Card fraud detection is solved. Taken 40 years, but we know what works. Blockchain fraud? We're still broken. Most teams copy the card playbook and then wonder why it falls apart in three days.

Here's what happened. 2020, everyone thought they'd be clever. Plug the Visa fraud model into crypto. Seven-two hours later, legitimate users can't move money. False positives everywhere. Lower the threshold, suddenly you're bleeding fraud losses. Oops.

2021, 2022. Teams finally figured out card models don't port. Different data. Different attacker behavior. Everything's different. The feedback loop that makes card detection work just doesn't exist on-chain.

By 2023, the teams that didn't go out of business started building actual blockchain-native detection. Took them long enough.

Why your credit card fraud detection is useless here

Card networks are closed. Visa and Mastercard know every merchant, every bank, every transaction for 50 years. Someone uses your card in London at 3pm and New York at 5pm? Physically impossible, flag it. Card gets disputed 30 days later, model learns, next similar transaction gets higher scrutiny. Feedback loop closes. Model improves.

Blockchain is the opposite situation. Public history but zero semantic information. A transaction doesn't tell you if you actually own that wallet. Recipient could be a real person or a smart contract deployed five seconds ago. No dispute system exists. If your wallet gets drained, it's drained. No chargeback. No insurance. No recovery. The money's gone and that's just reality.

So the features that matter for Visa? They're basically useless.

On cards, velocity is everything. Same card, ten merchants, ten cities, one hour? That's fraud. On-chain, that's just a bot processing payroll. Thousands of legitimate transactions hit that pattern daily. Your model flags all of them. You drown in false positives.

Geographic inconsistency was huge for cards. On-chain, addresses have no location. A wallet can send transactions from anywhere to anyone at any time. Geography features don't work at all.

Merchant category codes used to matter. Jewelry spike after a card compromise? Flag it. On-chain, there's basically two categories. Tokens. NFTs. Everything else is noise. You lose the semantic information that makes card models work.

What actually catches fraud on-chain

The teams that aren't failing right now focus on three things. Graph analysis. Wallet fingerprinting. Behavioral baselines.

Graph analysis is treating fraud as a network problem. You map the wallet interaction graph. What other wallets has this address touched? What's the distribution of token values? How central are they? Are they sending to known bad addresses?

Works because fraud clusters. A compromised wallet sends tokens to maybe five addresses. Those five disperse to fifty. The pattern shows up in the graph even if individual transactions look fine. Chainalysis and Elliptic are billion-dollar companies because they got good at this. They use ML to detect new money-laundering patterns but the backbone is always graph structure.

Wallet fingerprinting is behavioral modeling over time. What's your normal transaction size? What hours do you send transactions? Your favorite token? Do you interact with DEXes or stable pairs or new tokens? New transaction comes in. Does it match your historical pattern or is it weird?

Works because real wallet owners have actual patterns. You maybe swap 5 ETH every Friday. Always the same DEX. Only send stablecoins during business hours. Someone compromises your wallet, they don't know these patterns, they break them. Model flags the break.

Problem is data. A customer with five transactions gives you almost nothing. Some teams handle this with cohort fingerprints. You're a new Ethereum wallet with 10 ETH? You're in a cohort with thousands of others like you. Similar risk profile. Transactions normal for your cohort get lower scrutiny than transactions anomalous for it.

Behavioral baselines with temporal stuff. Wallet normally sends UTC daytime? 3am UTC transaction is suspicious. Normally sends to 3 addresses? Suddenly batch-send to 30? Worth investigating. Average transaction 0.5 ETH? Try to send 100? Flagged.

Best models combine all three. Graph analysis. Wallet fingerprinting. Baseline checking. New transactions against their wallet's history. Cohort baselines for new wallets. Weight the anomalies. Multiple dimensions of weirdness usually means fraud.

The false-positive trap is actually the main problem

Here's where it gets real. These approaches have false-positive rates between 5% and 15%. One in seven flagged transactions is legitimate. You're a payment processor, this destroys your conversion. Users get blocked repeatedly, they find another service.

Traditional solution is ML feedback. User disputes a block, you retrain the model. Over time it learns what's real and what's fraud. On-chain, this doesn't work. There's no dispute system. Transaction gets blocked, user doesn't message you saying whether it was legitimate or fraud. They just use a different service.

You have to get false positives right the first time. No feedback loop to fix it later. Teams implement graduated response instead.

Don't block high-risk transactions immediately. Ask for extra verification. Send an SMS code. Ask user to confirm the address. Require a time delay. Friction, sure. Better than blocking outright. Users accept a 30-second delay if the payment goes through. They won't accept a block.

Regulators care too. MAS Singapore and the EU AML directive need a clear decision boundary. What gets investigated. What gets extra verification. What gets blocked. False-positive rate of 20%? Excessive friction on legitimate users. Regulators say lower it. False-negative rate too high? Regulators say improve. Most teams end up at 8% false positives, 2% false negatives. Live with the false positives, use graduated response to manage them.

Dust and device fingerprinting break everything

Two attack patterns that break traditional models completely. Dust attacks. Device fingerprinting attacks.

Dust attack: attacker sends tiny amounts of a token to thousands of wallets. Legitimate wallets, new wallets, everything. Dust is worth nothing but contains data. Later when wallets that received dust do other transactions, the dust often gets included. Creates a link between dust sender and the later transaction. Exchanges use dust to tag wallets. Fraudsters use it to make theft look distributed.

Traditional models don't even detect dust because they don't look for it. You need a separate detector that flags receiving wallets with transactions to known poison addresses. Not an ML problem. It's a lookup problem.

Device fingerprinting is the opposite. Attackers use patterns that look legit on-chain but weird on the web. User visits site, authenticates, submits transaction. Blockchain sees a normal transaction from a wallet with 50 transactions. IP address is new. Browser is new. Device is new. User behavior is completely different than history.

Best models integrate off-chain signals. Don't rely on blockchain alone. Use IP reputation. Use device fingerprinting. Check if the IP matches the customer's registered country. Check if the browser matches previous usage. How long did the user sit on the payment page.

Teams winning at this treat it as a hybrid problem. Blockchain gives you one set of signals. Application layer gives you another. Combined, you get better detection than either alone.

Regulators want to see your work

Fraud detection oversight is tightening. Singapore MAS requires you to document your methodologies. EU wants this under PSD3. Show your false-positive rate, false-negative rate, appeals process, audit trail.

You can't just drop in a third-party fraud API anymore. Build it as a first-class system. Explain every decision. Log everything. Have an appeals process.

Teams investing in this now before it's required are building real advantages. Control false positives. Expand to new markets because regulators trust your systems. Compete on customer experience because your detection doesn't block legitimate transactions.

Start with graph analysis and behavioral fingerprinting. That's your baseline. Layer on device fingerprinting and IP reputation. Build graduated response. Document everything. You're building for regulators, not just users.

The hard part is knowing if it actually works. No feedback loop. Can't retrain on user disputes if users just leave. You might think you're 95% accurate when you're catching 60% of novel attacks. Uncertainty is baked in. You build ahead of evidence.