Indirect Exposure Crypto Compliance: Why the 10x-20x Gap Persists
articleVerifyo Editorial TeamJune 15, 2026

Indirect Exposure Crypto Compliance: Why the 10x-20x Gap Persists

About 47 per cent of crypto-onboarding programmes in 2026 apply direct-alerting standards that would have ranked in the top decile of strictness in 2020. Chainalysis says so plainly in its 27 May 2026 “New Rails” preview, and the trade press has carried the headline as a convergence story (1)(2)(17).

The headline is real. It also hides a second number from the same dataset: indirect exposure thresholds across four high-risk categories — ransomware, fraud shops, scams and darknet markets — remain 10 to 20 times higher than the direct equivalents the cohort has just converged on (2)(17). This is not a detection problem the analytics cohort has not noticed. It is an evidence-economics problem at a different layer of the compliance stack.

The convergence the 2026 crypto compliance numbers actually measure

The Chainalysis Compliance Benchmark 2026 measures a direct-alerting metric. Direct alerting fires when the wallet being screened transacts directly with a flagged address — a one-hop story. Within the crypto industry, the benchmark tracks how many newly onboarded organisations have raised their direct-alerting thresholds to a level that, in 2020, only the top decile reached. The meaning of the 47 per cent figure is precise: just under half now operate at or above what was top-decile strictness six years ago (2).

Crypto compliance teams reading the benchmark can verify their own risk posture against a stable point. On illicit-flow alerting, crypto exchanges set the floor at roughly $100; traditional financial institutions set the floor at roughly $55 (2). On non-illicit flows, the same benchmark records crypto exchanges at $950 against traditional financial-institution minimums at $150.

That is what the benchmark proves. The headline implication — that crypto compliance has caught up to traditional finance on alerting posture — holds only at the direct layer. Indirect risk does not fit that frame.

Why indirect exposure thresholds sit 10x-20x above the direct floor for high-risk categories

Indirect risk in crypto compliance refers to a wallet’s exposure to illicit activity that does not originate from a direct counterparty, but is traced through one or more intermediate wallet addresses on the blockchain (12). Indirect exposure measurements warn investigators of a target address’s possible link to criminal activity with enough context to investigate further (13). The four high-risk categories Chainalysis enumerates — ransomware, fraud shops, scams and darknet markets — carry indirect risk exposure thresholds that often run 10 to 20 times higher than their direct equivalents. The example is exact: an organisation that alerts on $10 of direct ransomware exposure may not flag indirect ransomware exposure until it reaches $100 (2)(17).

The reason indirect exposure thresholds run higher is not detection difficulty. The blockchain-analytics cohort can trace exposure across multiple hops. The reason is false-positive economics. At one hop, the set of potentially flagged counterparties is small. At hop N, the fan-out grows quickly, and each cleared transaction requires the compliance team to produce evidence that the implicated high-risk counterparty was screened to the entity’s own standard. Lower indirect thresholds widen alert volume; the cost of producing onboarding evidence per handoff is the structural bottleneck (11).

Merkle Science frames it plainly: it is essential for crypto businesses and financial institutions to analyse indirect exposure and look beyond the first hop (16). Chainalysis made the same case in 2020 (13). The methodology has not changed; the perimeter that depends on it has widened.

Comparative diagram of direct vs indirect crypto exposure detection — threshold gap of 10x to 20x across ransomware, fraud shops, scams, darknet markets.

What financial institutions inherit when digital-asset perimeters widen: the regulator frame

Three regulator frames make the indirect risk duty a perimeter obligation, not a vendor configuration choice. FATF Recommendation 15 and its Interpretive Note require countries to ensure virtual-asset service providers assess money laundering and terrorist financing risks and implement the full range of AML/CFT preventive measures — customer due diligence, record-keeping, suspicious transaction reporting, and screening all transactions for compliance with targeted financial sanctions (3). Under the FATF risk-based approach, countries should ensure measures are commensurate with the risks identified (4). FATF Recommendation 16, updated June 2025, places originator and beneficiary information obligations on every VASP-to-VASP transfer — the cross-rail counterparty layer that operationalises indirect monitoring across the crypto industry (5).

