All posts
Cryptocurrency2026/01/26Updated: By Iven W.

Chainalysis Explained: Blockchain Analytics, KYT & Crypto Compliance

What Chainalysis does: KYT, Address Screening, Reactor, address clustering, attribution, compliance workflows, private-chain limits, and key misconceptions.

Chainalysis is a blockchain-intelligence platform used for crypto transaction monitoring, address screening, investigations, and risk analysis. Its core value is not that it can automatically reveal the person behind every wallet. Instead, it combines observable blockchain activity with clustering, entity attribution, risk categories, and investigative context so compliance and investigation teams can decide what deserves review.

That distinction matters. A blockchain address is pseudonymous. Grouping addresses, linking a group to a named service, and identifying the natural person who used that service are different analytical claims. A Chainalysis alert is also not the same thing as proof that a transaction is illegal.

Key takeaways

  • KYT monitors crypto transactions and generates risk-based alerts.
  • Address Screening evaluates wallet or counterparty exposure before or during a workflow.
  • Reactor is for deeper tracing and investigations.
  • Address clustering is not the same as identity attribution. Good analysis separates those layers.
  • Blockchain analytics supports a compliance program; it does not replace legal obligations, KYC, case review, recordkeeping, or regulatory judgment.

What is Chainalysis?

Chainalysis describes itself as a blockchain data and intelligence platform. Its products are primarily used by organizations that need to interpret crypto activity at a level beyond a block explorer.

A block explorer can show that address A sent an asset to address B. A blockchain-intelligence system tries to add context:

  • Do multiple addresses appear to share common control?
  • Is an address or cluster associated with an exchange, protocol, sanctioned entity, scam, ransomware operation, mixer, or another known category?
  • Is the exposure direct or indirect?
  • Has the risk profile changed since an earlier screening?
  • Does a transaction deserve an alert, enhanced due diligence, or a deeper investigation?

The important phrase is tries to add context. On-chain facts and real-world attribution are not identical.

Chainalysis's current explanation of blockchain analytics describes the process as examining public-blockchain data and applying methods such as graph analysis, clustering, and attribution to produce useful intelligence.

How blockchain analytics turns addresses into compliance context

A useful way to understand the process is as a layered pipeline.

LayerQuestionTypical outputWhat it does not prove by itself
Raw blockchain dataWhat happened on-chain?Transactions, assets, addresses, contracts, timestampsWho a real person is
Structural clusteringWhich addresses appear to share control?Wallet segments or address groupsThe legal identity of the operator
AttributionWhat named service or entity is associated with the group?Exchange, service, protocol, illicit category, other entity labelWhich individual customer made a transaction
Risk analysisWhat exposure or behavior meets configured rules?Risk score, alert, direct/indirect exposureThat a crime or sanctions violation occurred
InvestigationWhat does the wider flow and off-chain context show?Trace, counterparties, evidence record, escalation contextA final legal conclusion without applicable legal process

This layered model is especially important because Chainalysis itself has recently pushed for clearer terminology around structural grouping, attribution, and operator-versus-beneficiary claims. Its 2026 data-quality work warns that collapsing all of those into the word “cluster” can create serious analytical errors.

For more detail, see Chainalysis's current material on address clustering and its 2026 report framework, Defining the Cluster.

What are KYT, Address Screening, and Reactor?

The three products answer different questions in a compliance workflow.

Chainalysis KYT: transaction monitoring

Chainalysis KYT, or Know Your Transaction, is designed to assess incoming and outgoing crypto transfers and generate alerts based on configured risk rules.

A typical use is not “KYT says criminal, therefore block.” It is closer to:

  1. A platform registers or observes a transfer.
  2. KYT evaluates the transaction and relevant counterparties using Chainalysis intelligence.
  3. A configured rule or exposure threshold triggers an alert.
  4. A compliance analyst reviews the alert and available context.
  5. The organization follows its internal policy and applicable reporting, blocking, escalation, or investigation procedures.

KYT therefore belongs to transaction monitoring, not identity verification. KYC asks who the customer is; KYT examines what is happening in the transaction flow.

Address Screening: counterparty risk before deeper review

Address Screening evaluates wallet addresses and, in supported workflows, liquidity-pool exposure. Chainalysis currently describes direct and indirect exposure, configurable risk settings, continuous monitoring, and API or user-interface workflows.

This is useful when an organization needs to ask a narrower question before processing activity: What risk context is associated with this address or its exposure?

