
According to a May 27 report preview from Chainalysis, nearly 47% of organizations onboarded in 2026 now use alerting standards that would have ranked in the top 10% for strictness in 2020. The firm measured alert severity, trigger sensitivity, and minimum dollar floors for indirect illicit exposure to assess compliance improvements. As reported by Chainalysis, standard compliance configurations today would have been considered industry-leading just five years ago, demonstrating how fast baseline compliance has moved since 2020. The industry has been raising its security and compliance in response to stricter regulations and growing threats from hackers, with North Korean-affiliated hackers alone responsible for an estimated $2 billion in crypto losses in 2025.
Despite improved direct monitoring, Chainalysis identified that indirect monitoring remains the main weak spot in crypto compliance. The report draws a clear distinction between direct and indirect exposure, with direct exposure covering funds that come straight from known illicit sources, while indirect exposure covers funds that pass through one or more intermediary wallets before reaching platforms. According to the report, for ransomware, fraud shops, scams, darknet markets, and sanctioned jurisdictions, indirect thresholds often sit 10 to 20 times above direct thresholds, leaving significant gaps for bad actors to move funds through extra wallet layers before detection. The industry's gap between direct and indirect monitoring creates an opening for illicit actors to exploit, with organizations that close this gap improving their regulatory defensibility and differentiating themselves as trustworthy counterparties.
As reported by Chainalysis, traditional financial institutions maintain tighter alerting standards than crypto exchanges across multiple categories. For indirect exposure to non-illicit flows, crypto exchanges set average alerting minimums at $950, compared with $150 for traditional financial institutions. The gap narrows for illicit flows, with crypto exchanges setting alerts for illicit flows from $100, while financial institutions set the floor at $55. This difference matters as more banks test stablecoins, tokenized assets, and crypto custody services. Categories such as ransomware, fraud shops, scams and darknet markets often have indirect thresholds 10 to 20 times higher than their direct equivalents, with legacy financial institutions having lower triggering thresholds for both illicit and non-illicit fund flows.
The findings align with a broader compliance push across the digital asset market, as reported by crypto.news. Polymarket tapped Chainalysis in April to monitor insider trading and manipulation across its prediction markets after volumes reached more than $7 billion monthly. Separate coverage shows rising pressure around cross-chain AML gaps, Binance monitoring duties, stablecoin controls, and North Korean hacking activity. Chainalysis reported that North Korean-linked actors stole more than $2 billion in crypto in 2025, adding urgency to stronger fund-flow monitoring systems across the industry. The data points to an industry in transition, one that has professionalized its approach to direct exposure but which may not yet be treating indirect risk with equivalent rigor.