Skip to content
Free guide: How to use AI in compliance
Built for crypto exchanges, wallets, on-ramps, and stablecoin issuers

AML for Crypto: How VASPs and CASPs Build Programs That Survive Post-Binance Enforcement

The Binance USD 4.3 billion settlement (November 2023), the KuCoin USD 297 million guilty plea (January 2025), the OKX USD 504 million settlement (February 2025), the Bittrex USD 53 million / bankruptcy (2022-2023), and the BitMEX USD 230M-plus enforcement with founder prison sentences are the operating reference for what regulators expect from AML for crypto in 2026. Each settlement turned on the same pattern: monitoring without typology coverage for crypto-native flows, sanctions screening that did not extend to wallet counterparties, and Travel Rule compliance that was either non-existent or non-functional. Done well in 2026, this layer is real-time, on-chain plus off-chain, identity-linked at the alert layer, and architecturally aligned with MiCA's July 1, 2026 transition deadline.

AML for crypto architecture for VASPs, CASPs, and crypto exchanges showing on-chain transaction monitoring, Travel Rule data flow, identity-linked alerts, and SAR filing pipeline
Used by crypto exchanges, wallets, and on-ramps to monitor real-time flows under FATF Travel Rule and MiCA without storing the documents centrally.
  • FATF Travel Rule
  • MiCA-aligned
  • FinCEN BSA
  • OFAC ready
  • EU TFR
  • Real-time monitoring
  • No central PII store

AML for crypto is the on-chain transaction-monitoring, sanctions-screening, Travel Rule, and SAR filing layer that VASPs and CASPs operate to satisfy FATF Recommendation 16, MiCA Title V, FinCEN Bank Secrecy Act, and equivalent regimes. It runs real-time scoring across wallets, smart contracts, and counterparties with identity-linked alert payloads.

What does crypto AML actually have to do?

The AML for crypto category covers four regulatory surfaces simultaneously, and the operating reality is that most crypto businesses underbuild on at least two of them.

  • Transaction monitoring at the on-chain plus off-chain layer. Crypto compliance is unique because the transaction record is publicly auditable but the counterparty identity is not. Mixer interaction, peeling chains, dust attacks, layering through bridges, and high-velocity wallet hopping are detectable signals on-chain. Identity-side signals (mule indicators, unusual deposit patterns, geo-IP anomalies) live off-chain. The AML for crypto architecture has to fuse both.
  • Sanctions screening at wallet plus counterparty layer. OFAC’s Tornado Cash designation (August 2022) established that smart contracts can be sanctioned. Stacks have to screen the wallet, the counterparty wallet, and the smart contract addresses involved, against OFAC SDN, EU consolidated, UK OFSI, UN, and increasingly state-level lists.
  • Travel Rule compliance. FATF Recommendation 16 requires originator and beneficiary information to flow with transfers above threshold (USD/EUR 1,000 in most jurisdictions, zero-threshold under EU TFR). Cross-VASP transfers must attach this metadata at every hop.
  • SAR filing pipeline. Suspicious activity that crosses the regulator’s threshold has to land in a SAR (or local equivalent) within the jurisdiction-specific filing window.

For the underlying transaction-monitoring architecture, see our AML transaction monitoring 2026 piece. For the deeper VASP regulatory framework, see our VASP KYC compliance under MiCA breakdown.

What are the regulatory baselines for crypto AML in 2026?

The regulations rhyme but the operator obligations and enforcement priorities differ materially. Three jurisdictions matter most for any cross-border crypto business.

European Union: MiCA Title V, EU TFR, AMLA direct supervision

MiCA’s transitional period ends July 1, 2026. Title V mandates obligations on Crypto-Asset Service Providers (CASPs), requiring documented procedures, named compliance officers, and audit-ready records. The EU Transfer of Funds Regulation (TFR) applies the Travel Rule with a zero-threshold rule for crypto transfers, the most stringent globally. The Anti-Money Laundering Authority (AMLA) operational from 2025 in Frankfurt, has direct supervisory authority over the largest CASPs and applies per-decision defensibility to every alert closure and SAR-filing decision. Penalties under MiCA reach EUR 15 million or 12.5% of annual turnover for legal persons.

