KYT and Wallet Screening for Digital Asset Businesses
Know-Your-Transaction is the operating process that scores a virtual-asset transfer before you credit it, before you pay it out, and while it sits on your book. Wallet screening is the address-level cut of that process: you look at the deposit address, the withdrawal address, the hops between them, and the clusters those hops touch. A numeric score from a blockchain-analytics vendor is an input. The legal decision is whether you credit, hold, return, freeze, escalate, or file.
KYT and transaction-monitoring work starts from those gates, not from a software demo. Digital-asset legal structuring tells a bank or a supervisor what the product is. The screen has to match that story.
What does KYT require of a digital-asset business in 2026?
Cabinet Resolution No. 134 of 2025 Article 8 requires financial institutions, DNFBPs and VASPs to apply CDD and ongoing monitoring: scrutinise transactions against the file and the assigned risk, including source of funds where needed, and keep CDD data current, with extra frequency for high-risk clients. Federal Decree by Law No. 10 of 2025 Article 19 already required CDD, continuous monitoring, TFS instructions, and records. KYT is how a VASP, an OTC desk, a custodian or a PSP that touches virtual assets performs that scrutiny on chain.
You identify the addresses that will send or receive. You collect exposure: direct hits and indirect hops to mixers, darknet markets, ransomware and scam clusters, sanctioned addresses, and unhosted wallets. You compare that exposure to stated purpose, expected volume, and risk rating. You then take a documented action: credit, delay, return, refuse, freeze, or file. A traffic-light without a typology, a hop count, an owner and a clock is not Article 8.
Ksenia Babochkina, Commercial Director at Medici Expert, put the banking consequence on the firm’s digital-assets page: “Crypto companies don't get rejected by banks for being crypto companies. They get rejected for not being able to explain themselves clearly.” A KYT file is part of that explanation: which events you screen, which typologies you treat as high, who may override a score, and where the STR went.
A KYT score leaves two other duties unfinished. You still collect originator and beneficiary information and transmit it under the Travel Rule. You still screen names against UAE local terrorist lists and United Nations lists, and you freeze on a true match. Those are separate processes with separate evidence.
Who must run wallet screening under UAE and FATF rules?
Federal Decree-Law 10 of 2025 binds financial institutions, DNFBPs and VASPs. Cabinet 134 Article 4 lists the virtual-asset activities: exchange with fiat, exchange between virtual assets, transfer, safekeeping or administration, and financial services related to an issuer’s offer or sale. If you do any of those as a business for another person from the State, Article 36(1) requires a licence, registration or listing. Article 36(4) extends the VASP transfer duties to financial institutions that send or receive virtual-asset transfers for a customer. A PSP that ramps to chain, a broker that settles in USDT, and a custodian that signs withdrawals sit in that set.
Your supervisor then adds a second layer. Dubai VASPs sit under VARA’s Compliance and Risk Management Rulebook, file VARA_EN_123_VER20250519, effective 19 June 2025, on top of the federal floor. VARA Rule III.G.1 requires Travel Rule compliance through federal AML-CFT laws, and III.G.7 requires you to handle deposits and withdrawals, unhosted VA wallets, and anonymity-enhanced transactions. ADGM and DIFC firms remain on the federal floor plus FSRA or DFSA modules. SCA remains the federal VASP supervisor outside those financial free zones. CBUAE’s Guidance for LFIs on Risks Related to VAs and VASPs is still live as of 18 August 2026. It does not create VASP law. Banks will sample whether your monitoring, sanctions screening and models receive an independent annual assessment.
FATF Recommendation 15 and its Interpretive Note apply Recommendations 10 to 21 to VASPs, with a USD/EUR 1,000 occasional-transaction CDD threshold. Recommendation 16 applies the Travel Rule to virtual-asset transfers. FATF agreed revisions to Recommendation 16 in June 2025, with national implementation expected by the end of 2030. For a UAE process in August 2026, Cabinet 134, VARA III.G and the CBUAE Virtual Assets Travel Rule are the binding texts.
Occasional CDD for VASPs attaches at AED 3,500, including linked transactions (Cabinet 134 Article 7(3)). Financial-institution wires attach at the same figure (Article 7(2)); other FI occasional transactions attach at AED 55,000. The CBUAE Virtual Assets Travel Rule uses daily aggregated AED 3,500 for beneficiary identity verification on received transfers (Article 1(10)–(11)). Below that amount you still collect the data set, without verifying it, unless you have a suspicion.
