Most overviews of AML providers are written for the buyer: a compliance officer choosing a screening tool. This one is written from the other end of the same data. We investigate crypto theft, and in almost every case we work on, the question of where stolen funds can still be stopped comes down to what the screening and analytics providers know about them, and how soon they know it.
So this is an overview of the market as an investigator sees it: what kinds of provider exist, what really separates one from another, how a theft case feeds into their data, and which questions are worth asking before you rely on any of them. There are no rankings and no prices: our work is investigation, forensics and recovery.
What do people mean by an "AML provider" in crypto?
The term covers several jobs that are often sold together, and a provider can be strong in one and ordinary in another.
Address screening
A check of a single wallet address against the provider's labels and risk categories: is this address, or the money that reached it, connected to sanctions, a hack, a scam, a darknet market or a mixer? It is a point-in-time answer about one address.
Transaction monitoring, or KYT
"Know your transaction" monitoring runs continuously over the deposits and withdrawals of a business. Every incoming transfer is scored as it arrives, and alerts go to the compliance team. This is the layer that decides whether stolen funds are noticed when they reach an exchange or a payment processor.
Investigation and tracing tools
Graph software that lets an analyst follow funds hop by hop, across swaps and bridges, and document the path. This is closer to our own daily work than screening is; the difference between a trace and a look at a block explorer is set out in what a blockchain investigator does.
Attribution and risk data
Underneath all three sits the dataset itself: which addresses belong to which exchange, service or known criminal actor, and which risk category each label carries. Screening and monitoring products are interfaces to that data, and its quality decides every answer built on it.
What actually differs between providers?
From inside a theft case, the differences that matter are these.
Chains and tokens covered. Coverage is not binary. A provider may support a chain for native coins but not for every token on it, or cover a newer network with fewer labels than an older one.
Where attribution comes from, and how fast new labels appear. Labels come from the provider's own research, from customers and partners, from public reports and from investigations. A hack address that is labelled within hours is useful; one labelled weeks later mostly describes history.
Risk categories and how transparent the score is. Providers group exposure into categories such as sanctions, stolen funds, scams, mixers or darknet markets, and turn that into a score. What matters is whether a compliance officer can see why a score is high — which label, how many hops away, what share of the funds — or only a number.
Cross-chain and bridge handling. Laundering routes rarely stay on one chain. Some tools follow value through a bridge automatically; others stop at the bridge contract and leave the analyst to connect the two sides by hand.
Audit trail. Whether a check can be reproduced later: what was screened, when, against which version of the data, and what the result was. For a compliance team this is the record a regulator asks for. For us it is part of the evidence, which we fix with SHA-256 hashes and a chain of custody when we handle it.
Why does one data source rarely see everything?
Because attribution is gathered, not given. Each provider sees the incidents its own customers, partners and researchers bring to it, and a label added by one does not automatically appear in another. For a business this means the choice of provider is also a choice of blind spots. For an investigator the consequence is simple: a stolen-funds marker has to reach more than one dataset to have a fair chance of being seen.
Where does a theft case meet these providers?
At the very start. When funds are stolen, the thief's problem is not holding them but converting them, and conversion almost always passes through a service that screens deposits. In our cases, stolen transactions are flagged to AML providers within four hours of intake, so the marker is already there when the funds reach a compliance team's screen. How that step works inside a case, and why it is not a subscription, is described on our AML monitoring page.
Flagging marks the funds; it does not stop them. A freeze is a separate step: depending on the case and jurisdiction, freeze requests to exchanges and stablecoin issuers may be submitted through law enforcement or other accepted legal or compliance channels, supported by our investigation report. A freeze, in turn, is not a payout.
Three of the providers we work with have announced their partnerships with us publicly. Global Ledger described it on 22 September 2025 as "a joint framework for data sharing and risk labelling" (Global Ledger announcement; our note: StarCompliance and Global Ledger). BitOK's announcement lists data exchange and enrichment: "Both teams will share blockchain intelligence to improve transaction labeling" (BitOK announcement; our note: StarCompliance and BitOK). In these two cases the point is the same: labels from theft investigations reach the data that screening relies on.
Beosin announced a "strategic collaboration with StarCompliance" on 8 October 2025, with a different focus: it pairs "Beosin's proactive security auditing" with "StarCompliance's investigation services" (Beosin announcement).
Which providers are well known, in their own words?
A short, neutral list, in alphabetical order. Each description is taken from the provider's own website as of September 2026; it is their claim, not our assessment.
