Should I Screen a Customer's Wallet Before Accepting a Crypto Payment?

By Alexandr Kerya · · 7 min read

TL;DR - Yes, screen a customer's funding wallet before accepting crypto: stolen or sanctioned coins can be frozen in your treasury later, and one bad payment can taint your whole balance.

Accepting crypto direct to your own wallet skips the deposit screen an exchange would normally run on incoming funds. That check is now yours. A customer can pass your know-your-customer step and still pay you with coins that trace back to a hack, a sanctioned service, or a mixer a few hops upstream. When that happens, the risk does not stay with the payer. It follows the money to you.

What risk are you actually taking when you accept a crypto payment?

Two risks, and they compound. The first is a contract-level freeze. Stablecoin issuers can blacklist an address directly on-chain, which locks the tokens wherever they sit. Tether and Circle have frozen billions of dollars of USDT and USDC and added thousands of addresses to their ban lists, often acting on law-enforcement requests tied to specific theft and fraud cases. The freeze attaches to the holding address, so it can land on your treasury weeks after a payment clears, regardless of whether you knew the source.

The second risk is a flagged history that travels. On-chain risk is transitive: it propagates downstream from a flagged origin to every address that touches the funds. A payment that came to you through two or three intermediaries can still carry a measurable link to a stolen-funds cluster. When you later move that balance to an exchange or off-ramp, the receiving venue runs its own screen, sees the exposure, and can hold the deposit for review. For more on why a faint multi-hop link weighs less than a direct one, see our explainer on direct vs indirect exposure.

How does a tainted payment reach an honest business?

It rarely arrives in one obvious step. The path usually runs through layers that strip the obvious signal but not the on-chain trail. A typical sequence: stolen funds leave an exploited protocol, pass through a mixer to break the visible link, get swapped at an unlicensed venue, and then land in a customer's wallet who pays you in good faith. Nothing in that final transfer looks wrong. The provenance is several hops back, where you cannot see it without tracing.

How tainted funds reach a business treasury through intermediary hops.Stolen funds move from a hack through a mixer and an unlicensed swap to a paying customer, then into a business treasury wallet. A screening step before acceptance branches off to catch the exposure.Hack /stolen fundsMixer /swapCustomerpays youYour treasurywalletScreen beforeyou acceptThe final transfer looks clean. The trail is two hops back.
A tainted payment looks ordinary at the moment it lands. Screening the customer's funding history before you accept is where the upstream link shows up.

This is why basic identity checks are not enough on their own. Knowing who your customer is tells you nothing about where their coins have been. A verified customer can hold tainted funds without knowing it themselves.

How do you screen a customer's wallet before accepting payment?

You can do it by hand. A block explorer such as Etherscan shows the inflows to an address, and you can cross-check each counterparty against the public OFAC SDN list and known mixer contracts. The limit is speed and reach: you are tracing multi-hop paths one address at a time, across whatever chain the payment settles on, while the customer waits at checkout.

Rather than reading a ledger line by line, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six EVM chains at once, with no signup and no keys. For a single payment you can run a focused wallet risk check or a pre-deposit crypto check on the sending address before you mark the invoice paid.

Whatever method you use, screen the wallet the funds will actually move from, and do it before you release goods or services. A clean result lowers your odds of inheriting a freeze; a flagged result lets you decline before the money is yours to worry about.

Should you pool every customer payment into one treasury wallet?

Pooling is convenient and it is also how a single bad payment contaminates a clean balance. When dozens of customer payments land in one address, the analytics picture of that address blends every source together. One stolen-funds deposit raises the risk reading of the whole wallet, and a contract-level freeze on that address locks all of it, not just the tainted slice.

Pooled treasury versus per-invoice receiving addresses.On the left, many payments flow into one pooled wallet where a single tainted deposit affects the whole balance. On the right, separate receiving addresses contain a tainted payment to one address.One pooled walletPer-invoice addressesTreasuryflaggedcleancleancontainedclean
Pooling lets one tainted payment flag the whole treasury. Separate receiving addresses keep the damage contained to a single invoice.

Separating receiving addresses by customer or by invoice keeps a problem payment isolated. It costs a little more bookkeeping, and it means a freeze or a flag hits one address instead of your operating funds. Sweep balances to your main treasury only after each payment screens clean.

What do you do when a payment screens as high-risk?

Match the response to where the exposure came from. Read the result before you react, because a faint, years-old multi-hop link is not the same as a direct transfer from a sanctioned address.

  • Direct or one-hop link to sanctions, an active mixer, or a stolen-funds cluster: decline the payment and do not move the funds. Ask for a different settlement method.
  • Indirect, multi-hop exposure with unclear provenance: pause, and request proof of where the customer sourced the funds before you accept.
  • Clean, or only a faint historical link: proceed, and keep the screening report with the invoice in case a later review asks for it.

If a tainted payment has already landed, do not sweep it into your main treasury. Keep it isolated, document how it arrived, and treat the screening record as your good-faith evidence. The published note on how issuers freeze stablecoin addresses covers what a contract-level freeze can and cannot do once funds are in your wallet.

FAQ

Do I really need to screen a wallet if my customer already passed KYC?

Yes. Identity verification tells you who the customer is, not where their coins have been. A verified customer can hold tainted funds without knowing it. Screening checks the on-chain provenance of the specific payment, which KYC does not.

Can my business funds be frozen because of a customer's payment?

Yes. Stablecoin issuers like Tether and Circle can blacklist an address at the contract level, which freezes the tokens wherever they sit. If a payment you accepted is later tied to a flagged source, the freeze can attach to your holding address regardless of your intent.

Which address should I screen, the customer or their wallet?

Screen the wallet the funds will move from, before you release anything. If the customer sends from a fresh address with no history, ask for the funding source or screen the address again the moment it is funded and before you confirm the payment.

Is it safe to keep all customer payments in one wallet?

It is convenient but riskier. One tainted deposit raises the risk reading of the whole pooled balance, and a freeze on that address locks all of it. Separate receiving addresses by invoice or customer, and sweep to your treasury only after each payment screens clean.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

How to Screen a Counterparty Wallet Before an OTC TradeWhy Circle and Tether Freeze Stablecoin AddressesDirect vs Indirect Exposure in a Crypto Wallet Risk ScoreWhat Triggers Enhanced Due Diligence on a Crypto Wallet?