What do you screen on a deposit, a withdrawal and a hop?
A wallet screen is a decision about an address and the path that funded it. You run it on every deposit address before you credit the customer, on every withdrawal address before you release, and on hops the analytics graph shows between those points and known clusters. The graph is a vendor product. The decision is yours. Cabinet 134 Article 8 requires you to scrutinise transactions against the purpose and risk you recorded at CDD. VARA Rule III.G.7 requires you to handle deposits, withdrawals, unhosted wallets and anonymity-enhanced transactions as a Travel Rule risk that sits beside the screen. Record how many hops you walk and who may override a score.
Deposit and withdrawal addresses
Pre-credit screening looks at the sending address, the receiving address you control, the hash, the asset and the amount. You want a direct-hit list and an N-hop exposure list. Write N in the procedure. A one-hop rule misses peeling chains. A twenty-hop rule drowns the team. Set hop depth by asset and by customer risk rating, then require a human to expand the graph when the first pass is inconclusive.
Pre-payout screening looks at the destination the customer pasted. A clean deposit history does not clean a withdrawal to a mixer, a sanctioned cluster, or an unhosted wallet the customer cannot show they control. Screen before you sign. If the customer changes the destination, screen again. Internal hot/cold sweeps still need a record so the ledger and the chain reconcile.
Mixers, darknet, sanctioned clusters and unhosted wallets
Typology labels are the language of the file. Mixers, tumblers, privacy-pool contracts and chain-hopping bridges sit at the top of most VASP matrices because they hide the path. Darknet markets, ransomware wallets, scam clusters, stolen-fund dumps and child-sexual-abuse material clusters are a stop on a direct hit. Sanctioned addresses are a freeze under TFS instructions. You still run name screening on the customer and on Travel Rule counterparties. An on-chain sanctioned cluster is extra evidence for that name-list process.
Unhosted wallets are defined in the CBUAE Virtual Assets Travel Rule: a wallet or address, including a smart contract, that the originator or beneficiary operates without a third-party service other than the technology itself. Article 3 requires EDD before you send to or receive from an unhosted wallet on a customer’s behalf, including extra identification and source-of-funds verification. If the customer instructs an outbound transfer and does not supply the originator data in Article 1(2), you decline. VARA III.G.7 names the same risk as unhosted VA wallets and requires you to show VARA, at licensing, how you will handle it.
Anonymity-enhanced transactions are the third VARA III.G.7 limb. CBUAE Virtual Assets Travel Rule Article 5 prohibits a UAE VASP from executing a transfer of a privacy token, defined as an asset that disguises holder or history that would otherwise be visible on the ledger. Confirm the live CBUAE text before you freeze a token list. Cabinet 134 Article 24 requires you to assess ML, TF and PF risk from new products, practices and technologies before launch. Adding a chain, a mixer-prone asset or a bridge is an Article 24 memo, then a screening-rule change.
When do you screen: pre-credit, pre-payout and ongoing?
The operating process puts a gate on the way in and a gate on the way out, then keeps watching addresses that remain on the book. Cabinet 134 Article 8 is ongoing: you audit transactions through the life of the relationship against the file, and you refresh CDD, with extra frequency for high-risk clients. Article 14 prohibits establishing or continuing a relationship, and prohibits executing a transaction, where you cannot apply CDD; you must consider an STR. A VASP that credits first and screens in a nightly batch has already executed. A signed withdrawal is an execution. Pre-payout screening, Travel Rule transmission and name screening have to finish before the signature.
Pre-credit and pre-payout gates
If a chain cannot hold inbound funds pre-credit, write the compensating control: quarantine wallets, delayed availability, or auto-return.
Pre-credit: the inbound transaction hits a deposit address you control. The workflow pulls the hash and the sending address, requests a screen, and holds availability until a pass, a documented override, or a return. Pass criteria: maximum indirect exposure, maximum hop depth, and a hard stop on direct sanctioned, darknet, ransomware or mixer hits. Overrides need a named role above the analyst and a reason code.
Pre-payout: the customer submits a destination. You screen it, confirm Travel Rule data for VASP-to-VASP transfers, confirm unhosted-wallet EDD where Article 3 applies, and confirm name screening on the customer and on any beneficiary name you hold. Only then do you sign. A trusted address book can shorten the path for an address you have screened before, provided you rescreen on a documented cycle and on any new exposure the vendor publishes.