Inside Europe, EU Regulation 2024/1624 — the AML Regulation — makes the duty concrete. Article 20 requires obliged entities to verify customer identity and check whether customers or beneficial owners are subject to targeted financial sanctions. Article 26 requires ongoing monitoring of business relationships and the transactions undertaken inside them, to ensure consistency with the entity’s knowledge of the customer’s risk profile and with the information about the origin and destination of the funds (6).

In the UK, the FCA’s Consultation Paper CP26/13 widens the population of crypto businesses inside the regulated perimeter and aligns with the UK FCA’s broader financial-crime expectations (7). OFSI’s Regulation 17A makes the operational consequence visible: Elliptic’s 26 May 2026 analysis records that its transaction-tracing capability lets UK VASPs and banks identify exposure to designated crypto exchanges across multiple hops, and Elliptic has updated its datasets so customers see the designated exchanges, banks and individuals reflected in their screening, monitoring and investigations workflows (8)(15). US regulatory frameworks follow the same logic: the Financial Crimes Enforcement Network has designated international convertible-virtual-currency mixing as a class of transactions of primary money laundering concern (9).

Where compliance teams burn budget on blockchain-data evidence

The blockchain-analytics cohort — Chainalysis KYT, TRM Labs, Elliptic, Merkle Science — does the detection work the regulator frame demands. These services read blockchain data, cluster wallet addresses into identified entities, trace exposure across multiple hops, and surface alerts at configured thresholds. That is transaction monitoring as the layer carrying that workload. TRM Labs notes no single factor is determinative for indirect risk (11); Chainalysis frames indirect exposure measurement as guidance for investigators (13); Elliptic markets the ability to detect hidden crypto exposure in fiat transactions (14); Merkle Science calls it essential to look beyond the first hop (16).

What compliance teams pay for, beyond the licence to those tools, is the evidence burden each cross-rail handoff produces. Under FATF, EU AMLR, UK FCA and OFSI, each handoff triggers the same question: was the counterparty screened to the standard the receiving entity applies. The conventional answer is to re-collect the underlying customer KYC documents into the receiving platform’s monitoring services and re-screen. That re-collection cost scales with the number of handoffs across multiple counterparties, and the perimeter is widening.

Blockchain data does not solve that side. Blockchain analytics tools identify what a wallet has transacted and the chain of intermediate addresses behind it; investigations workflows then assess the bad actors and illicit actors implicated. The identity payload behind the wallet — who the user is, what document supports the claim, what AML screen ran — is not in the blockchain data. It sits in the onboarding pipeline of whichever obliged entity verified the user. The gap between detection and evidence is where compliance officers configure budget. The detection side runs at scale across multiple blockchains; the identity-evidence side has been solved, until now, by re-keying documents.

Two-layer compliance architecture diagram — identity attestation layer above transaction monitoring layer, per-handoff KYC re-collection eli

What crypto businesses and compliance officers gain from a complementary attestation layer

This is where Verifyo sits. Before we name what we do, we name what we do not. We do not perform transaction monitoring. We do not run ongoing transaction-graph surveillance or sanctions-list propagation across hops — that work belongs to the KYT cohort. We do not offer KYB, business or entity verification, address verification, Travel Rule data exchange, Source of Funds or Source of Wealth flows, or EDD. We operate one live tier, Level 1 Standard KYC. Our screening runs at attestation time and remains valid until documented expiry. We do not describe that as real-time, continuous, or always-on, because it is not.

What we do is issue a Zero-Knowledge KYC attestation at verification time. The user is screened against sanctions, PEP, criminal, barred, military and adverse-media lists; the document is verified; the identity is bound to a wallet address. The receiving platform queries the attestation and reads booleans — kyc_status: verified, aml.sanctioned: false, age_over_18: true — without holding the underlying documents. The verification is reusable across integrating platforms across multiple chains, and verifier-private by design.

