Know Your VASP report Low risk
Vilnius Digital UAB is a exchange incorporated in Lithuania, assessed at 98/100 (low risk) from a desk review of 95/100 and an on-chain review of 100/100. Licence status is licensed with claimed evidence (Lithuania financial supervisory authority), MiCA authorised, KYC rigour strict, Travel Rule ready. The largest single deduction is 5 points for licence evidence: licence evidence is claimed. 1 clustered wallet(s) moved $0 in the reviewed window, of which $0 (0.00%) touched categories of severity 5 or above and 0.00% touched severity 8 or above. Attribution covers too little of the traced value to treat this as a clear result. Review required; a low-risk score here means little was identified, not that little is there. Original: Licensed, supervised and Travel Rule capable; standard measures apply.
Combined score weights the desk review at 45% and the on-chain review at 55%, because chain evidence is observed while the regulatory file is asserted.
Regulatory file
| Legal name | Vilnius Digital UAB |
|---|---|
| Trading name | Vilnius Digital UAB |
| Licence status | licensed (claimed evidence) |
| Regulator | Lithuania financial supervisory authority |
| Licence reference | LT-99A2DB80 |
| MiCA status | authorised |
| Jurisdiction | Lithuania (LT), risk 2/10 |
| Operational hubs | GB, LT, SY |
Controls
| KYC rigour | strict · Identity verification before first withdrawal, no anonymous tier. |
|---|---|
| Withdrawal KYC threshold | $0 |
| Travel Rule | ready · Originator and beneficiary data exchanged for VASP-to-VASP transfers. |
| Transaction monitoring | mature |
| Sanctions screening | in place |
| Source of funds checks | performed |
| Custody model | custodial |
Desk review deductions
5.0 points deducted from 100.
On-chain review of the provider's clusters
Risk composition of managed wallets
No on-chain activity was returned for the clustered wallets.
Screened wallets
| Address | Chain | Score | Risk | Inbound | Outbound | Transfers | Source |
|---|---|---|---|---|---|---|---|
| 0x8a9e6bcbda4a89fef93a76cb71645f26d09ffa69 | Ethereum | 100 | Low | 0 | 0 | 0 | live:alchemy |
| bc1qwpqea3p64vyf2rm7rs5csx9dny7w3n5wmrf9fv | Bitcoin | — | provider error (ProviderError) |
Compliance and provenance
| Travel Rule | counterparty ready · Originator and beneficiary data exchanged for VASP-to-VASP transfers. |
|---|---|
| Data source | live:alchemy · 1 of 2 clustered address(es) screened |
| Directory | 41 VASP profiles, 2463 labelled entities |
Label sources
- Sanctions: 943 designated addresses from the US Treasury OFAC SDN list, published 08/28/2026.
- Token contracts: 927 identified from public token lists.
-
Cited public labels:
519 addresses from
34 source(s), each with a URL.
- Aave address book: V3 Ethereum (98 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Ethereum.json
- FBI/IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (51 addresses) — https://www.ic3.gov/PSA/2025/PSA250226
- Aave address book: AaveV3Polygon (45 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Polygon.json
- Aave address book: V2 Ethereum (40 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Ethereum.json
- Aave address book: AaveV3Arbitrum (39 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Arbitrum.json
- Aave address book: AaveV3Optimism (31 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Optimism.json
- Aave address book: AaveV3Base (25 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Base.json
- Tornado Cash smart contracts (24 addresses) — https://docs.tornado.cash/general/tornado-cash-smart-contracts
- Bybit: wallet addresses ownership explained (21 addresses) — https://www.bybit.com/en/help-center/article/Bybit-Wallet-Addresses-Ownership-Explained
- Circle CCTP EVM contract addresses (20 addresses) — https://developers.circle.com/cctp/evm-smart-contracts
- Aave address book: AaveV3BNB (18 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3BNB.json
- Bitfinex: published public wallets (16 addresses) — https://github.com/bitfinexcom/pub/blob/main/wallets.txt
- Aave address book: AaveV2Polygon (16 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Polygon.json
- Aave address book: AaveV3EthereumLido (12 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3EthereumLido.json
- Crypto.com: Transparency First cold-wallet list (10 addresses) — https://crypto.com/en/company-news/transparency-first
- Uniswap v3 Arbitrum deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/arbitrum-deployments
- Uniswap v3 Optimism deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/optimism-deployments
- Uniswap v3 Polygon deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/polygon-deployments
- Lido deployed contracts (6 addresses) — https://docs.lido.fi/deployed-contracts/
- Uniswap v3 Base deployments (6 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/base-deployments
- Uniswap v3 Ethereum deployments (3 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/ethereum-deployments
- Chainalysis: Euler Finance flash loan attack (2 addresses) — https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/
- Morpho deployed contracts (2 addresses) — https://docs.morpho.org/get-started/resources/addresses
- Compound III USDC Ethereum roots (2 addresses) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdc/roots.json
- Aave address book: GhoEthereum (2 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/GhoEthereum.json
- Railgun privacy system contracts (1 address) — https://docs.railgun.org/wiki/learn/helpful-links
- Linea network contracts (1 address) — https://docs.linea.build/network/build/contracts
- Starknet L1-L2 messaging (1 address) — https://docs.starknet.io/documentation/architecture_and_concepts/Network_Architecture/l1-l2-messaging/
- Chainalysis: Wormhole hack February 2022 (1 address) — https://www.chainalysis.com/blog/wormhole-hack-february-2022/
- Compound III USDS Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usds/roots.json
- Compound III USDT Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdt/roots.json
- Compound III WBTC Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wbtc/roots.json
- Compound III WETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/weth/roots.json
- Compound III WSTETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wsteth/roots.json
- Demonstration data: excluded — 118 synthetic entities were not scored.
Screen window
- Up to 500 transfers across 3 indexer page(s) · default 3 hops · hop-2 budget 16 · hop-3 budget 12.
Artefact integrity
-
sha256+hmac · SHA-256
61de328b10b3f4b5262e818e983436a63ae770393b96514bf6f99bca97698338· sealed 2026-09-13T20:53:26+00:00 · HMAC present.
Frameworks covered
- FATF Recommendation 15 / 16 — Counterparty attribution and originator/beneficiary context.
- EU MiCA (Regulation 2023/1114) — Risk assessment record for crypto-asset service providers.
- EU AMLD / Transfer of Funds Regulation — Source and destination of funds with jurisdictional exposure.
- OFAC sanctions programmes — Direct and cluster-level exposure to designated addresses.
- FinCEN SAR / STR filing — Evidence pack: indicators, counterparties and transfer sample.
Informative
Notice / Disclaimer
Limits that apply to this artefact as a whole. Sources and hashes stay in provenance; this section is how to read them.
- This due diligence profile describes a synthetic service provider from the seeded VASP directory. Licence references, regulators and control ratings are fabricated for demonstration and describe no real business.
- Token-contract labels name contracts, not wallet owners.
- Demonstration data was excluded — 118 synthetic entities were not scored.
- Activity beyond the stated screen window is not in the score.
- Recompute the sha256+hmac digest against the JSON export to confirm this copy matches what was stored.