The answer still requires interpretation. Direct interaction with a listed address, indirect exposure several steps away, and a generic risk-category connection do not necessarily have the same legal meaning.

Reactor: investigation after a lead or alert

Chainalysis Reactor is the investigation layer. It is designed to trace fund flows, visualize relationships, examine attributed entities, add off-chain context, and document investigative findings.

A useful mental model is:

Address Screening → KYT monitoring → analyst review → Reactor investigation when needed.

That is not a mandatory universal sequence. Organizations can use the products differently, but it clarifies why “Chainalysis” is not one single wallet-risk score.

Can Chainalysis identify who owns a wallet?

Sometimes analytics can connect on-chain activity to a known service or entity, but an address does not reveal a person's legal identity on its own.

Chainalysis distinguishes between several concepts:

  • Structural claim: addresses share common control based on blockchain evidence.
  • Attribution claim: a wallet segment is associated with a named real-world service or entity based on additional evidence.
  • Operator claim: the named entity actually operates the wallet infrastructure rather than merely benefiting from or using it.
  • Customer identity: a specific person is linked to an account or activity through KYC records, legal process, seized records, admissions, or other evidence.

This corrects a common misconception: seeing a transaction touch an attributed exchange cluster does not automatically reveal which exchange customer made it.

It also explains why data quality matters. An incorrect clustering or attribution decision can send a compliance analyst or investigator toward the wrong subject. Chainalysis's 2026 data-quality publications explicitly discuss failure modes and the need to separate deterministic structural claims from attribution evidence.

Can Chainalysis analyze a private blockchain?

The better question is: Can the analyst access the relevant ledger data, and does the tool support that network and transaction model?

Classic blockchain analytics works well on public networks because transaction data is observable. A private or permissioned blockchain can restrict access, which means an outside analytics provider cannot infer hidden ledger activity merely because the system uses blockchain technology.

Some current Chainalysis materials discuss compliance in tokenized and permissioned environments, but that does not mean every private chain is automatically visible. For a private deployment, evaluate:

  • whether the ledger or required transaction data is accessible;
  • whether Chainalysis supports the network, assets, or token standards involved;
  • what information comes from on-chain data versus customer-provided or integrated data;
  • whether clustering and attribution methods that work on a public network are applicable to the private network's architecture.

So the answer to the Bing-style question “private blockchain analysis Chainalysis possible?” is sometimes, with appropriate access and support—not automatically.

How Chainalysis fits into crypto compliance

Blockchain analytics is one control inside a larger risk-based compliance program.

For example, a crypto business may combine:

  • customer onboarding and identity verification;
  • sanctions-list screening;
  • wallet or counterparty screening;
  • transaction monitoring;
  • alert triage and enhanced due diligence;
  • suspicious-activity reporting where required;
  • case management and recordkeeping;
  • legal and regulatory escalation.

This boundary is important because regulators generally do not prescribe “buy one blockchain analytics product and you are compliant.” OFAC states that U.S. persons and covered businesses should use a tailored, risk-based sanctions compliance program and that there is no single solution suitable for every circumstance. See OFAC FAQ 560 and its virtual-currency sanctions compliance guidance.

OFAC also allows exact searches for listed digital-currency addresses, but exact list matching is not the same question as indirect blockchain exposure. A vendor risk alert can add context around indirect exposure; the legal conclusion depends on the applicable sanctions rule and facts.

Does a risk alert mean funds are “tainted” or illegal?

No. “Tainted crypto” is an imprecise phrase that often hides several different questions.

An alert may reflect:

  • direct interaction with a known entity;
  • indirect exposure through one or more intermediaries;
  • interaction with a risk category defined by the organization;
  • a behavioral pattern;
  • a sanctions designation;
  • a newly updated attribution;
  • a policy threshold chosen by the customer.

Those are not interchangeable.

A well-designed workflow should therefore ask:

  1. What exactly triggered the alert?
  2. Is the exposure direct or indirect?
  3. What is the attribution confidence and evidence type?
  4. When did the activity occur relative to any designation or policy change?
  5. What law, regulation, or internal policy applies?
  6. Does the result require monitoring, enhanced due diligence, blocking, reporting, or no action?

The analytics helps answer the factual questions. Compliance personnel and legal rules determine the action.

Chainalysis vs CryptoQuant: different search intents

ChartMini also has a guide to CryptoQuant and on-chain market analysis, but it serves a different purpose.

