Frequently asked questions
Answers about AML checks, reports, units and integrations. If your question is not here, contact support.
An AML check shows where the funds on a crypto address or in a transaction came from and scores the risk of accepting them. It finds links to sanctioned addresses, darknet markets, mixers, scams and other risky sources. You get a risk level and a report with the breakdown by source.
Kytme is a marketplace of AML solutions: access to several data providers through one account and one API. You can check an address with a single provider or with several at once for a fuller picture. Checks run in the dashboard, through the API and in the Telegram bot.
You pay per check, with no subscription: buy a package of units and spend them as needed. Larger packages lower the price per unit. The cost also depends on the provider, and the price in units is shown before you confirm.
Units are the balance you pay for checks with. 100 units is roughly one API response with a risk score report for a wallet or a transaction. The exact cost per check depends on the provider and is shown before you confirm.
Sign up and confirm your email to get 100 units on your balance. They can be spent on any address or transaction check, with no card required. Further unit packages are bought in the dashboard.
You can check addresses and transactions on Bitcoin, Ethereum, BNB Smart Chain, Tron, Litecoin, Bitcoin Cash, Zcash, Dash, XRP and Solana. Tokens on those networks are supported as well: USDT and USDC on Ethereum, Tron and BNB Smart Chain, plus DAI, LINK, UNI, WBTC, SHIB, MATIC and WETH. The full list is in the dashboard and in the bot.
Unit balances are topped up in crypto. Card payments are not supported at the moment. Units become available as soon as the payment is credited.
The risk score and the source categories come from the provider that runs the check: we pass the result through unchanged and do not recalculate it. Scores for the same address can therefore differ between providers, because each one has its own database and methodology. Running the check with several providers gives a fuller picture.
These are the three categories of fund sources in a report. Trusted covers transparent sources such as exchanges, mining and payment services. Suspicious covers sources that need attention, including P2P exchange, lending and certain marketplaces. Dangerous covers sanctioned addresses, darknet markets, mixers, scams and stolen funds, and each category shows its share in percent.
The report contains the address or transaction hash, the provider, the check date, the overall risk level and a breakdown of fund sources with percentages. Every category is listed separately: exchanges, mining, mixers, darknet markets, sanctions and the rest. The report opens on the web by link and downloads as a PDF.
Providers recalculate risk continuously: address databases keep growing and the counterparties of an address keep transacting. An address that was clean at the last check can score differently later, for example when a counterparty ends up on a sanctions list. Address monitoring with alerts is available in the dashboard to catch such changes.
A mixer is a service that blends funds from many users to hide their origin. Exposure to a mixer means part of the funds passed through such a service, so the origin of that part cannot be confirmed. Exchanges and payment providers treat these deposits as high risk.
Yes, that is what the report is for. It can be handed to an exchange, a payment provider, a bank or a state authority as evidence of the origin of funds: it states the address, the date, the provider and the full source breakdown. The report is available by link and as a PDF.
A check of an address or a transaction takes seconds. The exact time depends on the provider and on the length of the address history. The result appears where you started the check: in the dashboard, in the API response or in the Telegram bot.
Units are deducted when you receive a risk score and a report. Checks of empty addresses with no transactions are not charged. The cost in units depends on the provider you choose and is shown before you confirm.
All checks are stored in the check log in your dashboard. It shows the date, the address or transaction, the provider and the result, and every report reopens without spending units again. Checks made through the API and in the Telegram bot land in the same log.
Two-factor authentication is enabled in the security section of your dashboard. You need an authenticator app: scan the QR code and confirm the code from the app. After that the code is requested at every sign-in.
Paste the address or transaction hash into the search field and start the check. Pick a provider, with the price in units shown next to it. The risk score and the report appear on the result page, and the report stays in your check log.
Get an API key in your dashboard and send an address or transaction hash to our endpoint: the response returns the risk score and the report data. One key gives access to every connected provider, and the provider is passed as a request parameter. Webhooks are available for monitoring incoming and outgoing transactions.
Yes, in the Telegram bot. Send the check command, pick the asset and the provider, then send the address or hash and the bot returns the risk score with a link to the report. Units are deducted from the same balance and the checks are saved in your log.
Yes, the provider is chosen for every check. You can check an address with one provider or with several and then compare their scores. Providers use different databases, so differing scores are normal, and a second check adds confidence on disputed addresses.
Check the address and keep the report: it shows which share of the funds is linked to risky sources and to which ones exactly. The report can be presented to an exchange, a payment provider or a state authority as evidence of the origin of funds. We do not return funds and do not lift blocks; we provide the document you can rely on.