Crypto Tracing as a Compliance Requirement: What VASPs and Exchanges Need to Know

Key Takeaways

  • Crypto tracing is now a foundational requirement for Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) compliance, moving far beyond its origins as a reactive law-enforcement forensics tool.
  • Regulatory pressure driven by global Travel Rule standards and Virtual Asset Service Provider (VASP) licensing regimes has shifted blockchain tracing from optional tech to a mandatory legal control.
  • Waiting until an enforcement action or security incident occurs is the most expensive way to implement tracking infrastructure.
  • Tracing and screening embedded directly at the infrastructure layer catch illicit risk before final settlement, whereas bolting on a third-party tool post-deployment leaves platforms playing catch-up.
  • Proactive compliance architecture safeguards banking partnerships, prevents the inadvertent handling of tainted capital, and protects operating licenses across global jurisdictions.

 

Every compliance officer at an exchange, Virtual Asset Service Provider (VASP), fintech, or treasury faces the same practical test this quarter: if a financial regulator audited your transaction monitoring systems tomorrow, would your controls actually catch illicit funds? Or would they find a static policy document sitting in a folder with no working system behind it? The difference between a written policy and a control that functions in live production is what regulatory bodies examine first.

Here’s why that matters right now. Illicit crypto addresses received at least $154 billion in 2025, according to Chainalysis’s 2026 Crypto Crime Report, up 162% from the year before. At the same time,  the Financial Action Task Force (FATF)’s July 2026 update shows 83% of jurisdictions have passed Travel Rule laws, yet only about 40% have started enforcing them. In plain terms: the rules already exist almost everywhere, and enforcement is racing to catch up. When it does, the businesses that treated tracing as optional will be the ones exposed.

The compliance teams best positioned for what comes next aren’t the ones with the most detailed Anti-Money Laundering (AML) policy documents. They are the ones that made an early infrastructure decision: building tracing natively in, rather than bolting it on later.

What Is Crypto Tracing?

Crypto tracing is the process of following the movement of funds across blockchain addresses and underlying entities to identify the origin, path, and destination of a digital asset transfer. The core objective is determining whether those funds connect to illicit activity: sanctions-designated wallets, stolen assets, darknet markets, ransomware demands, or obfuscation mixers.

It’s distinct from blockchain analytics, though the two work together in practice. Blockchain analytics covers broader risk scoring and pattern detection across a VASP’s entire transaction portfolio. Crypto tracing is specifically about following funds: mapping where money came from, where it went, and who’s connected to each step of that journey.

For compliance teams, crypto tracing is the operational foundation of Know-Your-Transaction (KYT) programs. It answers the question regulators care about most: not just who your customer is, but what funds they’re moving and where those funds have been.

Why Is Blockchain Data Traceable?

Every transaction executed on a public blockchain is permanently recorded in a distributed ledger open to public query. Unlike traditional wire transfers routed through opaque correspondent banking networks, on-chain transactions leave a complete, immutable trail across every public address they touch. That absolute transparency makes forensic tracing possible.

The practical challenge is that raw on-chain data contains wallet addresses, not names. This is where clustering heuristics and address labeling become essential: common-input ownership analysis, change address detection, and behavioral pattern matching group addresses likely controlled by the same entity.

Once those clusters form, known entities (exchanges, mixers, sanctioned actors, darknet markets) get labeled, and any address linked to that cluster inherits the label. The result is a continuously expanding map of the on-chain world that turns pseudonymous addresses into identifiable counterparties.

Who Needs Crypto Tracing, and Why Is It Urgent Now?

The short answer: anyone handling digital assets in a regulated capacity must implement crypto tracing, though the precise use case varies by institutional stakeholder.

