Skip to main content

August 2026 Product and Blockchain Intelligence Releases

In this edition:

Product releases

Blockchain intelligence releases


Behavioral rules in TRM Transaction Monitoring

Behavioral rules are a new rule type in Transaction Monitoring that flag accounts on aggregate activity patterns to a risk category or entity over a rolling time window, rather than one transaction at a time. For example, you can define a rule that triggers an alert when over $1,000 goes to a gambling service in a 24-hour period.

This release is currently only available for US customers.

How to use

  1. Navigate to Alert rules in Transaction Monitoring

  2. Click on New Rule and select Behavioral Alert

  3. Configure the counterparty category, direction, and threshold


TRM MCP enhancements: TRM Wallet Screening results and behavioral alerts

TRM MCP now connects to Wallet Screening, enabling your agents to analyze and investigate screening results. You can:

  • View recent wallet screening results and drill into the full details for a screened address to analyze what risk indicators triggered and why

  • See how risk has changed over time for a given screened address

  • Understand ownership attribution sources

  • Investigate the onchain transfers behind counterparty risk exposure

  • View all indirect exposure paths for a screened address and trace the intermediary hops connecting the address to a risk category or entity

TRM MCP now also surfaces behavioral alerts alongside transfer alerts, so your AI agent can pull full context and evidence, then dismiss, escalate, or reopen them without leaving the conversation.

This release also adds:

  • TRM MCP availability to EU customers

  • Portfolio balance returned as part of address and entity risk signals

  • Transfer counts and volume over a chosen window (last 30, 60, or 90 days)

  • Entity names on terminus addresses instead of just categories

  • Filtering alerts by destination address, closed date, and closed reason

  • Deeplinks from alert context directly to counterparty profiles in Block Explorer

  • View of Transaction Monitoring alerts for a specific time period (e.g., “How many alerts fired in Q2?”)

  • Ability to filter transaction monitoring alerts by destination address

  • Aggregate view of recent wallet risk exposure over the last 30, 60, or 90 days

  • Follow risk through cross-chain swaps and bridges when tracing an exposure path

How to use

  1. Connect to TRM MCP via your AI agent of choice

  2. Ask to see your recent Wallet Screening results or behavioral alerts

  3. Investigate a specific result with prompts (e.g., "Show me the screening results on this address in the last 30 days")

  4. Ask your agent to trace the exposure path, or to close or escalate an alert and draft the disposition reason


Dark mode theme

The platform now has a full dark theme, giving analysts a lower-light option for long investigation sessions. Dark mode covers investigation modules (Graph Visualizer, Triage, Cases, Deconflict), compliance modules (Transaction Monitoring, Entity Monitoring, Asset Monitoring, Wallet Screening, Entity Screening), and shared UI throughout.

How to use

  1. Use the sun/moon toggle in the app header to switch between light and dark

  2. To set Light, Dark, or System preference, navigate to the Settings tab in Account Profile and set your preference in Appearance


New user and environment management interface

Easily access environment and account settings through a new streamlined user interface.

How to use

  1. Click on your initials in the top right corner

  2. Click on:

    1. Settings - Manage organization and/or environment-level settings based on your role (e.g., user management, Risk Engine, API keys, and the audit log)

    2. My Account - Manage personal settings like AI feature enablement and language

    3. Platform Information - View supported assets and blockchains

We are also simplifying role types to the following:

  • Admins: Manage users and organization and/or environment-level settings

  • Members: View and access products that they hold a license for

We’ve added the ability to create user groups (e.g., segmenting users by region, team, or business line) within an environment to streamline bulk user management.

How to use

  1. Navigate to Settings and click on the Groups tab

  2. Click New group

  3. Add members and set each member's role within the group


Co-Case Agent™ enhancements: custom entity analysis and court-ready reports

Co-Case Agent can now analyze the custom entities you build in Graph Visualizer. Ask about an entity's activity, risk, counterparties, transfers, member addresses, and ownership in plain language, and Co-Case Agent plots supported counterparties and transfers onto your graph while keeping track of which entity you're asking about. Results flag when data is still loading, so you can distinguish a low activity entity from one with no activity. Exposure, attribution, and monitoring on custom entities aren't supported yet, and Co-Case Agent will let you know rather than guessing.

