Background Base

Article

Agent Compliance Series II | Fund Relationships

Why AML investigations should not only ask whether funds moved, but whether risk propagated through a relationship.

August 11, 20269 min read
Agent Compliance Series II | Fund Relationships

Why AML investigations should not only ask whether funds moved, but whether risk propagated through a relationship.

In the first article of this series, we discussed what happens after an alert. An alert can tell a compliance team that risk may be present. But once an AML investigation begins, the harder question is not simply whether an on-chain path exists. The harder question is whether the fund relationship along that path is strong enough to show that risk has propagated.

On-chain transactions naturally create relationships. Address A sends funds to B, B sends funds to C, C swaps into a stablecoin through a DEX, and the funds eventually enter an exchange deposit address. These are fund flows. But a fund flow is not automatically a risk relationship. If every transaction is drawn into the graph with equal weight, the graph becomes larger while the conclusion does not necessarily become clearer.

Compliance teams need to decide:

  • which relationships indicate direct or indirect exposure;
  • which relationships are merely infrastructure links;
  • which relationships show splitting, consolidation, or transfer behavior;
  • which relationships should be included in the investigation conclusion;
  • which relationships should be de-prioritized or filtered out.

This article focuses on how to evaluate fund relationships.

1. A public address example: a transaction relationship is not yet a risk conclusion

In April 2022, OFAC added the Ethereum address 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 to the SDN record for Lazarus Group as part of its North Korea Designation Update. For any VASP or trading platform, this type of public sanctions address is a clear risk starting point.

But a real investigation rarely stops at "this address is sanctioned." A more common question is: if a customer address does not directly match the sanctioned address, but its fund path is related to it, how should that relationship be assessed?

For example, a platform may observe the following path:

OFAC-listed address 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 -> intermediary address M1 -> intermediary address M2 -> customer deposit address C

At first glance, this is a 3-hop relationship. But "3-hop" is not a conclusion.

Analysts need to ask several more specific questions. Was the fund movement continuous? If M1 received 100 ETH and sent 99.8 ETH to M2 a few minutes later, and M2 then sent a similar amount to customer address C shortly after, the relationship is much stronger. Do M1 and M2 look like pass-through wallets? If they have limited history and mostly receive funds before quickly forwarding them, they may not be ordinary wallets. Was there service-provider isolation? If the path passed through a large exchange hot wallet, a custodian, or a high-liquidity infrastructure node, the relationship may have been diluted by normal transaction flow. Was the timing consistent with the same fund path? A path completed within 40 minutes has a very different compliance meaning from a path stretched across six months.

This is the core of fund-relationship analysis. AML investigations should not simply record that Address A and Address C have a 3-hop relationship. They need to explain why that relationship is strong, weak, or insufficient.

From Fund Flow to Risk Relationship

2. Tornado Cash: infrastructure nodes can change what a relationship means

Mixers provide another useful example. In August 2022, OFAC sanctioned Tornado Cash and listed multiple related Ethereum addresses and smart contract addresses, including 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b.

Treasury stated that Tornado Cash was used to obfuscate the origin, destination, and counterparties of virtual currency transactions. FinCEN later made a similar point in its proposed rule on convertible virtual currency mixing, emphasizing that mixing can make it harder to identify sources, destinations, and transacting parties.

This illustrates an important point: the meaning of a fund relationship changes depending on the intermediary node.

Consider two paths:

Path A: high-risk address -> intermediary wallet -> customer deposit address
Path B: high-risk address -> Tornado Cash contract -> new address -> customer deposit address

Both can be drawn as fund flows, but the investigative questions are different. For Path A, the key question is whether the intermediary wallet is simply passing funds through, whether the funds remain continuous, and whether the customer address has received risk from upstream. For Path B, the question becomes whether the original relationship can still be reliably explained after the mixer.

A mixer is not just another middle node. It changes the explainability of the relationship. This does not mean every relationship involving a DEX, bridge, or mixer-related infrastructure should be treated the same way. Different nodes require different treatment.

  • A DEX may simply be a venue for swapping.
  • A bridge may simply be a cross-chain route.
  • An exchange hot wallet may be a shared entry point for many users.
  • A mixer may significantly reduce visibility into origin, destination, and counterparty relationships.

