A regulator does not ask, “Did you do KYC?” but rather, “Where did this particular batch of USDT originate six wallet hops ago?” These are two very different questions, and they require two different products, which are almost always purchased from two different vendors – and that is the most costly mistake a compliance budget can make.
The crypto AML market is not one market; it is three markets: forensics (who moved what, provably?), screening (is this wallet dirty right now?), and Travel Rule (can you legally provide your counterparty with your data?). Most vendors listed below are actually excellent at one but merely average at the other two.
The stack
Every VASP ends up building the same four-step pipeline, whether it means to or not – verify the customer, screen the wallet, exchange data with the counterparty, keep a case trail:

By 2026, 85 of 117 monitored jurisdictions enforce Travel Rule law, and the EU removes the usual $1,000 floor entirely for VASP-to-VASP transfers. Step three stopped being optional for anyone touching Europe – regardless of size.
Where the ten sit

Nobody is both cheap and forensically deep at once. That single fact explains why most VASPs run two vendors instead of one. Notabene isn’t even trying to compete on this axis – which is exactly why it works alongside anyone else on the list.
The forensics tier
Chainalysis

Best for: admissible evidence and big cases
Standout: Attribution in Reactor is based mostly on law enforcement experience in the field, and not on public data – 1,500+ entities, 100+ blockchains, approx. 150 DeFi protocols
Price signal: most expensive choice on the list; available for enterprise and customization only
Watch out: DeFi tracing and cross-chain tracing is heuristic-based, not certain
Elliptic

Best for: cross-chain and hop-on-hop-off bridge assessment; compliance assessment for EU/UK exchanges
Standout: “Holistic Screening” looks at 1,100+ networks and 1,130+ bridges as a single graph rather than separate chains
Price signal: enterprise, custom – equal to Chainalysis
Watch out: investigation tools lag behind Reactor for the toughest adversaries
TRM Labs

Best for: rapidly expanding CASPs focusing on automation and flow of stablecoins
Standout: best in terms of attribution on Solana, Tron, Polygon, and flow of USDT/USDC
Price signal: €60,000-150,000 per year for a medium-sized CASP – underpriced relative to competitors
Watch out: fewer EEA regulators compared to Ellipt
Merkle Science

Best for: platforms where there is extensive exposure to altcoins via long-tail, APAC-focused VASPs
Standout: Behavior Rule Engine identifies illicit behaviors prior to transactions being completed
Price signal: only available on a customized basis – there is no standard pricing structure
Watch out: less enterprise presence outside of APAC
Crystal Intelligence

Best for: financial institutions and mid-sized VASPs that seek forensic analysis at reduced costs
Standout: supports 330+ blockchains, risk engine is built to be customizable to reduce false positives; plays a role in developing regulations in the UK and Europe
Price signal: mid-market – a real move down from the top 3
Watch out: smaller law-enforcement data pipeline than Chainalysis or Elliptic
The compliance-ops tier
Sumsub

Best for: VASPs that need a single provider for customer onboarding, AML and Travel Rule
Standout: KYC + sanctions/PEP + monitoring + Travel Rule to 1,800+ VASPs, all in one agreement
Price signal: from $1.35 to $1.85 per verification – simple and cost-effective
Watch out: AML is placed on top of ID verification solution, rather than being a forensic tool
AMLBot

Best for: smaller exchanges, OTC desks, cryptocurrency ATM providers on a budget
Standout: integrates KYC and wallet verification into one API; also provides ad hoc wallet verification for individuals who have had their cryptocurrency stolen
Price signal: the lowest barrier to entry on this list
Watch out: limited data compared to the forensics five – good for compliance yet not sophisticated cases
ComplyAdvantage

Best for: cryptocurrency businesses looking for financial technology-level sanctions/case management
Standout: Category Leader Chartis for sanctions and adverse media screening for 2026
Price signal: subscription pricing model
Watch out: poor blockchain scanning when compared to any KYT tool
Scorechain

