We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Dirty Crypto: How To Check If Your Funds Are Clean
Dirty crypto refers to funds whose transaction history is linked to illicit or high-risk activity. According to the Chainalysis Crypto Crime Report 2026, illicit cryptocurrency addresses received at least $154 billion in 2025, up 162% from the previous year. Stablecoins accounted for 84% of that volume: criminals use them for many of the same reasons as everyone else — fast transfers, low fees, and limited price volatility.
Illicit activity still represents less than 1% of overall crypto transaction volume. For regular users, however, the problem is not the percentage itself. Risky funds move through exchangers, P2P trades, and exchanges, and they can eventually reach a wallet whose owner had nothing to do with the original activity. You can receive high-risk crypto in an otherwise ordinary transaction — for example, as payment for goods, repayment of a debt, or USDT purchased through a service with weak AML controls.
In this guide, we explain what dirty crypto means, how AML services assess the origin of funds, how to check a wallet address or a specific transaction before sending funds to an exchange, and what to do if coins with a risky history have already reached your wallet.
What is dirty crypto?
The term usually describes cryptocurrency that is directly or indirectly linked to illicit activity, including theft, darknet markets, fraud, money laundering, sanctioned services, or terrorist financing. The token itself is technically no different from any other token; what matters is its transaction history.
Public blockchains preserve transaction history, while analytics companies label addresses and clusters associated with exchanges, mixers, darknet services, stolen funds, and other categories. If coins have passed through a known high-risk source, that connection may still be visible several transfers later. In compliance terminology, this is known as indirect exposure.
Common high-risk sources include:
These categories are only a general guide: different AML platforms and exchanges apply their own risk models. A critical label such as sanctions exposure or stolen funds can matter more than the overall risk percentage, while a licensed service and an illegal platform may receive very different classifications even if both fall under a broad category such as gambling.
How big is the problem? Cases from 2025–2026
The scale becomes easier to understand through a few concrete examples:
For an ordinary user, the important point is not the headline size of these crimes. Stolen or fraudulently obtained assets eventually have to be moved, exchanged, or spent. As a result, high-risk coins can pass through the same channels that legitimate users rely on every day.
How dirty crypto can reach a regular user
The most common scenarios are straightforward:
Stablecoins introduce another risk: the issuer can freeze tokens directly at the address level. According to Tether, by April 2026 the company had helped freeze more than $4.4 billion in assets across over 2,300 cases and had worked with law-enforcement agencies in 65 countries. A self-custody wallet does not bypass such a freeze: the tokens remain visible at the address, but they cannot be transferred.
Who decides whether funds are “clean”? How AML analytics works
The origin of funds is analyzed by specialist companies and services such as Chainalysis, Elliptic, Crystal, Scorechain, and AMLBot. They combine labels for known addresses with clustering of related wallets to estimate which services or risk categories funds have interacted with.
Exchanges and payment platforms can integrate these tools through APIs and screen incoming transactions before a deposit is fully credited. Depending on the platform, the model may consider direct and indirect exposure, the type of source, how recent the connection is, the amount involved, and other factors.
Consumer-facing AML checkers often summarize the result as a Risk Score — an overall percentage accompanied by a breakdown of the underlying categories. In practice, that breakdown is usually more useful than the headline number alone.
These thresholds are not an industry-wide standard. Each provider uses its own model, and a critical label — such as direct sanctions exposure or stolen funds — can outweigh a relatively low overall percentage.
How to check whether your crypto is clean
For a basic check, you only need a wallet address or the TXID of a specific transaction. The process is simple:
It is better to check before a transaction than after it. If a counterparty is willing to provide an address in advance, a quick AML check can reveal obvious high-risk labels before the funds reach your wallet. The same principle applies before sending a significant amount to an unfamiliar address.
What to do if you receive dirty crypto
Your first steps depend on where the funds are:
If an exchange places a deposit under compliance review, it mainly wants to know where the funds came from and why they were sent to you. Useful evidence may include screenshots of your agreement with the counterparty, their contact details, invoices or receipts, your wallet transaction history, and the AML report you saved at the time. The more consistently those records explain the transaction, the fewer gaps the compliance team has to resolve.
Answer the questions directly and do not invent details you cannot support. Review times vary by exchange, amount, risk category, and the quality of the documentation. If the platform refuses to release the funds and the amount is material to you, the next steps are best discussed with a lawyer who can account for the exchange’s jurisdiction and the circumstances of the transaction.
Several actions usually make the situation worse:
Can you “clean” dirty crypto?
If by “cleaning” you mean erasing the history of where the funds came from, there is no technically reliable way to do that. Mixers, cross-chain bridges, swaps between networks, and long chains of intermediary addresses do not remove earlier transactions from the analytical graph; modern analytics systems attempt to connect those movements across services and networks.
Accidentally receiving risky coins and deliberately trying to conceal their origin can have very different consequences. The safer approach is therefore to document how you received the funds, avoid adding unnecessary transactions, and resolve the issue through the exchange’s compliance team or a lawyer when the situation calls for it.
Prevention: how to reduce the risk
Why AML checks are becoming more common
Crypto services increasingly exchange information about senders and recipients under the Travel Rule. According to FATF, 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule by 2026, so these checks are becoming a routine part of compliance at regulated platforms.
In the EU, the AMLR will apply from July 10, 2027, tightening requirements for crypto service providers, including rules around anonymous accounts, anonymity-enhancing assets, and transactions involving self-hosted addresses. For users, the direction is clear: the source of funds will be scrutinized more often, making transaction records and basic AML screening increasingly useful when dealing with significant amounts.
Conclusion
Dirty crypto is ultimately about the history of funds and how that history is interpreted by exchanges and blockchain analytics providers. Even a legitimate user can receive coins with unwanted exposure through a P2P trade, an exchanger, a debt repayment, or an ordinary payment.
The best protection is to screen significant transfers before a transaction, keep supporting records, and avoid mixing suspicious funds into your main balance unless necessary. If a deposit is already under compliance review, trying to “clean” its history is not the answer. Clear documentation, a consistent explanation of the source of funds, and — when the amount or circumstances justify it — advice from a qualified lawyer are far more useful.
Related Posts
What Is a VPN: Settings, Privacy Rules, and the Best VPN Services in 2026
What is a VPN, and what does it actually do? VPNs have become a familiar privacy tool, but their capabilities are often misunderstood. Some people turn one on only to access a blocked website, others expect complete anonymity, and some install the first free VPN they find and use it for their primary accounts. A …
What Is a Passphrase or 25th Word and How to Use It
What is a passphrase and why does a hardware wallet owner need one? Start with the basic setup: a standard hardware wallet generates a 12- or 24-word seed phrase. The classic Ledger setup and most modern configurations use 24 words. This is enough as long as the seed does not leak and nobody physically forces …
How Coldcard Was Hacked — and Why a Firmware Update Won’t Fix Your Seed
On July 30, 2026, a series of thefts began from Bitcoin wallets whose seeds had been created on vulnerable versions of Coldcard firmware. During the first major incident, 1,082.65 BTC was drained from 1,196 addresses in just 41 minutes. The attackers did not need physical access to a Coldcard, phishing, or a transaction signed by …
Firmware Update for a Hardware Wallet: When to Update and When to Wait
A hardware wallet firmware update often feels like a minor thing: people buy a hardware wallet so it can sit in a drawer and not cause problems. Most of the time, that is exactly what happens — until the app suddenly says that a firmware update is available. That is where users tend to split …