Anti-Money Laundering

From Bitcoin Wiki
Jump to navigation Jump to search

Anti-money laundering (AML) refers to laws and regulations preventing financial services from being used to hide criminal proceeds or fund illegal activity. It can comprise registration or licensing, KYC, and transaction monitoring.

In Bitcoin, users are pseudonymous, identified by a random address. It does not perform AML checks. Bitcoin transactions are instead authorized with signatures, broadcast to the network and eventually recorded in the blockchain. The Bitcoin white paper described its privacy model as keeping public keys anonymous while making transactions public.[1] AML obligations therefore usually arise at the points where a person or business exchanges or holds bitcoin on behalf of others, rather than in Bitcoin's consensus rules themselves.

Whether a Bitcoin activity is regulated depends on the applicable law and the facts of the activity. An ordinary user spending their own bitcoin, a custodian operating customer wallets, a professional peer-to-peer dealer and a developer publishing wallet software do not necessarily have the same status. This article describes major frameworks and examples but is not legal advice.

Bitcoin features which affect AML

Bitcoin contains many concepts which are all inspected by AML compliance tools. Addresses and transactions do not contain a person's legal identity. A service can, however, associate addresses and transactions with customer records, bank transfers, IP addresses or other off-chain information.

Transactions can always be retrieved for analysis if they have been confirmed in a block or downloaded from the mempool, even if they dropped from the mempool later. Researchers have shown that address clustering and supplementary information can associate addresses with services and users.[2]

A self-custody user can control keys and transact without depositing bitcoin in an exchange. A transfer between two self-hosted wallets therefore has no regulated intermediary carrying out customer due diligence or filing a suspicious transaction report.

Protocol, users and service providers

A Bitcoin service can interact with customers and businesses across borders, including in jurisdictions with incompatible AML requirements. A few are examples are listed here

Bitcoin activity AML relevance
A person holding bitcoin in a self-custodial wallet and paying on their own behalf Not classified as a money transmitter. However, payment processors may still ask for personal information during payment.
A custodial Bitcoin exchange or hosted wallet Classified as virtual-asset service providers (VASPs) or money transmitter because it exchanges or controls bitcoin for customers.
A Bitcoin ATM, broker or payment processor Usually regulated as a money transmitter. There have been instances of Bitcoin ATMs being banned for AML reasons.
A professional peer-to-peer Bitcoin dealer Classified as a money transmitter even when trades are arranged informally or settled directly between wallets.
A miner or mining pool Many countries do not consider miners or mining pools as VASPs because producing bitcoin or distributing pool rewards is not necessarily money transmission.
A full node operator Not classified as a money transmitter.
A wallet software developer Not usually classified as a money transmitter, however, there have been instances where individuals developers of exchanges, swap services, and mixers have been prosecuted as money transmitters.
A Bitcoin mixer or tumbler A person that accepts and retransmits customers' bitcoin is treated as a regulated transmitter in many countries.

International framework

FATF standards

The Financial Action Task Force (FATF) sets international AML and counter-terrorist financing standards that jurisdictions implement through national law. Its definition of a virtual asset service provider (VASP) is a person conducting covered activities as a business for or on behalf of another person.

In the Bitcoin ecosystem, the definition can cover activities such as exchanging bitcoin for fiat currency, exchanging it for another virtual asset, and transferring or safeguarding bitcoin for customers.

FATF's guidance from 2021 says jurisdictions should assess Bitcoin-related risks, require covered VASPs to be licensed or registered, supervise them and apply preventive measures such as customer due diligence, recordkeeping and suspicious transaction reporting.[3] The standards call for a risk-based approach rather than treating every Bitcoin user and transaction as equally risky. This can include evaluating an entity based on service offered, customer profile, transaction pattern, source of funds, geographic exposure and strength of a counterparty's controls.

Implementation remains uneven. FATF reported in June 2025 that 99 jurisdictions had passed or were in the process of passing legislation implementing the Travel Rule, while continuing to identify gaps in licensing, registration, supervision and cross-border implementation.[4] Consequently, a Bitcoin transfer between services in different countries may encounter mismatched requirements.