 

WhoUse CaseRegulatory Pressure They Face
Law enforcementFollowing stolen and laundered funds to identify wallets, cash-out points, and entitiesRising caseloads tied to industrialized crime, including nation-state activity
RegulatorsAuditing whether VASPs’ monitoring controls actually functionFATF 2026: 83% of jurisdictions have Travel Rule laws; only ~40% have started enforcement, and the gap is closing
Exchanges & fintechsScreening deposits and withdrawals, flagging sanctioned counterparties, filing SARsTravel Rule thresholds now enforced: EU zero-value CASP-to-CASP; US $3,000; UK £1,000 domestic / zero cross-border; Australia from July 31, 2026
Treasuries & institutional desksVetting counterparty wallets and settlement rails before funds moveEnhanced due diligence requirements for self-hosted wallets and cross-chain settlement

The enforcement picture makes the urgency concrete. Regulators aren’t just checking whether a Travel Rule policy exists anymore. They’re testing whether the controls behind that policy function in production, at scale, under real transaction volumes.

How Does Crypto Tracing Work?

Effective crypto tracing follows a structured sequence from raw data to audit-ready output.

StepWhat Happens
1. Data collectionPull transaction and wallet data across chains and exchanges
2. LabelingAttach known identities to addresses using clustering heuristics and entity databases
3. Graph analysisMap fund flows across hops, clusters, and cross-chain bridges
4. Risk scoringScore wallets and transactions against known typologies: mixers, sanctioned entities, darknet markets, ransomware addresses
5. ReportingGenerate audit-ready output for SARs, licensing reviews, and internal case files

The critical design decision is where in your infrastructure this process runs. Tracing that happens before a transaction settles gives compliance teams the ability to intercept risk. Tracing that runs after settlement means building an investigation file on an exposure you’ve already accepted.

Mapping Crypto Tracing to Compliance Obligations 

Each tracing step doesn’t just move data forward. It directly satisfies a specific regulatory obligation. Here’s how the two connect, so your compliance team can point to exactly which control answers which requirement during an audit.

Tracing StepCompliance Obligation It SupportsWhat It Delivers for Auditors
Data collectionAML/CTF program foundationComplete, cross-chain transaction records that prove monitoring covers all activity, not just one chain
LabelingSanctions screening & KYTIdentifies whether a counterparty is a sanctioned entity, mixer, or high-risk actor before you transact
Graph analysisTravel Rule & source-of-funds checksConfirms where funds originated and traveled, the exact information the Travel Rule requires you to capture and pass on
Risk scoringKYT & enhanced due diligenceProduces the risk rating that triggers escalation, blocking, or enhanced review under your AML policy
ReportingSAR filing & licensing reviewsGenerates the documented, timestamped evidence trail regulators expect when you file a SAR or renew a license

Read this way, tracing stops being a technical process and becomes a compliance map. Labeling and risk scoring are what power your KYT and sanctions obligations. Graph analysis is what makes Travel Rule compliance provable rather than assumed. And reporting is what turns all of it into the audit-ready file a regulator or investigator can actually rely on.

What Happens When Exchanges Lack Tracing Infrastructure?

Diagram tracing illicit cryptocurrency fund flows across multiple wallet addresses and cross-chain bridges, with high-risk transactions flagged for AML compliance monitoring.

The enforcement record from 2023 to 2025 is unambiguous. Compliance programs that lacked functional transaction monitoring, not absent policies but absent controls, produced some of the largest penalties in financial services history.

$1.23 billion in AML/KYC/sanctions fines were issued in H1 2025 alone, a 417% increase in value year over year, according to Zyphe.

Specific consequences compliance teams need to understand:

MiCA licensing exposure: Non-compliant crypto-asset service providers face administrative fines of up to €5 million or 3 to 12.5% of annual turnover, plus personal liability for individual executives, according to AMLwatcher’s 2026 regulatory map. For a VASP operating across all 27 EU member states, a license withdrawal is effectively a business-ending event.

DOJ enforcement, OKX: In late 2025, the DOJ fined OKX over $504 million for AML failures ($84 million in civil penalties plus $420 million in forfeited proceeds) after the exchange facilitated more than $5 billion in suspicious transactions without adequate monitoring.