In order to use Co-Case Agent, your admin needs to enable AI features for your environment.

How to use

  1. Open a graph in Graph Visualizer and launch Co-Case Agent

  2. Select or name a custom entity to ask about (e.g., "Summarize this entity's risk and top counterparties")

  3. Co-Case Agent returns the summary, risk, counterparties, transfers, member addresses, or ownership breakdown, and plots supported counterparties or transfers onto your graph when you ask

Ask Co-Case Agent to generate an editable Word document from an off-ramp seizure assessment or any graph investigation. Every export writes an audit-log entry with the user, environment, and time.

How to use

  1. Confirm with your admin that AI features are enabled for your environment

  2. Open a graph investigation or an off-ramp seizure assessment in Graph Visualizer

  3. Use Co-Case Agent to generate the investigation report (formerly Full Graph Narrative)

  4. Export the report as a Word document (.docx)


CSV export for audit logs

Admins can now download the audit log as a CSV at the organization, environment, and group level. The export respects the filters applied to the table, and every download is recorded in the audit log.

How to use

  1. Open Settings and go to the audit log at the organization, environment, or group scope

  2. Apply any filters you need (action, user, date range)

  3. Click Download CSV to save the current view


Litecoin support added for real-time monitoring in Detect

Detect's real-time monitoring, previously limited to Bitcoin, Ethereum, and TRON, now covers Litecoin with the same detector options and alerting.

How to use

  1. Open Detect and create a detector

  2. Paste a Litecoin address and select Litecoin in the chain selector

  3. Set your triggers and save

    1. Receive email alerts when transactions match the parameters in the detector


Recurring counterparty detection for cross-chain swaps

Investigators can now see which counterparty addresses recur across an address's cross-chain swaps directly in the Behavioral Signature side panel. Select a recurring counterparty to plot it on the graph as a single node, instead of tracing through dozens or hundreds of individual swap instances one at a time. Currently, only cross-chain swaps are covered.

How to use

  1. Plot an address in Graph Visualizer

  2. Open the Behavioral Signature side panel by clicking the Cross-chain Swap tag under the address

  3. View the Recurring Counterparties section above the Instances table, listing each counterparty by swap count in descending order

  4. Select a counterparty to plot it to the graph as a single node


Cross-chain swap plotting prompt in Graph Visualizer

When you plot a transfer that contains a cross-chain swap from the transfer table, you are now prompted to plot the full swap or just the underlying transaction. The prompt is on by default and can be turned off in Graph Settings.

How to use

  1. Select one or more rows and plot them from the Graph Visualizer address transfers, entity transfers, or category transfers table

  2. When a selected row contains a cross-chain swap, choose Plot cross-chain swap(s) to show both sides or Plot transaction / Plot transfers to plot the rows as ordinary transactions

  3. To turn the prompt off, go to Graph Settings → General → Cross-chain swap prompt


Balance amount labels for graph nodes

Investigators can toggle on a new tag in Graph Visualizer to see each node's USD balance, so balances across several addresses on the same graph are visible at once instead of needing an investigator to open each address sidebar one at a time.

How to use

  1. Open Graph Settings and navigate to Node Appearance

  2. Turn on Show portfolio value

  3. Select Amount (Threshold stays the default)

  4. Balance amounts render below each node, abbreviated the same way as the entity sidebar


Sort cases by last updated timestamp in Case Management

Case Management now shows each case's last-updated time in the Cases table, My Work, and Case Properties, and investigators can use the field to sort cases. The timestamp updates on any shared case activity, including notes, sharing changes, or edits, so teams juggling multiple cases can see what changed most recently without opening each one individually.