- Beosin — describes itself as a "blockchain security and compliance solutions company"; its products include Trace and KYT (beosin.com).
- BitOK — lists KYT office ("Compliance solution to monitor risks, detect sanctions and ensure AML rules.") and Graph ("Comprehensive transaction analytics that helps to build graphs and trace funds.") (bitok.org).
- Chainalysis — describes itself as "the blockchain data platform"; its products include Reactor ("Investigate and trace funds across blockchains"), KYT ("Monitor transactions in real-time") and Address Screening (chainalysis.com).
- Crystal Intelligence — "the decision intelligence platform for digital assets" (crystalintelligence.com).
- Elliptic — "crypto compliance software trusted by banks, exchanges and governments to screen, monitor and investigate on-chain risk" (elliptic.co).
- Global Ledger — "blockchain visualization technology and crypto AML risk-scoring solutions" (globalledger.io).
- TRM Labs — "delivers blockchain intelligence to detect crypto-facilitated crime"; its products include Forensics, Transaction Monitoring and Wallet Screening (trmlabs.com).
The list is not complete and is not a recommendation. Of these, Beosin, BitOK and Global Ledger are our partners.
What should you ask a provider before relying on it?
These questions separate marketing from coverage:
- Which chains and which tokens on them do you cover, and with how many labels on the newer networks?
- Where do your labels come from, and how quickly does a newly reported theft address appear in the data?
- Can an investigator or a victim's representative submit stolen-funds information to you, and what evidence do you require?
- Which risk categories do you use, and does the result show the reason for a score — the label, the distance in hops, the share of exposure?
- Can a past check be reproduced — which data version, which time, which result?
- How do you correct a wrong label, and how fast?
If what you need is to run a check on an address yourself, that is a screening task, not an investigation. AMLOfficer, which was founded by StarCompliance, offers an AML check for it.
What will an AML provider not do for a victim?
An AML provider sells data and software to businesses; it does not take a victim's case or return money. Several warn about this on their own sites. TRM Labs asks visitors to "be vigilant about TRM impersonation scams, especially those claiming to assist with fund recovery"; Crystal Intelligence warns "Beware of scammers impersonating Crystal Intelligence"; Global Ledger's site carries the notice "Fraudulent sites are impersonating Global Ledger". A message from "an analyst at a blockchain analytics company" who can recover your funds for a fee is the pattern described in the seven red flags of an advance-fee recovery scam. We do not cold-message victims; anyone who approaches you in our name is not us.
What a victim needs instead is a trace — where the funds went, which services they reached, and where they can still be stopped. That is described on the crypto tracing page.
If you have lost a significant amount, send us the transaction hashes. The assessment is free, and we aim to respond within two business hours. Our published threshold is a loss from $200,000, with smaller cases reviewed individually. Write through the contact page, use the scam report form, or message @StarCompliance on Telegram.
Questions people ask about AML providers
What is the difference between address screening and transaction monitoring?
Address screening checks one address against a provider's labels at one moment. Transaction monitoring, often called KYT, scores every deposit and withdrawal of a business continuously and alerts the compliance team when a transfer carries risk.
Why can two providers give different risk scores for the same address?
Because each provider has its own attribution data, its own risk categories and its own scoring rules. A label known to one provider may not yet exist in another, and the same exposure can be weighted differently.
Does flagging stolen funds with AML providers freeze them?
No. Flagging marks the stolen transactions so that compliance teams see the history when the funds arrive. A freeze is a separate step, and a freeze is not a payout. In our cases, flagging happens within four hours of intake.
Can I ask an AML provider to recover my stolen crypto?
AML providers sell data and software to businesses; they do not take individual recovery cases. Several of them warn publicly about scammers impersonating them to offer fund recovery.
Is AML screening part of StarCompliance's investigation work?
Inside an investigation, AML monitoring is part of the case, not a standalone subscription: we flag stolen transactions and watch traced addresses for the life of a case. Screening and monitoring as a service is what AMLOfficer does; AMLOfficer was founded by StarCompliance. To check an address yourself, use the AMLOfficer AML check.
Which AML providers does StarCompliance work with?
Global Ledger, BitOK and Beosin have announced partnerships with us: Global Ledger and BitOK on data sharing and transaction labelling, Beosin on pairing its security auditing with our investigation services.
This column is informational material, not legal advice, and no outcome is promised: decisions on freezing and releasing funds are made by exchanges, issuers and courts. Provider descriptions are quoted from each provider's own website as of September 2026 and are not an endorsement or a ranking. Timelines are from StarCompliance casework and describe past cases.






