Bitcoin says every valid UTXO is spendable. Exchanges increasingly disagree. Here’s how to audit your stack for sanctions, hacks, mixers, and other AML exposure — and why nobody can certify that your Bitcoin is truly “clean.”
BJ McCurley left a brilliant comment under my recent article about sanctioned Bitcoin dust.
The article explained a bizarre new risk.
You never asked for it. You never approved it. You may never even notice it.
Yet an automated compliance system can notice. And suddenly perfectly legitimate funds sitting elsewhere in your account can end up under review.
One reader immediately asked the obvious follow-up:
How do I check whether the Bitcoin I already own has any of this “infected” history?
That question sounds simple. It isn’t.
In fact, once you start digging into it, you discover something far more disturbing than a list of AML tools.
There is no universal definition of “clean Bitcoin.”
There is no flag embedded inside a satoshi saying:
SANCTIONED.
There is no blacklist inside Bitcoin Core.
There is no consensus rule distinguishing a bitcoin that once passed through Coinbase from one that once passed through a ransomware wallet.
At the protocol level, Bitcoin does not care. A valid UTXO is a valid UTXO. But regulated financial institutions care enormously.
And they increasingly use proprietary blockchain-surveillance systems to assign something very close to a credit score to your Bitcoin.
That score may influence whether your exchange deposit is accepted. Whether it gets delayed. Whether your account gets reviewed. Whether you receive a source-of-funds request.
Or, in more serious cases, whether the funds become inaccessible while compliance investigates.
The uncomfortable reality is this:
Your Bitcoin can be completely valid according to every Bitcoin node on Earth and still be considered too risky for an exchange.
So yes. You can check your stack.
And after writing the last article, I think serious self-custodians increasingly should understand how.
But there is an enormous catch. You can never know exactly what the exchange will see.
Let’s kill one misconception immediately.
People use words like:
**Dirty Bitcoin.****Tainted coins.****Sanctioned sats.**Infected UTXOs.
They are useful shorthand.
Technically, they are misleading. Bitcoin itself contains no concept of taint.
Suppose you receive 0.1 BTC.
The network checks whether the inputs exist. Whether the signatures are valid. Whether those inputs have already been spent. Whether the transaction obeys consensus rules.
That’s basically the monetary question Bitcoin asks.
It does not ask:
Did these sats pass through a mixer four years ago?
It doesn’t ask:
Was one previous owner sanctioned?
It doesn’t ask:
Did Chainalysis classify the sender as high risk?
Those questions come from outside Bitcoin. They belong to the compliance layer.
And that distinction matters because the same Bitcoin can effectively have different reputations depending on who analyzes it.
Chainalysis describes wallet screening as the process of evaluating a crypto address against blockchain risk data.
That can include connections to sanctioned entities, scams, stolen funds, darknet markets, ransomware and mixers.
Importantly, the analysis isn’t limited to direct transactions.
Screening systems can also measure indirect exposure through intermediary hops and then assign risk according to the strength of that connection.
Think about that for a moment.
You might never transact with a sanctioned entity. The person who paid you might never transact with one either. But coins somewhere further upstream may have passed through infrastructure an analytics company has labeled risky.
Suddenly your perfectly ordinary wallet becomes part of a risk graph.
Arkham describes similar taint-analysis logic: wallets can receive higher or lower risk scores depending on their proximity to known illicit entities, with risk generally decreasing as the number of intermediary hops increases.
This is not Bitcoin consensus. It is probabilistic financial intelligence layered on top of Bitcoin consensus. And regulated exchanges build policies around it.
This is where things get really interesting.
Suppose you enter one of your Bitcoin addresses into several screening platforms.
One might say:
Low Risk.Another:
Medium Risk.Another might reveal mixer exposure. Another might see nothing. Another could associate the address with an entity the others have never labeled.
All of them are looking at the same blockchain.
How can they disagree?
Because blockchain surveillance is not merely reading transactions.
The transaction graph is public. The interpretation of that graph is proprietary.
Different providers have different:
Entity clusters.
Address labels.
Sanctions feeds.
Threat-intelligence teams.
Heuristics.
Mixer detection.
Exposure thresholds.
Risk categories.
Historical datasets.
Confidence models.
Exchange clients can then add yet another layer: their own internal risk policies.
Chainalysis itself says customers configure thresholds and risk rules according to their own regulatory requirements and risk appetite.
That means there is no universal Bitcoin credit bureau. There are multiple bureaus. And they don’t necessarily grade you the same way.
Imagine I run your UTXO through Tool A.Result:
2/100 risk.Great.Then Tool B says:
18/100.Still fine.Tool C identifies indirect exposure to a sanctioned service two transactions back.
Now what? Which one is correct?
Potentially all of them according to their respective models.
More importantly:
Which model does your exchange use?
You probably don’t know.
And even if you know the analytics vendor, you probably don’t know the exchange’s internal thresholds.
This is the core problem.
You can investigate your Bitcoin. You can reduce surprises. You can document provenance.
But you cannot download a universally recognized certificate saying:
Congratulations. These bitcoins are clean.
Such a certificate does not exist.
Let’s do the math. This oil windfall is a rounding error against a $40 trillion debt, guaranteeing the Fed prints another $10 trillion while bondholders lose everything to Gold and Bitcoin.
Quite a lot. You just need to understand what the results mean.
For Bitcoin, you should think in terms of UTXOs, not merely “my balance.”
Your wallet balance might say: 1.247 BTC.
But that balance may consist of ten separate unspent outputs.
Perhaps:
0.05 BTC bought on Kraken.
0.12 BTC from Coinbase.
0.01 BTC from a friend.
0.30 BTC from an old Bisq trade.
0.002 BTC from a Lightning swap.
0.40 BTC transferred from another wallet you owned.
And so on.
Each UTXO can have a different transaction history. That matters.
If you consolidate all of those UTXOs into one transaction, you create a new on-chain relationship between them.
So when auditing your stack, the useful unit is not simply:
Is my wallet clean?It is:
What is the history of each UTXO I may eventually spend or send to a regulated institution?
One of the most accessible options right now is PublicAML.