United States: FinCEN BSA, OFAC, FATF Recommendation 16

The Bank Secrecy Act applies to crypto exchanges as money service businesses (MSBs). FinCEN registration is required. Program obligations have to be reasonably designed and risk-based under 31 U.S.C. 5318(h)(2)(B)(iv), as amended by the Anti-Money Laundering Act of 2020. FinCEN proposed a rewrite of the AML/CFT program regulations on April 7, 2026 that would refocus supervision on effectiveness rather than paperwork volume. It withdrew the July 2024 proposal, comments closed on June 9, 2026, and FinCEN proposed a 12-month implementation period after any final rule, so the current MSB program requirements are what an examiner tests today. OFAC compliance covers the SDN list, sectoral sanctions, and the Tornado Cash precedent. The DOJ has prosecuted exchange executives directly: BitMEX (USD 230M-plus, founder guilty pleas with prison time), Binance (USD 4.3B, CZ guilty plea and prison sentence), KuCoin (USD 297M plus founder guilty pleas).

United Kingdom: FCA crypto registration, MLR 2017, OFSI

UK crypto businesses register with the FCA under the Money Laundering Regulations 2017. The FCA’s crypto register shows the persistent gap between applications and approvals, with the FCA rejecting roughly 80% of applications historically. OFSI handles sanctions implementation. The 2024-2025 enforcement wave focused on registration compliance and continued operations by unregistered firms.

Side-by-side: crypto AML regulatory obligations

Dimension EU US UK
Primary regulator National + AMLA (top CASPs) FinCEN, OFAC, DOJ, SEC, CFTC FCA, OFSI
Travel Rule threshold EUR 0 (zero-threshold under TFR) USD 1,000 EUR 1,000
Registration regime MiCA CASP authorisation FinCEN MSB registration FCA crypto registration
MiCA-equivalent timeline July 1, 2026 transition deadline n/a UK rules per HMT roadmap
Recent landmark Revolut UAB EUR 3.5M (Apr 2025) Binance USD 4.3B / KuCoin USD 297M / OKX USD 504M Continued unregistered-firm actions
Audit standard AMLA per-decision defensibility Reasonably designed + risk-based MLR 2017 risk-based

Where do crypto AML programs fail, and what does it cost?

Five reproducible failure modes show up across every recent crypto enforcement.

Sanctions screening at customer level only, not transaction-counterparty level

The pattern that produced the Binance USD 4.3 billion settlement: customers screened at onboarding, transaction counterparties not screened at every transfer. The fix is to extend screening to the wallet receiving funds, the wallet sending funds, and any smart contract intermediating. Tornado Cash interaction has to fire deterministically at the rule level.

Travel Rule non-compliance through unilateral disengagement

A common pattern: VASP A sends funds to VASP B without originator data, VASP B accepts the transfer because rejecting would reduce volume. Both sides are non-compliant. EU TFR’s zero-threshold rule and AMLA’s enforcement appetite make this strategy untenable from July 2026.

On-chain typology gaps

Mixer interaction, peeling chains, layering through cross-chain bridges, structuring at deposit, mule indicators in newly verified accounts. Programs that monitor for fiat-style typologies without crypto-native typologies miss the pattern that regulators specifically expect detection of.

KYC layer not joined to AML monitoring

Alerts fire on wallet IDs without joining to the verified KYC record. Mule networks scale because each mule looks like a fresh wallet. Every alert needs binding to the verified credential, the KYC tier, and the perpetual re-screening status. See our perpetual KYC piece.

Audit-trail reproducibility

When the regulator pulls the case file 18 months later, the closure rationale does not reproduce. Every recent crypto Final Notice and Consent Order cited reproducibility gaps. AMLA’s per-decision defensibility framing makes this structural, not stylistic.

Recent enforcement timeline

Date Action Penalty Why it matters for crypto AML
2022 Bittrex USD 53M + bankruptcy Sanctions screening gaps
Aug 2022 OFAC designates Tornado Cash Smart contract sanction Smart contracts can be sanctioned
Jun 2023 CFTC v. Ooki DAO USD 644K default judgment DAOs can be sued
Nov 2023 Binance + CZ USD 4.3B + prison Largest crypto resolution
Jan 2025 KuCoin USD 297M + founder pleas Permissionless onboarding no defence
Feb 2025 OKX USD 504M “We do not serve US persons” requires architectural enforcement
Mar 2025 Cash App / Block USD 160M Identity-linkage gaps
Apr 2025 Revolut Bank UAB EUR 3.5M AMLA-era documentation expectations
Jul 2026 MiCA transition deadline EUR 15M / 12.5% turnover CASP obligations apply

How does Zyphe deliver crypto AML with on-chain plus identity-linked monitoring?

