The distinction matters in crypto because blockchain activity can be screened even when a user has not completed a conventional identity-verification process. A service can therefore operate an account-light or no-KYC flow while still applying transaction-level checks.
KYC Identifies the Customer
Personal Identity
KYC can collect and verify personal information such as legal name, date of birth, nationality, residential address, or other identity data. Its purpose is to connect a service relationship to a customer rather than to analyze the blockchain transaction itself.
Documents and Verification
Identity evidence can include government-issued documents, electronic data sources, selfies, or liveness checks. The exact process varies by provider. For the complete definition and flow, see What Is KYC in Crypto?.
Account Context
KYC is commonly associated with onboarding and persistent customer relationships. Verified customer information can later support account ownership checks, due diligence, access controls, or additional review.
KYT Analyzes Transactions
Address History
Transaction screening can evaluate whether an address has prior activity, links to known services, or relationships with other addresses. The quality and interpretation of that information depend on the blockchain and the analytics system used.
Transaction Patterns
KYT can examine transfer size, frequency, routing, repeated counterparties, or patterns across several transactions. A pattern is contextual evidence; it does not by itself prove who controls an address.
Risk Signals
A service can combine blockchain data with internal or external risk indicators. A signal may change how a transaction is handled, but it is not the same thing as a verified identity.
What KYT Can Evaluate
Depending on the service and network, transaction-level analysis can consider:
- Source and destination addresses.
- Transaction history and graph relationships.
- Links to known services, contracts, bridges, or address clusters.
- Unusual routing, rapid movement, or repeated patterns.
- Asset and blockchain network involved.
- Internal order data connected to the transaction.
- Distance from a known or flagged source where the analytics model uses such relationships.
Transaction Screening vs Transaction Monitoring
Screening Individual Transactions or Addresses
Screening usually means checking a particular address, counterparty, or transaction at a specific point in time. A service can screen a deposit address before accepting funds, examine a transaction while processing an order, or review a destination before payout.
Monitoring Activity Over Time
Monitoring looks for patterns across a longer period. It can compare current activity with earlier transactions, expected account behavior, or repeated interactions with categories of services or addresses.
How the Two Can Work Together
A provider can screen a specific transaction and also monitor account activity over time. The exact workflow depends on the product, whether an account exists, and the provider's risk model.
Why Context Matters in KYT
Blockchain data can be rich but ambiguous. An address may interact with exchanges, bridges, smart contracts, aggregators, or many other users over time. A risk signal therefore needs context.
Useful context can include:
- Whether the interaction was direct or several transaction steps away.
- How recent the relevant activity was.
- The size of the transaction compared with the wider address history.
- Whether the address belongs to a known exchange, contract, bridge, or service.
- Whether the same pattern appears repeatedly or only once.
- Whether the service has other account or order information that changes the interpretation.
Different providers can use different data sources, labels, scoring systems, and thresholds, so the same blockchain activity can produce different outcomes.
When KYT Can Affect a No-KYC Flow
| Situation | Possible service response |
|---|---|
| Address or transaction needs screening | Continue automatically, pause, or send for review |
| Risk signals need more context | Request clarification or additional information |
| Service policy requires escalation | Delay, limit, reject, or request further checks |
A no-KYC starting flow does not mean transaction screening is absent. The identity layer and transaction-analysis layer are separate. This is one reason no-KYC should not be interpreted as a guarantee that every transaction will complete without review.
What Can Happen After a KYT Alert?
A transaction-level alert does not produce one universal outcome. Depending on the provider and context, a service may:
- Allow the transaction to continue automatically.
- Send the order for internal manual review.
- Ask for clarification about the transaction.
- Delay or restrict a payout while the case is reviewed.
- Apply a different risk classification.
- Request identity verification if the provider's policy allows it.
A risk alert is therefore an input into a service decision, not a standardized verdict that every provider must handle the same way.
How KYC and KYT Work Together
Where both controls are used, the relationship can be summarized as:
- KYC establishes or verifies customer identity.
- KYT evaluates transaction activity and addresses.
- The provider combines identity context with transaction-level risk signals.
- If the result needs more context, the service can apply additional review under its policies.
- The customer profile or transaction decision can be updated as new information appears.
KYT Does Not Identify a Person by Itself
Transaction screening can analyze blockchain addresses and activity, but a wallet address is not automatically a verified legal identity. Connecting on-chain activity to a person generally requires additional context such as an account record, public disclosure, payment information, or other off-chain evidence.
That distinction is important because transaction tracing and identity attribution are related but separate tasks. The mechanics are covered in Can Crypto Transactions Be Traced?.
KYT vs AML
| Concept | Main focus | Relationship |
|---|---|---|
| KYT | Transaction activity and blockchain risk signals | Can operate as a transaction-focused control within AML |
| AML | Broader financial-crime risk framework | Can include KYC, KYT, monitoring, record keeping, and review controls |
KYT is narrower than AML. AML is the broader financial-crime risk framework; KYT is one transaction-focused control that can operate inside that framework. See KYC vs AML for the wider relationship.
FAQ
What does KYT mean?
KYT commonly means Know Your Transaction. In crypto, the term is used for transaction-level screening or monitoring of addresses, transaction history, patterns, and related risk signals.
How is KYT different from KYC?
KYC focuses on customer identity. KYT focuses on transaction activity. One evaluates the customer relationship; the other evaluates the movement of funds and blockchain-related context.
What is transaction screening?
Transaction screening is a point-in-time check of a transaction, address, or counterparty against risk indicators or other relevant data.
What is transaction monitoring?
Transaction monitoring looks for patterns or changes across activity over time rather than checking only one transaction.
Can KYT trigger additional review?
It can. A provider can use transaction-analysis results as one reason to pause, review, or request more information. The exact response depends on the provider's policies.
Is KYT part of AML?
KYT can be used within a broader AML or risk-control framework, but AML includes many other controls beyond transaction screening.