ConceptioArchivearXiv CS
arXiv CSopen access

Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

arXiv:2607.18869v1 [cs.CR] 21 Jul 2026

HAO WU, Xi’an Jiaotong University and The Hong Kong Polytechnic University, China HAIJUN WANG∗ , Xi’an Jiaotong University, China SHANGWANG LI, Xi’an Jiaotong University, China YIN WU, Xi’an Jiaotong University, China MING FAN, Xi’an Jiaotong University, China TING LIU, Xi’an Jiaotong University, China XIAPU LUO, The Hong Kong Polytechnic University, China With the rapid advancement of decentralized finance (DeFi), security incidents related to cryptocurrency have become increasingly prevalent. After such incidents, attackers typically attempt to rapidly move stolen assets, concealing the origin of illicit funds and ultimately converting them into fiat currency. However, existing anti-money laundering (AML) methods struggle to cope with the semantic complexity of DeFi transactions. They either rely heavily on low-level token transfers, or perform protocol-agnostic money flow analysis, failing to capture the high-level intent of transactions. This limitation results in misleading tracing paths with substantial noise and fails when laundering activities span multiple blockchains. In this paper, we propose AMLGuard, a semantic-aware AML framework for account-based blockchains. AMLGuard tracks illicit fund flows from known malicious addresses by performing semantic analysis on complex DeFi transactions, enabling accurate and continuous laundering tracking. Given a complex transaction, AMLGuard combines static rule-based analysis with retrieval-augmented large language model (LLM) reasoning to infer implicit DeFi semantics, transforming raw transaction data into high-level semantic representations. Furthermore, for cross-chain transactions where laundering intent is not explicitly exposed, AMLGuard parses transaction parameters and performs argument parsing to recover cross-chain semantics, enabling seamless tracking across ledgers. Based on inferred semantics, AMLGuard abstracts each transaction into a DeFi Semantic Unit (DSU). These DSUs are analyzed and composed iteratively to update account states, expand the tracing frontier, and ultimately construct the illicit fund-flow topology. We evaluate the effectiveness of AMLGuard on 82 real-world laundering cases, involving illicit assets worth over $1 billion. Specifically, AMLGuard reconstructs compact illicit fund-flow topologies with destination precision of 94.4% and 87.6%, while achieving the highest address recall of 98.4% and 95.8% and destination recall of 94.1% and 93.8% on single-chain and cross-chain datasets. Furthermore, a case study demonstrates that AMLGuard can assist real-world AML investigation, substantially reducing analysis time and effort. CCS Concepts: • Security and privacy → Software and application security. ∗ Corresponding author

Authors’ Contact Information: Hao Wu, Xi’an Jiaotong University and The Hong Kong Polytechnic University, China, [email protected]; Haijun Wang, Xi’an Jiaotong University, China, [email protected]; Shangwang Li, Xi’an Jiaotong University, China, [email protected]; Yin Wu, Xi’an Jiaotong University, China, [email protected]; Ming Fan, Xi’an Jiaotong University, China, [email protected]; Ting Liu, Xi’an Jiaotong University, China, [email protected]; Xiapu Luo, The Hong Kong Polytechnic University, China, [email protected]. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]. ISSTA ’26, Oakland, California © 2026 Copyright held by the owner/author(s). Publication rights licensed to ACM. ACM ISBN XXX-X-XXXX-XXXX-X/2026/10 https://doi.org/XXXXXXX.XXXXXXX , Vol. 1, No. 1, Article . Publication date: July 2026.

2

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Additional Key Words and Phrases: Anti-money Laundering, Transaction Semantic Analysis, Blockchain ACM Reference Format: Hao Wu, Haijun Wang, Shangwang Li, Yin Wu, Ming Fan, Ting Liu, and Xiapu Luo. 2026. Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis. In Proceedings of The ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA ’26), October 03–09, 2026, Oakland, California. ACM, New York, NY, USA, 23 pages. https://doi.org/XXXXXXX.XXXXXXX

1

Introduction

In recent years, blockchain technology has witnessed rapid advancement, laying the foundation for a wide range of decentralized applications. Among these, Decentralized Finance (DeFi) has emerged as a transformative innovation, offering permissionless financial services (e.g., token deposits, lending, and exchanges) without relying on untrusted intermediaries. At the time of writing, DeFi protocols managed a total value of $119 billion in digital assets [22]. However, the inherent openness and pseudonymity of blockchain systems have also made them attractive targets for hackers. In 2025 alone, blockchain-related security incidents led to losses of about $ 3.35 billion [17]. In recent years, a wide range of techniques have been proposed to combat illicit activities on blockchain networks. On the one hand, many researchers have applied program analysis techniques to smart contract code [28, 49, 53, 54, 58, 64], enabling the early detection of code vulnerabilities, while others analyze transaction behaviors, aiming to identify suspicious activities in real time [37, 39, 63, 67]. On the other hand, once an attack has already succeeded and assets have been stolen, the problem fundamentally shifts from detection to incident response, where the core challenge is to trace illicit funds. In practice, after stealing crypto assets, hackers often engage in money laundering (ML), a process aimed at obscuring the origin of illicit assets. This often involves transferring funds through a series of anonymous addresses, interacting with various DeFi protocols, and eventually cashing out through exchanges. At this stage, anti-money laundering (AML) becomes the last and most crucial line of defense against blockchain financial crimes. It plays a crucial role in tracking illicit assets, identifying laundering accounts, and stopping hackers from successfully cashing out. With the introduction of smart contracts, anti-money laundering on account-based blockchains has become significantly more complex. These blockchain networks enable a wide variety of DeFi protocols, giving rise to highly diverse and complex transaction behaviors. In complex DeFi transactions (e.g., aggregator-based token swap), a single external transaction may orchestrate dozens of internal calls across DEX routers and token contracts, resulting in numerous token transfers among multiple addresses. Existing AML approaches [30, 33, 60, 65] largely operate at the level of raw token transfer and fail to capture the high-level semantics of such transactions. As a result, they significantly inflate the tracing space, introduce substantial semantic noise, and produce misleading laundering paths. In practice, public infrastructure contracts (e.g., DEX routers) may be incorrectly identified as laundering participants and recursively traced, diverting attention from truly suspicious entities. This limitation becomes even pronounced in cross-chain laundering scenarios, where existing solutions [32, 34, 68, 71] frequently fail to establish meaningful semantic associations across blockchain, leading to incomplete broken laundering traces. Although existing AML methods have demonstrated certain advancements, they still face three challenges. Challenge 1: Semantic Heterogeneity of DeFi Transactions. In real-world ML scenarios, the behaviors of hacker addresses go far beyond simple token transfers. They frequently interact with a variety of DeFi contracts, each implementing specialized logic for various financial services, inducing highly heterogeneous token movement patterns. Existing methods fail to accurately infer transaction semantics, producing excessive noise and misleading tracing paths. Challenge 2: Implicit Semantics Beyond Deterministic Rules. Many critical DeFi behaviors , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

3

cannot be reliably inferred through deterministic rules alone. Subtle protocol features such as transfer taxes, internal accounting, or multi-stage routing often encode intent implicitly across multiple token movements. Rule-based systems struggle to generalize to such evolving or previously unseen semantics. Challenge 3: Semantic Fragmentation in Cross-chain Laundering. The growing adoption of cross-chain protocols introduces a new dimension of semantic discontinuity. Cross-chain operations inherently span multiple ledgers, yet most decentralized bridges do not expose explicit, verifiable links between source-chain and destination-chain transactions. Existing methods fail to recover the underlying cross-chain intent, leading to broken laundering paths. To address these challenges, we propose AMLGuard, a semantic-aware anti-money laundering framework for account-based blockchains. AMLGuard traces suspicious addresses while transforming raw transaction data into high-level semantic representations that guide accurate and continuous laundering tracking. Given a complex transaction, AMLGuard aims to infer its underlying DeFi semantics, abstracting low-level token transfers into meaningful financial operations that reveal how illicit assets are transformed and where they should be traced next. To address challenge 1, from an account-centric perspective, AMLGuard introduces a unified semantic abstraction of DeFi operations tailored for AML analysis and applies lightweight static rules to identify explicit DeFi behaviors. To handle implicit and protocol-specific behaviors (challenge 2), it further leverages retrieval-augmented LLM reasoning to infer DeFi operations from structurally similar historical patterns. To overcome semantic fragmentation in cross-chain laundering (challenge 3), AMLGuard parses transaction parameters and performs argument parsing to identify the corresponding destination-chain address and transaction to be followed, enabling seamless continuation of the laundering trace across ledgers. Based on the inferred semantics, AMLGuard abstracts each transaction into a DeFi Semantic Unit (DSU), which captures essential DeFi behaviors while filtering out irrelevant execution noise. These DSUs are analyzed and composed iteratively to expand the tracing frontier and construct the illicit money-flow topology. To evaluate the effectiveness of AMLGuard, we curated a dataset of 82 real-world money laundering incidents involving over $ 1 billion in illicit assets, including 63 single-chain (𝐷𝑠 ) and 19 cross-chain (𝐷𝑐 ) cases. On average, AMLGuard traces 299 transactions and 44 labeled addresses per incident on 𝐷𝑠 , and 287 transactions and 74 addresses on 𝐷𝑐 , while achieving high destination precision (94.4% and 87.6%). Despite maintaining compact illicit fund-flow topologies with limited false positives, AMLGuard achieves the highest address recall of 98.4% and 95.8% and destination address recall of 94.1% and 93.8% on two datasets, respectively, outperforming existing methods. Finally, we evaluated the practical benefit of AMLGuard in real-world AML investigation through case studies, showing that it can reduce auditing time and improve the accuracy of laundering tracing. A prototype of AMLGuard, our datasets and experimental results are available online [41]. In summary, the contributions of this paper are as follows: • We propose a semantic-aware anti-money laundering framework AMLGuard capable of accurately analyzing transaction semantics, tracing cross-chain money laundering activities, and producing compact illicit money-flow topology. • To handle complex DeFi transactions, we design a semantic analysis module combining static rules with LLM reasoning to abstract low-level transaction data into high-level DeFi Semantic Units. Furthermore, to support cross-chain laundering, we introduce a cross-chain semantic recovery mechanism that infers cross-chain intent, enabling seamless money laundering trace. • We have conducted a comprehensive evaluation of AMLGuard using 82 real-world AML incidents. The results show that AMLGuard reconstructs compact illicit fund-flow topologies with destination precision of 94.4% and 87.6%, while achieving the highest address recall of 98.4% and 95.8% and destination recall of 94.1% and 93.8% on single-chain and cross-chain datasets. , Vol. 1, No. 1, Article . Publication date: July 2026.

