of review, not proof of anything.
- Moving funds around, splitting them, or routing them through another service does not remove exposure. It generally adds new exposure.
- You can screen an address or a transaction before you swap. That is the whole point.
Part 1: How Screening Actually Works
Coins Are Not Marked. This Is the Part Almost Everyone Gets Wrong
The mental model most people arrive with is that "dirty" crypto carries some invisible stain and screening detects it. That is not how this works, and understanding why explains nearly everything else.
On account-based networks (Ethereum, TRON, BNB Chain, Polygon, and most others) tokens are not objects at all. When you hold 500 USDT on TRON, there is no set of five hundred distinguishable tokens in your wallet. There is a single number, a balance, recorded in the token contract against your address. When someone sends you 100 USDT, the contract subtracts 100 from their number and adds 100 to yours. Nothing physical moves. There is nothing to mark.
So on these networks, "Are these specific USDT stolen?" is not a hard question. It is a question without meaning. All 600 USDT in your wallet are indistinguishable because they were never distinguishable.
However, Bitcoin works differently, which is why you may have encountered contradictory explanations. Bitcoin uses a UTXO model (unspent transaction outputs) where each output is a discrete chunk of value with traceable lineage, closer to a numbered banknote. This makes following specific outputs genuinely possible, and several formal methods exist for it (poison, haircut, and FIFO analysis, each producing a different answer about how contaminated a mixed output is). But even here, once outputs from multiple sources combine in one transaction, apportioning the result between them becomes a modelling choice rather than a fact.
Screening therefore answers a question that can be answered: How closely is this address connected to funds that compliance systems treat as risky?
Hops: Distance from the Source
A hop is one transfer between addresses. If stolen funds go from a thief's wallet to an intermediary, then to an exchange withdrawal address, then to a buyer, then to you, that is four hops.
Exposure weakens with distance but does not vanish. Screening traces back through multiple hops and weights findings by proximity: funds received directly from a sanctioned address are treated very differently from funds five transfers removed. This decay is why two people holding proceeds of the same theft can receive very different scores. One bought directly from the thief. The other bought from someone who bought from someone, six months later.
Clustering: Why Your Other Wallets Are Relevant
Blockchain analysis groups addresses that appear to share an owner. The best-known technique is the common-input-ownership heuristic. For example, if a single BTC transaction spends outputs from several addresses at once, whoever constructed it held the keys to all of them, so they are almost certainly one owner. Other methods identify change addresses, recognise the deposit-address patterns exchanges generate, and detect behavioural signatures such as consistent transaction timing.
As a result, exposure can reach an address that never directly received risky funds, because a different address in the same cluster did. Opening a fresh wallet resets nothing if that wallet is linked to your others by an identifiable pattern.
Where the Risk Labels Come From
Risk data is attribution — real-world identification of what an address belongs to. It is assembled from:
- Sanctions Lists. Government bodies publish specific crypto addresses tied to sanctioned entities. Authoritative, non-negotiable, and the most serious category of exposure there is.
- Law-Enforcement Actions. When a darknet market or fraud operation is seized, its addresses become known.
- Victim Reports, verified and attributed to addresses.
- Service Identification. Exchange deposit addresses, mixer contracts, gambling platforms, bridges — identified so funds passing through them can be recognised.
- On-Chain Behaviour Analysis. Patterns characteristic of specific services or laundering techniques.
In addition, attribution depends on who has collected what, different screening providers genuinely return different results for the same address. And that is not a defect in any of them. It reflects different data coverage. It also explains a frustrating experience: clearing on one platform and being flagged on another.
Direct vs. Indirect Exposure
This distinction matters more than the headline percentage.
- Direct Exposure means your address received funds straight from an identified risky source, or sent funds straight to one. One hop. The serious case.
- Indirect Exposure means the connection runs through intermediaries. For instance, your address received from an address that received from a mixer. Most flags on ordinary users' wallets are indirect, often several hops out.
This is why the direct/indirect split in a report tells you more than the headline percentage does.
Part 2: How a Risk Score Is Calculated
A percentage on its own tells you very little. It is the output of at least three separate inputs, and the number hides all of them.
