TL;DR - There is no fixed lookback window: exchanges and their blockchain analytics read your wallet's entire on-chain history, and they can re-flag an old deposit the moment a past counterparty is tied to crime.
When you send crypto to an exchange, the common worry is how deep the review goes. Does it stop at the wallet that paid you, or keep walking back to where the coins started? Most people expect a tidy cutoff, like a 90-day bank statement. On-chain there is no such cutoff, and that catches out even careful users with clean funds.
Is there a fixed lookback window?
No. A bank works from statements that cover a set period, so it is natural to assume a crypto exchange does the same. Blockchain analysis has no equivalent. The ledger is permanent and public, so every transfer your address has ever sent or received sits on-chain forever, and screening tools can read all of it in seconds.
A deposit check does not ask what happened in the last 90 days. It asks where these specific coins came from, then follows that trail as far as it needs to. If the path is short and clean, the review is over quickly. If it runs through dozens of wallets, the tools keep walking until they reach a known source.
How does an automated deposit check read your history?
The moment your funds land, the exchange runs them through a Know Your Transaction engine, usually from a provider such as Chainalysis, Elliptic, or TRM Labs. The engine traces the deposit backward through each hop and scores its exposure to categories like sanctions, mixers, scams, and stolen funds.
Three things shape the result:
Direct versus indirect exposure. Coins that came straight from a flagged address weigh far more than coins that passed through several honest wallets first.
Direction. Receiving from a risky source is treated differently from sending to one, and both are recorded.
Hop distance. The closer a tainted source sits to your deposit, the heavier it scores. Distance dilutes the signal but never erases it.
Screening starts at your deposit and walks the chain backward, hop by hop, until it reaches a known source. There is no point where the trail is too old to follow.
Why can a clean deposit get flagged months later?
This is the part that surprises people. A deposit can clear today and turn into a problem next year, with nothing on your end having changed. Risk labels are not fixed at the time of the transaction. When analytics firms identify a new bad actor, that intelligence propagates backward across all the history tied to it.
Say you received funds from a service that looked ordinary at the time. Months later that service is sanctioned, or it gets hacked and its addresses are tagged as a theft source. Your past interaction is now re-scored against the new label. The coins never moved, but their risk rating did. An exchange that re-screens dormant balances or reviews an account on withdrawal can surface exposure that was invisible when the money first arrived.
The ledger is fixed, but the labels on it are not. New intelligence about a bad actor applies backward to every transaction that ever touched it.
How far back does a manual source-of-funds review go?
Automated scoring is instant. A manual review is slower and digs deeper. It triggers on a large deposit or withdrawal, a jurisdiction concern, or a hit from the automated engine. At that point a compliance officer may ask you to document where the funds originated, sometimes back to the moment you first bought crypto with cash.
You can read your own history on a block explorer such as Etherscan, clicking back through transfers to see what an address has touched. That is slow, covers one chain at a time, and assumes you can recognise a risky counterparty by sight. Rather than tracing each hop by hand, screen the address with Plastron to see its sanctions, mixer, and stolen-funds exposure across Ethereum and six EVM chains at once. If a review does ask for paperwork, our guide on writing a source of funds letter for a crypto exchange covers what to send.
How do you check your own wallet before depositing?
The fix is to know what an exchange will see before you move anything. Screen the depositing address first, and you turn a surprise hold into a decision you make on your own terms.
Screen before you send. Run the address through a risk check so you know its exposure band ahead of the deposit, not after a freeze.
Vet unknown counterparties. If a payment came from someone you do not know, check that wallet before you forward the funds anywhere.
Do exchanges check the whole blockchain or just recent transactions?
They can reach the whole chain. Automated scoring focuses on tracing the deposit back to its source rather than reading a fixed time range, so age alone does not put a transaction out of view. The full history of an address is always available to the tools.
Can an exchange flag funds I received years ago?
Yes. If a counterparty from years back is later linked to sanctions, theft, or fraud, that label applies backward to your old interaction. A re-screen on withdrawal or account review can surface exposure that scored clean at the time.
Does moving coins through a new wallet reset the history?
No. A new address has its own empty history, but the coins carry their trail with them. Screening follows the funds across the hop into the new wallet, so the move adds a step rather than erasing the past.
How long does an exchange keep my transaction records?
Regulated exchanges typically retain records for at least five years to meet anti-money-laundering rules, and often longer. The on-chain history itself is permanent, so the blockchain record outlasts any single platform's files.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.