4

2

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Background

In this paper, we focus on blockchain networks running on the Ethereum Virtual Machine (EVM), which adopt an account-based model. In this model, an account typically refers to an entity that holds digital assets like cryptocurrencies or tokens on blockchain networks. Accounts can be categorized into two types: Externally Owned Accounts (EOAs), which are controlled by private keys , and Contract Accounts (CAs), known as smart contracts, which are self-executing programs with predefined logic. There are two types of transaction: external transactions, which are initiated by EOAs, and internal transactions, which are triggered during the execution of smart contracts. 2.1

Decentralized Finance

Decentralized Finance (DeFi) offers a wide range of financial services without relying on centralized intermediaries. DeFi protocols are typically implemented as smart contracts deployed on blockchain platforms. These services are powered by crypto assets, which serve as the medium for value transfer. They can generally be categorized into two types: native tokens (e.g., ETH on Ethereum) and tokens, which are custom assets created and managed through smart contracts. These tokens follow specific token standards that define their functionality and interoperability, e.g., ERC-20 and ERC-721. Decentralized Exchange (DEX) is a peer-to-peer marketplace, which allows users to swap tokens directly from their wallets without intermediaries. For instance, hackers can use Uniswap, one of the most widely used DEXs, to convert illicit tokens (e.g., DAI) into more liquid assets like ETH, facilitating the next stages of money laundering. Beyond exchanges, DeFi protocols also offer lending and staking services. Users can deposit assets as collateral to borrow other tokens or stake funds to earn rewards, mimicking traditional financial mechanisms in a decentralized manner. 2.2

Cross-chain Bridge

Cross-chain bridges can be broadly categorized into centralized (CeFi) and decentralized (DeFi) designs. CeFi bridges rely on custodial EOAs and internal ledgers for accounting, whereas DeFi bridges implement the bridging logic entirely through smart contracts. In this work, we focus on the latter because decentralized bridges typically do not provide a verifiable linkage between source and destination chain transactions, making them a major challenge for AML tracing. A typical DeFi cross-chain bridge consists of three components: the source chain part, the cross-chain layer, and the destination chain part. The source and destination chain parts host smart contracts that manage asset locking and minting, while the cross-chain layer is composed of off-chain relayers responsible for information propagation. With the cross-chain bridge, users can deposit assets on the source chain and withdraw corresponding assets on the destination chain. Here, we use a simplified example to illustrate the workflow of a cross-chain asset transfer: (1) The user invokes the cross-chain bridge contract on the source chain and sends the corresponding assets. The bridge contract locks the assets and emits an event. (2) Off-chain relayers monitor these events, verify the lock operation, and relay the validated message to the destination chain bridge contract. (3) The cross-chain bridge contract on the destination chain verifies the relayed information and releases (or mints) the bridged assets to the user-specified address. 2.3

Anti-money Laundering

The goal of anti-money laundering on blockchain is to track the flow of illicit funds from a designated hack address, construct the illicit fund-flow topology, and determine the final destination of tainted funds. Similar to the three-phase model of money-laundering in traditional finance [14], we define the three stages of the crypto ML process: , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

5

(1) Placement Phase: The attackers execute an exploit and place the stolen funds to attackercontrolled addresses. (2) Layering Phase: During this phase, the illicit assets are moved through a complex series of transfers. Attackers perform multi-hop transfers, interactions with DeFi protocols (e.g., swap, lending, and staking), or movements across cross-chain bridges to obscure the origin of funds and increase laundering complexity. (3) Integration Phase: Eventually, the laundered assets are aggregated into exit services such as CEXs or privacy-enhancing mixers for final cash-out or further obfuscation. In this work, we focus primarily on tracking laundering flows up to these exit services, most notably CEXs, where regulatory collaboration can help freeze illicit funds and trigger off-chain investigations via Know-Your-Customer (KYC) procedures. And tracing funds after entering privacyenhancing mixers is beyond the scope of this study, we provide further discussion in Section 6. 3

Motivating Example

On Oct. 28th, 2021, Cream Finance, a DeFi lending platform on Ethereum, suffered a devastating price manipulation attack, resulting in $130 million losses [19]. A simplified illustration of the hacker’s subsequent money laundering process is shown in Fig. 1. After the exploit, the hacker extracted a portfolio of stolen assets (e.g., ETH, DAI, LRC) and initiated the laundering by distributing the stolen funds to multiple mule addresses. Given the limited fiat liquidity of certain tokens on blockchain networks, these mule addresses utilized various DEXs to convert the stolen tokens into more liquid cryptocurrencies, primarily ETH. The laundering continued through a multi-layer obfuscation process involving 31 addresses across four layers of transfers, culminating in the integration of funds into coin mixers, cross-chain bridges and CEXs. swap

Money Mule

Token Transfer DeFi Operation

Cross Chain

DEX swap

Mule1

Mule

Victim

CEX

Mule2

swap Hacker Victim

…….

…….

Mule

Mule3

swap Mule4

Mule

DEX

……. Tornado.Cash

Mule

Fig. 1. Money Laundering Process of Cream Finance Incident

To concretely illustrate the challenges of on-chain AML, we examine the behaviors of mule addresses and take Money Mule 1 as an example [15], shown in Fig. 1. Upon receiving a large amount of DAI token from the hacker’s primary address, Money Mule 1 invoked the 𝑠𝑤𝑎𝑝_𝑖𝑛𝑡𝑜_𝑠𝑦𝑛𝑡ℎ function of the SynthSwap contract [51]. This operation involved staking approximately 2 million DAI to mint a synthetic asset, represented as a CRV/SS ERC-721 NFT, which served as a proof-ofstake certificate. Next, Money Mule 1 redeemed the synthetic NFT, converting it into renBTC [50] and then interacted with a cross-chain contract, executing a cross-chain transfer that further obfuscated the origin of the stolen assets. Taking the stake transaction as an example, the single external transaction triggered 134 internal transactions and resulted in 9 token transfers across 7 distinct addresses, resulting in highly , Vol. 1, No. 1, Article . Publication date: July 2026.

6

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

complex behaviors. However, from a token-centric perspective, its underlying intent is simply a token exchange. Existing AML methods fail to recognize this high-level semantics and instead treat intermediate token movements as laundering paths, introducing substantial noise and redundant branches. Protocol-agnostic money-flow analysis further risks misclassifying protocol-internal tax or accounting addresses as laundering participants, leading to incorrect traces. This issue is exacerbated when the assets enter cross-chain protocols: the source-chain transaction records only a bridge contract invocation, without any explicit on-chain linkage to the destination-chain transaction, making it difficult for existing methods to continue tracking the laundering flow. This example underscores the importance of transaction semantic analysis in on-chain AML. By abstracting low-level token transfers into high-level DeFi operations, semantic analysis filters protocol-internal noise, correctly captures how illicit assets are transformed, and guides accurate continuation of tracing. Cross-Chain Transfer

Heuristic Signature 0xc7c7f5b3 Matching 0x0000000…….0080 SemanticDestination Chain 0x0000000……..75e8 Parsing

Logic CA Location

...... 0x0000000……..0000

Money Mule

Proxy CA

Logic CA

Tx InputData

Recipient Address

Argument Alignment

4

Methodology

4.1

Overview of AMLGuard Token Flow Graph (TFG) Construction

Hacker Address

Iterative Semantic Refinement

Similar DeFi Operation Retrieval

Inputs Tx

Depth-First Tx Analysis

DeFi Operation Knowledge Base

DSU

Function Signature Matching

Iterative Laundering Tracing

Argument Mapping

Feedback & Revise

Hac Add

Outputs

Rule-based Operation Inference

LLM-based Semantic Inference

Argument Semantic Parsing

DeFi Operation Identification

Implicit DeFi Semantic Inference

Cross-chain Semantic Recovery

Cur Add

Illicit Money Flow Topology

Iterative Loop

Fig. 2. Overview of AMLGuard

Stac Addre

We introduce AMLGuard, an iterative framework to track crypto money laundering through Operation transaction semantic analysis. As shown in Fig.DeFi2,Apps AMLGuard progressively reconstructs illicit DeFi the Operation Knowledge Base Semantic Knowledge Base DeFi Transaction Token Flow Operation money-flow topology by analyzing each transaction and using its inferred to guide Constructionsemantics Analysis …. Graph Semantic subsequent exploration. Starting from a known hacker address, AMLGuard retrieves its transaction Transaction Similar De TFG Txs Tx Signature histories and performs the depth-first tracing process. Operation Pattern Depth-First Token Flow Graph Operation Re Database Matching Traversal (TFG) Construction Specifically, for each transaction, AMLGuard constructs a Token Flow Graph TFG (TFG) to capture Loop Hacker Address Operation Sem token movements. Based on the TFG, from an account-centric perspective, AMLGuard defines a Operation set Txs Pattern Inferenc New Mule Address of well-known DeFi operations and applies static graph search rules toTermination infer explicit DeFiAccount operations. State Condition Update & Transition Loop Stacked To handle implicit and protocol-specific operations, AMLGuard retrieves similar TFG structures DeFi Semantic Current Address Cross-Chain Address Set Parameter DeFi Semantic Unit and their associated semantics from a curated knowledge base, and employs LLM-based reasoning Mapping initial run iterative run AML Parameter Semantic Parameter Ex in a retrieval-augmented (RAG) pipeline to infer the most plausibleQuantitative DeFi operation. TheParsing inferred Analysis & Alignm per-transaction run intent is further validated and, if necessary, refined to ensure semantic correctness. For transactions involving cross-chain interactions, AMLGuard further analyzes transaction parameter and parses argument semantics to identify the corresponding destination-chain address and transaction to be traced. Based on the inferred semantics, AMLGuard abstracts each transaction into a DeFi Semantic Unit (DSU), which captures the essential financial behavior while filtering out low-level DeFi execution Token Flow Graph Operation Similar DeFi (TFG) Construction Knowledge Base Operation noise. These DSUs are iteratively composed toHacker update account states, expand the tracing frontier, Basic Retrieval TFG Feedback DSU Address and ultimately construct the illicit money-flow topology. & Revise Inputs

Tx

LLM-based

Operation Semantic

Correctness

Operation Inference Checker Inference 4.2 DeFi Operation Identification Depth-First Tx Analysis Rule-based Semantic Analysis LLM-based Semantic Analysis Raw blockchain transactions expose execution details but obscure the underlying financial intent, creating a semantic gap between low-level traces and high-level DeFi behaviors. To bridge this gap, AMLGuard performs semantic lifting by modeling token movements as a directed Token Flow Graph (TFG), from which transactions are abstracted into high-level financial behaviors. According

, Vol. 1, No. 1, Article . Publication date: July 2026.

CA1

CA1

Swap Operation

CA3

Raw Data ①Construction

Tx EOA Sender

CA2

CA3

②Semantic Analysis

Tx EOA Sender

CA4

CA4 CA5

CA2

CA5

Cr

initial run

iterative run

Quantitative AML Analysis

per-transaction run

Parameter Semantic Parsing

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

7

to the study [72], only a few DeFi operations span multiple transactions. Therefore, this paper focuses solely on the semantic analysis of single-transaction granularity. 4.2.1 Token Flow Graph Construction. Given a target address, we retrieve all its external transactions from blockchain. For each transaction (termed as tx), we further collect: (1) internal nativetoken transfers triggered during execution, and (2) token transfer events emitted in execution logs, including both ERC20 and ERC721 tokens. For these three types of token transfer actions (i.e., raw tx, internal txs, and token transfer events), we define each such movements as a transfer action, capture the sender, receiver, token, amount, and execution order within the transaction. Definition 4.1 (Transfer Action). A transfer action 𝑇 𝑎 <s, r, t, a, i> denotes that account s transfers the amount a of the token t to account r at time index i. Based on these transfer actions, we construct a Token Flow Graph to model intra-transaction token movements. In the TFG, nodes represent participant accounts, including externally owned accounts (EOAs) and contract accounts (CAs), collectively referred to as participant accounts (PAs). Directed edges encode token transfers between PAs. Multiple edges may exist between the same node pair, differentiated by token type, transfer amount, and execution index.