The first is proportion. What share of the value that reached an address traces back to risky sources? A wallet where a small fraction of incoming value has questionable origins is in a different position from one where most of it does, even though both may show some exposure.
The second is severity of category, and this is where the number is most misleading, because categories are not weighted equally. At the top sit sanctioned entities and terrorism financing, where any connection is treated as serious regardless of proportion. Below that come darknet markets, ransomware, stolen funds, and confirmed fraud. Further down are mixers and tumblers, unlicensed exchanges, and gambling in restricted jurisdictions. Lower still are the broad, ambiguous categories: peer-to-peer platforms, unidentified services, generic exchange exposure. The exact ordering and weighting vary between providers — this is a general picture of how the industry treats these categories, not a fixed scale.
The third is proximity. Direct connections weigh far more heavily than distant ones, for the reasons covered in Part 1. Funds received straight from an identified source are a different matter from funds several transfers removed.
Put together, this means two reports can show a similar headline percentage and describe entirely different situations. Exposure to gambling several hops removed is a routine result that many ordinary wallets carry. A direct connection to a sanctioned entity at the same percentage is a serious problem. The number alone cannot tell you which of the two you are looking at – the categories behind it can.
Why the Same Address Scores Differently over Time
Scores shift even when nothing new happens on the address. New attribution data arrives constantly, an unlabelled address gets identified when an investigation concludes, and every connected wallet updates. And as an address accumulates unrelated activity, the proportional weight of old exposure falls.
Part 3: If Your Swap Is under Review Right Now
The mechanics above explain why this happens. Here is what to do about it.
- Check your email and the support chat before anything else. The request will be specific about what is needed in your case, and guessing wastes time. There is no universal checklist, because what gets asked depends on what the screening surfaced.
- Find your order ID first. Support needs it to pull up the specific transaction. Digging for it mid-conversation adds a round trip that costs hours.
- Expect a request drawn from a standard set. A government-issued ID, a short selfie or liveness check to confirm the ID is yours, proof of where the funds came from such as an exchange receipt or wallet history, and for fiat-linked cases a source-of-funds document.
- The source-of-funds request is the one people struggle with, and it is worth understanding why it is asked. It is not a demand to justify your finances. It is the fastest way to establish that exposure the screening found came from a transfer you received rather than from activity of your own. A screening report you ran yourself, dated before the swap, is useful documentation here.
- Submit through the official channel only. Support will point you to a specific ticket or upload link. Anyone who contacts you unsolicited offering to speed up a case, clear a flag, or handle documents on your behalf is running a secondary scam, and people in review are exactly who it targets.
- Keep everything in one ticket. Opening a second, or raising the same case across several channels at once, splits the history and slows resolution rather than speeding it up.
- Expect a timeline tied to what is missing. Cases resolve as information arrives. Where an external liquidity provider or a regulator is involved, that adds time for reasons no platform controls.
On KYC: verifying your identity once is optional for most crypto-to-crypto swaps, and doing it upfront can widen the pool of available liquidity providers. If a transaction is selected for review, verification may be requested regardless of whether you have an account. Either way it happens once per identity, not once per swap.
SimpleSwap's own guide covers the same process from the platform's side, including what their support can and cannot speak to about an individual case.
Part 4: How to Avoid This Before You Swap
There is a gap between doing everything right and being safe, and most people find it the hard way. Funds you receive arrive with a history attached, assembled from transactions you were never part of. If the wallet paying you had prior contact with risky activity, that contact stays attached to the transfer, and surfaces when you swap.
Address Check vs. Transaction Check
Two different questions. Asking the wrong one is the most common mistake we see.
An address check looks at a wallet as a whole — its full transaction history, the addresses it has interacted with, and the cluster it appears to belong to. You provide a wallet address, and it answers: what kind of wallet is this, overall? Use it when you are assessing a counterparty before dealing with them at all. Its blind spot is recency: a single recent deposit barely shifts an assessment built on years of activity.
