AMLGuard's semantic net catches 98.4% of DeFi laundering addresses
A new hybrid system combines retrieval-augmented LLM reasoning with static rules to infer intent from complex DeFi transactions, achieving near-perfect address recall on real-world laundering cases worth over $1 billion.
In the year of our algorithm, on-chain analytics tools suffer from a peculiar form of blindness: they track token transfers, not intent. A swap, a flash loan, and a liquidity deposit all look like raw opcode sequences to Chainalysis or Elliptic. That gap is exactly where launderers hide. AMLGuard, a new system from a team of researchers, closes it by combining retrieval-augmented LLM reasoning with static rule-based analysis to infer the semantics of complex DeFi transactions [^claim_2580]. The result is a tracking system that catches 98.4% of laundering addresses on single-chain datasets and 95.8% cross-chain [^claim_2584][^claim_2585].
Existing anti-money laundering methods for DeFi rely heavily on low-level token transfers or protocol-agnostic money flow analysis, failing to capture high-level transaction intent [^claim_2579]. AMLGuard solves this by first parsing transaction parameters — especially for cross-chain transactions where laundering intent is not explicitly exposed — and performing argument parsing to recover cross-chain semantics [^claim_2581]. Each transaction is then abstracted into a DeFi Semantic Unit (DSU) based on inferred semantics [^claim_2582]. This abstraction compresses complex multi-hop laundering chains into graph primitives, making fund-flow topology reconstruction computationally cheap.
The system was evaluated on 82 real-world laundering cases involving illicit assets worth over $1 billion [^claim_2583]. On single-chain datasets, AMLGuard achieves destination precision of 94.4%, address recall of 98.4%, and destination recall of 94.1% [^claim_2584]. On cross-chain datasets, destination precision is 87.6%, address recall 95.8%, and destination recall 93.8% [^claim_2585]. The cross-chain precision drop of roughly 7 points quantifies the remaining gap — one that cross-chain messaging protocols like LayerZero or Chainlink CCIP could close by standardizing argument schemas.
For DeFi security, the implications are direct. A compliance-focused blockchain or regulated DeFi protocol can use AMLGuard’s 98.4% address recall as a baseline for Travel Rule compliance — missing fewer than 2% of laundering addresses. Bridge operators and security auditors (e.g., Forta, OpenZeppelin Defender) can adopt DSUs as a standard intermediate representation for threat intelligence feeds, compressing complex laundering flows into graph primitives that are computationally cheaper to analyze at scale. The 82-case benchmark also gives AML/analytics startups like TRM Labs and Merkle Science a ground-truth dataset to validate their own models.
The hybrid LLM+rule approach directly addresses a blind spot in existing tools, and the DSU abstraction provides a compact representation for cross-chain fund-flow reconstruction. Watch for adoption by on-chain compliance platforms and bridge security monitors — and for cross-chain messaging protocols to close the precision gap by standardizing argument schemas.
Provenance ledger
7/7 claims span-verified · SHA-256Every claim below is locked to a verbatim span of its source and re-verified against that source before publish. Citation markers in the text jump here.
[1] Existing anti-money laundering methods for DeFi rely heavily on low-level token transfers or protocol-agnostic money flow analysis, failing to capture high-level transaction intent. span-verified
existing anti-money laundering (AML) methods struggle to cope with the semantic complexity of DeFi transactions. They either rely heavily on low-level token transfers, or perform protocol-agnostic money flow analysis, failing to capture the high-level intent of transactions.
9e0a6ae90b8769cd58021aab45cd6da8fc827edc436deb83a02b4ee33910d46b [2] AMLGuard combines static rule-based analysis with retrieval-augmented large language model (LLM) reasoning to infer implicit DeFi semantics from complex transactions. span-verified
AMLGuard combines static rule-based analysis with retrieval-augmented large language model (LLM) reasoning to infer implicit DeFi semantics, transforming raw transaction data into high-level semantic representations.
b3d870d458f9cf4d2f7f5370cffb7e004516f5a863736eda352cc2cd6c7e5b5a [3] AMLGuard parses transaction parameters and performs argument parsing to recover cross-chain semantics for transactions where laundering intent is not explicitly exposed. span-verified
for cross-chain transactions where laundering intent is not explicitly exposed, AMLGuard parses transaction parameters and performs argument parsing to recover cross-chain semantics, enabling seamless tracking across ledgers.
fcf8172f7384cfd8c40348cc1f63c20e7624d2653ed7035ef9934ea49a98f2ec [4] AMLGuard abstracts each transaction into a DeFi Semantic Unit (DSU) based on inferred semantics. span-verified
Based on the inferred semantics, AMLGuard abstracts each transaction into a DeFi Semantic Unit (DSU).
9183ce7f5f33f22e7ccbc2f6bdee83e83df0b61e6d1b216d092e118797194086 [5] AMLGuard was evaluated on 82 real-world laundering cases involving illicit assets worth over $1 billion. span-verified
We evaluate the effectiveness of AMLGuard on 82 real-world laundering cases, involving illicit assets worth over $1 billion.
2ba79684230c9c57db475f409c80437613371cb123684fae6c3f077a137181d8 [6] On single-chain datasets, AMLGuard achieves destination precision of 94.4%, address recall of 98.4%, and destination recall of 94.1%. span-verified
AMLGuard reconstructs compact illicit fund-flow topologies with destination precision of 94.4% and 87.6%, while achieving the highest address recall of 98.4% and 95.8% and destination recall of 94.1% and 93.8% on single-chain and cross-chain datasets.
a49170aea364c497d9933f36e4769ac5f66e330cb84524a4ff100a8354851168 [7] On cross-chain datasets, AMLGuard achieves destination precision of 87.6%, address recall of 95.8%, and destination recall of 93.8%. span-verified
AMLGuard reconstructs compact illicit fund-flow topologies with destination precision of 94.4% and 87.6%, while achieving the highest address recall of 98.4% and 95.8% and destination recall of 94.1% and 93.8% on single-chain and cross-chain datasets.
a49170aea364c497d9933f36e4769ac5f66e330cb84524a4ff100a8354851168