Ongoing monitoring after funds sit on the book
Addresses you custody change risk after the deposit. A cluster can be attributed later. Ongoing KYT rescreens hot wallets, recurring counterparties, and customers whose on-chain behaviour has drifted from the CDD purpose. High-risk files get a shorter cycle. Event-driven rescreens fire on a vendor re-attribution, a sanctions listing, a large withdrawal request, or a product change under Article 24.
This is also where wallet screening meets the ledger. Kristian Redin, Partner and COO at Medici Expert, wrote on the accounting page: “We've seen companies discover discrepancies between wallets and ledgers only at audit time. By then, fixing it is far more expensive.” Reconcile chain, custodian sub-ledger and books on a documented cycle. Crypto compliance in 2026 is the wider stack around model defence. Fiat-monitoring rules stay in the payments AML programme if you also run a PSP.
How do Travel Rule messages differ from KYT scores?
The Travel Rule moves identity data with a transfer. KYT scores the path of value on the ledger. You need both on the same ticket.
Cabinet 134 Article 36(2)(a) requires the originating VASP to obtain and retain accurate originator and beneficiary information and to transmit it immediately and securely. Minimum content: originator name, account number or virtual-asset wallet address, and residential or business address; beneficiary name and account number or wallet address. The beneficiary VASP retains that information and produces it on request (Article 36(2)(b)). VARA Rule III.G adds deposits and withdrawals, unhosted wallets, anonymity-enhanced transactions, a sunrise plan, threshold-chipping monitoring, and a licensing demonstration of the controls.
The CBUAE Virtual Assets Travel Rule, still listed in-force on 18 August 2026, fills the gaps. Article 1(2) adds originator address, identity or travel-document number, customer number, or date and place of birth. Article 1(4) prohibits execution to an unregulated VASP. Articles 1(7)–(8) and 1(12)–(15) set the path when the counterparty cannot receive the message or when data is missing: reject, execute, delay, return, report, or follow up. Domestic transfers may travel with a wallet or unique reference if the full set is available by other means, with a three-working-day clock to produce it on request (Article 1(6)). The CBUAE page still cites Cabinet 10 of 2019 and points records to that Decision’s Article 24. Cabinet 134 moved records to Article 25. Write procedures to Article 25.
A clean KYT score on a withdrawal to an unregulated counterparty still fails CBUAE Article 1(4) and VARA III.G.8 if you have no sunrise plan. A Travel Rule message that names a beneficiary does not tell you the destination sat three hops off a mixer. Run them as two controls on one ticket ID.
Name-list TFS screening is a third control. Cabinet 134 Article 36(3) and Decree-Law 10 Article 19(1)(e) require VASPs to implement TFS instructions forthwith. An on-chain cluster labelled “sanctioned” is evidence for that procedure. UAE local lists, UN lists and freeze-on-match stay in their own document.
How do you escalate an alert to freeze, STR and records?
An alert is a work item with a clock, an owner and a close code. Cabinet 134 Article 17 requires you to build and update indicators of suspicion. Decree-Law 10 Article 18 and Cabinet 134 Article 18 require you to notify the Financial Intelligence Unit without delay on suspicion, regardless of value. Banking secrecy is no defence. Article 19 prohibits telling the customer that an STR has been or will be submitted, or that an investigation is underway, subject to group information-sharing under Article 32. VARA Rule III.H.4 requires a freeze on a designated-entity match and eight-year freeze records. Name who may freeze a wallet, who may file, and who covers those seats at night.
Alert disposition
Write close codes the independent tester can sample. Direct sanctioned, darknet, ransomware or child-abuse cluster: freeze or refuse, consider STR, no customer contact about the filing. Direct mixer: hold or return, EDD on source of funds, STR if the purpose on file cannot absorb it. Indirect exposure within policy limits: document the hop path and credit or pay. Above limits: escalate, expand the graph, decide hold, return, or senior-management override. Unhosted wallet: complete Article 3 EDD before you move; decline outbound if originator data is missing. Missing Travel Rule message: CBUAE Article 1(12)–(13). Vendor timeout: fail closed on payouts; quarantine or return deposits.
Each close needs the hash, addresses, asset, amount, typology, hop depth, customer ID, rating, decision, owner, timestamp, and any STR or freeze reference. Overrides need a second person.
STR, tipping-off and goAML
The UAE channel is goAML. Name who holds the credentials, the deputy, and the backup. Decree-Law 10 Article 18 is “without delay” and regardless of value. Occasional-CDD and Travel Rule verification thresholds do not gate an STR.