Compliance investigations should not only ask which nodes appear in the path. They should ask whether those nodes make the risk relationship stronger, weaker, or harder to explain.

How Intermediary Nodes Change Relationship Meaning

3. Four relationship types: do not turn every line into risk

Many on-chain investigations slow down because the graph keeps expanding. More addresses, more edges, more hops. But only a few relationships may actually support a conclusion. A practical approach is to classify fund relationships into four types.

3.1 Strong risk relationships

A strong risk relationship usually combines several features: a short path from a high-risk source, close timing, high amount continuity, pass-through-like intermediary behavior, no obvious service-provider isolation, and downstream behavior such as swapping, bridging, splitting, or cashing out.

For example:

  • a sanctioned address sends out 100 ETH;
  • 12 minutes later, M1 sends 99.7 ETH onward;
  • 8 minutes later, M2 splits 99.5 ETH into five deposit addresses;
  • the intermediary addresses have limited history.

The key is not whether the path is 2-hop or 3-hop. The key is that time, amount, path, and behavior together suggest the fund relationship is still effective.

3.2 Weak associations

A weak association may involve distant hops, long time gaps, broken amount continuity, or multiple ordinary service providers in between. This type of relationship should not directly support a high-risk conclusion. At most, it may be retained as background context or used for ongoing monitoring.

3.3 Infrastructure relationships

This category is especially easy to misread. Exchange hot wallets, DEX pools, bridge contracts, and stablecoin-related contracts can connect large volumes of legitimate and high-risk funds. If two addresses both interact with the same infrastructure node, that does not mean they are controlled by the same party, nor does it mean risk has effectively propagated.

For example, Customer C deposits into a large exchange. The same exchange hot wallet has also received high-risk funds. This does not, by itself, show that Customer C received those specific risky funds. Further evidence would be needed: continuous fund movement in the same time window, amount correspondence, internal or on-chain support for the same path, or other shared behavioral patterns.

Without that evidence, the relationship is more likely an infrastructure relationship than a risk-propagation relationship.

3.4 Behavioral relationships

A behavioral relationship is not created by a single transaction. It emerges when multiple addresses exhibit similar behavior over time: receiving similar amounts in the same window, using the same bridge route, entering the same exchange within a short period, repeatedly splitting and consolidating funds, or interacting with the same set of intermediary wallets.

These relationships can be valuable because they may suggest common control, coordinated activity, or the same funding network. FATF's virtual asset red flag indicators also highlight transaction size, frequency, pattern, source of funds, and rapid movement as important signals for potential money laundering and terrorist financing risk.

This is where AML Agents can be particularly useful. It is difficult for human analysts to continuously detect behavioral similarity across large numbers of addresses and transactions.

Four Types of Fund Relationships

4. An Agent should not be a graphing tool. It should be a relationship evaluator.

If an Agent simply draws every address and transaction, it does not necessarily improve investigation efficiency. A larger graph is often just a larger burden. A useful Agent should produce relationship judgments in the context of a specific case.

Return to the public sanctions-address example. Suppose customer deposit address C does not directly match an OFAC-listed address, but the system finds the following:

  • the upstream path includes 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 within two hops;
  • M1 and M2 are short-lived addresses;
  • the full movement from the sanctioned address to the customer deposit address happened in less than one hour;
  • the amount moved from 100 ETH to 99.7 ETH and then to 99.5 ETH, showing high continuity;
  • there is no obvious exchange, custodian, or service-provider isolation in the middle;
  • the customer quickly initiates swaps or withdrawals after the deposit.

In this case, the Agent should not simply output:

Customer address C has a 2-hop relationship with a sanctioned address.

That statement is too coarse. The Agent should help the analyst produce something closer to an investigation note:

Customer address C does not directly match the sanctions list, but its upstream funds originate within two hops from a public OFAC-listed address. The transfer occurred within one hour, amount continuity is high, the intermediary addresses are short-lived and exhibit pass-through behavior, and no ordinary service-provider isolation appears in the path. This relationship is closer to strong indirect exposure than ordinary background association. Enhanced due diligence and monitoring of subsequent swaps and withdrawals are recommended.

