TL;DR - Your exchange runs every incoming deposit through blockchain-analytics software that traces the funds backwards to a named source - an exchange, a mixer, or a sanctioned service - then scores the risk and decides whether to clear, hold, or block it.
You send crypto from your own wallet to your exchange account, and within seconds the exchange seems to know its entire history - sometimes enough to freeze it on arrival. It can feel like surveillance, but there is no magic involved. Every transfer you have ever made is recorded on a public ledger that anyone can read, and exchanges pay for tools that read it at scale. This guide explains exactly how that tracing works, what the exchange can and cannot see, and how to check a deposit's history yourself before it becomes a problem.
How does an exchange trace where my deposit came from?
Public blockchains like Ethereum and Bitcoin record every transaction in the open: amounts, timestamps, and the addresses on both ends. Nothing is hidden, and nothing is ever deleted. When a deposit lands, the exchange's compliance system takes the sending address and follows the money backwards - looking at where those coins came from, then where those came from, and so on up the chain.
This backward walk is what blockchain-analytics firms such as Chainalysis, TRM Labs, and Elliptic automate. As TRM Labs describes its own tracing, the tools "recursively map outgoing transfers from each address until funds reach a known entity such as an exchange." Each of those firms maintains a giant labelled database that ties millions of addresses to real-world entities - this address belongs to Binance, that one to a Tornado Cash deposit contract, this cluster to a known theft. The moment your funds' trail touches one of those labels, the exchange has its answer about the origin.
What can blockchain analytics actually see - and what can't they?
The trace goes deep, but it has hard limits worth understanding:
They can see the full on-chain path. Every address your coins passed through, every amount, every timestamp - all of it is visible without any cooperation from you.
They can label known services. Exchanges, mixers, bridges, gambling sites, sanctioned entities, and major scams are tagged in the analytics databases, so the tool recognises them when the trail hits one.
They cannot see your identity from the chain alone. An address is a pseudonym. The chain says "funds moved from 0x9f3a... to the exchange" - it does not say your name. The exchange links that to you only because you registered the account and made the deposit.
They lose the thread inside pooled services. Once funds enter a custodial service, they are co-mingled. Chainalysis notes that tracing "through a service" is hard precisely because "only the exchange knows which deposits map to which customer" once funds are pooled in shared wallets.
That last point is the key asymmetry: the world can see that money left an exchange, but only the exchange itself can match an internal customer to a specific on-chain movement. That is also why exchanges are the choke point where AML rules actually bite.
What about my deposit's history makes it high or low risk?
Not all history is equal. A trace that ends at a clean exchange is fine; one that ends at a sanctioned mixer is not. Compliance systems weight a deposit on two axes: what the source is, and how close it is to your funds.
This is the concept of exposure. Direct exposure - funds that came straight from a flagged address with no buffer in between - is the strongest signal and almost always triggers a hold. Indirect exposure, where a flagged source sits a few hops back through other wallets or a swap, carries less weight. Distant exposure, many hops removed, is usually discounted heavily. The exact thresholds differ between providers and exchanges, which is why the same deposit can clear one venue and be held at another. Elliptic, for example, notes that legitimate users "frequently have indirect exposure to high-risk services like mixers, DEXs or privacy protocols," which is the main source of false positives in screening.
Can I check where my funds came from before I deposit?
Yes - and it is the single best way to avoid a frozen deposit. You can pull up any sending address on a block explorer such as Etherscan and read its transaction history line by line. The catch is that the explorer shows you raw transfers; it will not tell you that an address three hops back is a Tornado Cash contract or a sanctioned exchange like Garantex, because it does not carry the labelled entity database the exchanges use. Screen any address with Plastron and you see the same risk picture the exchange's tools build - sanctions exposure, mixer contact, and proximity to stolen-funds and scam clusters across Ethereum and six other chains - in seconds, with no wallet connection needed. Checking the source before you move funds is how you find out a deposit is risky before the exchange does, while you can still do something about it.
How do I keep my deposits from getting flagged on arrival?
You do not need to be a compliance expert - just predictable and clean:
Screen incoming funds before you accept them. If someone pays you in crypto, check the sending address before you forward it to an exchange, so a stranger's tainted coins cannot become your problem.
Avoid mixers and sanctioned services entirely if you ever intend to move funds to a regulated exchange. Even indirect contact can add risk weight.
Be wary of "free" coins. Unsolicited airdrops and refunds from unknown addresses can carry history you did not choose. Screen them before they touch a deposit.
Keep your own records. A simple log of where your crypto came from turns a source-of-funds question into a two-minute reply instead of a week-long hold.
Use established on-ramps. Funds with a clean, traceable path from a regulated exchange or a well-known service almost never trip a deposit screen.
The takeaway is simple: your exchange is not spying on you, it is reading a public ledger that you also have full access to. The only difference is the labels - and you can close that gap by screening the source yourself before you hit send.
Frequently asked questions
Can my exchange see my whole transaction history?
It can see everything that is on the public blockchain - every address your funds passed through, the amounts, and the timestamps - by tracing the deposit backwards. It cannot see anything off-chain, and it cannot link other addresses to you by name unless you connect them to a verified account yourself.
Does using a private wallet hide my deposit's origin?
No. A self-custody or "private" wallet is still just a public address on a public chain. Analytics tools trace through it the same way they trace any other address. Privacy from the chain comes only from services like mixers - which are exactly what raises a deposit's risk score, not lowers it.
How many hops back does an exchange look?
There is no universal number; it depends on the provider and the exchange's risk appetite. Direct (one-hop) exposure to a flagged address is weighted most heavily, indirect exposure of a few hops carries less, and distant exposure many hops back is usually discounted. This is why the same deposit can clear one exchange and be held at another.
If the blockchain is public, why can only the exchange identify me?
Because identity lives off-chain. The ledger shows pseudonymous addresses, not names. The exchange ties a deposit to you only because you completed KYC and made the deposit from a known account. Anyone can trace the funds; only the venue that holds your verified identity can attach your name to them.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.