A transaction check looks at one specific transfer, identified by its hash. You provide a transaction hash (txid), and it answers: where did this particular payment come from? Use it when someone has just sent you funds and that transfer is what you care about. Its blind spot is scope: it tells you nothing about the wallet's wider history.
This produces a result that regularly catches people out: a wallet-level result can come back unremarkable while one recent deposit into it is heavily exposed. That is arithmetic. Aggregate scores are dominated by volume, and a single transfer against years of history barely registers.
If what you care about is the payment someone just sent you (the funds you are about to swap) – check it by transaction hash.
A technical footnote consistent with Part 1: on account-model networks, a transaction check assesses the sending address's funds at that moment, since the specific tokens cannot be isolated. On Bitcoin, it can trace the actual outputs spent.
Reading the Report
A screening result is not a black-box score. It returns:
- Overall Risk Percentage — the aggregate, least informative alone
- Category Breakdown — which sources the exposure traces to, in what proportion
- Direct vs. Indirect Split — how close the connections are
- Blacklist Status — whether the address appears on sanctions or law-enforcement lists. Binary, and categorically different from a percentage
- Balance and Cluster Data, where available.
If the Result Comes Back High Risk
Treat it as information, not a verdict. High exposure does not establish that anything illegal occurred, and says nothing definitive about the sender. It tells you that accepting the transfer carries a real chance of a later review — when you swap it, or when any service screens it.
Before the Funds Arrive:
- Ask the counterparty where the funds came from, and keep their answer.
- Request documentation where the amount justifies it: an exchange withdrawal receipt, a screenshot of the source transaction.
- Decide whether the transfer is worth accepting. That call is much easier to make now than later.
If the Funds Already Arrived:
- Save the report with its date. A dated record of what you knew and when is the single most useful document you can have.
- Collect context on the source before chats get deleted and memory fades.
- Consider keeping exposed funds separate from your main wallet so cluster connections do not spread.
Two limits worth stating plainly. A check you run beforehand has no effect on the screening a swap goes through later. That assessment happens regardless. And no tool can guarantee that any particular service will accept any particular transfer, because every platform sets its own thresholds and uses its own data. What you gain is foresight, the ability to weigh the risk while you still have a choice.
Where to Run the Check
Head to the AML Сhecker, pick whichever option suits you (the Telegram bot or the web page itself ), then paste in the address or transaction hash, select the blockchain, and run it. AMLBot covers 35+ blockchains and 350+ assets, USDT and USDC on TRC-20 and ERC-20 included, screening against the risk categories described above: fraud schemes, stolen funds, mixing services, sanctions listings, darknet marketplaces, ransomware operations, and exchanges with a record of fraud.
Part 5: How Ordinary People End Up Flagged
The routine paths, roughly by frequency.
- Peer-to-Peer Trading (P2P). You sell crypto to a stranger for a bank transfer, or buy from one, with no visibility into where their funds originated. The single most common way a clean wallet acquires exposure.
- Accepting payment for work or goods. A client pays in USDT. You delivered the work. Their funds still carry their history.
- Buying from a small or unlicensed exchange. Platforms with weak inbound screening pass on whatever they receive.
- Gambling platforms. Withdrawing winnings means receiving funds pooled from every depositor.
- Privacy tools used for entirely legitimate reasons. Someone who used a mixer to avoid linking a salary address to their spending has broken no law in most jurisdictions. Screening still registers the interaction, because it cannot read motive.
- Bridges and cross-chain swaps. Some bridges pool liquidity, so what arrives on the destination chain is not what left. Depending on design, this can attach unrelated exposure.
- Airdrops and unsolicited transfers. Anyone can send tokens to your address unasked. This is occasionally deliberate — small amounts of tainted crypto sent to many addresses, sometimes called dusting, to contaminate them or assist clustering.
- Inheriting an old wallet or buying an account. History predating your involvement is still history.
The Scale of It
The volume gives context for why this reaches ordinary users at all. Users have run over 500,000 wallet checks through AMLBot to date. The cumulative value carrying exposure to scams, hacks, sanctions listings, darknet markets, mixers, or ransomware: north of $100M.
