How to Run an AML Check on a Crypto Payment Address
Last Week's $12,000 USDT Foreign-Trade Order Nearly Got My Account Banned
Last Wednesday, a Southeast Asian client asked to settle a $12,000 foreign-trade order in USDT-TRC20. For cross-border sellers like us who routinely use virtual credit cards for ads and store expenses, crypto settlement isn't unusual. But this time, the transaction hash the client sent after paying showed the funds had been split and moved through multiple transfers on the block explorer.
I was about to withdraw that USDT to a well-known exchange, then pay AWS server costs via a Paddle or Depay virtual card. But I had second thoughts and ran a quick check on the funds' origin. That check sent a chill down my spine - the upstream address was linked to a hacker address tied to stolen funds. If I'd sent it straight to the exchange, my account would very likely have been frozen on money-laundering suspicion.
This incident made me realize: whether you're collecting B2B foreign-trade payments, playing virtual card arbitrage, or farming cards, as long as you touch crypto, anti-money-laundering (AML) checks on crypto are a survival skill you must master. Drawing on my own hands-on experience, here's how to run an effective AML check on a crypto receiving address.
Why You Must AML-Check Every Crypto Payment You Receive
Many people think crypto is decentralized, so as long as you hold the private key you're safe. The reality is that every fiat on/off-ramp (CEX exchanges, payment platforms, virtual card issuers) is heavily regulated.
If you receive "tainted" coins (e.g., funds from the dark web, ponzi schemes, ransomware, or mixers) and move them into an exchange or virtual card platform:
- Exchange risk controls: at best they demand proof of funds; at worst they freeze your account and even report you to local law enforcement.
- Virtual card bans: platforms like Depay and Dupay will kill your card the moment they detect a problematic top-up source, and recovering the balance is extremely difficult.
- Guilt by association: on the blockchain, funds are traceable. Even if you're the 5th recipient, a tainted source can still get you labeled high-risk.
How I Run an AML Check on a Receiving Address (Hands-On)
There are plenty of on-chain tracing tools on the market, but I wouldn't advise beginners to buy enterprise tools like Chainalysis or CipherTrace at hundreds of dollars a month. For individual foreign-trade sellers and indie site developers, I've put together a low-cost or even free workflow.
1. Get the Target Address and Extract the TxID
When a client says they've paid, the first move isn't waiting for block confirmations - it's asking for the transaction hash. Once you have the TxID, enter it on Tronscan (Tron) or Etherscan (Ethereum) and find the source address that initiated the transfer. Remember: we're not just checking the client's direct payment address - the crucial one is the upstream address that funded the client.
2. Run a Risk Scan with Tools
I use three tools most often, each with different strengths. Here's a side-by-side comparison:
- Tronscan / Etherscan (free, basic defense): built-in risk labels. If an address has been reported by exchanges or labeling agencies, the explorer shows a red "Reported" or phishing/illegal label right on the address page. The downside is slow updates - many thief addresses have no labels.
- Breadcrumbs.app (free tier, visual tracing): I strongly recommend this one. Its visualization is excellent. Paste in an address and it pulls up a tree diagram mapping fund flows and origins. Normal retail transfers show clean lines; money laundering shows an extremely complex spider-web of splits.
- MistTrack (free address lookups, professional AML): by SlowMist, very Chinese-user-friendly. It outputs a risk score (0-100). I usually use it for the final judgment report.
3. Review the Risk Report and Set Red Lines
Using last week's order as an example: after entering the source address into MistTrack, it generated a detailed report showing 32% of the address's funds came from high-risk labels (including the Tornado Cash mixer and a scam ponzi scheme).
In daily operations, I've set clear red-line standards for myself - feel free to borrow them:
- Risk score 0-10 (safe zone): funds originate from exchange hot wallets or normal person-to-person transfers. Safe to accept.
- Risk score 11-25 (yellow zone): may contain traces of OTC trading. Usually fine to accept, but best to let it sit in your cold wallet for a while rather than immediately moving it to an exchange or virtual card.
- Risk score >25 or direct hit on a sanctioned address (red zone): e.g., OFAC sanctions list, darknet markets, or mixers. Insist the client re-sends from a different address (e.g., withdraw directly from Binance or OKX) or return the funds to the original address.
Everyday Risk-Control Advice, in the Spirit of VirtualCardX
As someone who studies virtual credit card tricks on VirtualCardX, I've seen too many cases where dirty money got a virtual card killed. Virtual card issuers (e.g., Visa/Mastercard issued via WaveCrest, Ist) have zero tolerance for money laundering.
To protect the profits you've worked hard for and the virtual cards you've nurtured, here are three daily operating rules:
- Set up an "isolation wallet": never let clients pay directly to the address bound to your exchange or virtual card platform. Keep a separate TronLink wallet as a buffer pool. Funds enter the buffer, get AML-checked, and only then are consolidated into the exchange once confirmed clean.
- Push clients through exchange channels: if a client's wallet looks high-risk, screenshot the AML report and send it to them, stating clearly: "For compliance reasons, please withdraw directly from your Binance/OKX account; direct personal-wallet transfers aren't accepted." This blocks 90% of dirty money.
- Keep on-chain evidence: for every large payment, save Tronscan transaction records and client communication screenshots. If an exchange's risk control ever audits you, these are your strongest proof of "good-faith third party" status.
The convenience of cross-border payments and crypto assets shouldn't become a breeding ground for laundering - but even more importantly, we must never become the "scapegoat" for hackers' laundering. Get into the habit of checking coins before accepting them; it takes two minutes but protects real money in your accounts. If you have more questions about USDT payments or virtual card top-ups, feel free to discuss in the comments.