Crypto Donation Checklist: 7 Checks Before Your Nonprofit Says Yes

By Alexandr Kerya · · 5 min read

Screen a donor's wallet for sanctions, mixer, and stolen-funds exposure before your nonprofit accepts the crypto gift, not after it's already spent.

Accepting a crypto donation doesn't put your nonprofit under a regulator's microscope. Skipping the wallet check before you spend it does. This checklist applies the first time a donor asks to give in Bitcoin or Ethereum, before a gift over $10,000 lands from someone the gift officer has never met, and every time a recurring donor sends from a new address. Run it before the funds move to your operating wallet or an exchange - that's the point you can no longer undo the transfer.

Before you start

You don't need the donor's legal name or a bank statement to run this check. Wallet screening reads public blockchain data - what an address received, sent, and touched before it ever reached you. All you need is the exact address the gift will move from, confirmed before the transfer, not pulled from a screenshot after the fact. One address. That's the whole input.

A manual look is possible. Open the address on Etherscan and scroll the transaction history, checking whether anything looks obviously wrong. That shows what moved, not what it means - spotting a mixer contract or a sanctioned address by eye takes practice most gift officers don't have time to build. Instead of reading a raw transaction list, screen the donor's wallet with Plastron and get one risk score covering sanctions, mixer exposure, and stolen-funds history before the gift is booked.

Diagram showing a donor's wallet address flowing through checks for the sanctions list, mixer exposure, and stolen-funds clusters before producing a single risk score.Donor walletSanctions listMixer exposureStolen-funds clusterDonor historyRisk score
Screening a donor's wallet checks three risk signals before your nonprofit records a single crypto gift as received.

What can go wrong if you skip the screen?

A donor doesn't need bad intent for this to go wrong. Blockchains record every hop permanently, and once the gift lands in your nonprofit's wallet, compliance systems downstream treat that history as yours.

  • Frozen bank or processor account. If the crypto-to-fiat conversion carries mixer or stolen-funds exposure, the exchange or processor you route it through can hold the deposit for a source-of-funds review, sometimes for 2-3 weeks.
  • Sanctions liability. A direct or near-direct link to an OFAC-listed address is a legal exposure for the organization, not a footnote you can explain away in a board memo.
  • Inherited taint. In August 2022, OFAC added the Tornado Cash mixer to the SDN list, and every wallet that had ever routed funds through it picked up exposure retroactively - a gift accepted the week before could look very different the week after.

The taint doesn't ask permission first.

The checklist

Run these steps in order, before the gift is logged as received or moved to an exchange. No skipping steps for a large or urgent one.

  1. Get the donor's wallet address in writing before the transfer.
    • A dated pledge form or gift-acceptance email works; a screenshot pulled from a group chat does not.
    • Confirm which chain the donor plans to send on, since a mismatched network can strand or lose the gift.
  2. Screen the address before you record the gift as received.
    • Check for sanctions-list hits, mixer exposure, and stolen-funds clusters in a single pass.
    • A clean result clears the address for that gift - it doesn't vouch for the donor's identity.
  3. Check the address specifically against the sanctions list.
    • A direct match to the OFAC SDN list means the gift cannot be accepted, full stop.
    • The list changes often enough that an address clean six months ago can be listed today.
  4. Check for mixer and stolen-funds exposure, not just sanctions.
    • A wallet with no sanctions hit can still carry heavy exposure to a hacked protocol or a known scam cluster.
    • Treat a high stolen-funds score the way you'd treat a check drawn on an account under a fraud hold.
  5. Verify the address character by character before you confirm receipt to the donor.
    • Address-poisoning scams plant a look-alike address in a wallet's recent history, hoping a bookkeeper copies the wrong one.
    • Copy the address from the signed pledge, never from a similar-looking past transaction.
  6. Log the screening result in the gift file.
    • Attach the score, the date, and the screening tool used to the same record as the pledge and the receipt letter.
    • An auditor or a banking partner will ask for this before your organization moves the funds anywhere else.
  7. Re-screen recurring or major donors before each new gift.
    • A wallet's exposure isn't fixed. It changes every time the address transacts with someone new.
    • Build the re-screen into the gift-acceptance workflow, not into memory.

What happens if a donor's wallet comes back flagged?

A flagged result is a prompt to pause, not an accusation against the donor. Hold the gift in the same wallet rather than forwarding it to an exchange or your operating account.

Ask the donor directly about the source of funds, and request a different address if the exposure looks material. Document the wallet address, the screening result, and the correspondence in the same gift file described above. Hold first. Ask second.

A distant, low-severity link usually just means keeping better records. A direct hit to a sanctioned address or a fresh hack means stopping before the funds move again - even a wallet with old Tornado Cash residue can carry that kind of exposure years after the fact.

How often should you re-screen a recurring donor?

A one-time check at the first gift isn't enough for a donor who gives every quarter. Re-screen before each gift on high-value or recurring relationships, and always when the donor pays from an address you haven't seen before.

Plastron's own dataset tracks more than 3,900 labeled addresses, and 780 of them tie back to OFAC sanctions alone - a number that only grows as new designations land. A clean result from last year's gift tells you nothing about this year's.

It's a habit, not a gate. Treat the re-screen the way you'd treat renewing a vendor's W-9 - due before the money moves, not after.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

Crypto Payment Safety Checklist for FreelancersShould I Screen a Customer's Wallet Before Accepting a Crypto Payment?How to Audit Your Wallet for Tornado Cash Residue Before Sending to CEXCircle Froze 16 USDC Wallets by Mistake. Could Yours Be Next?