The two layers are complementary. The KYT cohort owns transaction monitoring and indirect-exposure hop tracing; Verifyo does not, and does not claim to. What a reusable, verifier-private Zero-Knowledge KYC attestation removes is the per-handoff cost of re-collecting onboarding evidence as the obliged-entity perimeter widens. The receiving platform confirms the wallet’s owner was screened to a documented Level 1 standard set at attestation time, and proceeds. Our compliance infrastructure runs alongside the existing monitoring layer; it does not replace it. For compliance officers who assess where budget is burned, the attestation layer addresses cost-of-evidence at scale, not detection.

The verdict is plain. Detection and evidence are different workloads at different layers of the compliance stack. The Chainalysis preview measures progress on the detection side, and the progress is real. The indirect risk gap persists because the evidence side has not caught up.

Learn how Zero-Knowledge KYC works at verifyo.com.

Sources

(1) Chainalysis. The New Rails: How Digital Assets Are Reshaping the Foundations of Finance. 27 May 2026. https://www.chainalysis.com/reports/the-new-rails/

(2) Chainalysis. Crypto Compliance Program Benchmark 2026. 27 May 2026. https://www.chainalysis.com/blog/crypto-compliance-program-benchmark-2026

(3) FATF. Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers. October 2021. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets.html

(4) FATF. Virtual Assets (topic page). 2026. https://www.fatf-gafi.org/en/topics/virtual-assets.html

(5) FATF. FATF Updates Standards on Recommendation 16 on Payment Transparency. June 2025. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html

(6) European Parliament and Council. Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing. 31 May 2024. https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng

(7) FCA. CP26/13: Cryptoasset Perimeter Guidance (Consultation Paper). 15 April 2026. https://www.fca.org.uk/publications/consultation-papers/cp26-13-cryptoasset-perimeter-guidance

(8) UK Government / OFSI. The Russia (Sanctions) (EU Exit) Regulations 2019 — Regulation 17A. 2019. https://www.legislation.gov.uk/uksi/2019/855/regulation/17A

(9) FinCEN. FinCEN Proposes New Regulation to Enhance Transparency in Convertible Virtual Currency Mixing and Combat Terrorist Financing. 19 October 2023. https://www.fincen.gov/news/news-releases/fincen-proposes-new-regulation-enhance-transparency-convertible-virtual-currency

(11) TRM Labs. Key Considerations for Evaluating Indirect Risk on the Blockchain. 19 May 2024. https://www.trmlabs.com/resources/blog/key-considerations-for-evaluating-indirect-risk-on-the-blockchain

(12) TRM Labs. Indirect Risk (glossary). 22 May 2026. https://www.trmlabs.com/glossary/indirect-risk

(13) Chainalysis. Cryptocurrency Risk: Blockchain Analysis Indirect Exposure. 25 November 2020. https://www.chainalysis.com/blog/cryptocurrency-risk-blockchain-analysis-indirect-exposure

(14) Elliptic. Crypto Compliance (solutions page). 2026. https://www.elliptic.co/solutions/crypto-compliance

(15) Elliptic. UK Designates Cryptoasset Exchanges in Sweeping New Sanctions Package. 26 May 2026. https://www.elliptic.co/blog/uk-designates-cryptoasset-exchanges-in-sweeping-new-sanctions-package

(16) Merkle Science. Why Does the Crypto Industry Need to Understand Indirect Risk Exposure. 30 June 2021. https://www.merklescience.com/blog/why-does-the-crypto-industry-need-to-understand-indirect-risk-exposure

(17) Crypto Briefing. Chainalysis Crypto Compliance Standards 2026. 28 May 2026. https://cryptobriefing.com/chainalysis-crypto-compliance-standards-2026/

Tags:Crypto ComplianceZero-Knowledge KYCAML MonitoringIndirect ExposureRegTech

Want to learn more?

Explore our other articles and stay up to date with the latest in zero-knowledge KYC and identity verification.

Browse all articles