How to use

  1. Open Case Management to see the Last Updated column in the Cases table, My Work, and Case Properties

  2. Click the Last Updated column header to sort cases

  3. Bookmarked cases stay pinned at the top regardless of sort order


New TRM Academy courses

20 new Intel Insights threat modules

These are short, self-paced lessons on how a single typology moves money onchain and what an investigator can and cannot conclude from it. Topics span laundering and infrastructure (mixers, stablecoin laundering, cross-chain bridges, ransomware), fraud and scams (pig butchering, scam compounds, AI-enabled crime), cyber and theft (hacks and exploits, drainer malware), and sanctions and method (A7 Network sanctions evasion, on-chain attribution methods).

AI Fundamentals course

This is a self-paced introduction to how AI actually works — models and inference, prompting, capabilities and limits, and risk and oversight — ending in an applied, scored scenario the learner carries from a first prompt to a defensible finish. It's product-agnostic and requires no TRM platform access.

Updated TRM Advanced Crypto Investigator (TRM-ACI) certification

The TRM Advanced Crypto Investigator (TRM-ACI) certification has been rebuilt around how funds move today. New material covers account abstraction and the Pectra upgrade — including identifying the true sender behind a paymaster-funded transaction — a new NFT section, and a new section on bridges and cross-chain swaps, with Ethereum tracing logic now applied across TRON and Solana. The course runs about 16 hours and ends in a new 55-question exam. Prior ACI holders can now recertify using the refreshed certification as the recert path (accessed from the Store tab in TRM Academy).


Counter Narcotics

New darknet market coverage adds $215M in visibility

TRM added roughly $215M in newly visible narcotics proceeds, a 21% increase and the third consecutive month near $200M. New service heuristics covering marketplace deposit and escrow infrastructure contributed alongside deeper coverage of marketplaces already tracked, and the mix broadened: Western darknet markets added roughly $54M, up from about $12M the previous month.

Why it matters: A materially larger share of darknet-market drug proceeds is now traceable, and coverage holds when a marketplace reorganizes how it moves funds rather than decaying between rebuilds.

New fentanyl-linked attribution across the supply chain

TRM added $349M in newly attributed fentanyl-linked activity, driven almost entirely by retrospective attribution of laundering infrastructure that carries years of prior transaction history.

Why it matters: More of the fentanyl economy is traceable, with attribution reaching back across the full history of the networks moving the proceeds.


Facilitation and Money Laundering

Daily attributed illicit volume up 40%

TRM increased daily attributed illicit volume by 40% month-over-month. The gain reflects both new entity attribution and deeper coverage of services already tracked.

Why it matters: A larger share of illicit flow is visible and attributable on any given day, raising the odds that suspicious activity surfaces during screening and monitoring rather than being reconstructed after the fact.

New payment service deposit-address coverage

A new deposit-address heuristic for a payment service reached production, adding roughly 103,000 previously unlabeled deposit addresses.

Why it matters: Deposits routed through the service are now attributable rather than appearing unlabeled.

New cross-chain swap service attributed

TRM attributed a cross-chain swap service with almost no public footprint, with attribution now covering $130.6M in volume through its main Ethereum contract along with its Bitcoin deposit infrastructure. The service sits behind several mainstream wallet and swap interfaces, so funds routed through it were not obviously identifiable as having used it.

Why it matters: Funds can now be followed through a swap service that was effectively invisible, including where it is reached indirectly through third-party wallet interfaces.

Expanded coverage of Chinese-language guarantee services

TRM attributed additional Chinese-language guarantee and escrow services that underpin online scam-services marketplaces, including a newly created entity on TRON and its treasury infrastructure.

Why it matters: Scam-services marketplaces depend on a guarantee layer to broker their transactions, and that layer is now attributed.

Multiple new China-nexus gambling networks attributed

TRM attributed multiple China-nexus gambling networks, each typically operating across many sites, and several with notable exposure to scam networks.

Why it matters: Gambling networks are a common layer for moving illicit proceeds, and several of these connect directly to scam infrastructure. That exposure is now visible and traceable.