CA1

CA1

Swap Operation

CA3

Raw Data ①Construction

Tx EOA Sender

CA2

CA3

②Semantic Analysis

Tx EOA Sender

CA4

CA4 CA5

CA2

CA5

Fig. 3. An Example Showing the Workflow of Transaction Semantic Analysis

Definition 4.2 (Token Flow Graph). A token flow graph TFG ::=<V, E>, where V is the set of accounts (including EOAs and CAs), E is the set of directed edges, i.e., E = {𝐸 1, ..., 𝐸𝑚 }, where each 𝐸𝑛 ::=< 𝑇𝑛 .𝑡,𝑇𝑛 .𝑎,𝑇𝑛 .𝑖 >, 𝑇𝑛 ∈ T, T is the set of transfer actions involved in the raw tx. Fig. 3 illustrates a token swap operation from our motivating example. In this example, the tx sender first transfers the tokens to the 𝐶𝐴1 , which subsequently interacts with multiple intermediate contracts. Eventually, the swapped tokens are transferred back to the sender. Such transactions involve multiple token transfers and complex contract interactions, making it difficult to directly trace illicit fund conversions and movements from raw transaction traces. 4.2.2 Rule-based DeFi Operation Identification. To systematically model DeFi operations relevant to anti-money laundering analysis, we conduct an in-depth study of DeFi application types listed on DeFiLlama [22], a widely used DeFi analytics platform. Specifically, we focus the top 15 DeFi application types that collectively account for over 95% of the ecosystem’s Total Value Locked (TVL). Our analysis reveals that, despite their seemingly diverse functionalities and business logics, most DeFi applications exhibit highly similar financial behaviors from a token-flow perspective. Conceptually, they resemble traditional banking systems, aggregating liquidity through deposits, redistributing liquidity via swaps or lending, extracting values through fees or liquidation, and returning assets or profits to users. From an token-centric viewpoint, the seemingly diverse financial behaviors can be distilled into a small set of fundamental interactions with DeFi applications. , Vol. 1, No. 1, Article . Publication date: July 2026.

P

8

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Motivated by this observation, we introduce a unified conceptual abstraction of DeFi operations tailed for the AML analysis. Rather than explicitly modeling user intent, our abstraction characterizes transaction by how tokens are transformed, transferred or exchanged across accounts and contracts. Based on this principle, we define five core DeFi operations that form the foundation for transaction semantic analysis in our system. (1) Approve: the authorization process for token transfers, whereby an account grants another account or contract permission to spend a specified amount of tokens; (2) Transfer: the transfer of native tokens or ERC tokens between accounts, including NFT mint/burn and token distributions such as airdrops; (3) Swap: the exchange of one type of token for another type of token or proof-of-ownership token. Beyond DEXs, it also subsumes liquidiy-related behaviors such as adding or removing liquidity,as well as certain deposit or withdrawal interactions that result in token-type transformation. (4) Deposit: the action of depositing tokens into smart contracts,commonly observed in staking or yield-farming protocols; (5) Withdraw: the retrieval of previously deposited tokens, including reclaiming staked assets or receiving borrowed tokens in lending protocols. Table 1. DeFi Operation Identification Rules and Semantic Units DeFi Operation

Identification Rules

Semantic Units

Approve

𝐴𝑝 (𝑂𝐴𝑜𝑤𝑛𝑒𝑟 , 𝑃𝐴𝑠𝑝𝑒𝑛𝑑𝑒𝑟 , 𝑡 1, 𝑎 1, 𝑖 1 )

𝑂 𝐴𝑝𝑝𝑟𝑜𝑣𝑒 < 𝑂𝐴, 𝑃𝐴, (𝑡 1, 𝑎 1, _ ) , (𝑡 1, 𝑎 1, _ ) >

Transfer

𝑇 𝑎(𝑂𝐴1, 𝑂𝐴2, 𝑡 1, 𝑎 1, 𝑖 1 )

𝑂𝑇 𝑟𝑎𝑛𝑠 𝑓 𝑒𝑟 < 𝑂𝐴1, 𝑂𝐴2, (𝑡 1, 𝑎 1, _ ) , (𝑡 1, 𝑎 1, _ ) >

Swap

𝑇 𝑎(𝑂𝐴, 𝐴𝑖 , 𝑡 1, 𝑎 1, 𝑖 1 ) ∧ 𝑇 𝑎(𝐴𝑖 , 𝐴 𝑗 , 𝑡 2, 𝑎 2, 𝑖 2 ) ∧ ... ∧ 𝑇 𝑎(𝐴𝑘 , 𝑃𝐴, 𝑡𝑛 , 𝑎𝑛 , 𝑖𝑛 )

𝑂𝑠𝑤𝑎𝑝 < 𝑂𝐴, 𝑃𝐴, (𝑡 1, 𝑎 1, _ ) , (𝑡𝑛 , 𝑎𝑛 , _ ) >

Deposit

𝑇 𝑎(𝑂𝐴, 𝐴𝑖 , 𝑡 1, 𝑎 1, 𝑖 1 ) ∧ 𝑇 𝑎(𝐴𝑖 , 𝐴 𝑗 , 𝑡 1, 𝑎 1, 𝑖 2 ) ∧ ... ∧ 𝑇 𝑎(𝐴𝑘 , 𝐶𝐴, 𝑡 1, 𝑎 1, 𝑖𝑛 )

𝑂 𝐷𝑒𝑝𝑜𝑠𝑖𝑡 < 𝑂𝐴, 𝐶𝐴, (𝑡 1, 𝑎 1, _ ) , (𝑡 1, 𝑎 1, _ ) >

Withdraw

𝑇 𝑎(𝐴𝑖 , 𝐴 𝑗 , 𝑡 1, 𝑎 1, 𝑖 1 ) ∧ 𝑇 𝑎(𝐴 𝑗 , 𝐴𝑘 , 𝑡 1, 𝑎 1, 𝑖 2 ) ∧ ... ∧ 𝑇 𝑎(𝐴𝑘 , 𝑂𝐴, 𝑡 1, 𝑎 1, 𝑖𝑛 )

𝑂𝑊 𝑖𝑡ℎ𝑑𝑟𝑎𝑤 < 𝐴𝑖 , 𝑂𝐴, (𝑡 1, 𝑎 1, _ ) , (𝑡 1, 𝑎 1, _ ) >

To infer DeFi operation from the TFG, we design a set of operation-specific graph search procedures over on directed TFG. The algorithm initiates graph traversal from the tx sender, explores token flow paths and matches candidate subgraphs against predefined identification rules, shown in Table 1. We use the swap operation as a representative example. Specifically, we perform a depth-first search (DFS) on the TFG to detect cyclic token-flow paths that originate and end at EOAs, where the token types of the first and the last transfer edges differ. And the time index of the traversed edges must be monotonically increasing. If such a subgraph is detected, it is identified as a swap operation. In practice, the account providing the input tokens and the account receiving the output tokens may differ. To ensure the semantic integrity of the match, the terminal account in the path is either a leaf node or a node whose outgoing edges have already been fully explored during the search. This constraint prevents premature or ambiguous matches and ensures that the inferred subgraph captures a complete semantic unit. As shown in Fig. 3, once a swap operation is inferred, the intermediate token transfers within the rectangular area can be treated as low-level execution details. The essential semantic signal lies in the tokens sent and received by EOAs, which jointly characterize the swap behavior. Accordingly, we abstracts the set of fine-grained transfer action into a single DeFi operation, reducing transaction complexity and providing an interpretable representation for downstream AML tracing. 4.3

Implicit DeFi Semantic Inference

While the rule-based method reliably identifies many standard DeFi operations, a subset of transactions remains challenging to classify. In practice, protocol-internal accounting behaviors–such as fee redistribution or tightly coupled composite operations–often introduce token movements that deviate from canonical patterns. To address such ambiguous cases, we leverage the in-context reasoning ability of LLMs to infer the most plausible DeFi semantics from noisy token-flow structures, enabling robust semantic analysis beyond rigid graph search rules. , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis Inference Prompt Template for DeFi Transaction

Serialization token flow sequence Initiator Address → Addr1(CA) | (DAI, 2000000) Addr1(CA) → Addr2(CA) | (DAI, 2000000) …… Addr4(CA) → Zero Addr | (Synth sUSD, 1996841) Zero Addr → Add4(CA) | (Synth sBTC, 64.85) Zero Addr → Add5(EOA) | (Synth sUSD, 4992) Zero Addr → Initiator Address | (ERC721, ID126…)

Factual Consistency Check  

Logical Consistency Check 

Swap:

9

You are a blockchain analysis expert specialized in semantic understanding of DeFi Similar transactions for Anti-money Laundering analysis. sequence RAG You will receive the full ordered token flow sequence of a single transaction. Based on the [similar token flow sequence] and [inferred DeFi operation], infer the economic intent and DeFi operation type performed by the transaction initiator for [token flow sequence to be tested]. A single transaction may correspond to multiple Tested DeFi DeFi operations. If so, explicitly decompose the transaction sequence Operation 1. Identify what DeFi operation the transaction initiator performed 2. Summarize the core economic meaning of the transaction. 3. Extract the minimal and essential token movement chains (core token flows) that explain the transaction effect. 4. Identify key state changes, including incoming tokens, outgoing tokens, minted tokens, and burned tokens. 5. Determine the direction of the token trace. [similar token flow sequence]: {similar token flow sequence} [inferred DeFi operation]: {defi operation} [token flow sequence to be tested]: {token flow sequence}

For each inferred DeFi operation, the output Must be in the JSON form: { <transaction_summary>: <string>, <tx_type>: <type>, <core_token_flows>: <dict>, • denote the inferred source and destination addresses <trace_direction>: <dict> • denote that account s transfer Feedback } the amount a of the token t to account r at time index i. Deposit:

Withdraw:

Fig. 4. LLM-based DeFi Semantic Inference

4.3.1 Retrieval-Augmented Operation Infernce. We adopt a RAG pipeline to ground LLM-based semantic inference in domain knowledge. The core idea is to expose the LLM to previously analyzed DeFi operations with similar token-flow structures, enabling analogy-driven reasoning. To this end, we construct a DeFi Operation Knowledge Base by serializing TFGs and computing their embeddings for similarity search. During serialization, we normalize address representations by labeling contract types, removing irrelevant identifiers, and replacing token addresses with standardized token symbols, as shown in Fig. 4. For each entry, we curate a concise semantic annotation that summarizes key token state transitions, the DeFi operation, and its implications for subsequent tracing. This results in a structured mapping between token-flow patterns and high-level semantics. The details are shown in Section 5.1. Given a complex TFG to analyze, AMLGuard applies the same serialization and embedding procedure to retrieve the most similar reference operations and their semantic annotations from the knowledge base. These retrieved examples are then incorporated as few-shot demonstrations in a structured prompt that guides the LLM in inferring the DeFi semantics. As illustrated in Fig. 4, the prompt template consists of: (1) inference instructions defining the expected reasoning behavior, (2) the retrieved reference operations alongside the target TFG, and (3) a constrained output schema. Conditioned on these contextual examples, the LLM infers the most plausible DeFi operation or operation composition corresponding to the observed token flow pattern. 4.3.2 Iterative Semantic Validation and Refinement. The inference process is performed iteratively to ensure both robustness and semantic correctness. First, outputs that do not conform to the predefined schema are automatically rejected and regenerated. More importantly, to mitigate hallucinations and enforce semantic reliability, we incorporate an operation correctness check that validates the inferred DeFi semantics against the observed token movements in the TFG. The module enforces two complementary forms of consistency. Factual consistency verifies that the inferred semantic description is grounded in the TFG, ensuring that all claimed core token flows correspond to actual graph edges, and that referenced token symbols and transferred amount are compatible with recorded transfer actions. Logical consistency evaluates whether the inferred operation satisfies a set of operation-specific feasibility constraints, which encode necessary structural and semantic properties of valid DeFi Operation (Fig. 4). Importantly, these , Vol. 1, No. 1, Article . Publication date: July 2026.