Central Bank of Ireland, Coinbase Europe: In November 2025, the Central Bank of Ireland issued its first-ever crypto enforcement action, fining Coinbase Europe €21.5 million for AML/CFT transaction monitoring failures across a four-year period.

Scale of enforcement: 139 fines totaling $1.23 billion were issued in H1 2025 alone, a 417% jump in value compared to the same period in 2024.

Incident response cost: Without tracing infrastructure already in place, a hack or exploit means building an investigation from zero, under simultaneous regulatory scrutiny, reputational pressure, and the expectation of an accurate SAR filed under time constraints.

The pattern across nearly every major enforcement action is the same. Not an absence policy. A monitoring program that couldn’t hold up under scrutiny.

Best Practices for Implementing Crypto Tracing Responsibly

Effective tracing implementation rests on five operational pillars. Each one addresses a distinct failure mode that regulators have documented in enforcement actions.

PillarWhat It Covers
Onboarding screeningWallet risk checks and sanctions/PEP screening before a customer relationship starts
Ongoing KYTContinuous monitoring of deposits, withdrawals, and counterparty exposure, not just a one-time check at onboarding
Case managementStructured escalation path from flagged transaction to investigation to SAR filing, with documented rationale at each step
Incident responsePre-built playbook for tracing exposure the moment a hack, exploit, or sanctions designation occurs
Governance frameworkNamed ownership, board-level reporting, and a documented review cadence regulators can audit

Why Ongoing KYT Is Not a Cost Center

Many teams still file KYT under “operational overhead,” a line item to minimize. That framing gets the economics backward. Ongoing KYT isn’t money spent; it’s money and license protected.

Consider what it actually guards. A single enforcement action, the €21.5 million against Coinbase Europe or the $504 million against OKX, dwarfs the annual cost of any monitoring program many times over. KYT is the control that keeps those numbers off your balance sheet. Spending on it is buying down a liability that can end the business outright.

It’s also a revenue protector, not a revenue drag. Banking partners, institutional counterparties, and payment rails increasingly refuse to work with VASPs that can’t demonstrate functional transaction monitoring. Strong KYT keeps those relationships open, which keeps deposits, settlement, and trading volume flowing. Weak KYT quietly closes doors you may not notice until a partner walks away.

And it’s a license safeguard. In the EU, a MiCA license lets you operate across 27 member states. Losing it isn’t a fine; it’s the loss of your entire addressable market. Ongoing KYT is the day-to-day evidence that keeps that license defensible when a regulator asks you to prove your controls work.

The Business Case for Proactive Compliance Architecture

Crypto tracing has moved from a forensics capability used by law enforcement to a baseline compliance requirement for any business operating in the virtual asset space. The question for compliance officers and risk leads is no longer whether to implement it. That question was settled by the regulatory and enforcement trajectory of the past two years.

The question that remains is build versus buy, and when. Building tracing in-house means acquiring data licensing agreements, maintaining address labeling accuracy across chains, and staffing a team with the blockchain forensics expertise to operationalize it. For most exchanges, fintechs, and VASPs, the timeline and cost of that build consistently outpace what’s achievable by integrating tracing at the infrastructure layer — where it runs before settlement, not after.

This is where infrastructure design determines compliance outcomes. ChainUp’s MPC wallet infrastructure distributes signing authority across independent environments using advanced threshold signature schemes, ensuring no single compromised credential or node can ever reconstruct a master private key.

However, as industry security incidents have demonstrated, bulletproof cryptographic key security still relies on human intent at the approval layer. If an authorized signer is socially engineered into approving a malicious transaction, cryptographic keys alone cannot determine whether the intent behind the signature is legitimate. That is why wallet security and transaction monitoring must work in tandem.

