# Compliance Screening Becomes an Attack Surface

As exchanges automate sanctions screening against public ledgers, third parties keep weaponizing unsolicited transfers to freeze innocent accounts, forcing venues and regulators toward provenance-based rules and making compliance infrastructure itself a target.

- Conviction: 38 / 100 (weakening)
- Horizon: Emerging (watchlist)
- Tracking since: 2026-08-26T00:00:00.000Z
- Last updated: 2026-08-27T14:00:27.996Z
- Canonical: https://polylog.news/crypto/trends/sanctions-screening-attack-surface
- Publisher: Polylog
- Affected regions: United States, Europe

## Recent score history

- 2026-08-27: 38
- 2026-08-28: 43

## Recent evidence

- [confirms] KuCoin Will Screen Transfers That Merely Touched 17 Named Platforms, Including HTX (2026-08-28): KuCoin's policy of restricting wallets over indirect exposure to 17 named venues makes an unsolicited or upstream-tainted transfer sufficient to freeze an account. That widens the surface third parties can weaponize, since the victim need not have transacted with the sanctioned venue at all.
- [confirms] Kraken says 12,000 tiny transfers from HTX-linked wallets triggered its sanctions screening and locked customers out (2026-08-26): Kraken said roughly 12,000 tiny transfers from HTX-linked wallets tripped its automated sanctions screening and locked customers out of their accounts; access was restored but the flagged funds remain frozen, and HTX denies sending the deposits. Dusting at that volume weaponizing an exchange's own compliance automation against its users is the mechanism the thesis predicts, and the funds staying frozen shows venues still lack a provenance rule to unwind it.