Best for: small/medium size VASPs that require compliance with Anti-Money Laundering and Travel Rule requirements
Standout: built-in compatibility with Notabene – don’t need to purchase any additional solutions for Travel Rule compliance
Price signal: moderate, oriented towards Europe
Watch out: limited chain analytics compared to the top five
The Travel Rule specialist
Notabene

Best for: a nearly-complete stack that is just missing Travel Rule
Standout: exchange of information between VASPs, verification of unhosted wallets according to EU standards; integration with Scorechain, more TRM Labs integrations
Price signal: price for connecting one VASP to another, not the price of AML stack
Watch out: no wallet screening nor transaction monitoring functionality – requires KYT vendor too
Which one do you actually need

A shortcut around the feature-by-feature comparison: match your actual constraint to the vendor built around it
Retire this name
CipherTrace is another company that comes up in older compilations. It was bought out by MasterCard in 2021, and as of the beginning of 2024, it was informing its customers about shutting down Armada, Inspector, and Sentry.
One nuance worth keeping straight when you cite this: Mastercard has been explicit that CipherTrace as a company was not shutting down entirely, only those three products – a distinction a Mastercard spokesperson drew directly with Fortune at the time. The shutdown also followed Mastercard’s own decision to pull a CipherTrace expert’s court testimony after questions about the underlying data’s verifiability, which is a separate credibility flag worth knowing if this name comes up in a legal or licensing context rather than just a procurement one.
Where teams get it wrong
- Buying Reactor-grade investigations tooling for a first compliance program that only needed onboarding and Travel Rule.
- Trusting “100+ blockchains supported” without checking whether customers’ actual chains – usually Tron and Solana for stablecoins – get the same depth as Bitcoin and Ethereum.
- Ignoring false misdetection rates until they cost more in blocked real customers than the fines they prevented.
- Assuming the EU’s zero Travel Rule floor doesn’t apply just because a transfer sits under FATF’s usual $1,000 line.
- Treating “the counterparty’s jurisdiction has Travel Rule legislation” as equivalent to “the counterparty is actually supervised on it” – FATF’s 2026 review found only 40% of jurisdictions with a law on the books have taken real enforcement action, so the legal floor and the practical risk floor are not the same line.
What getting it wrong actually costs
None of the vendors above are cheap, but the numbers on the other side of the ledger make the spend look small. Crypto exchanges were the single most-fined category of financial business for AML/CFT failures in 2025, according to research from the Institute for Financial Integrity – more than money transmitters, securities firms, and casinos combined. A few of the individual cases put that in perspective:

- Binance – $4.3 billion in fines by the US DOJ, FinCEN, and OFAC (2023), the biggest corporate crime penalty in crypto history, because of a lack of KYC measures and handling transactions linked to sanctions against certain organizations.
- OKX – $504 million paid to the US Department of Justice (February 2025) due to insufficient KYC screening that allowed billions of suspicious transactions to go through.
- BitMEX – $100 million (2025), an extension of US enforcement pressure on exchanges with historically thin AML programs.
- KuCoin – $19.6 million, the largest domestic crypto AML penalty Canada’s financial intelligence unit (FINTRAC) has ever issued.
- Coinone – $3.5 million from South Korea’s Financial Intelligence Unit (April 2026), for multiple identified AML failures.
The common denominator in almost all of these cases is three consistent deficiencies, in the same sequence: poor KYC practices at onboarding, ineffective transaction monitoring, and a lack of sanctions screening that enabled illicit activity to proceed uninterrupted for months and years until somebody discovered it.
The actual takeaway
It’s rare to find a VASP that uses just one AML service provider – most use two, with forensics-grade choice for wallet risk, along with an AML compliance and operations suite or Notabene for client onboarding and Travel Rule. “Which is better” is not the right question; “what is missing” is.