Zyphe ships four primitives mapped to the crypto-specific surface.

Real-time on-chain plus off-chain monitoring. Zyphe’s AML monitoring product runs real-time scoring at authorisation time for cliff-edge rules (sanctioned counterparty, structuring at deposit, mule signatures) and batch pattern detection for cross-product behavioural rules (peeling chains, velocity over a window, mixer interaction). The on-chain typology library covers FATF Recommendation 20 named typologies plus crypto-native patterns. Median alert-to-triage time under 4 hours for cliff-edge rules at production customers.

Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule indicators fire deterministically at the rule level because identity attributes are right there in the alert payload. See our decentralised KYC primer for the underlying credential architecture.

Travel Rule compliance. Originator and beneficiary data flows with every cross-VASP transfer through the IVMS101 schema. Zyphe integrates with the major Travel Rule networks (TRP, TRUST, Sumsub Travel Rule, Notabene) and handles the data exchange without exposing the underlying PII. EU TFR’s zero-threshold rule satisfied at the AML for crypto architecture layer.

SAR filing pipeline with clock tracking. Alert open to SAR filed (or alert closed with documentation), the clock is visible. Backlog metrics (median, 95th-percentile age, broken down by typology) surface to the CCO weekly. Audit-export available in regulator-ready formats on demand.

The Zyphe precision rate (alerts that produce a SAR or documented escalation) runs at approximately 22% versus a published industry baseline of 5-8%, because the identity layer eliminates the noise that comes from monitoring against unverified wallets. A senior MLRO at a tier-1 European exchange we work with framed it on a customer call in March 2026: “the OKX settlement was the moment our board stopped asking whether we needed to integrate identity into monitoring and started asking how fast. The Zyphe stack closed the gap in nine weeks.”

How do you implement crypto AML across exchanges, brokerages, and crypto-native fintechs?

Three patterns covering the most common deployment shapes.

Centralised exchange

Real-time scoring at deposit, withdrawal, and trade execution. Sanctions screening at wallet and counterparty layer. Travel Rule data flow on cross-VASP transfers. KYC tier-driven monitoring intensity (standard CDD for low-risk, EDD with elevated thresholds for high-risk). Per-decision triage records for every alert. Median onboarding time for the AML for crypto stack: 2-4 weeks against the Zyphe sandbox.

Crypto brokerage and OTC desk

Higher per-transaction value plus institutional counterparty depth. KYB on every counterparty institution. Source-of-funds documentation on transactions above threshold. Sanctions screening at every layer (entity, directors, UBOs, wallets). Adverse media monitoring at counterparty level.

Crypto-native fintech (wallet, custody, staking)

Wallet-level KYC at sign-up. Transaction monitoring against the customer’s verified credential. Sanctions screening on counterparty wallets. Where staking or yield products are offered, additional securities-law monitoring layer. Custody-side coverage extends to the custodian’s own counterparties at higher diligence depth.

For the broader implementation pattern, see our AML transaction monitoring 2026 piece.

What are the real edge cases crypto AML still struggles with?

Five edge cases worth flagging in procurement.

Self-hosted wallet attribution. A transaction to or from a self-hosted wallet has no counterparty KYC data. The architecture has to risk-tier these flows separately and apply documented enhanced diligence rather than blanket-blocking.

Cross-chain bridge layering. Funds bridged from Ethereum to Polygon to Arbitrum and back create attribution gaps. Stacks have to integrate with chain-analysis providers (Chainalysis, TRM Labs, Elliptic) that maintain cross-chain heuristics.

Mixer and privacy-pool interaction. Tornado Cash is sanctioned. Privacy Pools 2.0 and similar compliant-mixer designs are not. The AML for crypto system has to distinguish, with documented residual risk where the distinction is unclear.