Travel Rule

The "Travel Rule" as defined by FATF does not refer to travellers. It refers to the financial history of a customer being shared by one provider to another. This is usually accomplished via a centralized regulatory service. In this way, a user's financial history "travels" between two platforms.

VASPs are required to collect identifying information of a transaction above a defined threshold such as USD or EUR 1,000, but national thresholds and implementations differ. Even below such a threshold, FATF's model still calls for specified names and wallet addresses or a unique transaction reference, and suspicious circumstances can trigger verification.[3]

This is why exchanges may freeze an account ask a customer for information about the owner of a destination address even if there has been no transfer to a restricted entity.

Self-hosted wallets and peer-to-peer transfers

FATF defines a peer-to-peer transfer as one made without a VASP or other obliged entity, such as a transfer between two self-custody wallets. Its 2021 guidance says such transfers are not explicitly subject to AML controls under the FATF standards.

United States

Enforcement of the FATF recommendations is done by FinCEN. In the United States, the Bank Secrecy Act (BSA) authorizes reporting and recordkeeping requirements intended to help detect and prevent money laundering. The Financial Crimes Enforcement Network (FinCEN) administers the federal BSA framework.[5]

Obligations of a covered Bitcoin money transmitter

A Bitcoin business that qualifies as a money transmitter must generally register with FinCEN as a money services business within 180 days of starting that activity. It must maintain a written, risk-based AML program. FinCEN describes four minimum elements:

Policies, procedures and internal controls A designated person responsible for compliance Training for appropriate personnel Independent review of the program

The program should should include:

Identifying customers Retaining transaction and wallet information Monitoring cash and Bitcoin flows Responding to law-enforcement requests and reporting suspicious activity

FinCEN says covered money transmitters must file a suspicious activity report (SAR) when a transaction conducted or attempted through the business is both suspicious and at least USD 2,000. The listed grounds include suspected criminal proceeds, evasion of the Bank Secrecy Agreement (BSA), lack of an apparent lawful purpose or use of the business to facilitate crime. The report is generally due within 30 days of detection, and a copy and supporting documentation must be retained for five years.[6]

FinCEN's 2019 guidance also states that a transmittal of USD 3,000 or more, or its equivalent in convertible virtual currency, may trigger the federal Funds Travel Rule, irrespective of suspicious activity, where the transaction information is shared with regulatory third-parties.[7]

Enforcement examples

In July 2017, FinCEN assessed a USD 110 million civil money penalty against BTC-e and a USD 12 million penalty against Alexander Vinnik for willful BSA violations. FinCEN described BTC-e as a foreign-located exchange doing business in the United States that exchanged fiat currency and bitcoin among other virtual currencies, and said it failed to register and maintain compliant AML, reporting and recordkeeping controls.[8]

In October 2020, FinCEN assessed a USD 60 million civil money penalty against Larry Dean Harmon, operator of Helix and Coin Ninja. FinCEN described Helix as an unregistered Bitcoin mixer that accepted and transmitted bitcoin, and called the action its first penalty against a Bitcoin mixer for BSA violations.[9] The action concerned an operated service taking part in customer transactions; it did not make every privacy tool or collaborative Bitcoin transaction legally identical to a custodial mixer.

European Union

Regulation (EU) 2023/1113 extends information requirements to transfers of bitcoin and other cryptocurrencies involving a crypto-asset service provider (CASP). For a regulated Bitcoin exchange or custodian, this means transfers must be accompanied by specified information about the originator and beneficiary. The regulation has been in effect since 30 December 2024.[10]

This regulation does not apply to peer-to-peer Bitcoin transfers made without a CASP. However, it does apply when a CASP is involved in a transfer to or from a self-hosted address.

For transfers exceeding EUR 1,000 sent or received on behalf of a CASP's client to or from a self-custody address, the CASP must verify whether that address is effectively owned or controlled by the client. CASPs must also use risk-based procedures for transfers that lack required information and for suspicious or higher-risk patterns involving self-hosted addresses.[10]

These risk-based procedures are also the cause of several false positives, where customers' accounts are frozen and KYC is demanded.