A procedure that tells the desk to “call the client to explain the mixer hit” is a tipping-off script. If you suspect a crime and have reasonable grounds to believe that applying CDD would alert the customer, Cabinet 134 Article 14(2) lets you withhold those measures and requires an STR that states why. Incomplete CDD on a non-suspicion file stays blocked under Article 14(1).
CBUAE Virtual Assets Travel Rule Article 4 requires you to take originator and beneficiary information into account when you decide whether to file, and to attach the KYT graph, the Travel Rule message or the evidence it was missing, and the unhosted-wallet EDD pack.
What evidence does a reviewer want for each screening event?
A bank, a PSP, VARA, DFSA, FSRA or CBUAE desk will sample tickets. Cabinet 134 Article 25 requires transaction records for at least five years from completion or from the end of the relationship, and a second five-year clock for CDD, monitoring, STRs and analysis, measured from the most recent listed event. Records must let a third party reconstruct the transaction. VARA Rules I.F.2 and III.I.2 require books and specified AML records, including virtual-asset transactions whether or not they sit on a public ledger, for no less than eight years, and without a fixed end date where records may relate to UAE national security. If you hold a VARA licence, the KYT ticket clock is eight years.
August 2026.
Inbound deposit, pre-credit
Screen the sending address, your deposit address, hash, asset, amount, and direct and N-hop exposure. Evidence: vendor response, hop depth, typology labels, AED equivalent, customer risk rating, hold/credit/return decision, owner, timestamp. Do not make funds available until pass, documented override, or return. Art. 8 + Art. 14.
Outbound withdrawal, pre-payout
Screen destination address, asset, amount, Travel Rule counterparty status, and unhosted versus VASP. Evidence: the inbound screen pack, Travel Rule payload or unhosted EDD pack, name-screening result, signature timestamp after the pass. Do not sign before screen + Travel Rule + TFS name screen. CBUAE VA TR Art. 1 and 3; Cabinet 134 Art. 36.
Destination change or internal sweep
Screen the new destination, or your own wallets. Evidence: a new payout ticket, or books reconciliation. Treat a new destination as a new payout. Sweeps remain Art. 25 / VARA III.I records.
Mixer, darknet, ransomware, scam or CSAM cluster
Screen direct hit versus N-hop, contract addresses, bridge hops. Evidence: graph export, hop path, SoF/SoW, freeze or refuse, STR number if filed. Direct illicit hit: stop. Mixer: hold or return, consider STR. Art. 17–19.
Sanctioned address or cluster
Screen on-chain designation plus name lists. Evidence: TFS hit pack, freeze log, notification to competent authority per TFS instructions. Freeze forthwith (Decree-Law Art. 19(1)(e); VARA III.H.4). Name-list process is a separate procedure.
Unhosted wallet send or receive
Screen hosted versus unhosted determination, extra ID, source of funds. Evidence: EDD memo, ownership/control evidence you accepted, decline log if data missing. CBUAE VA TR Art. 3; VARA III.G.7(b).
Anonymity-enhanced transaction / privacy token
Screen asset settings, mixins, shielded pool, privacy-token flag. Evidence: product matrix, Article 24 memo, execute/decline log. CBUAE VA TR Art. 5 (no privacy-token execute); VARA III.G.7(c).
Travel Rule gap, unregulated VASP, or AED 3,500 chipping
Screen counterparty licence, payload completeness, linked transfers. Evidence: message or gap analysis, linkage memo, sunrise file. CBUAE VA TR Art. 1(4), 1(7)–(15); Cabinet 134 Art. 7(3); VARA III.G.8–9.
Vendor timeout or false-positive close
Screen the fail-closed rule, or why the typology does not attach. Evidence: timeout log, or analyst note plus senior review above a threshold. Payouts fail closed. Keep the close. Art. 25(2) / VARA III.I.
STR or freeze
Screen the full ticket plus goAML acknowledgement or freeze instruction. Evidence: STR number, attachments (graph, Travel Rule data, EDD), freeze wallet list. Without delay, any value (Decree-Law Art. 18). VARA freeze records 8 years.
New chain, asset or bridge; periodic rescreen
Screen the Article 24 assessment and current exposure versus last rating. Evidence: dated memo and rule-pack change, cycle calendar and rating changes. No launch before Art. 24. High-risk files get a shorter rescreen cycle (Art. 8).
Independent testing should sample tickets across pass, hold, return, freeze and STR, and confirm ledger, hash and ticket share one ID.
