TL;DR - Direct exposure is value your wallet received straight from a flagged address, while indirect exposure reaches you through one or more intermediate hops, and screening tools weight direct exposure far more heavily.
You run an address through a screening tool and it comes back with a risk score you did not expect. The wallet never touched a sanctioned entity or a mixer, yet the score is not clean. The reason is almost always indirect exposure: tainted funds that reached the address after passing through other wallets first. Knowing the difference between direct and indirect exposure tells you whether a score is a real problem or background noise.
What is direct exposure in a wallet risk score?
Direct exposure means your address transacted with a flagged counterparty in a single hop, with no wallet in between. You either received funds straight from that address or sent funds straight to it. There is no intermediary to dilute the link.
Screening engines such as Chainalysis, Elliptic, and TRM Labs maintain large clusters of labelled addresses: sanctioned entities, known mixers, ransomware wallets, scam operations, and addresses tied to stolen funds. When your wallet has a direct edge to one of those clusters, that is direct exposure. It is the strongest signal a risk model can have, because the connection is unambiguous and one transaction wide.
Direct exposure also records direction. Receiving funds from a sanctioned address is treated separately from sending funds to one, and both are logged against the wallet. A single direct transfer from a high-risk source is often enough to push a score into the red on its own.
What is indirect exposure, and why is it harder to spot?
Indirect exposure is value that originated at a flagged address but reached your wallet through one or more intermediate hops. The coins started somewhere risky, moved through a chain of ordinary-looking wallets, and then landed with you. On the surface your direct counterparty looks clean, so a quick glance at who paid you reveals nothing.
This is the exposure that catches careful users out. You can vet the wallet that paid you, confirm it has no obvious flags, and still inherit risk from two or three hops back. A block explorer shows you the single transaction that funded your address; it does not walk the trail backward to its source. That backward walk is exactly what a compliance engine does, and it is where indirect exposure surfaces.
Both paths start at the same flagged source. The direct edge scores heavily; the indirect path is diluted by each clean hop, but it is not erased.
Why does direct exposure weigh more than indirect?
Risk models treat proximity as a proxy for intent. A direct transfer from a flagged address suggests you dealt with that entity yourself. Funds that arrive after several hops are far more likely to have reached you by chance, through a counterparty who had no idea what they were passing on.
So the weighting follows the distance. Direct exposure can trip an alert at a very small value, because even a tiny direct transfer from a sanctioned source is a hard signal. Indirect exposure usually needs a larger amount, or several converging paths, before it moves a score by the same degree. Each hop dilutes the weight a little more.
The key point is that dilution is not deletion. Distance lowers how much indirect exposure counts, but it never drops the contribution to zero. A wallet sitting four or five hops from a major theft can still carry a measurable score, especially when the tainted share of its balance is large. That is why an address with no direct flags is not automatically clean.
Weight drops with each hop but stays above zero. A distant link is a small score, not a clean bill of health.
How do you check your own direct and indirect exposure?
A block explorer like Etherscan shows the transactions in and out of an address, which is enough to see your direct counterparties. It will not trace funds backward through multiple hops or tell you which clusters those counterparties belong to, so indirect exposure stays invisible on a manual lookup. Rather than checking one source at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six chains at once.
When you read a score, separate the two layers. Ask whether the exposure is direct, meaning a counterparty you dealt with yourself, or indirect, meaning something that reached you through the chain. Direct flags deserve immediate attention, since they are the kind a compliance team will ask you to explain. A small indirect score from a distant source is usually low priority, but it still belongs in any source-of-funds record you keep.
If you are accepting a large transfer or vetting a counterparty before a trade, checking both layers in advance is the cheapest insurance there is. It costs nothing to screen an address, and it is far easier to walk away from a risky wallet than to explain an inherited flag to an exchange weeks later.
FAQ
Does indirect exposure mean my funds are tainted?
Not by itself. Indirect exposure means risky value reached your wallet through intermediaries, often without your knowledge. A small score from a distant source is common and usually low risk, but a large indirect share from a serious source is worth investigating and documenting.
How many hops away does exposure stop counting?
There is no fixed cutoff. Weight falls with each hop, so distant links contribute less, but the contribution never reaches exactly zero. How far a tool looks depends on its model and the size of the tainted share at each step.
Can a wallet with no direct flags still score as risky?
Yes. A clean set of direct counterparties only rules out direct exposure. Indirect exposure from funds that passed through several wallets first can still raise the score, which is why a manual look at who paid you is not the whole picture.
Is direct exposure always worse than indirect?
For the same amount and source, yes, because proximity implies you dealt with the flagged entity yourself. A very large indirect exposure can still outweigh a tiny direct one, so the amount and the source category matter alongside the hop distance.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.