What Is a Peel Chain in Crypto Money Laundering?

By Alexandr Kerya · · 6 min read

TL;DR - A peel chain is a laundering method that splits a large sum across a long string of wallets, peeling off small amounts at each hop to dodge detection, but blockchain analysts can still walk the trail back.

If you have ever looked at a stolen-funds investigation and seen a diagram that fans out into hundreds of tiny transfers, you were looking at a peel chain. It is one of the oldest tricks for laundering crypto, and it works by drowning a single large theft in a flood of small, ordinary-looking payments. Understanding the shape of a peel chain helps explain why a wallet that only ever received a modest amount can still get flagged, and why the address that paid you matters as much as the size of the payment.

What is a peel chain?

A peel chain is a sequence of wallets that a launderer uses to move a large balance forward in steps, shaving a small slice off at each stop. Picture a wallet holding 100 ETH from a hack. The launderer sends a small fraction, say 2 ETH, to a cash-out point such as an exchange deposit address, and forwards the remaining 98 ETH to a brand-new wallet they also control. From that new wallet they peel off another small slice and forward the rest again. Repeat this hundreds of times and the original sum trickles out through a long tail of tiny, unremarkable transactions.

The name comes from that motion: each hop peels a thin layer off the main stack, like peeling an onion one sheet at a time. The bulk of the money keeps moving down a central spine of hop wallets, while the peeled slices branch off toward places where the funds turn into something spendable.

How does a peel chain work?

The mechanics are deliberately repetitive, because repetition is what makes the whole thing cheap to run and tedious to follow. A typical chain looks like this: a large deposit lands in a wallet, a script sends a small fixed amount to an off-ramp, the remainder goes to a fresh address, and the same script runs again from there. Because the peeled amounts stay small, each one sits below the thresholds that trigger automatic review at many exchanges, and none of them looks like a headline-grabbing transfer on its own.

A flow diagram of a peel chain. A wallet holding 100 ETH from a hack forwards most of its balance to a new wallet while peeling a small 2 ETH slice off to an exchange deposit. The next wallet holds 98 ETH and repeats the step, peeling another slice to a second cash-out point, and the pattern continues down a long spine of hop wallets until the stolen sum has trickled out through many tiny transfers.
Most of the balance flows down a spine of hop wallets while small slices peel off to cash-out points at each step.

Two details make a peel chain effective. The first is automation: the hops are generated by software, so a chain can run to hundreds or thousands of addresses without anyone clicking a button. The second is patience. Spread the peels out over days or weeks and the activity blends into normal exchange flow, which is exactly the camouflage the launderer is paying for.

Why do launderers use peel chains?

The goal of a peel chain is to break the obvious link between a dirty source and a clean withdrawal. A direct transfer from a hacked-protocol address to an exchange is trivial to spot. Splitting that same value into a long series of small steps is an attempt to bury the connection under so many hops that a human reviewer gives up before reaching the end.

Peel chains also target a specific weakness in older monitoring systems: fixed-amount thresholds. If a deposit only draws a compliance alert above a certain size, then keeping every peel below that line lets the money slip through one slice at a time. The same logic explains why peel chains often end at many different exchanges and services rather than one, so no single endpoint sees enough volume to stand out. Investigators have documented this pattern in major thefts, including the laundering that followed the 2016 Bitfinex breach, where stolen bitcoin moved through long chains of small transfers.

Can blockchain analysis still trace a peel chain?

In most cases, yes. A peel chain is repetitive by design, and that repetition is itself a fingerprint. Analytics firms such as Chainalysis, TRM Labs, and Elliptic build detection around the pattern: a steady spine of wallets that each hold funds for a short time, forward almost everything to a single next address, and peel a similar small ratio to an off-ramp. Software can follow that spine across hundreds of hops far faster than a person, and address-clustering links the hop wallets back to one controller.

A two-column comparison. The left column, what a peel chain hides, lists the single large transfer, the direct source-to-exchange link, and amounts kept under fixed alert thresholds. The right column, what it leaves behind, lists a repeating fixed-ratio peel pattern, automated timing between hops, the cash-out endpoints where slices land, and address clusters that tie the hop wallets to one controller.
A peel chain hides the single obvious transfer, but the repeating pattern it creates is exactly what tracing tools look for.

The endpoints are the other weak spot. Every peeled slice has to land somewhere it can become cash, and those cash-out points are usually regulated services that keep records. Trace enough peels to the same handful of deposit addresses and the chain reassembles itself, which is why a peel chain slows an investigation down without truly stopping it.

How do I know if my own wallet touched a peel chain?

This matters for ordinary users because peel chains do not only end at the launderer's own accounts. A slice can land in a wallet that later pays you, or you might accept funds from a counterparty who is one or two hops off a chain you never saw. To check by hand, you would trace the incoming address backward through each transaction on a block explorer such as Etherscan, looking for the tell-tale spine of forward-and-peel hops, which is slow and easy to lose track of.

Rather than walking that trail one transaction at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six other chains at once, with no wallet connection needed. Knowing whether incoming funds sit close to a known laundering pattern before you accept or forward them is the difference between a clean record and an unexpected source-of-funds request. For more on how the trail survives, see how exchanges trace a deposit's origin and how funds get followed across blockchains.

FAQ

Is receiving funds from a peel chain illegal?

Receiving funds is not a crime by itself, and intent usually matters. The risk is practical: if the money traces back to a theft or a sanctioned source, an exchange can freeze it and ask you to prove where it came from, regardless of whether you knew its history.

How is a peel chain different from a mixer?

A mixer pools many users' funds together to break the link in one step, while a peel chain stretches a single user's funds across a long series of small transfers. A mixer hides the link; a peel chain dilutes it. Both raise risk flags when a wallet has touched them.

Can small transactions really avoid detection?

They can slip past simple fixed-amount thresholds, which is the point of keeping peels small. Modern monitoring looks at patterns and clustering rather than single amounts, so a long run of small forward-and-peel hops is now one of the more recognisable laundering shapes.

Does it matter which chain the funds are on?

Peel chains appear on every major chain, and launderers often combine them with bridging to another network. The receiving chain tells you little about risk on its own, so the useful question is where the value started several hops back.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

Can a Wallet Be Flagged for Receiving Funds From a Mixer?How Does My Exchange Know Where My Crypto Deposit Came From?Chain-Hopping: Can Exchanges Trace Crypto Across Blockchains?AI Agents Are Getting Crypto Wallets. Are They Getting Screened?