A private attribution layer now decides who is cut off from crypto

Who Decides Which Crypto Address Is Sanctioned

Three things happened on 9 September 2026. The US Treasury sanctioned Xinbi Guarantee, another Telegram-based guarantee marketplace built to cash out the proceeds of global scams. The Secret Service froze $52.8 million in crypto assets tied to that bazaar. And TRM Labs announced it had doubled its valuation to $2 billion in a Series C extension led by Blockchain Capital, with annual recurring revenue up fourfold in three years.

Coverage treated the first item as policy and the third as venture capital. They are the same circuit. An OFAC designation aimed at crypto infrastructure doesn’t rest on a name and a passport: it rests on a set of addresses clustered, labelled and attributed to an entity. That work — the clustering, the common-spend heuristic, the “illicit marketplace” tag, the tracing of funds across bridges and mixers — is done mostly by three or four private companies. And one of them has just doubled its price.

The layer that matters isn’t asset classification

The visible regulatory debate is still anchored in whether a token is a security or a commodity, who supervises what and under which licence. Meanwhile, operational power has shifted to a different layer: attribution. Deciding that address X belongs to cluster Y, that the cluster is the treasury of a designated entity and that, therefore, any counterparty touching it incurs sanctions risk. That decision has immediate consequences — frozen funds, closed accounts, rejected deposits — and it happens outside the classic administrative procedure.

TRM says its software is used by more than 600 government agencies and private institutions across 75 countries. In July, ICE awarded it a sole-source contract worth roughly $95 million over one year for forensic software and support to the Homeland Security Task Forces. Chainalysis challenged the award in federal court, calling it “arbitrary, capricious and unreasonable”. The litigation is revealing for what it disputes and what it doesn’t: the contract is being fought over, not the method. No one is asking a court to open up the attribution model.

This is the structural problem. When a bank rejects a transfer because of a conventional AML alert, there is a procedure, a supervisor, and an imperfect but real right to an explanation. When an exchange blocks a withdrawal because a blockchain intelligence provider assigned a high risk score to the originating address, the user has no idea which model decided it, on what training data, with what error rate, or to whom to appeal. The provider isn’t a party to the procedure: it’s an input. But its output functions de facto as administrative evidence with no right of rebuttal.

The addressable market is labelled crime

TRM’s announcement includes two figures worth reading together. Losses from digital crime reported to the FBI’s IC3 rose to $21 billion in 2025 from $16 billion in 2024. And the company argues, citing its own AI-in-Crime Adoption Index, that criminal adoption of AI grew 40% year on year in 2026.

There’s no reason to think those figures are false. There is reason to point out that the vendor of the solution is also the producer of the statistic that sizes the problem. In any other sector that would be called a methodological conflict of interest and independent verification would be demanded. In blockchain analytics it gets cited as market data — including in this piece. The bias isn’t necessarily bad faith: providers measure what their own system labels, and a system that expands labelling coverage detects more crime by construction, even if the underlying crime isn’t growing at the same rate.

The economic incentive points in one direction only. A chain intelligence firm’s valuation grows with the volume of activity classified as illicit, with the number of jurisdictions mandating screening, and with the depth of screening obligations. A false negative — letting funds from a sanctioned entity through — is a reputational and contractual disaster. A false positive — flagging a clean address — is a cost borne by the end user, who has no channel to contest it. Systems get calibrated towards whatever hurts the seller least.

When AI replaces the analyst

TRM describes its expanding business as “AI-powered investigations”. It’s the logical lever: manual attribution doesn’t scale to 75 countries or hundreds of thousands of clusters, and automating it improves margins. But it changes the nature of the error.

Classic attribution combined deterministic heuristics — common spend, address reuse — with human intelligence: leaks, test purchases, KYC data from cooperating exchanges, forum analysis. An analyst could explain why a cluster belonged to a specific entity. A model trained on behavioural patterns produces a probability, and that probability propagates: if cluster A is attributed by inference and cluster B is linked to A by transactional proximity, the error is inherited. In a network where risk spreads by hops, a false positive doesn’t affect one address: it affects its whole neighbourhood.

Nobody publishes error rates. There is no benchmark dataset, no cross-evaluation between providers, no obligation to preserve a record of why an address received a given label on a given date. Anyone who has compared two providers across the same set of addresses knows they disagree, sometimes markedly. That divergence is the empirical proof that we are dealing with judgements, not instrument readings.

Buying the software means importing the jurisdiction

The geopolitical dimension is the least discussed. The designation lists feeding these tools are, at their core, American: OFAC defines who is outside the system. A financial intelligence unit in Latin America, Southeast Asia or the Gulf that deploys this software isn’t acquiring a neutral crime detector; it is adopting a risk map built on someone else’s foreign policy priorities and on a tolerance threshold set in Washington.

The result is an extraterritorial extension that requires no treaty and no transposition into national law. It’s bought on an annual licence. And the alternative — not buying it — isn’t freedom either: it means being cut off from correspondent banking relationships and dollar liquidity circuits, because the counterparty on the other side does screen. Sovereignty over digital sanctions is exercised today by choosing a vendor, and there are three candidates.

Where this reading could be wrong

The argument has weak points worth stating. First, an OFAC designation doesn’t rest on chain analytics alone: it incorporates human intelligence, international cooperation and traditional financial records. Attributing the sanctions decision to a private provider overstates its role; what it supplies is evidentiary material, not the legal test. Second, the Chainalysis suit against the ICE award shows there is real competition and that US procurement has challenge mechanisms: an oligopoly with internal litigation is less airtight than a silent monopoly.

Third, TRM’s revenue growth may come as much from the private sector — banks, custodians, tokenisation platforms required to screen — as from public contracts, and the former reflects genuine regulatory demand rather than punitive expansion. Fourth, and most uncomfortable for the thesis: well-applied clustering heuristics are fairly robust, and much of the crime being labelled is obvious without any sophisticated model, like a scam bazaar operating openly on Telegram.

What would disprove the thesis? A provider publishing independently verified false-positive rates that turned out to be low. The emergence of an appeals register showing a meaningful share of labels revoked on review. A court ordering discovery into attribution methodology in a forfeiture case, with the method surviving scrutiny. None of those three things has happened yet, and that absence is precisely the data point.

What it means if you’re building or investing

If you run an exchange, a custodian or a tokenised asset platform, your screening policy is a product decision, not a compliance formality. Three concrete things: negotiate into the vendor contract the right to know the basis for a label and to document internal overrides, because without that you can’t defend your judgement to your supervisor or your client. Cross-check at least two sources on blocking decisions with material impact and measure the discrepancy rate: it’s the best in-house indicator of uncertainty you’ll get. And set an explicit false-positive budget, with a review channel and a deadline, instead of letting the vendor’s risk aversion set the threshold by default.

If you invest, the moat at these companies isn’t the model: it’s the labelled dataset and the institutional relationships that feed it, something that accumulates slowly and can’t be replicated with more compute. That justifies high multiples and explains why the Series C extension comes from the same investor that led February’s $70 million round. But the symmetric risk is also underpriced: the day a court or a European regulator demands explainability and traceability for the risk scores that trigger financial exclusion, the advantage of opacity turns into a liability. The interesting space to build in isn’t a fourth scoring provider, but the infrastructure that doesn’t exist today: attribution auditing, adversarial review, comparative evaluation. Someone is going to have to watch the watchers, and so far nobody has put a price on that service.

Telegram