Fraud

+$281M in new scam-activity leads

TRM added $281M in new scam-activity leads.

Why it matters: More scam-linked funds are identified and actionable, expanding the pool of traceable leads.

Published analysis of the $116M Coldcard exploit

TRM published analysis of the largest hardware wallet exploit of 2026, tracing $116M drained from Coldcard wallets.

Why it matters: The year's largest hardware-wallet compromise is traced and documented, supporting exposure checks against the stolen funds.

H1 2026 hack analysis published

TRM published its H1 2026 hack analysis, finding that the number of crypto hacks reached a record high while total losses fell below $1B for the half.

Why it matters: The threat is shifting toward more frequent attacks with smaller average losses, quantified rather than reduced to a single headline number.


Sanctions

$6.3B traced through a newly designated Iran-linked exchange

OFAC designated Shelbit, an Iran-linked exchange, on 7 August. TRM published analysis tracing more than $6.3B in blockchain flows through Shelbit's infrastructure between May 2024 and March 2026.

Why it matters: Exposure to a newly designated exchange can be screened and traced, with 23 months of flow analysis behind it.

Expanded attribution of the A7 sanctions-evasion network

TRM added $2B in newly detected volume through A7, the Russia-linked sanctions-evasion network.

Why it matters: Customers can now screen and trace an additional ~$2B in A7-linked flow that was previously not detectable.

New Iran-linked exchange attribution

TRM shipped new heuristics covering Iran's domestic exchanges, adding roughly 127,000 addresses and $700M in newly attributed volume. A data partnership also doubled coverage of Iranian diaspora exchanges, from 14 to 29 entities.

Why it matters: Following OFAC's designation of Iran's major domestic exchanges, coverage now runs deeper across both the domestic platforms and the diaspora exchanges that connect them to the global market.

Attribution behind OFAC's ISKP terrorist-financing action

OFAC sanctioned 134 cryptocurrency addresses tied to roughly $2M in ISKP terrorist financing. TRM attributed the designated infrastructure and published analysis of how the group raises, moves, and conceals funds across currencies and platforms — building on TRM's tracking of the group's crypto donations since 2022.

Why it matters: Exposure to a designated terrorist-financing network can be screened and traced immediately, with the on-chain context behind the designation.

New coverage of sanctioned cybercrime infrastructure

OFAC designated FirstVPN, a VPN provider that sold anonymizing infrastructure to cybercrime groups, along with a sanctioned individual supplying malware-obfuscation services. TRM already maintained an attributed entity for FirstVPN before the designation and now covers the 20 newly listed addresses for FirstVPN and its administrator across eight blockchains — Bitcoin, Ethereum, Litecoin, Tron, Dogecoin, Dash, Zcash, and Solana.

Why it matters: The designated addresses are screenable across all eight chains immediately. The broader signal is that payments to anonymity and obfuscation services are worth treating as risk in their own right, not just the wallets of the groups buying them.


Blockchain support

New blockchain support: Midnight (NIGHT)

We've added new Standard support for Midnight (NIGHT). Support includes:

  • TRM Forensics

  • TRM Wallet Screening

  • TRM Transaction Monitoring

  • Ownership (all categories), counterparty (all categories), and indirect risk indicators (severe and high risk categories)

View all of our blockchain coverage in the Supported Blockchains page in Platform Information and learn more about TRM's blockchain support tiers.

Seed Analysis adds support for Polkadot, NEAR, Injective, and Bittensor

Seed Analysis expanded to multiple new blockchains, letting investigators derive addresses and detect on-chain activity for wallets across more networks. In the same period, a law enforcement agency recovered £800,000 in criminal assets using the tool alongside TRM's seizure training.

Why it matters: Investigators working seized wallets can recover activity across more networks without leaving the tool, and turn what they find into seizable assets.


Questions? Reach out to your TRM account team or contact us through the in-platform support widget.

Did this answer your question?