DeFi protocol interaction. A user interacting with a DeFi protocol (Uniswap, Aave, Curve) creates indirect counterparty exposure. The AML for crypto stack has to surface this without blanket-blocking DeFi flows. See our KYC for DeFi protocols guide.

MiCA-grandfathered activity. Pre-MiCA crypto-asset activity that does not fit cleanly into post-MiCA CASP categorisation. Transitional documentation depth matters more than usual.

How do you evaluate crypto AML in the next 30 days?

Five concrete moves for a crypto-business CCO, MLRO, or VP of risk.

  1. Inventory typology coverage. Pull your current rule library and check coverage against FATF Recommendation 20 plus crypto-native patterns (mixer interaction, peeling chains, mule indicators). Gaps are the regulator’s first finding.
  2. Pressure-test sanctions screening at counterparty layer. Send a synthetic transaction to a known-sanctioned address in your sandbox. If the rule the AML for crypto architecturehe architecture is wrong.
  3. Audit Travel Rule coverage. Pull 50 cross-VASP transfers from the last 90 days. Confirm originator/beneficiary data flowed for each. EU TFR zero-threshold rule is the post-July-2026 baseline.
  4. Run an audit-export drill. Pull a SAR filed 18 months ago and trace the evidence chain. If reconstructhe AML for crypto architecturethan an hour, the AML for crypto architecture is the problem.
  5. Update your DPIA and the AMLA per-decision defensibility documentation. AMLA-era supervision expects per-decision documentation, not just process documentation.

Stop running AML on yesterday's batch.

If you are running AML for a crypto programme, you already feel the gap between what your stack reports and what your regulator asks. Book a 30-minute walkthrough and we will run a real monitoring scenario, show you the audit trail, and price it against your current vendor.

Frequently asked questions

AML for crypto is the on-chain transaction-monitoring, sanctions-screening, Travel Rule, and SAR filing layer that VASPs and CASPs operate to satisfy FATF Recommendation 16, MiCA Title V, FinCEN Bank Secrecy Act, and equivalent regimes. It runs real-time scoring across wallets, smart contracts, and counterparties with identity-linked alert payloads.

Crypto AML extends bank AML to the on-chain layer where transaction records are public but counterparty identity is not, requires Travel Rule data exchange across VASPs, includes smart-contract-level sanctions screening (Tornado Cash precedent), and operates under crypto-specific regulatory regimes (MiCA, FinCEN MSB rules, FCA crypto registration). The technical architecture differs materially.

MiCA Title V mandates obligations on CASPs starting July 1, 2026 (end of transitional period). Documented AML procedures, named compliance officers, audit-ready records, sanctions screening, Travel Rule compliance under EU TFR's zero-threshold rule, and per-decision defensibility under AMLA supervision. Penalties up to EUR 15 million or 12.5% of annual turnover.

The EU Transfer of Funds Regulation applies the Travel Rule to crypto transfers with no minimum threshold. Every cross-VASP transfer requires originator and beneficiary data to flow with the transaction, regardless of value. This is the most stringent Travel Rule globally. Stacks have to support IVMS101 schema and Travel Rule network integration.

OFAC's August 2022 Tornado Cash designation established that smart contracts can be sanctioned. Stacks have to screen wallet addresses, counterparty addresses, and smart contract addresses against OFAC SDN, EU consolidated, UK OFSI, and UN lists. Interaction with sanctioned smart contracts triggers automatic alerts and SAR filing consideration.

The Binance settlement (November 2023) cited the largest pattern of crypto AML failures in history: sanctions screening gaps, Travel Rule non-compliance, transaction monitoring without typology coverage, and audit-trail reproducibility gaps. Founders received prison sentences. Programs in 2026 are explicitly benchmarked against the post-Binance enforcement bar.

End-to-end Zyphe integration for a centralised exchange fits in 2 to 4 weeks against the sandbox. Production hardening with full Travel Rule network integration and audit-export configuration adds another 2 to 4 weeks. Total typically 4 to 8 weeks for an in-house engineering team with budget allocated.

Sanctions, PEP, and adverse media re-screening run continuously at the credential layer. On-chain transaction monitoring runs in real time at authorisation and in batch for cross-product behavioural patterns. Travel Rule data flows automatically. Per-decision triage records and SAR clock tracking surface metrics to the CCO weekly.