10

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

constraints are not intended to uniquely identify or confirm a specific DeFi operation. Instead, they are designed to invalidate implausible or inconsistent inferences produced by the LLM. For example, in a Swap operation, let the inferred core token flow have 𝑜𝑢𝑡_𝑡𝑜𝑘𝑒𝑛 : 𝑡𝑜𝑘 1 , 𝑜𝑢𝑡_𝑎𝑑𝑑𝑟𝑒𝑠𝑠 : 𝑎 1 , and occur at 𝑡𝑖𝑚𝑒_𝑖𝑛𝑑𝑒𝑥 : 𝑖𝑛 . One swap feasibility constraint requires that once address 𝑎 1 receives Token 𝑡 1 as core flow of the swap operation, it must not subsequently act as a sender of token 𝑡𝑜𝑘 1 at any time index 𝑖 > 𝑛. The presence of such post-swap outgoing transfers of token 𝑡𝑜𝑘 1 from address 𝑎 1 violates swap semantics and is flagged as a logical inconsistency, which triggers revision and enables the system to correct erroneous inferences. When a check fails, the module produces concise and structured diagnostics that are fed back into a revision prompt to iteratively refine the inference. The revision prompt follows the same structure as the inference prompt and is therefore omitted for brevity. In this stage, we explicitly instruct the LLM to (1) interpret the reported inconsistencies, and (2) revise its inference accordingly, reusing the same retrieved reference example. To prevent infinite correction loops, a maximum iteration limit is imposed. Overall, the iterative inference-and-verification workflow substantially reduces hallucinations, improves semantic fidelity, and yields more reliable transaction semantics for downstream tracing and state-updating. 4.4

Cross-Chain Semantic Recovery

Although above transaction semantic analysis enables the interpretation of intra-chain behaviors, cross-chain protocols inherently fragment money-flow continuity, introducing blind spots that impede end-to-end laundering tracing. To overcome this limitation, we propose a cross-chain semantic recovery mechanism that reconstructs cross-chain intent from source-chain evidence. Our approach combines two complementary techniques, i.e., 1) matching function signature templates and 2) utilizing argument semantic analysis. In laundering scenarios, attackers typically initiate cross-chain requests on the source chain by transferring assets into protocol-controlled vault contracts. Semantically, such actions correspond to Deposit DeFi operations. We systematically inspect all inferred Deposit transaction semantics and match the invoked contract functions against a curated set of cross-chain function signature templates collected from Chainspot [20], based on their official documentation. Once a signature match is identified, the associated function arguments are decoded to recover essential cross-chain semantics, such as the destination chain and the intended recipient address. In the remainder of this section, we focus on the second technique–argument semantic analysis–and detail how AMLGuard leverages protocol-specific calldata semantics to recover cross-chain intent and enable continuous laundering tracking across heterogeneous blockchains. An example is shown in Fig. 5. Cross-Chain Transfer

Logic CA Location

Heuristic Signature 0xc7c7f5b3 Matching 0x0000000…….0080 SemanticDestination Chain 0x0000000……..75e8 Parsing ...... 0x0000000……..0000

Money Mule

Proxy CA

Logic CA

Tx InputData

Recipient Address

Argument Alignment

Fig. 5. An Example Showing the Workflow of Cross-Chain Semantic Recovery

4.4.1 Function Signature Matching. In cross-chain transactions, the sender typically encodes transaction metadata, such as the destination chain and the recipient address, into the inputdata field. However, inputdata is a raw hexadecimal byte sequence, where the first four bytes specify the , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

11

function selector and the remaining bytes encode arguments, rendering cross-chain semantics opaque at the execution level. To recover these semantics, we first decode the inputdata by resolving the invoked function and its parameter layout. Specifically, we leverage the Web3 library to retrieve the ABIs of the target contract and reconstruct all candidate function signatures. By matching the extracted function selector against these signatures, we precisely determine the invoked function and its associated parameters, thereby exposing the semantic structure of the cross-chain request. In practice, many cross-chain protocols adopt proxy-based architectures, where users interact with proxy contracts rather than the underlying logic contracts that implement cross-chain functionality. As proxy contracts often do not expose the ABI of the delegated logic, direct signature resolution is often feasible. To address this, we implement a proxy resolution mechanism that identifies the underlying logic contracts by inspecting contract storage layouts. AMLGuard supports three widely adopted proxy patterns: EIP-1967 [45], EIP-1967 beacon [45], and EIP-2535 diamond [24]. Once the logic contract is resolved, we retrieve its ABI sets and apply the same signature-matching procedure. This mechanism enables reliable identification of cross-chain function invocations and provides a necessary foundation for subsequent argument semantic analysis. 4.4.2 Argument Semantic Parsing. After resolving the invoked cross-chain function and its ABI, we perform argument semantic parsing to recover cross-chain intent from decoded calldata. Specifically, we align each function argument with its runtime value in the inputdata field according to the ABI-defined type system, producing a strcutured mapping between argument names, types and values. We categorize function arguments into three classes and process them accordingly: (1) Primitive type (e.g., address and uint) are directly mapped to their decoded values. (2) Opaque types include string and bytes. String arguments are analyzed to identify embedded addresses or protocol-specific annotations, while bytes arguments are examined as raw byte sequences to extract candidate EVM addresses or other encoded identifiers. (3) Structured types (e.g., tuples and arrays) are recursively flattened, ensuring that all nested fields are normlized into name-type-value triples. Based on the normalized argument mapping, we perform heuristic semantic parsing to recover key cross-chain intents. Destination chains are inferred when integer values corresponding to known chain identifiers and their argument names contain chain-related keywords (e.g., chain, id). Recipient addresses are identified from address-type fields, or extracted from string and bytes arguments containing valid address patterns whose names also match predefined recipient-related terms. To reduce noise, parameters associated with non-routing roles (e.g., tokens, senders) are excluded. Through semantic parsing, we obtain the destination chain identifier and recipient address encoded in the transaction. These semantics are then used to refine the corresponding Deposit operation and transform it into a Transfer operation, enabling end-to-end tracking. 4.5

Semantic-guided Laundering Tracing

4.5.1 DeFi Semantic Unit Abstraction. Building on the semantic analysis described above, our goal is to distill each transaction into a representation that captures (1) the initiator’s actionable intent, (2) the resulting token-state transitions, and (3) the next-hop direction for laundering-trace expansion. To achieve this, we introduce the DeFi Semantic Unit (DSU), a unified abstraction that standardizes heterogeneous DeFi transactions, serving as the atomic semantic element for laundering tracing. Definition 4.3 (DeFi Semantic Unit). A DeFi Semantic Unit 𝑂𝑇 ::= < S, R, S𝑡 , R𝑡 >, where T represents the type of DeFi operations, S is the logical initiator of the operation, R is the target entity of the operation, and S𝑡 /R𝑡 ::=< 𝑡𝑠 , 𝑎𝑠 , 𝑐𝑠 > 𝑜𝑟 < 𝑡𝑟 , 𝑎𝑟 , 𝑐𝑟 > denotes the token type, amount, and corresponding blockchain associated with the initiator or target (e.g., token approved or transferred). , Vol. 1, No. 1, Article . Publication date: July 2026.

12

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Each DSU encapsulates the intent and effect of a single operation, while abstracting away low-level execution details. First, it enables quantitative analysis of each account involved in the transaction. Second, it determines which entities warrant further tracing and which can be safely pruned. For example, if an account 𝐴 exchanges one token for another and the output token is received by account 𝐵. The resulting swap DSU focuses solely on the token balance changes of 𝐴 and 𝐵. The DEX contract and its auxiliary addresses are excluded from further analysis. For cross-chain transaction, the initial DSU is typically inferred as a Deposit operation on the source chain. After cross-chain semantic recovery, AMLGuard refines this DSU by updating the receiver address and chain attribute, transforming it into a Transfer DSU. This refinement restores semantic continuity across chains and enables end-to-end laundering tracing. This abstraction prunes irrelevant paths and substantially reduces tracking overhead while preserving all laundering-relevant information. Then, AMLGuard parses the token semantics encoded in each DSU and updates the states of all involved accounts accordingly. Given a DSU that encodes token transfer, AMLGuard extracts the sender s and receiver r along with associated token flow information < 𝑡𝑠 , 𝑎𝑠 , 𝑐𝑠 > and < 𝑡𝑟 , 𝑎𝑟 , 𝑐𝑟 >. The Account State for account s and r are then deterministically updated. Specifically, for the sender and receiver, AMLGuard deducts and increases the token amount for the token balance mappings respectively. Meanwhile, the current DSU is appended to the operation history of account, preserving a chronological record of semantically meaningful interactions for each account.

4.5.2 AML Workflow. AMLGuard formulates anti-money laundering as an iterative, semanticguided tracing process. Algorithm 1 summarizes the workflow which takes an initial hacker address and a specified block number as input, and outputs the laundering topology together with the final destinations of illicit asset. The algorithm initializes a stack-based address set 𝑆𝑇𝑎 with the seed hacker address and an empty visited transaction map 𝑉 𝑖𝑠𝑖𝑡𝑒𝑑𝑇 𝑥𝑀𝑎𝑝 to record analyzed transactions for each address (L1-L2). It then performs depth-first traversal over addresses in 𝑆𝑇𝑎 . At each iteration, the address at the top of the stack is selected as the current analysis target ca (L3) and its previously unanalyzed transactions are processed sequentially (L4). Each transaction 𝑡 is semantically analyzed to infer its corresponding DeFi Semantic Unit (DSU) via SemanticAnalyze(t) (L5). If the transaction involves a cross-chain interaction, cross-chain semantic recovery is invoked to reconstruct the transaction intent and the recovered destination-chain and recipient information is incorporated into DSU (L6). The inferred DSU is then used to deterministically update the states of involved accounts (L7) and the transaction is marked as visited to prevent redundant analysis in subsequent iterations (L8). After processing a transaction, AMLGuard evaluates whether the inferred DSU satisfies the forward expansion policy (L9). If the transaction is deemed to propagate illicit funds to a new address, the receiver address encoded in the DSU is pushed onto the stack, and the algorithm immediately shifts focus to the newly discovered address by breaking the inner loop (L10). This depth-first expansion strategy prioritizes continuous tracing of fund flows along suspected laundering paths, enabling AMLGuard to follow the end-to-end movement of illicit assets. When no further expansion is triggered, AMLGuard continues analyzing the remaining transactions of the current address. Once all transactions associated with 𝑐𝑎 have been processed, the address is removed from the stack (L14), and the algorithm resumes from the next address on the stack (L3). The iterative process ends when the address stack becomes empty. Upon termination, it outputs the reconstructed laundering topology, highlighting the final holders of illicit assets and their aggregation at exit services such as centralized exchanges. This semantic-guided workflow enables concise reconstruction of money laundering behaviors while avoiding redundant exploration and execution-level noise. , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