TopicChainalysisCryptoQuant-style market analytics
Primary userCompliance, investigations, risk, government, institutionsTraders, researchers, market analysts
Core questionWho or what is this activity exposed to, and does it deserve review?What do exchange flows, miner activity, holder behavior, or market metrics suggest?
Typical outputRisk alerts, entity context, tracing, investigation graphCharts, market indicators, on-chain metrics
Main mistake to avoidTreating an alert as proof of illegality or identityTreating an on-chain metric as a guaranteed price signal

Broad crypto market education remains owned by the crypto trading beginner guide. Tax reporting belongs in the crypto tax guide. Airdrop wallet-safety and claim verification belong in the crypto airdrop guide.

What are the main limitations of blockchain analytics?

Coverage is not universal

A provider must support the relevant network, asset, token standard, and transaction structure. Cross-chain activity, new protocols, bridges, privacy-enhancing systems, or non-public ledgers can create visibility gaps.

Attribution can change

Entity labels depend on evidence. New intelligence can improve or change an attribution after the original transaction occurred.

Heuristics have failure modes

A clustering rule that works for ordinary Bitcoin transactions may need safeguards around collaborative transaction structures such as CoinJoin. Different blockchain architectures require different methods.

On-chain evidence is not the whole case

Investigations frequently need exchange records, customer KYC, device or communications evidence, legal process, business records, and other off-chain facts.

Risk settings are policy choices

A compliance team chooses thresholds and categories based on its obligations and risk appetite. Two organizations can receive the same underlying blockchain intelligence and make different policy decisions.

A practical checklist for evaluating blockchain-analytics output

Before treating a label or risk score as decisive, ask:

  • What network and assets are actually covered?
  • Is this a raw on-chain fact, a structural cluster, an attribution, or a risk score?
  • What evidence supports the entity label?
  • Is exposure direct or indirect?
  • What known failure modes apply to the clustering method?
  • Is the result current, or could attribution have changed?
  • What additional KYC or off-chain evidence is needed?
  • Which legal or internal compliance rule turns this fact into an action?

This checklist is more durable than memorizing a vendor's current coverage count or marketing statistic.

What ChartMini can and cannot do here

ChartMini can replay historical cryptocurrency price candles for chart-reading practice. It does not provide blockchain-forensics or compliance functionality.

ChartMini does not:

  • identify or cluster wallet addresses;
  • provide entity attribution;
  • screen sanctions exposure;
  • monitor wallet risk;
  • trace funds across blockchains;
  • reproduce Chainalysis KYT, Address Screening, or Reactor;
  • generate AML, SAR, or regulatory-compliance decisions.

Price replay and blockchain intelligence solve different problems.

Frequently asked questions

What does Chainalysis do?

Chainalysis provides blockchain intelligence, transaction-monitoring, address-screening and investigation tools for organizations such as crypto businesses, financial institutions, regulators and law-enforcement teams. Its products turn supported on-chain activity and attribution data into risk signals and investigative context.

What is the difference between Chainalysis KYT and Reactor?

KYT is designed for ongoing transaction monitoring and risk-based alerts on incoming and outgoing crypto transfers. Reactor is an investigation platform used to trace flows, examine entities and counterparties, and document a deeper investigation after a lead or alert requires review.

Can Chainalysis identify the person behind every crypto wallet?

No. A blockchain address does not contain a legal identity by itself. Blockchain analytics can group addresses using structural evidence and can attach an entity attribution when supported by additional evidence, but clustering, attribution and identifying a specific natural person are different claims.

Can Chainalysis analyze a private blockchain?

Not simply because it is a blockchain. Analytics requires access to the relevant ledger data plus support for the network and transaction model. Classic blockchain intelligence is built around observable on-chain data; a private or permissioned network that is not externally visible requires authorized data access or an appropriate integration.

Does a Chainalysis risk alert prove that a transaction is illegal?

No. A risk alert is an input to a compliance or investigation workflow, not a legal judgment by itself. Organizations set policies and thresholds, review the underlying exposure and context, document decisions, and apply the laws and regulations that govern their activity.

Does ChartMini provide Chainalysis-style blockchain analytics?

No. ChartMini is a historical chart-replay tool for candlestick and price-action practice. It does not screen wallet addresses, attribute blockchain entities, monitor AML or sanctions exposure, trace on-chain funds, or provide Chainalysis KYT or Reactor data.

Source notes

Current source checks for this update:

Educational overview only. Crypto AML, sanctions, reporting, and investigation obligations depend on jurisdiction, business model, transaction facts, and current law.