Why a Clean Wallet Screening Result Doesn't Prove Ownership

By Alexandr Kerya · · 7 min read

Wallet screening tells you whether an address carries sanctions, mixer, or stolen-funds risk, while ownership verification proves your customer actually controls that address, and EU-regulated exchanges need both once a transfer to an unhosted wallet reaches 1,000 euros.

Your compliance vendor just confirmed the counterparty's wallet screens clean: no sanctions hits, no mixer exposure, nothing tied to a known hack. Your auditor is still asking for proof that the customer on the other end actually controls that address. Those are two different checks, and mixing them up is how VASPs end up compliant on paper and exposed in an exam.

What does wallet screening actually check?

Wallet screening pulls one address's full on-chain history and checks it against sanctions lists, mixer contracts, darknet-market clusters, and addresses tied to known hacks and scams. The industry shorthand is KYT, short for Know Your Transaction, and it answers a narrow question: is this specific address risky right now?

OFAC's Specially Designated Nationals list alone carries 780 crypto-linked entries as tracked in Plastron's corpus this year, and that is before you count the addresses tied to scams and exploits that never make a sanctions list at all. Plastron's own dataset holds 3,901 labeled addresses across those categories, most of them tagged for scam or fraud activity rather than sanctions.

You can run that same lookup yourself on a block explorer like Etherscan, for free, and read the raw transaction list. What you will not get there is a risk score, a sanctions match, or exposure across chains other than the one you are looking at. Screen the address with Plastron instead, and the same lookup returns sanctions, mixer, and stolen-funds exposure across Ethereum and six other EVM chains in one pass.

What does wallet ownership verification prove?

Ownership verification asks a completely different question: does this specific customer actually control the address, not just is the address clean. Three methods cover most of the market. The customer signs a challenge message with the wallet's private key, an approach vendors call user attestation. The customer completes a gasless micro-deposit, sometimes called the Satoshi test, proving control without moving real funds. Or, for an exchange-to-exchange transfer, the receiving platform authenticates the connection and matches it against the account holder's identity records under the Travel Rule. Sumsub and similar KYC vendors document this exact set of methods under the label unhosted wallet verification, sold as a separate product line from their transaction-risk screening tools.

None of that touches risk. A wallet can pass ownership verification and still be a fresh address with zero history, or one a scammer set up an hour ago specifically to receive a victim's funds. Verification proves whose hands are on the keys. It says nothing about what those hands have done.

Head-to-head

Screening and verification solve different problems, and the table below lines up where they actually differ.

Wallet screening versus ownership verification, side by sideLeft column, wallet screening: checks on-chain risk, automated, free tools exist, answers is this address risky. Right column, ownership verification: proves control of the wallet, needs a signature or micro-deposit, required above 1,000 euros to an unhosted wallet under EU Regulation 2023 1113, answers does the customer control it.Wallet Screening- Checks on-chain risk history- Sanctions, mixer, scam clusters- Fully automated, instant- Free manual option existsAnswers: is it risky?Ownership Verification- Proves who controls the keys- Signature or micro-deposit- Needs the customer to act- Required above EUR 1,000 (EU)Answers: is it theirs?
Wallet screening checks risk; ownership verification checks control. EU Regulation 2023/1113 requires the latter above 1,000 euros to an unhosted wallet.
CriteriaWallet screeningOwnership verification
What it answersIs this address risky?Does the customer control it?
Data sourceOn-chain history, sanctions lists, mixer and scam clustersCryptographic signature, micro-deposit, or identity match
Common termKYT (Know Your Transaction)Wallet attribution or control verification
Required bySanctions regimes, FATF Recommendation 16EU TFR, Regulation (EU) 2023/1113, above 1,000 euros to unhosted wallets
Can be automatedYes, fullyPartly; identity matching still needs a human review path
Free option availableYes, manual block-explorer lookupNo, verification requires the customer's active participation

Which one does the EU's Travel Rule actually require?

EU Regulation 2023 1113 ownership-check trigger for unhosted wallet transfersFlow: a transfer to an unhosted wallet always requires wallet screening and basic originator information regardless of amount. If that transfer reaches 1,000 euros or more, the CASP must also complete ownership verification of the receiving wallet. Below 1,000 euros, screening and standard due diligence are enough.Transfer tounhosted walletScreening alwaysruns, any amountGreater or equal toEUR 1,000: addownership verificationUnder EUR 1,000:standard due diligenceis enough
Under Regulation (EU) 2023/1113, screening applies to every unhosted-wallet transfer; ownership verification is only mandatory once the transfer reaches 1,000 euros.

Regulation (EU) 2023/1113 became fully applicable on December 30, 2024, alongside MiCA, and it does not carry the exemption most compliance teams expect. Fiat wire transfers under 1,000 euros get reduced data requirements. Crypto transfers do not. Every transfer a licensed CASP makes carries full originator and beneficiary information regardless of size.

The ownership piece kicks in at a specific point. CASPs must assess whether the customer actually owns or controls an unhosted wallet once a transfer to that wallet reaches 1,000 euros, using a risk-based methodology the EBA sets out in its regulatory technical standards. Screening a wallet clean does not satisfy that requirement. The regulation asks who controls the address, and a sanctions check has no way to answer that.

A CASP that only screens and skips the ownership check when it applies does not fail the transfer. It fails the audit. Supervisors expect working papers for every above-threshold unhosted-wallet transfer, not a clean screening report standing in for one.

Can you pass one and fail the other?

Yes, in both directions. A wallet can screen clean and still belong to someone other than your customer: a burner address, a shared custodial pool, or a scammer's fresh receiving address. It can also fail ownership verification for reasons that have nothing to do with risk. Customers lose seed phrases, use hardware wallets that do not support message signing, or simply refuse an extra step for a routine withdrawal. None of that makes the wallet dangerous. It just means the paperwork is not done.

For a below-threshold retail withdrawal or a one-off P2P trade, screening alone is usually the right call. Verification adds friction the transaction does not need, and the risk it is guarding against is small there. Once a transfer crosses into VASP-to-VASP territory above 1,000 euros to an unhosted wallet, that changes. Screening alone will not satisfy an examiner, no matter how clean the address comes back.

FAQ

Does passing wallet screening mean the wallet is verified?

No. Wallet screening tells you an address has no sanctions, mixer, or stolen-funds exposure. It says nothing about who controls the private key. A scammer's fresh receiving address can screen completely clean the first time it is ever used.

What is the Satoshi test in crypto compliance?

The Satoshi test is a gasless micro-deposit a customer confirms from their wallet to prove they control it, without moving any real funds. Exchanges use it as one of the standard ownership-verification methods alongside cryptographic message signing.

Does the EU Travel Rule apply to wallets below 1,000 euros?

Yes, for the basic originator and beneficiary information requirement. Regulation (EU) 2023/1113 applies to crypto transfers of any size. The specific requirement to assess wallet ownership for a transfer to an unhosted wallet only kicks in once that transfer reaches 1,000 euros.

Can a scammer's wallet pass ownership verification?

Yes, if the scammer controls the private key, which they usually do. Ownership verification confirms who holds the keys, not whether that person is trustworthy. That is exactly why screening and verification stay separate checks, not substitutes for each other.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

KYC vs KYT: What's the Difference in Crypto Compliance?Self-Custody and the Travel Rule: How Wallet Screening Affects Peer-to-Peer TransfersCustodial vs Non-Custodial Wallets: Who Gets AML Screened?Can Wallet Screening See Restaked ETH After the Kelp DAO Hack?