13

Algorithm 1 Semantic-Driven Money Laundering Tracking Input: Seed address ℎ, start block 𝑏𝑛 Output: Illicit money-flow topology 𝐺, Laundering destinations 𝐷𝑒𝑠 1: Initialize address stack 𝑆𝑇𝑎 ← {ℎ} and visited map 𝑉 𝑖𝑠𝑖𝑡𝑒𝑑𝑇 𝑥𝑀𝑎𝑝 ← ∅ 2: while 𝑆𝑇𝑎 ≠ ∅ do 3: 𝑐𝑎 ← 𝑆𝑇𝑎 .𝑝𝑒𝑒𝑘 ( ) 4: for each unanalyzed transaction 𝑡 of 𝑐𝑎 do 5: 𝐷𝑆𝑈 ← 𝑆𝑒𝑚𝑎𝑛𝑡𝑖𝑐𝐴𝑛𝑎𝑙 𝑦𝑧𝑒 (𝑡 ) // Perform Transaction Semantic Analysis 6: 𝐷𝑆𝑈 ← 𝐶𝑟𝑜𝑠𝑠𝐶ℎ𝑎𝑖𝑛𝑅𝑒𝑐𝑜𝑣𝑒𝑟 (𝑡, 𝐷𝑆𝑈 ) // Recover Cross-Chain Transaction Intent 7: Update account states according to 𝐷𝑆𝑈 // Update Account Balance State 8: 𝑉 𝑖𝑠𝑖𝑡𝑒𝑑𝑇 𝑥𝑀𝑎𝑝 [𝑐𝑎] ← 𝑉 𝑖𝑠𝑖𝑡𝑒𝑑𝑇 𝑥𝑀𝑎𝑝 [𝑐𝑎] ∪ 𝑡 // Mark 𝑡 as visited for 𝑐𝑎 9: if 𝐷𝑆𝑈 satisfies expansion policy then 10: 𝑆𝑇𝑎 .𝑝𝑢𝑠ℎ (𝐷𝑆𝑈 .𝑟 ); // Expand Illicit Money Flow Topology 11: break 12: end if 13: end for 14: Pop 𝑐𝑎 if all its transactions are processed 15: end while 16: (𝐺, 𝐷𝑒𝑠 ) ← 𝑃𝑜𝑠𝑡𝐴𝑛𝑎𝑙 𝑦𝑠𝑖𝑠 ( ) // Perform Quantitative Post-Tracing Analysis

5

Evaluation

We aim to address the following research questions: • RQ1. How effective is AMLGuard in tracking money laundering compared to the state-of-the-art methods? • RQ2. What about the efficiency of AMLGuard? • RQ3. What are the effects and contributions of different components of AMLGuard in enhancing the accuracy and completeness of laundering tracking? • RQ4. How helpful is AMLGuard in assisting manual audits for money laundering investigation? 5.1 Experiment Setup Dataset. Due to the lack of publicly available large-scale AML datasets for EVM blockchains, we constructed a comprehensive AML dataset to support research in crypto-native AML domain. Tracing the money laundering process of an attack is often labor-intensive and time-consuming. To accelerate this process, we collect detailed money laundering reports published before June 2025 by five reputable blockchain security firms: CertiK [18], Beosin [9], SlowMist [46], BlockSec [11], and SharkTeam [44]. These reports must include laundering tracing efforts and AML-related insights, providing valuable information for our dataset construction. As a result, we collected 82 security incidents, encompassing seven blockchain networks, e.g., ETH [25], BSC [12], and Arbitrum [7]. We involve three authors of this paper with expertise in blockchain security, each having two years of experience in blockchain security research. For each incident, three authors independently reconstruct the money laundering paths using blockchain explorers [26], guided by the reported clues. To reduce annotation overhead and focus on important laundering paths, transfer paths with negligible value are excluded. The independently reconstructed paths are then jointly consolidated through joint review into a unified laundering trace. During this process, we further leveraged the decompilation provided by blockchain explorers and cross-chain protocol documentation to semantically recover interrupted cross-chain transactions. To evaluate the consistency of the reconstructed laundering traces, we compute Cohen’s Kappa coefficient among the three authors based on their independent annotations. The obtained Kappa score is 𝐾 = 0.9320, indicating a strong agreement among annotators and demonstrating the reliability of our dataset construction , Vol. 1, No. 1, Article . Publication date: July 2026.

14

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

process. As a final verification step, we cross-check the reconstructed paths using MetaSleuth [10], a commercial AML tool developed by BlockSec [11]. While MetaSleuth may miss certain flows and cannot automatically recover complete laundering processes, it provides a reliable reference for cross-checking. Following this procedure, we ultimately obtained 82 high-quality laundering traces, consisting of 63 single-chain datasets (𝐷𝑠 ) and 19 EVM cross-chain datasets (𝐷𝑐 ). DeFi Operation Knowledge Base Construction. To enable implicit DeFi semantic inference, AMLGuard builds a high-quality DeFi Operation Knowledge Base covering DeFi protocols most frequently leveraged in real-world crypto money laundering. Guided by total value locked (TVL) from DeFiLlama [22], we focus on four dominant protocol categories, i.e., DEXs, Cross-chain, staking protocols, and lending protocols, and select five representative EVM-compatible protocols from each category. For each protocol, we first identify its core logic contracts and then randomly sample 100 on-chain business transactions per protocol for manual inspection. Transactions sharing identical function signatures and argument patterns are deduplicated to reduce semantic redundancy. Each transaction is independently analyzed by two authors, extracting its essential semantic features as defined in Section 4.3. Disagreements are resolved through joint discussion with a third author, ensuring annotation consistency and semantic accuracy. This process yields 1,787 unique DeFi transactions with precise semantic labels, spanning common laundering-relevant operations across the four type protocols. Implementation. We implement AMLGuard using over 3K lines of Python code, built on top of the Scrapy crawler framework [2]. Transaction and contract data are retrieved via blockchain explorer APIs [26] and Web3 API [5]. For implicit DeFi semantic inference, AMLGuard adopts GPT-4o from OpenAI [42] as the default large language model. In the RAG pipeline, semantic similarities are computed using the text-embedding-3-small model, with the top-2 most relevant candidates at each step. The maximum number of LLM-based inference refinement iterations is set to three. All experiments were conducted on machines equipped with the Intel(R) Xeon(R) Platinum 8163 CPU and 1TB RAM running Ubuntu 18.04.6 LTS. Evaluation Metrics. We evaluate the effectiveness of money laundering methods from two complementary perspectives. First, Coverage evaluates the ability to capture actual laundering activities and potential under-reporting, quantified by metrics: (1) Recall: the proportion of groundtruth laundering addresses that are successfully traced. (2) Destination Recall: the proportion of ground-truth destination addresses recovered at the end of the laundering trace. Second, Filtering evaluates the effectiveness of excluding irrelevant paths in the AML process. We adopt (1) Destination Precision, defined as the proportion of identified destination addresses that are genuine laundering destinations, to assess the quality of the final tracing results. Directly measuring false positives is impractical, as our ground truth intentionally excludes minor paths and some baseline methods often produce large, noisy graphs with many intermediate nodes. In practice, AML results are presented as tracing graphs that require manual analyst verification, making compact illicit topologies highly desirable. We therefore indirectly quantify potential false positives and over-expansion by metrics: (2) Average AML Nodes per Incident: the average number of addresses in tracing graph per incident. (3) Average Transactions per Incident: the average number of transactions analyzed per incident. 5.2

RQ1: Effectiveness of AMLGuard

To evaluate the effectiveness of AMLGuard, we compare its performance with five state-of-the-art transaction tracing methods that satisfy the following two conditions: 1) open-source availability or ease of replication; 2) suitability for automated large-scale experiments. Consequently, we included TRacer [65], Haircut [40], Poison [40], APPR [4], and XBlockFlow [60] for evaluation. The first four are open-source and tested directly on our datasets: TRacer employs ranking-based relevance , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

15

estimation and supports DeFi swap tracing; Haircut and Poison are taint-based heuristics with proportional and biased propagation respectively; and APPR applies approximate personalized PageRank to bias graph search. Although XBlockFlow is closed-source, we faithfully replicate its approach based on their paper for evaluation. We exclude DenseFlow [33] because it targets a fundamentally different setting: it assumes a pre-constructed laundering graph and focuses on extracting salient subgraphs, rather than tracing illicit flows from a given suspicious address. Thus, we select the above five methods as baselines. Table 2. Tracking Performance Comparison on Datasets 𝐷𝑠 and 𝐷𝑐 among Baselines Method

𝐷𝑠

𝐷𝑐

Re

D-Re

D-Prec

Avg. Tx

Avg. Node

74.5% 72.3% 72.3% 86.5% 93.4%

47.6% 43.9% 37.8% 56.1% 87.7%

88.1%

167K 74K 76K 228K 214

AMLGuard w/o SA 85.2% 80.7% AMLGuard w/o LBSA 94.8% 89.1% AMLGuard 98.4% 94.1%

87.6% 91.7% 94.4%

221 290 299

TRacer Haircut Poison APPR XBlockFlow

Re

D-Re

D-Prec

Avg. Tx

Avg. Node

59K 27K 29.6K 98K 38

9.8% 22.7% 9.8% 18.2% 14.1% 22.7% 14.1% 22.7% 48.5% 60.1%

65.6%

202K 29K 50K 215K 84

65K 14K 21.6K 76K 26

28 55 44

42.3% 56.3% 82.5% 87.8% 95.8% 93.8%

63.4% 81.2% 87.6%

96 174 287

23 36 74

Table 2 summarizes the overall tracing performance. Filtering metrics directly reflect the manual verification cost faced by security analysts. AMLGuard traces on average 299 transactions and 44 labeled nodes per incident on 𝐷𝑠 and 287 transactions and 74 nodes on 𝐷𝑐 , while achieving a destination precision of 94.4% and 87.6%, respectively. Compared to other methods, AMLGuard maintains a compact illicit topology with substantially fewer false positives. Although directly measuring precision for the four heuristic-based baselines is impractical, these methods trace tens of thousands of transactions and nodes per incident. This excessive expansion arises from their inability to correctly interpret DeFi semantics, causing frequent misclassification of benign DeFi contracts as laundering participants and introducing substantial irrelevant noise. Despite keeping the traced topology small, AMLGuard achieves the highest recall (98.4%) and destination recall (94.1%) on 𝐷𝑠 , demonstrating its superior ability to identify laundering participants and trace the final destinations of illicit funds. On the cross-chain laundering dataset 𝐷𝑐 , AMLGuard maintains 95.8% recall and 93.8% destination recall, substantially outperforming the best baseline (48.5% and 60.1%, respectively). This result highlights the critical role of cross-chain semantic recovery in enabling continuous tracing across blockchains. Although XBlockFlow achieves relatively high recall and precision with fewer traced entities on 𝐷𝑠 , its lack of cross-chain semantic recovery leads to inaccurate tracing results on 𝐷𝑐 . To better understand the root causes of false negatives, we manually analyze the incidents where incomplete laundering paths are observed, and summarize the main reasons as follows: 1) In some cases, mule addresses grant approve permissions to centralized exchange (CEX) addresses, which then actively transferred tokens out. However, since AMLGuard currently treats CEX addresses as terminal exit services, it does not trace their subsequent internal operations. This could be improved in the future by incorporating passive token movement analysis. 2) To mitigate path explosion, when AMLGuard encounters addresses that acted as complex intermediaries, involved in multiple overlapping laundering flows, it excludes addresses whose outgoing transfer amount exceeds their incoming transfer amount based on a heuristic algorithm. And upon further inspection, most false positives are also attributed to addresses involved in multiple laundering processed, which complicated the evaluation of their asset states. Overall, these results highlights the ability of , Vol. 1, No. 1, Article . Publication date: July 2026.

