A hands-on training workbook with live KYT API integration • Set up a scenario on the left, work the flow on the right
A hands-on workbook for practicing KYT alert triage. Each tab is a realistic alert scenario (sanctions, terrorist financing, CSAM, fraud, gambling) with real, Data-Solutions-verified transaction hashes and addresses. You register the transfer against a live KYT instance, then work through the alert exactly like you would on the job.
In the KYT API Configuration card (top left), paste your KYT API token. The Base URL defaults to /proxy/api/kyt — a same-origin relay that avoids the browser's CORS block on direct calls to Chainalysis. Click Test Connection to confirm it works.
Use the category tabs (Sanctions, Terrorist Finance, CSAM, Fraud, Gambling) to pick a typology, then the sub-tabs (Direct — Sent/Received, Indirect — Fast/Slow) to pick a variant.
Each scenario tells the story first: transaction details, the fund-flow diagram, and a timeline of events. For indirect scenarios, the diagram shows the real 2-hop chain (source entity → intermediary → your platform) with a Time Gap — under a few hours usually means the same actor moving funds fast; weeks or months usually means unrelated intermediaries.
At the bottom of that scenario, the Register in KYT card has every field pre-filled with the scenario's real data — User ID, Network, Asset, Direction, Address, and Transaction Hash — all editable. Click Register Transfer in KYT to create the user (if needed), register the transfer, and poll until it's processed. The log and results (transfer summary, alerts, exposure, network identifications) appear right below the button.
The moment you click Register Transfer in KYT, a side window opens automatically — log in there once. When the alert comes back, that same window jumps straight to it, and every "Open" link afterward (in the Alerts table, or "View User") re-uses that same window instead of opening new tabs. Chainalysis blocks its apps from being embedded inline, so this controllable side window is the way to view the real alert and Reactor graph.
Every timestamp in the Flow timeline is shown in UTC. Pick a zone from the Timeline timezone dropdown (top of page) to also see it converted to that local time, side by side.
This page is an internal training aid for practicing KYT alert triage workflows. It is not a production compliance tool, is not a substitute for your institution's actual case-management system, and must not be used to make or record real compliance decisions.
This tool is provided "as is," with no warranty of any kind, express or implied, including accuracy, availability, or fitness for a particular purpose. The people who built it accept no responsibility or liability for actions taken, or not taken, based on anything shown here — including alert data, exposure figures, verdicts, or any other content on this page.
Your KYT API key is entered directly into your browser and sent only to the Chainalysis KYT API (via a same-origin relay used solely to avoid a browser CORS restriction). It is not logged, stored server-side, or shared with any third party by this tool. Treat it as you would any production credential — do not share screenshots or recordings that include it, and rotate it if you suspect exposure.
Registering a transfer here makes a real call to your organization's KYT instance. While the transaction hashes used in these scenarios are real, verified on-chain data, using this tool may create real user and transfer records in your KYT instance. Use a training/sandbox instance where possible, and follow your organization's own policies for what's appropriate to register.
This is an internal, unofficial training utility. It is not an official Chainalysis product and is not endorsed by Chainalysis. Use of the Chainalysis KYT API remains subject to your organization's own agreement with Chainalysis.
| ⚡ Fast (Same Actor) | 🐢 Slow (Different People) | |
|---|---|---|
| Transit | Minutes–hours | Weeks–months |
| Wallets | Freshly created, no history | Established, independent activity |
| Exposure % | High (>30%) | Low (<20%) |
| Action | Freeze + SAR | EDD + document |
| # | Date | Amount | Note |
|---|---|---|---|
| 1 | Jun 12 | 500 | Test |
| 2 | Jun 19 | 2,000 | After fake profits |
| 3 | Jun 28 | 5,000 | Escalating |
| 4 | Jul 6 | 15,000 | Major |
| 5 | Jul 15 | 47,500 | THIS ALERT — Total $70K |
| Date | Dir | Amount | Running |
|---|---|---|---|
| Jul 1 | Sent | 2,000 | -$2K |
| Jul 3 | Recv | 1,200 | -$800 |
| Jul 8 | Sent | 5,000 | -$5.8K |
| Jul 14 | Sent | 3,500 | -$9.3K |
| Jul 22 | Recv | 8,750 | -$550 |