
The connection
We ran a backward trace on TRON wallet TF38iTPSe5…fN9xFs and followed its incoming funds. One hop back, the path reaches an address that sits on the U.S. Treasury's OFAC sanctions list. Here is exactly what the engine found:
- Watched wallet: TF38iTPSe5…fN9xFs
- Traced to: an OFAC-sanctioned source TXGHxdYbGy…Q9bhUf
- Chain: TRON
- Distance: 1 hop (a direct funding relationship)
- Largest transfer on the path: up to $4.00M
- Intermediate wallets: none at one hop; deeper relays, if any, are redacted (they can be uninvolved exchanges or victims)
- Sanctioned exposure
- A wallet has sanctioned exposure when its funds can be traced, through one or more transactions, back to an address under sanction (for example an OFAC-designated party). It is a compliance risk flag for the exposed wallet, even when that wallet is not itself sanctioned.
Why a single hop matters
Distance is the whole point of exposure analysis. Funds five or six hops removed from a sanctioned address have usually passed through exchanges, swaps, and ordinary users, so the link is weak. One hop is different. It means the watched wallet received value that came, in a single transfer, from the sanctioned source itself. For a compliance team that is close to the top of the risk ladder, because there is no chain of intermediaries to explain the money away.
The amount matters too. Up to $4.00M moved along this path, so this is not dust or a spam token sent to poison an address. A transfer that size, one hop from a sanctioned party, is the kind of pattern a bank or exchange may screen before funds settle. You can review a supported address with TrustSniffer's wallet-risk checker, or browse known-flagged addresses in the sanctions directory.
What we can — and can't — say
The OFAC designation on the source address is a matter of public record. The exposure of the watched wallet is our own on-chain finding, and we present it as a risk signal, not a verdict. A one-hop connection is not proof that the recipient is a sanctioned actor or knowingly did anything illegal. The receiving address could be an exchange deposit wallet, a service that co-mingles many users, or a victim. What it does mean is that anyone transacting with this wallet should look closer before moving funds.
What to do if a wallet you use is exposed
- Stop and screen it. Do not send to or accept funds from the address until you understand the exposure.
- Check the distance and direction. One hop from a sanctioned source is high risk; many hops through exchanges is usually not.
- Check your counterparties. If you received funds from an exposed wallet, the exposure can carry to you — screen anyone in the path.
- Document it. If you are a business, record the check and your decision; regulators expect a paper trail.
For more first-party TRON forensics, see our trace of $130M through the TRON network behind Iran's sanctioned central-bank wallets and the report on ten USDT addresses frozen on TRON. The aggregate picture lives on the Risk Index.
How TrustSniffer knows this
This finding comes from TrustSniffer's own backward-exposure engine, which starts from a wallet and walks back through its incoming transfers on TRON, hop by hop, checking each source against sanctions and issuer blacklists. The sanctioned source here is matched against the OFAC designation list. Intermediate amounts are shown as an upper bound on the largest single transfer along the path.
Sources
- OFAC sanctions search — U.S. Treasury
- TRON network
- TrustSniffer sanctions directory and wallet-risk checker



