How wallet screening works: OFAC-listed addresses, direct and indirect exposure, risk scores, issuer freezes, and what to do when an address is flagged.
Wallet screening checks a blockchain address against sanctions lists and blockchain analytics before funds go to it, and after funds arrive from it. The list check catches addresses regulators have published. The analytics check scores how close an address sits to sanctioned parties or illicit activity, which matters because published lists are incomplete.
A wallet address is a new kind of counterparty. It carries its own history, it can belong to someone other than your customer, and once tokens move to it they don't come back on request. Screening is how a payments team decides, before money moves, whether it should.
This article is for information only and is not legal advice.
Key takeaways
If you're mapping where screening fits in the wider payment system, start with what stablecoin infrastructure is. Wallet screening is one control inside its compliance layer.
Wallet screening is the check a payments team runs on a blockchain address before it sends funds to that address or accepts funds from it. It has two parts, and they answer different questions.
List screening asks: is this exact address on a sanctions list? It's a lookup. Either the address appears in a published entry or it doesn't.
Exposure screening asks: how close is this address to risky activity? It uses blockchain analytics, which clusters addresses that likely belong to the same entity and labels clusters by type (exchange, mixer, scam, darknet market, sanctioned entity). The tool then traces where an address's funds came from and went to, and returns a risk score.
Customer screening, covered in ongoing sanctions screening, checks names. Wallet screening checks identifiers that names can't reach. Both feed the same alert queue.
The US Treasury's Office of Foreign Assets Control (OFAC) adds digital currency addresses to some entries on the Specially Designated Nationals (SDN) List. OFAC first did this on November 28, 2018, for two individuals tied to Iran.
The listings are useful and incomplete at the same time. OFAC's FAQ 562 says its digital currency address listings are "not likely to be exhaustive." The same answer says that anyone who identifies an address they believe belongs to or is associated with an SDN, and who holds property in it, should block it and report it to OFAC.
Two practical consequences follow:
Blockchain analytics scores a wallet by tracing its transaction history and measuring how much of its activity touches labeled risky entities. The output is usually a score or a risk tier, plus the categories behind it.
The scoring rests on two kinds of exposure:
| Exposure type | What it means | Example | How strong a signal |
|---|---|---|---|
| Direct exposure | The address transacted with a risky address in one transfer | Received USDT straight from a sanctioned address | Strong. Usually triggers review or a block |
| Indirect exposure, one hop | Funds passed through one intermediate address | Sanctioned address to an unlabeled wallet to your counterparty | Moderate. Depends on amount and timing |
| Indirect exposure, several hops | Funds passed through two or more addresses | Mixer output routed through a chain of fresh wallets | Weaker with each hop, unless the pattern looks deliberate |
| Ownership attribution | The address is clustered with an entity that is itself risky | An address controlled by a listed exchange | Strong. Treat like direct exposure |
| No exposure found | No labeled risky activity in the traced history | New wallet, or one only used with regulated exchanges | Clean for now. Not a guarantee |
Two settings decide how noisy this gets. The hop limit sets how far back the trace goes. The threshold sets what share or amount of exposure counts. Set them too wide and every wallet that ever touched an exchange looks risky. Set them too narrow and layering through a few fresh wallets walks right past you.
Neither setting has an industry standard number. Write down what you chose and why, and tune it the way you'd tune any monitoring rule. The transaction monitoring red flags list shows how the same rule-tuning discipline works for amounts and velocity.
Screen outbound transfers before they're signed, and screen inbound transfers as soon as they land. The timing differs because blockchains let anyone send to any address, but nobody can pull a confirmed transfer back.
Outbound (pre-transaction). You control the send. Screen the destination address, and the customer behind it, before the transaction is broadcast. A match stops the payment. Nothing has moved yet, so nothing needs unwinding.
Inbound (post-transaction). You don't control the send. A stranger can push tokens to your deposit address at any time, including from a sanctioned wallet. Screening happens on arrival, and the decision is about the funds you now hold: credit them, hold them for review, return them, or block and report them.
Stored addresses (periodic). A wallet that passed at registration can be listed later, or start receiving from risky sources. Rescreen saved addresses when lists or analytics data change, and before each outbound payment, not only once.
The inbound case is where programs get caught out. A small deposit from a listed address (sometimes called dusting) can land in a clean customer's wallet without their involvement. Your policy should say whether that triggers a block, a review, or just a note on file, and the answer can depend on amount and direct versus indirect exposure.
Stablecoin issuers can block addresses at the token contract level, which freezes every unit of their token held by that address. This is a separate control from your own screening, and it can hit you even when you did everything right.
Circle (USDC). Circle's Stablecoin Access Denial Policy says that when an address is denied access, it can no longer send or receive Circle's stablecoin, and all of the stablecoin it controls is blocked onchain. Circle says it blocks addresses to comply with a law, regulation, or legal order, may block in response to urgent law enforcement or sanctions-related government requests, and may reverse a block once the authority confirms the obligation has lifted. The USDC terms reserve the same right.
Tether (USDT). Tether's terms of service reserve the right to blacklist any address holding Tether tokens for suspected prohibited uses, to freeze tokens, and to bar transactions to or from sanctioned persons.
What this means in a payment flow:
How issuers decide is also part of the depeg and issuer risk picture for any payment flow that holds stablecoins.
When an address is flagged, stop the money first and decide second. The workflow below works for both list matches and high exposure scores, with the outcome changing by severity.
Steps 4 and 5 mirror how Travel Rule exceptions are handled: hold, ask, then decide with a written reason.
Wallet screening reduces risk. It doesn't remove it, and a few limits are worth stating plainly.
None of this is a reason to skip screening. It's a reason to pair it with identity checks, monitoring, and a clear hold-and-review process.
BlindPay runs KYC, KYB, sanctions screening, and transaction monitoring inside the API flow, before money moves. Customers are verified before their first transaction, and entities or individuals on OFAC, EU, UN, or other sanctions lists are not supported, per the prohibited activities list.
External wallets are registered per customer as blockchain wallets. On EVM networks, the customer can sign a message and BlindPay recovers the address from the signature, so the address is proven to be under the customer's control instead of pasted in. These wallets are non-custodial: BlindPay never holds their keys and cannot access, freeze, or recover funds in them. For Brazilian customers, each external wallet is also declared as self-custodied or not, as explained in self-custody wallets.
A sanctions or watchlist screening match is one of the documented compliance hold triggers. The payin or payout moves to on_hold, and the compliance team reviews it. If the flag can't be cleared internally, BlindPay sends a request for information about the parties and the purpose of the payment, and an unanswered request may lead to a refund to the sender after 24 hours, as described in on-hold transactions. A hold can last up to 30 days; a timeout without a decision fails the transaction. If prohibited activity is identified, funds may be frozen pending investigation.
Payouts run over Pix, SPEI, ACH, RTP, SEPA, and SWIFT (POBO/COBO) from USDC or USDT on supported networks, with these checks applied to each one.
Write your inbound rule first: what happens to funds that arrive from a listed address, a high-score address, and a one-hop exposure. Then set your hop limit and threshold, and test both on a sample of real deposits before you turn on automatic blocks.
The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.
Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.
Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.