16

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

AMLGuard to interpret DeFi transaction semantic and recover cross-chain semantic, which enables precise and reliable anti-money laundering tracing. 5.3

RQ2: Efficiency of AMLGuard

We evaluate the efficiency of AMLGuard by measuring its runtime in laundering path tracing. We report the average analysis time per incident (TPI) as an end-to-end efficiency metric. As shown in Fig. 6, AMLGuard achieves an average analysis time of 476.2 s per incident on 𝐷𝑠 and 399.7 s on 𝐷𝑐 . In comparison, TRacer incurs significantly higher analysis time (501.9 s and 800.5 s), as it lacks accurate DeFi semantic understanding and consequently processes a large number of redundant interactions. Haircut, Poison, and APPR do not conduct semantic analysis. Instead, they rely on the graph-based heuristics algorithm, which leads to faster runtime but at the cost of lower accuracy and higher noise. XBlockFlow applies taint analysis and ignores complex DeFi transactions, which reduces the number of analyzed transactions (Table 2) and leads to lower analysis time.

TPI

600

800.5

(a) TPI (Time per Incident)

(b) TPT (Time per Tx) Ds Dc

501.9

476.2 399.7

400 265.3

200 0

171.0 55.038.8

cer aircut TRa H

127.4 123.6

1.5 0.58

100

TPT (log scale)

800

10 1 10 2

0.004 0.003 0.001 0.0007

10 3

26.828.5

n

o Pois

d R w APP ockFlo LGuar l M B A X

1.61.4

cer

TRa

rcut Hai

0.001 0.0006 0.0007 0.0003

on Pois

d R w APP ockFlo LGuar l M B A X

Fig. 6. Efficiency Comparison on Datasets 𝐷𝑠 and 𝐷𝑐

Compared to baseline methods, AMLGuard performs fine-grained transaction semantic analysis, which introduces additional time overhead. To quantify this overhead, we further evaluate the average analysis time per transaction (TPT). As shown in Fig. 6, AMLGuard spends 1.6 s per transaction on 𝐷𝑠 and 1.4 s on 𝐷𝑐 , which is higher than the baseline methods. This overhead stems from fine-grained DeFi semantic analysis. However, the additional cost is amortized by significantly reducing the total number of transaction analyzed, as shown in Table 2. Overall, AMLGuard strikes a practical balance between tracing capability and computational efficiency, achieving accurate laundering path reconstruction within an acceptable processing time. 5.4

RQ3: Component Contribution and Effect Analysis

5.4.1 Ablation Study. AMLGuard integrates three core components to enable transaction-level semantic analysis. To quantify the contribution of each component, we conduct an ablation study with two system variants. Variant1 (AMLGuard w/o SA) disables the entire semantic analysis pipeline for complex DeFi transactions. Only exit-related operations (e.g., CEX deposits) are explicitly processed, while the remaining tracing logic is unchanged. Variant2 (AMLGuard w/o LBSA) disables only the LLM-based semantic inference module. Transactions that cannot be interpreted by rule-based analysis are skipped without constructing semantic abstractions. The results are summarized in Table 2. On the dataset 𝐷𝑠 , variant1 achieves 85.2% recall and 80.7% destination recall, while on the dataset 𝐷𝑐 , the recall and destination recall drop sharply to 42.3% and 56.3%, respectively. Compared with the full system, this indicates that transaction-level , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

17

semantic analysis is critical for uncovering hidden token transfer behaviors, particularly in crosschain laundering scenarios. In addition, destination precision drops from 94.4% to 87.6% on 𝐷𝑠 , and from 87.6% to 63.4% on 𝐷𝑐 , indicating that insufficient semantic understanding leads to inaccurate destination identification. Variant2 shows a milder but consistent degradation. Recall, destination recall, and destination precision drop to 94.8%, 89.1%, and 91.7% on 𝐷𝑠 , and to 82.5%, 87.8%, and 81.2% on 𝐷𝑐 . This suggests that while rule-based DeFi operation identification can capture common DeFi patterns, LLM-based semantic inference is critical for correctly interpreting complex and evolving DeFi transactions beyond the coverage of static rules. 5.4.2 Effectiveness of LLM-based DeFi Operation Inference. In our constructed AML dataset, approximately 77.1% of transactions are resolved by static rules, while the remaining 22.9% require LLM-based inference to identify implicit DeFi behaviors. Among the transactions requiring LLMbased inference, we find that 69.7% of cases are correctly inferred in the first attempt. The remaining cases are resolved through iterative refinement, with 21.6%, 7.3%, and 1.4% successfully addressed after one, two, and three additional iterations, respectively. These results demonstrate the effectiveness of LLM-based inference in resolving implicit DeFi behaviors within our dataset. However, since the involved protocols may overlap with the knowledge acquired during the inference process, we further evaluate whether LLM-based DeFi operation inference can generalize to previously unseen protocols. We conduct a controlled experiment on previously unseen protocols. For each DeFi operation category, we select three representative protocols excluded from the RAG knowledge base and additionally include 1inch, a large-scale DEX aggregator supporting diverse and composite DeFi interactions. For each selected protocol, we collect all related transactions and randomly sample a total of 200 DeFi transactions, distributed proportionally across protocol types. The ground-truth DeFi operation labels and details are independently annotated by three authors following the same criteria as before. Table 3. Performance of LLM-based DeFi Operation Inference (Metrics: accuracy/time/monetary cost) Metrics Pure w/o Feedback w/o RAG gpt-4o 67.0% / 3.2s / 0.0056$ 83.5% / 4.9s / 0.0059$ 86.5% / 4.8s / 0.0080$ deepseek-v3 71.5% / 3.6s / 0.0054$ 87.0% / 4.8s / 0.0055$ 83.5% / 4.9s / 0.0074$ gemini-2.5-flash 67.0% / 4.3s / 0.0053$ 88.5% / 5.8s / 0.0054$ 85.5% / 5.7s / 0.0085$

Full 97.0% / 5.8s / 0.0074$ 96.5% / 5.6s / 0.0064$ 97.5% / 6.5s / 0.0064$

We evaluate three representative LLMs: gpt-4o, deepseek-v3, and gemini-2.5-flash, under identical settings. For each model, we further compare four inference variants: Pure, which relies solely on the LLM for operation inference; w/o Feedback, which removes the feedback mechanism; w/o RAG, which disables retrieval-augmented context; and Full, which adopts the complete AMLGuard design. In addition to inference accuracy, we also measure the corresponding inference time overhead and monetary cost of different configurations. The results are shown in Table 3. Under the Full configuration, all models achieve over 96% accuracy , with average inference time of 5.8s, 5.6s and 6.5s, and an average monetary cost of approximately $ 0.007 per tx. In practice, both the time and monetary overhead are negligible, as laundering campaigns typical interact with the same protocols repeatedly. Once an operation is inferred, AMLGuard constructs and caches the corresponding operation signature, eliminating redundant LLM invocations for subsequent transactions. Across all three LLMs, the ablation results exhibit consistent trends. Taking gpt-4o as a representative example, the Pure variant, which relies solely on the LLM, achieves only 67% accuracy, indicating that raw transaction data alone is insufficient for reliable semantic inference. Removing the feedback mechanism (w/o Feedback) leads to a substantial drop from the full configuration (97.0% to 83.5%), highlighting the importance of iterative semantic validation in correcting ambiguous or , Vol. 1, No. 1, Article . Publication date: July 2026.

ration Knowledge Base 18

ow

Operation Semantic

Operation Correctness Checker

….

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Feedback

Similar DeFi

+ TFG & Revise Transaction partially inferred operations. Similarly, disabling retrieval-augmented context (w/o RAG) further Similar DeFi to 86.5%, demonstrating LLM-based DeFi accuracy that in-context DeFi examples play a critical role in TFG degrades Pattern Operation Retrieval Inference guiding the LLM toward correctOperation intent interpretation.

Matching

Operation Pattern

Operation Semantic Table 4. Performance DeFi Semanticof Unit Cross-Chain Semantic Recovery Inference Construction

State ansition

Incident From To Tx DeFi Succ Semantic Incident Wault.Finance BSC ETH 3 Unit 3 XKingdom DeFi Semantic Unit QBridge BSC ETH 51 51 Li.Fi Invoked Parameter Paraluni Cross-Chain BSC ETH 5 Tx5 SenecaUSD Function Mapping New Free DAO BSC ETHIdentification 2 2 WooPPV2 emantic Parameter Extraction BSC Token Hub BSC ETH 46 46 Sonne Finance ng & Alignment BSC CirculateBUSD ETH 3 3 UtopiaSphere Chibi Finance Arbitrum ETH 2 2 DeltaPrime Exactly Protocol Optimism ETH 5 5 Clober DEX OKK DEX ETH BSC, Polygon 93 91 Magic Radiant Capital Arbitrum ETH 93 93 Total

From Arbitrum ETH ETH Arbitrum Optimism BSC Arbitrum BASE Arbitum -

To Tx Succ ETH 5 5 Arbitrum 6 3 Arbitrum 15 15 ETH 29 28 ETH, Arbitrum 52 47 ETH 10 4 ETH 2 2 ETH 13 7 ETH 13 13 448 424

5.4.3 Effectiveness of Cross-chain Semantic Recovery. To evaluate the cross-chain semantic recovery capability, we further analyze the cross-chain transactions involved in each incident of the dataset DSU Iterative 𝐷 summarized in Table 4. Overall, AMLGuard successfully recovers 424 out of 448 𝑐 . The results are Argument Operation Extraction Laundering cross-chain transactions, achieving a recovery accuracy of 94.6%. The remaining failures are mainly edge Base & Alignment Tracing Basic caused by proxy-based cross-chain contracts, where the logical contract invoked during analysis Argument Feedback DSU Mapping used at the time of laundering. Outputs & Revise differs the logic contract In future work, we plan to incorporate historical slot-state Argument analysisSemantic to accurately locate the logic contract and improve recovery accuracy. Correctness Checker

5.5

mantic Analysis

Parsing

RQ4: Case Study

Cross-chain Semantic Recovery

Illicit Money Flow

Topology To evaluate how AMLGuard assists auditors in real-world AML investigations, we conduct a comparative user study under three settings: Expert Only, Expert with MetaSleuth [10] and Expert with AMLGuard. In both settings, experts are allowed to use blockchain explorers to assist their investigation. We select two recent real-world incidents as case studies: the Li.Fi incident [8] (July 2024, $11.6 M loss) and the 0xInfini incident [16] (February 2025, $49 M loss). We recruit six auditors with at least two years of auditing experience and extensive expertise in analyzing transaction behaviors. Each incidents is investigated in two rounds under the three experimental settings. Victim

Hacker Cross Chain Mixer Source Chain Money Mule Target Chain Money Mule CEX

Fig. 7. Tracing Visualization for Li.Fi Incident

Under the Expert Only setting, auditors rely solely on blockchain explorers and spend approximately 25 mins (Li.Fi) and 8 mins (0xInfini) manually reconstructing the laundering process. With MetaSleuth assistance, investigation time is reduced to 21 mins and 5 mins, respectively; however, the lack of precise account-state tracking and the inability to support cross-chain tracing still impose , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

