AML for crypto is the on-chain transaction-monitoring, sanctions-screening, Travel Rule, and SAR filing layer that VASPs and CASPs operate to satisfy FATF Recommendation 16, MiCA Title V, FinCEN Bank Secrecy Act, and equivalent regimes. It runs real-time scoring across wallets, smart contracts, and counterparties with identity-linked alert payloads.
What does crypto AML actually have to do?
The AML for crypto category covers four regulatory surfaces simultaneously, and the operating reality is that most crypto businesses underbuild on at least two of them.
- Transaction monitoring at the on-chain plus off-chain layer. Crypto compliance is unique because the transaction record is publicly auditable but the counterparty identity is not. Mixer interaction, peeling chains, dust attacks, layering through bridges, and high-velocity wallet hopping are detectable signals on-chain. Identity-side signals (mule indicators, unusual deposit patterns, geo-IP anomalies) live off-chain. The AML for crypto architecture has to fuse both.
- Sanctions screening at wallet plus counterparty layer. OFAC’s Tornado Cash designation (August 2022) established that smart contracts can be sanctioned. Stacks have to screen the wallet, the counterparty wallet, and the smart contract addresses involved, against OFAC SDN, EU consolidated, UK OFSI, UN, and increasingly state-level lists.
- Travel Rule compliance. FATF Recommendation 16 requires originator and beneficiary information to flow with transfers above threshold (USD/EUR 1,000 in most jurisdictions, zero-threshold under EU TFR). Cross-VASP transfers must attach this metadata at every hop.
- SAR filing pipeline. Suspicious activity that crosses the regulator’s threshold has to land in a SAR (or local equivalent) within the jurisdiction-specific filing window.
For the underlying transaction-monitoring architecture, see our AML transaction monitoring 2026 piece. For the deeper VASP regulatory framework, see our VASP KYC compliance under MiCA breakdown.
What are the regulatory baselines for crypto AML in 2026?
The regulations rhyme but the operator obligations and enforcement priorities differ materially. Three jurisdictions matter most for any cross-border crypto business.
European Union: MiCA Title V, EU TFR, AMLA direct supervision
MiCA’s transitional period ends July 1, 2026. Title V mandates obligations on Crypto-Asset Service Providers (CASPs), requiring documented procedures, named compliance officers, and audit-ready records. The EU Transfer of Funds Regulation (TFR) applies the Travel Rule with a zero-threshold rule for crypto transfers, the most stringent globally. The Anti-Money Laundering Authority (AMLA) operational from 2025 in Frankfurt, has direct supervisory authority over the largest CASPs and applies per-decision defensibility to every alert closure and SAR-filing decision. Penalties under MiCA reach EUR 15 million or 12.5% of annual turnover for legal persons.
United States: FinCEN BSA, OFAC, FATF Recommendation 16
The Bank Secrecy Act applies to crypto exchanges as money service businesses (MSBs). FinCEN registration is required. Program obligations have to be reasonably designed and risk-based under 31 U.S.C. 5318(h)(2)(B)(iv), as amended by the Anti-Money Laundering Act of 2020. FinCEN proposed a rewrite of the AML/CFT program regulations on April 7, 2026 that would refocus supervision on effectiveness rather than paperwork volume. It withdrew the July 2024 proposal, comments closed on June 9, 2026, and FinCEN proposed a 12-month implementation period after any final rule, so the current MSB program requirements are what an examiner tests today. OFAC compliance covers the SDN list, sectoral sanctions, and the Tornado Cash precedent. The DOJ has prosecuted exchange executives directly: BitMEX (USD 230M-plus, founder guilty pleas with prison time), Binance (USD 4.3B, CZ guilty plea and prison sentence), KuCoin (USD 297M plus founder guilty pleas).
United Kingdom: FCA crypto registration, MLR 2017, OFSI
UK crypto businesses register with the FCA under the Money Laundering Regulations 2017. The FCA’s crypto register shows the persistent gap between applications and approvals, with the FCA rejecting roughly 80% of applications historically. OFSI handles sanctions implementation. The 2024-2025 enforcement wave focused on registration compliance and continued operations by unregistered firms.