As for where it originates — AMLBot's Crypto Crime Report for 2025–2026 drew on more than 2,500 investigations and put social engineering at 65% of 2025 cases. Phishing pages, support-desk impersonation, fake project teams. The attack surface is the person, not the protocol.
Once taken, funds move. A separate AMLBot analysis traced $4.2B in stablecoins through six major privacy protocols, broken down by chain and risk profile. That is the machinery screening is built to notice.
All of that money went somewhere. Some was sold, swapped, or paid out to people who had no idea what they were receiving, and their addresses now carry it. The same filtering that catches someone laundering stolen crypto is what keeps those funds from landing in your wallet on the next swap.
Part 6: What Not to Do
These are the moves people reach for instinctively when a swap goes under review, and each one makes the situation materially worse.
- Do not route funds through a mixer to "clean" them. This removes nothing. It adds mixer exposure on top, a higher-severity category than most of what you started with. You will have converted a modest indirect flag into a serious direct one.
- Do not split the transfer into many small transactions. Deliberately breaking up a transfer to stay under detection thresholds has a name in financial regulation (structuring) and it is an offence in its own right in many jurisdictions, independently of the underlying funds. Analysis systems detect the pattern easily.
- Do not chain transfers through several wallets you control. Clustering links them. You have not created distance; you have created a suspicious pattern across multiple addresses instead of one.
- Do not retry the same swap on another service hoping it passes. A second attempt elsewhere works from the same on-chain history, and that history is the input every screening system reads. You may get a different answer, since thresholds and datasets vary, but you are gambling on a threshold, not removing a problem.
- Do not engage anyone offering to clear, unfreeze, or recover your funds for a fee. A well-established secondary scam that targets people who have just had a bad experience and are motivated to act fast.
- Do not ignore a request for information. Silence is the most common reason a routine review becomes a long one.
Part 7: What Can Realistically Happen
- Most likely: nothing. Modest indirect exposure sitting in a self-custodial wallet produces no consequence until you move funds to a service that screens. Many people hold wallets with some exposure and never encounter an issue.
- Common: a review when you interact with a service. A swap, deposit, or withdrawal triggers additional checks. You may be asked for verification or source-of-funds documentation. Most resolve.
- Less common: funds held pending review. A service may hold a transaction while assessing. Timelines depend on documentation required and whether third parties are involved.
- Uncommon but real: a stablecoin issuer freeze. Specific to centralised stablecoins and worth understanding, because it is the one scenario where funds become genuinely inaccessible in self-custody. Issuers of USDT and USDC retain the technical ability to blacklist an address at the contract level, typically on law-enforcement request. The tokens remain visible in the wallet but cannot be moved. This applies to the issuer's own tokens only — ETH, TRX, BTC and other assets in the same wallet are unaffected.
- Rare: law-enforcement involvement. Where funds trace directly to a significant crime. This sits outside any commercial platform's control.
For a typical user with indirect, low-severity exposure, the realistic expectation is a request for documentation, not a loss of funds.
Part 8: Reducing Exposure Going Forward
- Screen before you accept, not after. Check the sender's address before agreeing to a transfer, and the transaction hash after funds arrive but before you swap — finding exposure then still leaves you options, finding it mid-swap does not.
- Separate wallets by purpose. One for P2P, one for long-term holdings, one for DeFi. Exposure in one does not automatically follow into another, provided you do not link them by moving funds between them in identifiable patterns.
- Be selective in P2P. Established counterparties with long histories, on platforms that screen. Ask about source of funds for larger amounts and keep the answer.
- Keep records as a habit. Transaction hashes, exchange receipts, counterparty conversations. Storage costs nothing; the value when you are asked is substantial.
- Prefer licensed venues for fiat on- and off-ramps. They screen inbound, so less passes through to you.
- Screen your own address periodically. Attribution data updates. Better to learn about new exposure on your own schedule than during a swap you need to complete.
FAQ
Does a Flag Mean My Crypto Is Stolen?
No. A flag indicates exposure to sources compliance systems classify as risky. Exposure can be indirect, several transfers removed, and can come from a service you never used.