How should OTC desks, custodians and PSPs apply the same rails?
An OTC desk that pre-funds USDT to a client wallet is executing a virtual-asset transfer. Screen the receiving address before you send, complete Travel Rule or unhosted-wallet EDD, and keep the ticket for the same clock as an exchange withdrawal. If you receive from the client first, screen before you credit the OTC ledger and before you pay fiat. A chat-desk that settles on trust and screens on Monday has already executed.
A custodian screens deposits into client VA wallets and screens every instruction that moves client assets to an external address. VARA’s books rules still require you to reconcile distributed-ledger balances to internal records. KYT tickets are part of that trail. The instructing affiliate’s CDD does not erase your Article 8 duty on the movement you sign.
The moment a PSP or EMI sends or receives virtual-asset transfers for a customer, Cabinet 134 Article 36(4) applies the VASP transfer duties. Screen the chain leg. Keep the fiat-monitoring book in its own procedure. If you rely on an upstream VASP’s screen, you remain responsible for CDD you rely on (Article 20), and you still need that VASP’s licence status (CBUAE Virtual Assets Travel Rule Article 1(4)). VARA III.G.8 requires a sunrise plan: named counterparties, the alternative path, the risk rating, and the point at which you decline further transfers. Article 24 requires the ML/TF/PF assessment before you add a chain, a Layer-2, a privacy asset, or a new deposit flow.
FAQ
What is KYT in crypto?
Know-Your-Transaction is the process of scoring a virtual-asset transfer against the customer’s profile and against on-chain exposure to illicit, sanctioned or obfuscating clusters, then taking a documented action. Wallet screening is the address-level cut of that process. Cabinet 134 Article 8 is the UAE duty this process performs. A vendor score is an input, not the decision.
Does a wallet risk score replace KYC or KYB?
CDD identifies the customer and the beneficial owner, verifies identity, and records purpose and expected activity (Cabinet 134 Articles 6–11). Wallet screening tests whether a given transfer matches that file. Corporate onboarding evidence lives in a KYB procedure. A green badge on an address does not identify a UBO.
How do you check if a wallet address is flagged?
Submit the address and, where you have it, the hash to your screening system at the hop depth in your procedure. Read direct hits and indirect exposure by typology, then apply pass, hold, return, freeze or STR. A public “AML checker” page is not a record a supervisor or a bank will accept: you cannot show hop depth, typology version, owner or retention.
Do unhosted wallets fall under the Travel Rule in the UAE?
VARA III.G.7 names unhosted VA wallets as a risk you must handle. The CBUAE Virtual Assets Travel Rule Article 3 requires enhanced due diligence, including extra identification and source-of-funds verification, before you send to or receive from an unhosted wallet, and requires you to decline an outbound transfer if the originator data is missing. KYT exposure on that wallet feeds that EDD.
What is the AED 3,500 threshold for?
Cabinet 134 Article 7(3) requires VASPs to apply CDD to occasional transactions of AED 3,500 or more, including linked transactions. The CBUAE Virtual Assets Travel Rule uses daily aggregated AED 3,500 as the point at which a beneficiary VASP must verify the beneficiary’s identity on a received transfer. Suspicion has no value floor: Decree-Law 10 Article 18 requires an STR regardless of amount. FATF’s USD/EUR 1,000 VASP occasional-CDD figure is the overlay.
How long must VASPs keep KYT records?
Cabinet 134 Article 25 requires at least five years, with the CDD, monitoring and STR clock running from the most recent listed event. VARA-licensed VASPs keep specified books and AML records, including virtual-asset transactions, for at least eight years (Rules I.F.2 and III.I.2), and without a fixed end date where records may relate to UAE national security. A reviewer must be able to rebuild the ticket from the hash.
Can a PSP that only touches fiat skip wallet screening?
If you only clear fiat, chain screening is not your product. If you send or receive virtual-asset transfers for a customer, Cabinet 134 Article 36(4) applies the VASP transfer duties. Screen the chain leg, keep Travel Rule data, and keep TFS name screening. Put fiat-monitoring rules in a separate procedure.
Does blockchain analytics software make the legal decision?
The software clusters addresses and returns typologies and scores. You set hop depth, pass thresholds, fail-closed rules, override rights and retention. Cabinet 134 Article 22 assigns the compliance officer the duty to monitor, assess suspicion and decide whether to notify the Unit. A model that you cannot explain to a supervisor is a finding. Independent testing should sample tickets against the event map above.
