Screening crypto wallet addresses: what it catches and where it stops
Wallet screening catches addresses that a sanctions authority has published, matched exactly. It misses unlisted addresses controlled by the same person, funds that passed through intermediaries, and anything published after your last check.

Charles Archibong, Co-founder
· 5 min read

Key takeaways
- OFAC adds digital currency addresses to the SDN List, but says its address listings are not likely to be exhaustive.
- Address matching is exact: OFAC's own search tool uses no fuzzy logic for addresses, so one wrong character means no match.
- List screening does not trace funds through intermediate addresses; OFAC points to lookbacks and blockchain analytics for that.
- Re-screen stored addresses when lists change, and look back at past activity when a new address is listed.
Sanctioned-wallet screening catches one thing well: an address that a sanctions authority has published, matched character for character. It does not catch the other addresses the same person controls, funds that reached your customer through one or more intermediate wallets, or an address listed after your last screening run. It is a necessary control and a narrow one.
That shapes how to use it. Screen every address you hold and every counterparty address you pay or receive from, re-screen when lists change, look back at past activity when a newly listed address appears, and put transaction monitoring and, where your risk calls for it, blockchain analytics behind it.
What do sanctions lists actually publish about wallets?
The US Treasury's Office of Foreign Assets Control (OFAC) publishes wallet addresses on its sanctions list, and its FAQs on them are specific.
Addresses are listed against people and entities. OFAC may add digital currency addresses (opens in a new tab) to the Specially Designated Nationals (SDN) List "to alert the public of specific digital currency identifiers associated with a blocked person" (FAQ 562, March 2018).
The listings are partial. The same FAQ says OFAC's address listings "are not likely to be exhaustive". If you identify other wallets you believe belong to a listed person, OFAC expects you to block the property and report it.
The format is fixed. Each listed address carries a field such as "Digital Currency Address - XBT" or "Digital Currency Address - ETH", followed by an identifier of up to 256 characters (FAQ 563 (opens in a new tab)).
Matching is exact. OFAC's own search tool "does not use fuzzy logic, so only exact matches will be returned" when searching addresses (FAQ 594 (opens in a new tab)).
The obligation is the same as for fiat. OFAC says compliance obligations are the same whether a transaction is in digital currency or traditional currency (FAQ 560 (opens in a new tab)).
OFAC is a US authority, and its rules bind US persons and others subject to its jurisdiction. Firms outside the United States may choose to screen against OFAC lists alongside UN, UK, EU and national lists, but which lists bind you depends on where you operate. Requirements differ by jurisdiction, and this article is general information, not legal advice.
What does wallet screening catch, and what does it miss?
Scenario | Caught by list screening? | Why |
|---|---|---|
Customer withdraws to an address published on a sanctions list | Yes | Exact match against a published address |
Customer receives funds directly from a listed address | Yes, if you screen the sender address | The sender is the listed address |
Customer deposits from an unlisted address controlled by a listed person | No | The address is not published; OFAC says its listings are not exhaustive |
Funds from a listed address reach your customer after two hops | No | List screening looks at one address, not its history |
An address is listed a week after your customer used it | Only on re-screening | The list changed after the check |
An address pasted with a character missing or altered | No | Exact matching; a different string is a different address |
The customer themselves is a sanctioned person | No, not by wallet screening | That is name screening's job |
The gaps in the middle rows are where OFAC's own guidance for the virtual currency industry (opens in a new tab) (October 2021) points further. It says unlisted addresses "that share a wallet with a listed virtual currency address may pose sanctions risk", suggests a "historic lookback of transactional activity" after an address is listed, and says firms "may consider deploying blockchain analytics tools" to identify those risks.
How should you run wallet screening in practice?
Screen at the point of use, in both directions. Screen a withdrawal destination before you send, and a deposit source before you credit. OFAC's guidance lists screening transactions for "physical, digital wallet, and IP addresses" as a best practice.
Store the addresses your customers use. An address you have seen is an address you can re-screen. Keep the network with it.
Normalise carefully. Match on the exact string for the network. Address formats differ between networks in length and in whether letter case carries meaning, so decide normalisation per network rather than lower-casing everything.
Re-screen on list updates. OFAC's guidance asks for "ongoing sanctions screening and risk-based re-screening", including after list updates.
Look back when a new address is listed. Search your own history for any customer who sent to or received from it. A historical hit is not the same as a current one, but it tells you whom to review.
Know what you will do on a hit. For US persons, OFAC's FAQ 646 (opens in a new tab) says blocked virtual currency means denying all parties access, reporting to OFAC within 10 business days and then annually while it remains blocked. Write your own procedure for your jurisdictions before the first hit, not during it.
OFAC's guidance also notes that it may impose civil penalties "generally based on a strict liability legal standard", which is why the speed of re-screening after a designation matters.
A worked example: one withdrawal, three checks
An illustrative exchange serving customers in Kenya receives a withdrawal request to an address the customer has not used before.
Check 1, the address. The destination is screened against current sanctioned-wallet data. No match.
Check 2, the customer. The customer passed name screening at onboarding and is re-screened on schedule. No match.
Check 3, the behaviour. The customer has received deposits from dozens of unrelated addresses this week and is now consolidating to one new external address. That pattern is not a sanctions hit, but it resembles the nested activity the FATF's seventh targeted update (opens in a new tab) (July 2026) describes, where platforms pose as retail users, and it goes to an analyst.
All three checks answered different questions. Only the first was wallet screening.
Where does Myaza Trust help?
Watchlist Screening includes a WALLET screening type. You attach up to 20 wallet addresses to a customer record through the Identity Hub; they are checked against sanctioned-wallet data (for example, OFAC SDN listings), one screen covers all attached addresses, and a changed set of addresses re-screens promptly instead of waiting for the next scheduled run (screening documentation). A wallet match arrives as a screening.match event with type WALLET for an analyst to review. Wallets are treated as risk attributes of a customer, never as identity keys, because shared and custodial addresses would otherwise link unrelated people.
For customers with access to our Fraud Monitoring area, transactions sent to the v1 transactions API have the counterparty wallet screened before the decision: the recipient on outbound crypto and the sender on inbound. If the address is missing, the result is a review decision with an insufficient-data reason rather than a clear (monitoring documentation). Transaction Monitoring rules such as many distinct inbound counterparties and rapid movement cover the behavioural side.
What we do not do: wallet screening here is list matching. It does not trace funds through intermediate addresses or cluster addresses into wallets, so it complements blockchain analytics rather than replacing it.
Your wallet screening checklist
Screen destination and source addresses before funds move.
Store every address with its network, so you can re-screen it.
Re-screen stored addresses when lists change.
Run a lookback across your history when a new address is listed.
Write the block, reject and report procedure for each jurisdiction you serve.
Decide, on risk, whether you also need analytics that follow funds across hops.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