Why Would a Wallet Get Flagged If Its Owner Never Did Anything Wrong?
Because risk sits in the history of an address and its connections, not in the person using it. A wallet that received funds a few hops removed from a mixer, a sanctioned entity, or a hacked exchange shows that exposure regardless of who holds it now. This is the most common reason an ordinary user ends up in a review.
Am I Now on Some Kind of List?
Almost certainly not in the sense you mean. A risk score is a calculated assessment of an address, not an entry in a register of people. Sanctions lists are separate and much narrower: specific addresses published by government bodies, and inclusion is not something that happens quietly or by accident.
Can a Flag Be Removed?
Not in the sense of deleting a record – the on-chain history behind the assessment does not change. Two things can change. The assessment shifts as an address accumulates unrelated activity and the proportional weight of old exposure falls. And where a flag rests on an attribution that appears factually wrong, that attribution can be disputed with the data provider — a correction to the underlying label, not removal of a mark.
How Far Back Does Screening Look?
Multiple hops, with weight decreasing by distance. Providers set different depths and decay curves, which is one reason results vary between tools.
Why Did One Service Clear My Funds and Another Flag Them?
Different attribution datasets and different risk thresholds. Neither is necessarily wrong. Each service also sets its own policy on what score triggers review, so identical data can produce different outcomes.
I Bought This on a Major Exchange. How Is It Flagged?
Exchanges screen deposits, but screening is probabilistic rather than absolute, and withdrawals draw on pooled liquidity. Receiving funds with exposure from a well-run platform is entirely possible.
Does Moving Funds to a New Wallet Help?
No. It adds a hop, which marginally reduces distance-weighted exposure on paper, but clustering generally links wallets controlled by the same person — and a pattern of moving flagged funds between fresh addresses is itself a recognised signal.
Can My Funds Be Frozen While in My Own Wallet?
For most assets, no — self-custody means you hold the keys. The exception is centralised stablecoins: USDT and USDC issuers can blacklist an address at the contract level, usually on law-enforcement request. Other assets in the same wallet are unaffected.
How Is an AML Check Different from a Block Explorer?
An explorer is a ledger viewer. It renders what moved, when, and between which addresses. What it cannot tell you is who those addresses belong to. A screening check adds that layer, matching counterparties against attribution data and naming what it finds — a sanctions listing, a reported fraud operation, a mixing service, a darknet marketplace. Movements versus meaning.
What Score Should Worry Me?
Category matters more than number. Any direct sanctions exposure is serious regardless of percentage. High indirect exposure to unidentified services is common and usually routine.
Someone Sent Me Crypto I Did Not Ask For. Is That a Problem?
Usually not, if you leave it alone. Unsolicited transfers are sometimes used to contaminate addresses or assist clustering. The safe response is not to move or spend it, and to keep it separate from funds you use.
Is Checking an Address Legal? Am I Doing Surveillance?
You are reading public blockchain data. Every transaction on a public chain is visible to anyone. Screening organises that public information against known attribution. It accesses nothing private.
Does Checking Cost Anything?
There are a few ways to run a check, depending on what you need. The AMLBot Telegram bot is the quickest option for a one-off check — paste in an address or transaction hash and you get a report back in the chat, no account setup required, the first check is free. If you are running a business that needs to screen transfers automatically, the AMLBot API handles it at volume and plugs straight into your own platform. Pricing differs between them, since a single check and an integrated screening pipeline are different things. Current options are at amlbot.com/crypto-checker.
About the Partners
SimpleSwap is a self-custodial, multi-source swap aggregator live since 2018, connecting 20+ liquidity providers across CEX and DEX sources and giving users access to 2,800+ swappable assets without giving up control of their funds.
AMLBot is an all-in-one crypto compliance platform operating since 2019, covering AML wallet screening, real-time transaction monitoring (KYT), KYC/KYB verification, blockchain investigations, and crypto asset recovery through a single platform and API. It works with more than 1,000 crypto businesses worldwide, alongside financial institutions and law-enforcement agencies.
The two teams have worked together since 2025, combining self-custodial swaps with transaction-screening controls.