Now consider the opposite case. Suppose the relationship between customer address C and a high-risk address looks like this:

high-risk address -> DEX pool -> multiple ordinary user transactions -> exchange hot wallet -> customer address C

If there is no amount continuity, timing continuity, or path continuity, the Agent should not treat the relationship as strong risk. A better judgment would be:

The relationship appears to arise mainly from public infrastructure and shared service nodes. There is insufficient evidence of a continuous fund path. The signal can be retained as background context but is not enough, on its own, to support a high-risk conclusion.

This is what the Agent should do: not merely tell the analyst that a relationship exists, but explain why it is strong, weak, or mostly noise.

5. From relationship judgment to risk narrative

An AML investigation cannot end with a graph. A graph can support understanding, but it cannot replace the conclusion. Many investigation records are weak because they describe the path without explaining the relationship.

For example:

Address C has a 3-hop relationship with a high-risk address.

This sentence sounds informative, but it does not support a decision. It does not explain whether the three hops are continuous, what the intermediary nodes are, whether the amount remains consistent, whether the timing is meaningful, whether infrastructure isolation appears, or whether there is splitting, consolidation, or cash-out behavior.

A stronger version would be:

Address C does not directly match the sanctions list, but upstream funds flowed through two intermediary addresses within a short time window. Amount continuity is high, the intermediaries do not show obvious service-provider attributes, and funds quickly entered an exchange deposit address. The relationship shows strong indirect exposure characteristics. Enhanced due diligence and ongoing monitoring are recommended.

If the relationship is weak, the note should say so:

Address C's association with high-risk funds appears mainly through a public liquidity pool and an exchange hot wallet. There is no verifiable continuous fund path. Current evidence is insufficient to support a high-risk conclusion. The signal should be retained as background context and monitored for future behavior.

The difference is not style. The first version only describes distance on a graph. The second explains relationship quality.

Agent Output: From Path Facts to Risk Narrative

6. How ChainTrust approaches fund relationships

At ChainTrust, we do not treat a fund relationship as a simple transaction edge. It needs to be decomposed into at least four layers:

Path relationship: where funds came from, where they passed through, and where they went.

Node relationship: what role each address, contract, bridge, DEX, exchange, OTC service, or other service provider plays in the path.

Entity relationship: whether multiple addresses may belong to the same wallet cluster, service provider, or controlling entity.

Risk relationship: whether the path, nodes, and entity relationships are strong enough to show that risk has propagated.

This is why ChainTrust continues to invest in CT Data, CT Check, CT Monitor, CT Assess, and CT Probe. CT Data provides the underlying on-chain data and entity relationship foundation. CT Check identifies known address and entity risks. CT Monitor tracks whether risk relationships change over time. CT Assess places fund relationships into customer, business, and institutional policy context. CT Probe helps analysts reconstruct paths, assess relationship quality, and form explainable investigation leads after an alert.

The value of Agent Compliance is not to help AI draw more lines. It is to help analysts decide:

  • which lines represent risk relationships;
  • which lines are only infrastructure links;
  • which lines should be included in the investigation conclusion;
  • which lines should be down-weighted or filtered.

Conclusion: fewer meaningless edges, clearer critical relationships

Crypto AML investigations are becoming more complex. But complexity does not mean every relationship should be amplified. In many cases, investigations are slowed not by a lack of information, but by too many irrelevant edges. Every additional line on a graph becomes another relationship the analyst must explain or exclude.

The value of next-generation AML capability is not a bigger graph. It is a clearer explanation of relationships.

A good investigative lead should tell the compliance team where the risk came from, why the relationship matters, whether intermediary nodes strengthen or weaken the relationship, and whether the evidence is sufficient to support the next action.

When an Agent can help analysts do this, a fund path becomes a compliance judgment.

The next article will discuss how these investigative leads enter an institution's compliance decision workflow.

ChainTrust Labs

Learn more about ChainTrust KYT, on-chain risk monitoring, and investigation products:

https://chaintrustlabs.com/

References

[1] OFAC | North Korea Designation Update | 2022.04.14

[2] U.S. Department of the Treasury | U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash | 2022.08.08

[3] OFAC | Cyber-related Designation: Tornado Cash | 2022.08.08

[4] FinCEN | FinCEN Proposes Rule to Increase Transparency Around Convertible Virtual Currency Mixing | 2023.10.19

[5] FATF | Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing | 2020

[6] ChainTrust official website