Side-by-side: crypto AML regulatory obligations
| Dimension | EU | US | UK |
|---|---|---|---|
| Primary regulator | National + AMLA (top CASPs) | FinCEN, OFAC, DOJ, SEC, CFTC | FCA, OFSI |
| Travel Rule threshold | EUR 0 (zero-threshold under TFR) | USD 1,000 | EUR 1,000 |
| Registration regime | MiCA CASP authorisation | FinCEN MSB registration | FCA crypto registration |
| MiCA-equivalent timeline | July 1, 2026 transition deadline | n/a | UK rules per HMT roadmap |
| Recent landmark | Revolut UAB EUR 3.5M (Apr 2025) | Binance USD 4.3B / KuCoin USD 297M / OKX USD 504M | Continued unregistered-firm actions |
| Audit standard | AMLA per-decision defensibility | Reasonably designed + risk-based | MLR 2017 risk-based |
Where do crypto AML programs fail, and what does it cost?
Five reproducible failure modes show up across every recent crypto enforcement.
Sanctions screening at customer level only, not transaction-counterparty level
The pattern that produced the Binance USD 4.3 billion settlement: customers screened at onboarding, transaction counterparties not screened at every transfer. The fix is to extend screening to the wallet receiving funds, the wallet sending funds, and any smart contract intermediating. Tornado Cash interaction has to fire deterministically at the rule level.
Travel Rule non-compliance through unilateral disengagement
A common pattern: VASP A sends funds to VASP B without originator data, VASP B accepts the transfer because rejecting would reduce volume. Both sides are non-compliant. EU TFR’s zero-threshold rule and AMLA’s enforcement appetite make this strategy untenable from July 2026.
On-chain typology gaps
Mixer interaction, peeling chains, layering through cross-chain bridges, structuring at deposit, mule indicators in newly verified accounts. Programs that monitor for fiat-style typologies without crypto-native typologies miss the pattern that regulators specifically expect detection of.
KYC layer not joined to AML monitoring
Alerts fire on wallet IDs without joining to the verified KYC record. Mule networks scale because each mule looks like a fresh wallet. Every alert needs binding to the verified credential, the KYC tier, and the perpetual re-screening status. See our perpetual KYC piece.
Audit-trail reproducibility
When the regulator pulls the case file 18 months later, the closure rationale does not reproduce. Every recent crypto Final Notice and Consent Order cited reproducibility gaps. AMLA’s per-decision defensibility framing makes this structural, not stylistic.
Recent enforcement timeline
| Date | Action | Penalty | Why it matters for crypto AML |
|---|---|---|---|
| 2022 | Bittrex | USD 53M + bankruptcy | Sanctions screening gaps |
| Aug 2022 | OFAC designates Tornado Cash | Smart contract sanction | Smart contracts can be sanctioned |
| Jun 2023 | CFTC v. Ooki DAO | USD 644K default judgment | DAOs can be sued |
| Nov 2023 | Binance + CZ | USD 4.3B + prison | Largest crypto resolution |
| Jan 2025 | KuCoin | USD 297M + founder pleas | Permissionless onboarding no defence |
| Feb 2025 | OKX | USD 504M | “We do not serve US persons” requires architectural enforcement |
| Mar 2025 | Cash App / Block | USD 160M | Identity-linkage gaps |
| Apr 2025 | Revolut Bank UAB | EUR 3.5M | AMLA-era documentation expectations |
| Jul 2026 | MiCA transition deadline | EUR 15M / 12.5% turnover | CASP obligations apply |
How does Zyphe deliver crypto AML with on-chain plus identity-linked monitoring?
Zyphe ships four primitives mapped to the crypto-specific surface.
Real-time on-chain plus off-chain monitoring. Zyphe’s AML monitoring product runs real-time scoring at authorisation time for cliff-edge rules (sanctioned counterparty, structuring at deposit, mule signatures) and batch pattern detection for cross-product behavioural rules (peeling chains, velocity over a window, mixer interaction). The on-chain typology library covers FATF Recommendation 20 named typologies plus crypto-native patterns. Median alert-to-triage time under 4 hours for cliff-edge rules at production customers.
Identity-linked alerts. Every alert carries the verified KYC credential, the KYC tier, and the perpetual re-screening status. Mule indicators fire deterministically at the rule level because identity attributes are right there in the alert payload. See our decentralised KYC primer for the underlying credential architecture.
Travel Rule compliance. Originator and beneficiary data flows with every cross-VASP transfer through the IVMS101 schema. Zyphe integrates with the major Travel Rule networks (TRP, TRUST, Sumsub Travel Rule, Notabene) and handles the data exchange without exposing the underlying PII. EU TFR’s zero-threshold rule satisfied at the AML for crypto architecture layer.
