Crypto deposits arrive fast, sometimes faster than compliance teams can react. For iGaming operators accepting digital assets, wallet screening is no longer a background process reserved for high-value transactions. Incidents across the sector over the past two years have demonstrated, repeatedly, that gaps in screening workflows can expose a platform to regulatory action, banking partner terminations, and reputational damage that takes years to repair.
What Wallet Screening Actually Involves
Wallet screening is the process of evaluating a blockchain address before accepting funds from it. On-chain analytics tools assign risk scores to wallets by tracing the provenance of funds across transaction histories. A wallet that has received value from a sanctioned mixer, a darknet marketplace, or a known ransomware address carries that history with it, even if the funds have passed through several intermediary wallets in the meantime.
Operators sometimes assume that because a player passed KYC verification, the source of their crypto is clean. That assumption has cost several platforms significantly. Identity verification confirms who someone is; it does not confirm where their funds came from. Both checks are required, and they serve different compliance purposes.
Incident Patterns Operators Should Recognise
Reviewing operational incidents from crypto-accepting platforms reveals a set of recurring failure points:
- Single-layer screening only: Some operators screen the depositing wallet but not the originating wallet one or two hops back in the transaction chain. Funds laundered through a personal intermediary wallet can pass a shallow check and fail a deeper one.
- Delayed screening on fast networks: On high-throughput chains, deposits confirm in seconds. Operators who run screening after confirmation, rather than at the point of deposit request, sometimes process withdrawals before the compliance alert even surfaces.
- Inconsistent risk thresholds: Platforms that set screening thresholds too high, for instance flagging only wallets with more than 50 percent exposure to illicit sources, will miss wallets carrying significant absolute value from tainted origins even when the percentage looks acceptable.
- No re-screening on withdrawal: A wallet that was clean at deposit may have since been linked to illicit activity through updated blockchain intelligence. Operators who skip re-screening at the withdrawal stage can inadvertently complete the laundering cycle.
The Operational Response When Tainted Funds Arrive
When a screening tool flags a deposit, the compliance team faces an immediate operational decision under time pressure. The response protocol needs to be written and rehearsed before the incident occurs, not improvised during it.
A workable framework for most operators includes three stages. First, freeze the funds at the wallet or account level while the investigation is open. Second, escalate to the MLRO within a defined window, typically two to four hours for high-risk flags. Third, file a Suspicious Activity Report with the relevant financial intelligence unit if the investigation confirms reasonable grounds for suspicion, and do not inform the player that a report has been filed.
Tipping off a subject of an SAR filing is a criminal offence in most jurisdictions. Operators must train customer support staff on what they cannot say, not just what compliance officers must do.
Choosing and Configuring Screening Tools
The market for blockchain analytics tools is mature. Platforms including Chainalysis, Elliptic, and TRM Labs each maintain databases of flagged addresses and exposure categories. The choice of tool matters less than how it is configured and integrated. Key operational considerations include:
- API response time relative to deposit confirmation speed on each supported chain.
- Coverage of the specific chains and tokens your platform accepts, including newer layer-2 networks.
- Customisable risk scoring thresholds aligned with your regulator's expectations and your own risk appetite.
- Audit trail exports that satisfy regulatory record-keeping requirements.
Regulatory Expectations Are Tightening
Regulators in the Netherlands, Malta, Gibraltar, and increasingly in emerging markets are asking crypto-accepting operators to demonstrate that wallet screening is systematic, documented, and reviewed periodically. An ad hoc approach that relies on individual staff judgement will not satisfy an inspection. What regulators want to see is a written policy, a configured tool with documented thresholds, evidence of MLRO oversight, and records of every flag and its resolution.
At OnlineShine, our compliance practice works with operators to design screening workflows that are proportionate to transaction volumes and chain diversity. Getting this architecture right before a regulator asks is considerably less costly than retrofitting it under enforcement pressure.