19

significant manual effort. In contrast, under the Expert with AMLGuard setting, auditors complete the investigations in just 10 mins and 3 mins, including AMLGuard’s execution time, corresponding to a manual effort reduction of over 60%. Taking the Li.Fi incident as an example, the hacker employed over 100 intermediary addresses for multi-hop fund transfers, involving numerous token swaps and cross-chain transfers. Existing tracing tools fail in this setting, as they neither interpret complex DeFi semantics nor recover cross-chain intent, and thus generate large, noisy transaction graphs that are impractical for manual analysis. The auditor had to manually analyze complex DeFi operations and reconstruct the path step-by-step. In contrast, AMLGuard automatically inferred high-level DeFi semantics, recovers cross-chain transfer intent, and presented an end-to-end flow of the stolen assets. The reconstructed laundering graph by AMLGuard is shown in Fig. 7. The results demonstrate that AMLGuard can effectively support real-world AML investigations by reducing analysis time and effort, thereby enabling regulators to take timely actions. 6

Discussion

Internal Validity. Our ground-truth dataset is constructed based on manual analysis, which may introduce potential inaccuracies. The accuracy of the annotated laundering paths directly impacts the effectiveness of AMLGuard. To mitigate this, we perform double verification of each case and cross-validate the results using MetaSleuth [10]. Furthermore, AMLGuard operates on accountbased blockchains, where token balances are aggregated at the account level. When illicit funds enter an account that holds benign assets, subsequent outgoing transfers cannot be unambiguously attributed to the laundered funds. This limitation stems from the inherent ambiguity of the accountbased execution model rather than the implementation of AMLGuard. External Validity. Our framework focuses on laundering behavior observable on EVM-compatible chains up to known exit services, such as CEXs and coin mixers. In our ground-truth dataset, 66 out of 82 laundering incidents involve partial fund flows into mixers, demonstrating that mixer-related laundering represents a significant portion of real-world cases. However, real-world AML investigations may need to track laundering activities beyond these observable exit services, particularly after funds are routed through mixers. While these behaviors fall outside the scope of this paper, prior research has explored such threats in depth [13, 21, 23, 29, 55]. Importantly, our framework is modular by design and can be extended to incorporate specialized tracking for mixer-based laundering. Scope and Future Directions. While AMLGuard focuses on forward tracing from known illicit sources to identify laundering flows, backward propagation from suspicious addresses or exit services can provide complementary evidence for AML investigations. Through further analysis, we identify backward propagation as a promising yet challenging direction for improving AML investigation. Specifically, two key challenges remain: (1) how to accurately associate destinationchain transactions with their corresponding source-chain activities, especially when internal transactions lack sufficient information; and (2) how to define appropriate stopping criteria for backward tracing, particularly when the tracing process reaches benign entities or victim protocols. Addressing these challenges and developing comprehensive backward propagation techniques represent important directions for future work. In addition, some DeFi operations may span multiple transactions rather than being completed within a single atomic transaction. Such multi-transaction workflows introduce additional challenges for operation inference because their semantics depend on the interactions among multiple intermediate states. However, compared with single-transaction operations, multi-transaction workflows provide weaker atomicity guarantees and expose intermediate states publicly, making them potentially more vulnerable to front-running and MEV attacks. Moreover, in our analysis of real-world laundering cases, we do not observe such complex DeFi operations being exploited in , Vol. 1, No. 1, Article . Publication date: July 2026.

20

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

practice. Therefore, AMLGuard currently focuses on transaction-level DeFi operation inference, while extending the framework to support more complex multi-transaction DeFi workflows remains an interesting direction. 7

Related Work

Crypto-native Anti-Money Laundering. In blockchain systems, pseudonymous accounts and real-world identities are usually unlinked. In the cryptocurrency world, the first publicly available dataset related to ML is the Elliptic dataset [56], which consists of a transaction network formed by Bitcoin transactions, categorized into licit and illicit transactions. Several studies have applied different AML techniques to identify illicit fund flows [1, 3, 38, 52, 56, 62]. Furthermore, many studies have also focused on addressing AML challenges in account-based blockchain platforms [13, 27, 32, 34, 36, 47]. Wu et al. [65] introduce an innovative personalized ranking method for effective transaction tracing on account-based blockchains. And Wu et al. [60] construct the first cryptoasset ML dataset on the Ethereum blockchain platform and conduct a comprehensive analysis for main stages of blockchain ML. Lin et al. [33] design the suspiciousness metric for accounts and transactions based on the traits of ML behavior and trace ML activities by finding dense subgraphs. Transaction Behavior Analysis. Smart contracts execute their functions by interacting with diverse transactions that include different actions and semantics [31, 35, 59]. Recently, many studies have sought to analyze the transaction behaviors of smart contracts to enhance blockchain security [6, 43, 57, 61, 66, 67, 72]. Zhang et al. [69] replay history transactions and record EVM bytecodelevel traces, utilizing some pre-defined rules to detect logic vulnerabilities. DeFiRanger [63] constructs cash flow trees from transaction sequences, lifts the semantics of trees to high-level DeFi actions and employs specific patterns to identify price manipulation. SPCon [37] mines past history transactions of a contract to recover a likely access control model, which can be checked against information policies, identifying access control bugs. DeFiWarder [48] also replays history transactions and performs role mining to infer the semantics of different accounts, detecting abnormal token leakage vulnerabilities. Zhang et al. [70] analyze attacking transactions to extract structured attack patterns and synthesize counterattack smart contracts capable of front-run the attacks. 8

Conclusion

We propose AMLGuard, a semantic-aware anti-money laundering framework that enables tracing of illicit funds on account-based blockchains. Given a complex DeFi transaction, AMLGuard performs transaction semantic analysis to infer its underlying semantics, tracing complex money laundering activities. Evaluation on 82 real-world laundering cases shows that AMLGuard can produce compact illicit fund-flow topologies, while achieving high address recall and precision. 9

Data Availability

Our replication package is available online: https://figshare.com/s/e01b691346bb352701e5. Acknowledgments This work was supported by National Natural Science Foundation of China (62372367, 62232014, 62272377, 62372368), and Shaanxi Province Sanqin Talent Introduction Program. REFERENCES [1] Ismail Alarab, Simant Prakoonwit, and Mohamed Ikbal Nacer. 2020. Competence of graph convolutional networks for anti-money laundering in bitcoin blockchain. In Proceedings of the 2020 5th international conference on machine learning technologies. 23–27. , Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

21

[2] Reem Alshammari, Rwan Alrashed, Atheer Almutiri, Mathail Alwalah, Wadha Al-marrai, Dana Alqahtani, and Amani Alzahrani. 2021. Data extraction based on web scrapy. In Innovations in Bio-Inspired Computing and Applications: Proceedings of the 11th International Conference on Innovations in Bio-Inspired Computing and Applications (IBICA 2020) held during December 16-18, 2020 11. Springer, 506–514. [3] Erik Altman, Jovan Blanuša, Luc Von Niederhäusern, Béni Egressy, Andreea Anghel, and Kubilay Atasu. 2023. Realistic synthetic financial transactions for anti-money laundering models. Advances in Neural Information Processing Systems 36 (2023), 29851–29874. [4] Reid Andersen, Fan Chung, and Kevin Lang. 2006. Local graph partitioning using pagerank vectors. In 2006 47th annual IEEE symposium on foundations of computer science (FOCS’06). IEEE, 475–486. [5] Web3 API. 2026. https://web3py.readthedocs.io/en/stable/web3.main.html. Accessed: January, 2026. [6] Simon Joseph Aquilina, Fran Casino, Mark Vella, Joshua Ellul, and Constantinos Patsakis. 2021. EtherClue: Digital investigation of attacks on Ethereum smart contracts. Blockchain: Research and Applications 2, 4 (2021), 100028. [7] Arbitrum. 2026. Arbitrum. https://arbitrum.io/. Accessed: January, 2026. [8] Beosin. 2024. Li.Fi Incident. https://beosin.com/resources/beosin-trace-analyzes-the-10-million-loss-of-lifi-protocol. Accessed: Januray, 2026. [9] Beosin. 2026. https://beosin.com/. Accessed: January, 2026. [10] BlockSec. 2024. MetaSleuth. https://metasleuth.io/. Accessed: January, 2026. [11] BlockSec. 2026. https://blocksec.com/. Accessed: January, 2026. [12] BSC. 2026. https://www.bnbchain.org/. Accessed: January, 2026. [13] Vitalik Buterin, Jacob Illum, Matthias Nadler, Fabian Schär, and Ameen Soleimani. 2024. Blockchain privacy and regulatory compliance: Towards a practical equilibrium. Blockchain: Research and Applications 5, 1 (2024), 100176. [14] Stefan D Cassella. 2018. Toward a new model of money laundering: Is the “placement, layering, integration” model obsolete? Journal of Money Laundering Control 21, 4 (2018), 494–497. [15] Certik. 2024. Cream Finance Incident Hacker Address. https://etherscan.io/address/ 0x49B9eb77B300014F99b39b35904c2DBc069e428E. Accessed: January, 2026. [16] Certik. 2025. 0xInfini Incident. https://www.certik.com/resources/blog/0xinfini-incident-analysis. Accessed: January, 2026. [17] Certik. 2025. Hack3d: The Web3 Security Report 2025. Accessed: May, 2025. https://www.certik.com/resources/blog/ hack3d-the-web3-security-report-2025 [18] Certik. 2026. https://www.certik.com/. Accessed: Januray, 2026. [19] Certik. 2026. Cream Finance Attack Incident. https://x.com/CreamdotFinance/status/1453455806075006976. Accessed: Januray, 2026. [20] Chainspot. 2025. https://chainspot.io/portal/bridges. Accessed: Januray, 2026. [21] Ravindu De Silva, Wenbo Guo, Nicola Ruaro, Ilya Grishchenko, Christopher Kruegel, and Giovanni Vigna. 2024. {GuideEnricher}: Protecting the Anonymity of Ethereum Mixing Service Users with Deep Reinforcement Learning. In 33rd USENIX Security Symposium (USENIX Security 24). 3549–3566. [22] DefiLlama. 2025. https://defillama.com/. Accessed: Januray, 2026. [23] Hanbiao Du, Zheng Che, Meng Shen, Liehuang Zhu, and Jiankun Hu. 2023. Breaking the anonymity of ethereum mixing services using graph feature learning. IEEE Transactions on Information Forensics and Security 19 (2023), 616–631. [24] Multi-Facet Proxy EIP-2535: Damonds. 2025. https://eips.ethereum.org/EIPS/eip-2535. Accessed: Januray, 2026. [25] Ethereum. 2026. https://ethereum.org/en/. Accessed: January, 2026. [26] Etherscan. 2026. https://etherscan.io/. Accessed: January, 2026. [27] Steven Farrugia, Joshua Ellul, and George Azzopardi. 2020. Detection of illicit accounts over the Ethereum blockchain. Expert Systems with Applications 150 (2020), 113318. [28] Josselin Feist, Gustavo Grieco, and Alex Groce. 2019. Slither: a static analysis framework for smart contracts. In 2019 IEEE/ACM 2nd International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB). IEEE, 8–15. [29] Chris Gilbert and Mercy Gilbert. 2024. Unlocking privacy in blockchain: Exploring zero-knowledge proofs and secure multi-party computation techniques. Available at SSRN 5258791 (2024). [30] Yicheng Huo, Yufeng Hu, Yajin Zhou, Ting Yu, Lei Wu, and Cong Wang. 2025. Shedding light on shadows: Automatically tracing illicit money flows on EVM-compatible blockchains. Proceedings of the ACM on Measurement and Analysis of Computing Systems 9, 3 (2025), 1–35. [31] Ziqiao Kong, Cen Zhang, Maoyi Xie, Ming Hu, Yue Xue, Ye Liu, Haijun Wang, and Yang Liu. 2025. Smart contract fuzzing towards profitable vulnerabilities. Proceedings of the ACM on Software Engineering 2, FSE (2025), 153–175. [32] Dan Lin, Jiajing Wu, Yuxin Su, Ziye Zheng, Yuhong Nan, Qinnan Zhang, Bowen Song, and Zibin Zheng. 2025. Connector: Enhancing the traceability of decentralized bridge applications via automatic cross-chain transaction association. IEEE , Vol. 1, No. 1, Article . Publication date: July 2026.