Trustformer KYT sits directly inside that same transaction pipeline, screening every transfer against sanctions lists, risk-scored wallet clusters, and 43 distinct risk categories across 12,000+ tokens — evaluating the transaction before it is broadcast, not via an unmonitored dashboard. It traces fund flows up to 20 layers deep, meaning that if a withdrawal request interacts with an address linked three hops downstream to a mixer or sanctioned wallet, the system flags and halts it automatically.

The compliance architecture that holds up under strict regulatory enforcement isn’t one where wallet custody and transaction monitoring are separate systems awkwardly bolted together. It is an integrated ecosystem where secure MPC signing authority, policy rules, and real-time compliance screening run as native functions of the same infrastructure — ensuring that even if a credential is compromised upstream, automated KYT intelligence catches the threat before settlement.

Frequently Asked Questions

What is crypto tracing, and how does it differ from blockchain analytics?

Crypto tracing is the process of following funds across blockchain addresses and entities to identify illicit connections: sanctioned wallets, stolen assets, mixer services, or darknet market exposure. Blockchain analytics is the broader discipline of risk scoring and pattern detection across a transaction portfolio. Tracing is specifically about mapping where funds came from, where they went, and which entities are connected to each step.

Who is required to implement crypto tracing under AML/CTF regulations?

Any entity classified as a Virtual Asset Service Provider under FATF standards, including exchanges, custodians, crypto payment processors, and stablecoin issuers, must implement transaction monitoring controls as part of a full AML/CTF program. In the EU, this obligation sits inside MiCA and the Transfer of Funds Regulation. In the US, it falls under the Bank Secrecy Act and FinCEN rules. In Australia, Travel Rule obligations take effect on July 31, 2026.

What is know-your-transaction (KYT), and how does it relate to tracing?

KYT is the ongoing monitoring of individual transactions and counterparty wallets after a customer relationship has been established. Crypto tracing is the underlying capability that powers KYT: it maps fund flows, labels addresses, and scores wallet risk. KYT without tracing infrastructure is a monitoring policy without a functional control.

What Travel Rule thresholds apply to crypto transfers in major jurisdictions?

As of 2026: the EU applies a zero-value threshold for all CASP-to-CASP transfers under the Transfer of Funds Regulation; the US applies a $3,000 threshold under the Bank Secrecy Act Funds Transfer Rule; the UK applies £1,000 domestically and zero for cross-border transfers; Australia implements Travel Rule obligations from July 31, 2026.

What are the penalties for failing to implement adequate transaction monitoring?

Penalties range from civil fines to criminal prosecution and license revocation. Under MiCA, administrative fines reach up to €5 million or 3 to 12.5% of annual turnover, with personal executive liability. In the US, the DOJ fined OKX $504 million in 2025 for AML monitoring failures. The Central Bank of Ireland fined Coinbase Europe €21.5 million for transaction monitoring failures across four years. Across all jurisdictions, $1.23 billion in AML/KYC/sanctions fines were issued in H1 2025 alone, a 417% year-over-year increase.

Why is it more effective to embed tracing at the infrastructure layer than to add a monitoring tool post-deployment?

Tracing is embedded at the infrastructure layer, screening transactions before settlement, letting compliance teams intercept risk before it becomes an accepted exposure. Adding a monitoring tool after deployment means reviewing transactions that have already settled, which creates regulatory and reputational exposure that a SAR filing can’t fully remediate. The operational gap between pre-settlement and post-settlement tracing is the gap between catching a problem and documenting one.

Share this article :

Speak to our experts

Tell us what you're interested in

Select the solutions you'd like to explore further.

When are you looking to implement the above solution(s)?

Do you have an investment range in mind for the solution(s)?

Remarks

Advertising Billboard:

Subscribe to The Latest Industry Insights

Ooi Sang Kuang

Chairman, Non-Executive Director

Mr. Ooi is the former Chairman of the Board of Directors of OCBC Bank, Singapore. He served as a Special Advisor in Bank Negara Malaysia and, prior to that, was the Deputy Governor and a Member of the Board of Directors.

ChainUp: Leading Provider of Digital Asset Exchange & Custody Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.