If an exchange has frozen your USDT or USDC and support keeps repeating “flagged by our compliance vendor,” you are dealing with one of three companies: Chainalysis, TRM Labs, or Elliptic. These blockchain analytics firms sell risk-scoring software to every major exchange, and their scores are the actual reason your funds are stuck, not a human decision made by the exchange itself. Understanding how the scoring works changes how you fight it.
What these companies actually sell
Exchanges do not manually review every wallet. They pipe every incoming and outgoing transaction through an API call to one of these three vendors, which returns a risk score, usually 0 to 100, plus a category label: “sanctions,” “darknet market,” “mixer,” “stolen funds,” “scam,” or a dozen other tags. If the score crosses a threshold the exchange has configured, usually somewhere between 60 and 85 depending on the exchange’s risk appetite, the transaction gets auto-frozen and routed to a human reviewer, sometimes days or weeks later.
Chainalysis (Reactor and KYT) dominates among US-regulated exchanges and is the tool law enforcement uses, which is why its labels carry the most weight with compliance teams. TRM Labs is common at newer or non-US platforms and leans more aggressive on labeling clustered wallets. Elliptic has strong UK and EU exchange penetration and is more conservative about labeling addresses without a confirmed law-enforcement or sanctions match.
How a wallet actually gets a bad score
The scoring is not about who you are. It is about the transaction graph your wallet sits inside. Three mechanisms drive almost every freeze we see:
- Direct exposure. Your wallet received funds directly from an address the vendor has already tagged (a hacked exchange, a sanctioned address, a known scam wallet). This produces the highest scores and the fastest freezes, often within minutes of the deposit hitting the exchange.
- Indirect exposure through hops. The vendors trace funds through multiple wallet hops, typically 2 to 6 hops depending on the vendor’s settings. If tainted funds passed through three wallets before reaching yours, you can still get flagged, with a lower but still actionable score. This is the mechanism behind most of the “innocent bystander” freezes we handle: someone paid you in USDT for a legitimate service, and their wallet had received funds from a mixer or a scam four transactions earlier.
- Mixer and privacy-tool contact. Any interaction with Tornado Cash, Sinbad, or similar mixing services, even years-old and even a tiny amount, triggers an automatic high-risk tag on the entire downstream cluster of wallets. This is the single most common false-positive trigger we see, because the taint persists indefinitely and spreads to every wallet that ever touched the output.
Why appeals fail (and what actually works)
Most freeze appeals fail because the customer argues intent (“I didn’t know,” “I’m not a criminal”) when the exchange’s compliance team is not evaluating intent. They are evaluating whether they can document, in writing, why the funds are clean enough to release without regulatory exposure to themselves. An appeal that works gives them that documentation directly.
A source-of-funds package that actually moves a case forward includes:
- A written transaction narrative: where each deposit came from, in plain language, matched to invoice numbers, employer records, or a sale listing.
- On-chain proof: the specific transaction hashes showing the path of funds into your wallet, screenshotted and hash-linked so the compliance analyst does not have to trace it themselves.
- Third-party corroboration: if you were paid for freelance work, the client’s confirmation email or invoice. If you sold an asset, the buyer’s confirmation. Exchanges weight third-party statements far higher than your own explanation.
- A direct statement addressing the specific tag the vendor applied, if you can determine it. Some exchanges will tell you the category (“indirect mixer exposure,” “sanctioned entity, 4 hops”) if you ask compliance directly rather than general support. Once you know the tag, you can address that exact allegation instead of guessing.
How long resolution actually takes
Timelines vary by vendor confidence and exchange backlog, based on the cases we track:
- Low-confidence indirect exposure (4+ hops, small amount): 5 to 15 business days once a complete documentation package is submitted, assuming no sanctions match.
- Direct exposure to a known scam or hack wallet: often permanent. Exchanges rarely release funds that touched a hack address directly, regardless of your documentation, because releasing them creates their own regulatory liability. In these cases, the more realistic path is a claim against the counterparty who paid you, not the exchange.
- Sanctions list matches (OFAC SDN, EU consolidated list): these require the exchange’s legal team, not just compliance, and can take 30 to 90 days even for clear false positives, because a license application to OFAC may be required before funds can move.
What to check before you assume you are a victim of a false positive
Not every freeze is unjust. Before spending money on recovery help, pull your own transaction history on a block explorer and trace the last 5 to 10 incoming transactions. If you cannot explain where a deposit came from, or if a counterparty you dealt with disappeared right after paying you, the flag may be accurate even if you personally did nothing wrong. Knowing this before you appeal changes what kind of documentation is worth gathering, and whether the realistic goal is getting your funds released or documenting a fraud claim against whoever sent you the tainted funds in the first place.
For a walkthrough of what happens after Tether specifically blacklists an address, see our piece on what the smart contract actually does, and if the freeze originated from an OTC or P2P trade, our breakdown of the OTC/P2P trap covers the specific documentation exchanges expect in that scenario.