United Kingdom

Since January 2020, in-scope UK Bitcoin businesses have been required to register with the Financial Conduct Authority (FCA) and comply with the Money Laundering Regulations. The FCA regime covers exchange providers, including businesses operating exchange ATMs or certain peer-to-peer services, and custodian wallet providers that safeguard customers' assets or private keys.[11] FCA registration is a legal requirement for covered activity, not an endorsement of a Bitcoin business.

The UK's Travel Rule for cryptocurrency businesses took effect on 1 September 2023. The FCA states that covered businesses must collect, verify and share information about cryptocurrency transfers.[12]

See also

References

  1. Satoshi Nakamoto (31 October 2008). "Bitcoin: A Peer-to-Peer Electronic Cash System". https://bitcoin.org/bitcoin.pdf. Retrieved 7 August 2026.
  2. Meiklejohn, Sarah; Pomarole, Marjori; Jordan, Grant; Levchenko, Kirill; McCoy, Damon; Voelker, Geoffrey M.; Savage, Stefan (December 2013). "A Fistful of Bitcoins: Characterizing Payments Among Men with No Names". ;login: 38 (6). https://www.usenix.org/publications/login/december-2013-volume-38-number-6/fistful-bitcoins-characterizing-payments-among. Retrieved 7 August 2026.
  3. 3.0 3.1 "Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers". Financial Action Task Force. 28 October 2021. https://www.fatf-gafi.org/content/dam/fatf/documents/recommendations/Updated-Guidance-VA-VASP.pdf. Retrieved 7 August 2026.
  4. "FATF urges stronger global action to address Illicit Finance Risks in Virtual Assets". Financial Action Task Force. 26 June 2025. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-update-virtual-assets-vasps-2025.html. Retrieved 7 August 2026.
  5. "The Bank Secrecy Act". Financial Crimes Enforcement Network. https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act. Retrieved 7 August 2026.
  6. "Money Services Business (MSB) Suspicious Activity Reporting". Financial Crimes Enforcement Network. https://www.fincen.gov/money-services-business-msb-suspicious-activity-reporting. Retrieved 7 August 2026.
  7. "Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies". Financial Crimes Enforcement Network. 9 May 2019. https://www.fincen.gov/system/files/2019-05/FinCEN%20Guidance%20CVC%20FINAL%20508.pdf. Retrieved 7 August 2026.
  8. "FinCEN Fines BTC-e Virtual Currency Exchange $110 Million for Facilitating Ransomware, Dark Net Drug Sales". Financial Crimes Enforcement Network. 27 July 2017. https://www.fincen.gov/news/news-releases/fincen-fines-btc-e-virtual-currency-exchange-110-million-facilitating-ransomware. Retrieved 7 August 2026.
  9. "First Bitcoin Mixer Penalized by FinCEN for Violating Anti-Money Laundering Laws". Financial Crimes Enforcement Network. 19 October 2020. https://www.fincen.gov/news/news-releases/first-bitcoin-mixer-penalized-fincen-violating-anti-money-laundering-laws. Retrieved 7 August 2026.
  10. 10.0 10.1 "Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113". European Banking Authority. 4 July 2024. https://www.eba.europa.eu/sites/default/files/2024-07/6de6e9b9-0ed9-49cd-985d-c0834b5b4356/Travel%20Rule%20Guidelines.pdf. Retrieved 7 August 2026.
  11. "Cryptoassets: AML / CTF regime". Financial Conduct Authority. https://www.fca.org.uk/firms/financial-crime/money-laundering-terrorist-financing/cryptoassets-aml-ctf-regime. Retrieved 7 August 2026.
  12. "FCA sets out expectations for UK cryptoasset businesses complying with the Travel Rule". Financial Conduct Authority. 17 August 2023. https://www.fca.org.uk/news/statements/fca-sets-out-expectations-uk-cryptoasset-businesses-complying-travel-rule. Retrieved 7 August 2026.