22

H. Wu, H. Wang, S. Li, Y. Wu, M. Fan, T. Liu, and X. Luo

Transactions on Information Forensics and Security (2025). [33] Dan Lin, Jiajing Wu, Yunmei Yu, Qishuang Fu, Zibin Zheng, and Changlin Yang. 2024. DenseFlow: Spotting cryptocurrency money laundering in ethereum transaction graphs. In Proceedings of the ACM Web Conference 2024. 4429–4438. [34] Dan Lin, Ziye Zheng, Jiajing Wu, Jingjing Yang, Kaixin Lin, Huan Xiao, Bowen Song, and Zibin Zheng. 2025. Track and trace: Automatically uncovering cross-chain transactions in the multi-blockchain ecosystems. IEEE Transactions on Services Computing (2025). [35] Han Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang, Kaixuan Li, Yang Liu, and Yixiang Chen. 2024. Using My Functions Should Follow My Checks: Understanding and Detecting Insecure {OpenZeppelin} Code in Smart Contracts. In 33rd USENIX Security Symposium (USENIX Security 24). 3585–3601. [36] Jiayi Liu, Changchun Yin, Hao Wang, Xiaofei Wu, Dongwan Lan, Lu Zhou, and Chunpeng Ge. 2023. Graph embeddingbased money laundering detection for Ethereum. Electronics 12, 14 (2023), 3180. [37] Ye Liu, Yi Li, Shang-Wei Lin, and Cyrille Artho. 2022. Finding permission bugs in smart contracts with role mining. In Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis. 716–727. [38] Joana Lorenz, Maria Inês Silva, David Aparício, João Tiago Ascensão, and Pedro Bizarro. 2020. Machine learning methods to detect money laundering in the bitcoin blockchain in the presence of label scarcity. In Proceedings of the first ACM international conference on AI in finance. 1–8. [39] Bruno Mazorra, Victor Adan, and Vanesa Daza. 2022. Do not rug on me: Leveraging machine learning techniques for automated scam detection. Mathematics 10, 6 (2022), 949. [40] Malte Möser, Rainer Böhme, and Dominic Breuker. 2014. Towards risk scoring of Bitcoin transactions. In Financial Cryptography and Data Security: FC 2014 Workshops, BITCOIN and WAHC 2014, Christ Church, Barbados, May 7, 2014, Revised Selected Papers 18. Springer, 16–32. [41] The Prototype of AMLGuard. 2026. https://figshare.com/s/e01b691346bb352701e5. Accessed: Januray, 2026. [42] OpenAI. 2026. https://openai.com/. Accessed: Januray, 2026. [43] Bofeng Pan, Natalia Stakhanova, and Zhongwen Zhu. 2024. EtherShield: Time-interval Analysis for Detection of Malicious Behavior on Ethereum. ACM Transactions on Internet Technology 21, 1 (2024), 1–30. [44] SharkTeam. 2026. https://sharkteam.org/. Accessed: January, 2026. [45] EIP-1967: Proxy Storage Slots. 2025. https://eips.ethereum.org/EIPS/eip-1967. Accessed: Januray, 2026. [46] SlowMist. 2026. https://slowmist.com/. Accessed: January, 2026. [47] Jie Song, Sijia Zhang, Pengyi Zhang, Junghoon Park, Yu Gu, and Ge Yu. 2024. Illicit Social Accounts? Anti-Money Laundering for Transactional Blockchains. IEEE Transactions on Information Forensics and Security (2024). [48] Jianzhong Su, Xingwei Lin, Zhiyuan Fang, Zhirong Zhu, Jiachi Chen, Zibin Zheng, Wei Lv, and Jiashui Wang. 2023. Defiwarder: Protecting defi apps from token leaking vulnerabilities. In 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE). IEEE, 1664–1675. [49] Yuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu, Haijun Wang, Zhengzi Xu, Xiaofei Xie, and Yang Liu. 2024. Gptscan: Detecting logic vulnerabilities in smart contracts by combining gpt with program analysis. In Proceedings of the IEEE/ACM 46th international conference on software engineering. 1–13. [50] Redeem Transaction. 2022. https://etherscan.io/tx/0x8d714c2fdcd90eb44b075d34233ead8b97fe6fcf13b2428520b58fd57feba52f. Accessed: January, 2026. [51] Stake Transaction. 2022. https://etherscan.io/tx/0x34eec380808c47d699587eaa904bacb71bfc35d9a0de6cfae6a19b8bac217af6. Accessed: January, 2026. [52] Dylan Vassallo, Vincent Vella, and Joshua Ellul. 2021. Application of gradient boosting algorithms for anti-money laundering in cryptocurrencies. SN Computer Science 2, 3 (2021), 143. [53] Haijun Wang, Yurui Hu, Hao Wu, Dijun Liu, Chenyang Peng, Yin Wu, Ming Fan, and Ting Liu. 2024. Skyeye: Detecting imminent attacks via analyzing adversarial smart contracts. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering. 1570–1582. [54] Haijun Wang, Ye Liu, Yi Li, Shang-Wei Lin, Cyrille Artho, Lei Ma, and Yang Liu. 2020. Oracle-supported dynamic exploit generation for smart contracts. IEEE Transactions on Dependable and Secure Computing 19, 3 (2020), 1795–1809. [55] Zhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou, Lifeng Gao, Pascal Berrang, Benjamin Livshits, and Arthur Gervais. 2023. On how zero-knowledge proof blockchain mixers improve, and worsen user privacy. In Proceedings of the ACM Web Conference 2023. 2022–2032. [56] Mark Weber, Giacomo Domeniconi, Jie Chen, Daniel Karl I Weidele, Claudio Bellei, Tom Robinson, and Charles E Leiserson. 2019. Anti-money laundering in bitcoin: Experimenting with graph convolutional networks for financial forensics. arXiv preprint arXiv:1908.02591. [57] Cong Wu, Jing Chen, Ziming Zhao, Kun He, Guowen Xu, Yueming Wu, Haijun Wang, Hongwei Li, Yang Liu, and Yang Xiang. 2024. Tokenscout: Early detection of ethereum scam tokens via temporal graph learning. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 956–970.

, Vol. 1, No. 1, Article . Publication date: July 2026.

AMLGuard: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis

23

[58] Hao Wu, Haijun Wang, Shangwang Li, Yin Wu, Ming Fan, Wuxia Jin, and Ting Liu. 2025. RPHunter: Unveiling Rug Pull Schemes in Crypto Token via Code-and-Transaction Fusion Analysis. arXiv preprint arXiv:2506.18398 (2025). [59] Hao Wu, Haijun Wang, Shangwang Li, Yin Wu, Ming Fan, Yitao Zhao, and Ting Liu. 2025. Detecting State Manipulation Vulnerabilities in Smart Contracts Using LLM and Static Analysis. In Proceedings of the 16th International Conference on Internetware. 317–320. [60] Jiajing Wu, Dan Lin, Qishuang Fu, Shuo Yang, Ting Chen, Zibin Zheng, and Bowen Song. 2023. Toward understanding asset flows in crypto money laundering through the lenses of Ethereum heists. IEEE Transactions on Information Forensics and Security 19 (2023), 1994–2009. [61] Jiajing Wu, Kaixin Lin, Dan Lin, Bozhao Zhang, Zhiying Wu, and Jianzhong Su. 2025. Safeguarding blockchain ecosystem: Understanding and detecting attack transactions on cross-chain bridges. In Proceedings of the ACM on Web Conference 2025. 4902–4912. [62] Lei Wu, Yufeng Hu, Yajin Zhou, Haoyu Wang, Xiapu Luo, Zhi Wang, Fan Zhang, and Kui Ren. 2021. Towards understanding and demystifying bitcoin mixing services. In Proceedings of the Web Conference 2021. 33–44. [63] Siwei Wu, Zhou Yu, Dabao Wang, Yajin Zhou, Lei Wu, Haoyu Wang, and Xingliang Yuan. 2024. DeFiRanger: Detecting DeFi Price Manipulation Attacks. IEEE Transactions on Dependable and Secure Computing 21, 4 (2024), 4147–4161. [64] Yin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu, Hao Wu, Ming Fan, Ting Liu, and Haijun Wang. 2024. Advscanner: Generating adversarial smart contracts to exploit reentrancy vulnerabilities using llm and static analysis. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering. 1019–1031. [65] Zhiying Wu, Jieli Liu, Jiajing Wu, Zibin Zheng, and Ting Chen. 2023. TRacer: Scalable graph-based transaction tracing for account-based blockchain trading systems. IEEE Transactions on Information Forensics and Security 18 (2023), 2609–2621. [66] Zhiying Wu, Jieli Liu, Jiajing Wu, Zibin Zheng, Xiapu Luo, and Ting Chen. 2023. Know your transactions: Real-time and generic transaction semantic representation on blockchain & web3 ecosystem. In Proceedings of the ACM Web Conference 2023. 1918–1927. [67] Maoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang, Yebo Feng, Haijun Wang, Yue Xue, Hao Zhang, Ye Liu, and Yang Liu. 2024. Defort: Automatic detection and analysis of price manipulation attacks in defi applications. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis. 402–414. [68] Haaroon Yousaf, George Kappos, and Sarah Meiklejohn. 2019. Tracing transactions across cryptocurrency ledgers. In 28th USENIX Security Symposium (USENIX Security 19). 837–850. [69] Mengya Zhang, Xiaokuan Zhang, Yinqian Zhang, and Zhiqiang Lin. 2020. {TXSPECTOR}: Uncovering attacks in ethereum from transactions. In 29th USENIX Security Symposium (USENIX Security 20). 2775–2792. [70] Zhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang, and Kaiyuan Zhang. 2023. Your exploit is mine: Instantly synthesizing counterattack smart contract. In 32nd USENIX Security Symposium (USENIX Security 23). 1757–1774. [71] Zongyang Zhang, Jiayuan Yin, Bin Hu, Ting Gao, Weihan Li, Qianhong Wu, and Jianwei Liu. 2022. CLTracer: A Cross-Ledger Tracing framework based on address relationships. Computers & Security 113 (2022), 102558. [72] Juantao Zhong, Daoyuan Wu, Ye Liu, Maoyi Xie, Yang Liu, Yi Li, and Ning Liu. 2025. Detecting Various DeFi Price Manipulations with LLM Reasoning. In 2025 40th IEEE/ACM International Conference on Automated Software Engineering (ASE). 1781–1793.

, Vol. 1, No. 1, Article . Publication date: July 2026.

Record · ID 386743 · SHA-256 262c914fe5a095b5
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.