SAR filing pipeline with clock tracking. Alert open to SAR filed (or alert closed with documentation), the clock is visible. Backlog metrics (median, 95th-percentile age, broken down by typology) surface to the CCO weekly. Audit-export available in regulator-ready formats on demand.
The Zyphe precision rate (alerts that produce a SAR or documented escalation) runs at approximately 22% versus a published industry baseline of 5-8%, because the identity layer eliminates the noise that comes from monitoring against unverified wallets. A senior MLRO at a tier-1 European exchange we work with framed it on a customer call in March 2026: “the OKX settlement was the moment our board stopped asking whether we needed to integrate identity into monitoring and started asking how fast. The Zyphe stack closed the gap in nine weeks.”
How do you implement crypto AML across exchanges, brokerages, and crypto-native fintechs?
Three patterns covering the most common deployment shapes.
Centralised exchange
Real-time scoring at deposit, withdrawal, and trade execution. Sanctions screening at wallet and counterparty layer. Travel Rule data flow on cross-VASP transfers. KYC tier-driven monitoring intensity (standard CDD for low-risk, EDD with elevated thresholds for high-risk). Per-decision triage records for every alert. Median onboarding time for the AML for crypto stack: 2-4 weeks against the Zyphe sandbox.
Crypto brokerage and OTC desk
Higher per-transaction value plus institutional counterparty depth. KYB on every counterparty institution. Source-of-funds documentation on transactions above threshold. Sanctions screening at every layer (entity, directors, UBOs, wallets). Adverse media monitoring at counterparty level.
Crypto-native fintech (wallet, custody, staking)
Wallet-level KYC at sign-up. Transaction monitoring against the customer’s verified credential. Sanctions screening on counterparty wallets. Where staking or yield products are offered, additional securities-law monitoring layer. Custody-side coverage extends to the custodian’s own counterparties at higher diligence depth.
For the broader implementation pattern, see our AML transaction monitoring 2026 piece.
What are the real edge cases crypto AML still struggles with?
Five edge cases worth flagging in procurement.
Self-hosted wallet attribution. A transaction to or from a self-hosted wallet has no counterparty KYC data. The architecture has to risk-tier these flows separately and apply documented enhanced diligence rather than blanket-blocking.
Cross-chain bridge layering. Funds bridged from Ethereum to Polygon to Arbitrum and back create attribution gaps. Stacks have to integrate with chain-analysis providers (Chainalysis, TRM Labs, Elliptic) that maintain cross-chain heuristics.
Mixer and privacy-pool interaction. Tornado Cash is sanctioned. Privacy Pools 2.0 and similar compliant-mixer designs are not. The AML for crypto system has to distinguish, with documented residual risk where the distinction is unclear.
DeFi protocol interaction. A user interacting with a DeFi protocol (Uniswap, Aave, Curve) creates indirect counterparty exposure. The AML for crypto stack has to surface this without blanket-blocking DeFi flows. See our KYC for DeFi protocols guide.
MiCA-grandfathered activity. Pre-MiCA crypto-asset activity that does not fit cleanly into post-MiCA CASP categorisation. Transitional documentation depth matters more than usual.
How do you evaluate crypto AML in the next 30 days?
Five concrete moves for a crypto-business CCO, MLRO, or VP of risk.
- Inventory typology coverage. Pull your current rule library and check coverage against FATF Recommendation 20 plus crypto-native patterns (mixer interaction, peeling chains, mule indicators). Gaps are the regulator’s first finding.
- Pressure-test sanctions screening at counterparty layer. Send a synthetic transaction to a known-sanctioned address in your sandbox. If the rule the AML for crypto architecturehe architecture is wrong.
- Audit Travel Rule coverage. Pull 50 cross-VASP transfers from the last 90 days. Confirm originator/beneficiary data flowed for each. EU TFR zero-threshold rule is the post-July-2026 baseline.
- Run an audit-export drill. Pull a SAR filed 18 months ago and trace the evidence chain. If reconstructhe AML for crypto architecturethan an hour, the AML for crypto architecture is the problem.
- Update your DPIA and the AMLA per-decision defensibility documentation. AMLA-era supervision expects per-decision documentation, not just process documentation.