Why AML checkers disagree (60% gap) and how much to trust them
The skeptical narrative: AML checkers are unreliable, 60% disagreement between Chainalysis and Ciphertrace, only 4-5 hops deep, retrospective re-scoring. What's true and how to interpret risk scores.
A skeptical narrative circulates in crypto communities: "AML checkers are unreliable, Chainalysis and Ciphertrace disagree by 60%, they only go 4-5 hops deep, they do retrospective re-scoring." Let's unpack what's true and what's exaggerated.
What gets criticized (and what's true)
"60% disagreement between providers"
Partially true. Different AML providers use different data and algorithms:
- Chainalysis — proprietary clustering + its own on-chain intelligence
- TRM Labs — focus on sanctions and scams
- Elliptic — emphasis on entity attribution
- Ciphertrace — token-level analysis
For the same address, the risk score can differ: 35 at Chainalysis, 72 at TRM. This is not a bug but different models.
"They only check 4-5 hops deep"
True for retail checkers. Deep tracing (10+ hops) requires exponentially more computation and costs $10-50 per check (vs $0.05-0.50 at retail). L3 tracing exists at Chainalysis/GraphSense but isn't mass-market.
"Retrospective re-scoring"
True. If an address is "clean" today but tomorrow its transaction neighbor gets sanctioned — today's check is outdated. This is normal in the AML industry.
What the criticism misses
For sanctions lists (OFAC, EU) — parity with Chainalysis: the address is either on the list or not. This is a binary fact with no interpretation. VerifAML uses OFAC SDN directly — 100% accuracy on sanctions.
| Category | VerifAML accuracy vs Chainalysis |
|---|---|
| Sanctions exposure | 100% parity (public data) |
| Token-safety (GoPlus) | ~95% parity |
| Known scam/hack addresses | ~70-85% parity |
| Entity attribution | ~20-40% parity |
| Multi-hop tracing | ~10-20% parity (no L3) |
Honest assessment of VerifAML
We do not promise 100% accuracy. That's marketing lie. Reality:
- Sanctions: accurate screening via OFAC + EU. If the address is on a list — you'll know. That's the main thing.
- Scam/mixers: for EVM — coverage ~70-85% via eth-labels and GoPlus (honeypot, blacklist, drainer). For BTC/TRON, scam coverage is currently limited — there are no reliable public bulk lists of scam addresses. We don't know all scam addresses.
- Deep tracing: not done (Phase 3+). For retail scenarios (P2P before a trade) this is overkill.
What this means for you
Don't treat risk score as truth
Score = probability of risk per our data. 0 = "we found no traces," not "the address is definitely clean." 35 = "there are signs," not "the address is definitely dirty."
Use multiple sources
For critical decisions (large trade, OTC) — check the address in 2-3 AML services. If all show high risk — that's a strong signal. If one is high, others low — possibly a false positive.
Check close to the trade moment
AML data changes (retrospective re-scoring). A check a week ago doesn't guarantee relevance. Check minutes before the trade.
Related materials
Transparency about accuracy level is our principle. We don't promise the impossible.