How Many Hops From a Sanctioned Address Still Flag Your Wallet?

By Alexandr Kerya · · 6 min read

TL;DR: There is no fixed safe number of hops. Blockchain analytics trace funds through every intermediary address back to a sanctioned or hacked source, so indirect exposure can flag your wallet even several transactions away - though most tools weight the risk by how close the tainted source is.

"It is three hops back, so I am fine" is one of the most common - and most wrong - assumptions in crypto compliance. Distance from a sanctioned entity or a hacked protocol does reduce how heavily a screening tool scores your wallet, but it does not create a clean cutoff after which the link disappears. Here is how hop distance actually maps to flag risk, why an address that looks clean can still inherit exposure, and what to check before you move funds.

Is there a safe number of hops from a sanctioned address?

No. There is no magic number of intermediary transactions that resets a wallet to clean. Elliptic, a blockchain analytics firm, is explicit that compliance teams should not assume reduced risk simply because a transfer is indirect, and warns that relying on predetermined hop limits - like three or five hops - can cause organizations to miss sanctions exposure entirely.

The reason is the way illicit actors move money. A sanctioned wallet rarely sends funds straight to an exchange. It "peels" the balance across dozens of intermediary addresses - the technique Elliptic attributes to the Lazarus Group - precisely so that any tool with a fixed lookback stops counting before it reaches the deposit. A hard three-hop limit is an invitation to launder in four. That is why modern screening traces the trail to its origin rather than stopping at an arbitrary depth.

A trace diagram showing a sanctioned source address sending funds through three intermediary hop wallets to your wallet, with a note that there is no fixed hop cutoff and that risk decays with distance but never reaches zero.
Analytics follow the trail to its source, not to a fixed hop limit - distance lowers the score but never zeroes it.

Why does indirect exposure flag a clean-looking wallet?

Screening tools separate two kinds of exposure. Direct exposure is a transaction straight to or from a flagged entity. Indirect exposure, as Chainalysis defines it, measures the services and entities at the origin or destination of your funds when there are intermediary addresses sitting between you and them. Your wallet can have zero direct exposure and still carry meaningful indirect exposure to a sanctioned mixer or a hacked protocol several hops upstream.

When tainted value lands in your address, the source label travels with it. A wallet that received coins originating from a sanctioned entity inherits a slice of that risk, and the inheritance propagates downstream to anyone you pay next. This is the same model that lets a single mixer withdrawal flag a wallet - a pattern covered in detail in can a wallet be flagged for receiving funds from a mixer. Most engines apply a proximity weight: a direct hop scores far higher than a fifth-hop trace, so the number that ends up on your report reflects both the severity of the source and how close you are to it.

What that means in practice: a distant exposure often produces a low-but-nonzero score. A risk-tolerant exchange may let it through; a conservative one running strict policies can still route the deposit to manual review. The hop count does not decide the outcome on its own - the exchange's risk appetite does.

How do screening tools trace funds across hops?

Under the hood, a screening engine treats the blockchain as a graph: addresses are nodes, transactions are edges. Starting from your wallet, it walks backward edge by edge, attributing each address it reaches to a known entity - an exchange, a mixer, a sanctioned cluster, a hacked-protocol drain wallet - using clustering heuristics and labelled datasets. It keeps walking until it hits attributed sources or exhausts the relevant paths, then aggregates what it found into a risk score weighted by proximity and severity.

You can reproduce the first layer of this by hand. Open your address on a block explorer like Etherscan and read the inbound transactions one by one, then click into the senders to walk back another hop. The trouble is that this shows you transfers, not risk - the explorer will not tell you that a sender three hops back is a sanctioned cluster or sits on the OFAC SDN list, and it stops at the single chain you are looking at. To see the actual exposure, screen the address with Plastron - it runs the same sanctions, mixer, and stolen-funds checks an exchange uses, traces across Ethereum and six more EVM chains at once, and returns your risk score instantly.

A comparison panel contrasting direct exposure (a transaction straight to or from a flagged entity, scored high) with indirect exposure (a flagged source reached through one or more intermediary hops, scored lower but still nonzero and able to trigger manual review).
Direct exposure is a transaction with the flagged entity itself; indirect exposure reaches it through intermediary hops and scores lower, but rarely zero.

What should you do if your wallet has indirect exposure?

If a screen shows exposure to a sanctioned or hacked source a few hops back, the worst move is to forward the funds to an exchange and hope the distance hides it. Work the problem instead:

  • Identify the tainted path. A good report names the transaction hash that introduced the exposure and the entity it traces back to, so you know which inflow is the problem.
  • Stop moving the affected funds. Forwarding them to another account spreads the exposure and can flag a second wallet you control.
  • Gather provenance. If the funds reached you from a KYC'd counterparty or a regulated exchange withdrawal, that documentation gives a reviewer a chain of custody to work with.
  • Screen before you off-ramp. Knowing your score before a deposit lets you address a flagged inflow in a source-of-funds explanation instead of being blindsided by a freeze.

Indirect exposure is not an accusation, and a distant, low-severity link is often cleared quickly once you can show where the funds came from. The point of screening first is simply to see what the exchange will see - and to never be surprised by a hop you did not know was there. If the source turns out to be a drained protocol rather than a sanctioned entity, the response differs slightly; that case is covered in what to do if you received crypto from a hacked protocol.

FAQ

How many hops away from a sanctioned wallet is still risky?

There is no safe cutoff. Analytics trace funds to their origin regardless of hop count, so even a distant link can register as indirect exposure. The score usually shrinks with distance, but a conservative exchange can still flag a multi-hop exposure for review.

Does routing funds through several wallets clean tainted crypto?

No. Adding intermediary hops is exactly the laundering pattern screening tools are built to detect. Peeling a balance across many addresses can defeat a fixed-depth lookback, but engines that trace to the source follow it through, and deliberate layering can itself look suspicious.

If my risk score is low because the exposure is distant, can I ignore it?

Not safely. A low-but-nonzero score still means a flagged source sits somewhere in your history. Whether it matters depends on the exchange's risk policy, so it is better to know the exposure exists and be ready to explain it than to assume distance makes it invisible.

Will an exchange freeze a deposit that is several hops from a hacker?

It can. Exchanges screen incoming deposits for indirect exposure, and a link to stolen or sanctioned funds - even a few hops back - can trigger a hold or a source-of-funds request while compliance reviews the trail.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

How to Check if an Ethereum Address Is SanctionedCan a Wallet Be Flagged for Receiving Funds From a Mixer?What to Do If You Received Crypto From a Hacked ProtocolFATF Says Criminals Are Building Stablecoins No One Can Freeze