CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Bitcoin ATM Scams: What Banks and Accounting Firms Must Do Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Bitcoin ATM Scams: What Banks andAccounting Firms Must Do Now

Crypto ATM fraud has moved from a niche concern to a supervisory priority across the US, UK, Canada, and Australia. Regulators in each jurisdiction have either restricted these kiosks outright or introduced licensing and transaction rules, and financial intelligence bodies have described them as a primary channel for collecting and laundering fraud proceeds. For banks, accounting firms, and CFOs with exposure to crypto-active clients, the practical question is no longer whether this typology matters, it is whether your controls are calibrated to catch it.

Bitcoin ATM Scams: What Banks and Accounting Firms Must Do Now

How the Scam Actually Works

The mechanics are consistent and deliberately simple. A fraudster impersonates a trusted authority, a government agency, law enforcement, a bank's own fraud team, a utility company, or even a romantic contact, and then manufactures urgency. The victim is told that overdue taxes, an account compromise, or some other emergency requires immediate cash payment. The cash has to go into a Bitcoin ATM, and the scammer supplies a QR code that routes the deposit directly into a wallet they control.

Why Kiosks Are Preferred by Fraudsters

Bitcoin ATMs remove friction. Unlike a bank wire, there is no cooling-off period, no second-factor confirmation, and no human counterparty at the receiving end to ask questions. The cash-to-crypto conversion is effectively instantaneous. Once the transaction is on-chain, the fraudster can move funds across wallets, through mixers, and onto exchanges in a matter of minutes. The victim often realises what has happened only after the funds are irretrievable through ordinary means.

The FBI's Internet Crime Complaint Center has documented that losses attributable to this typology are large and rising, though the precise annual figures depend on the reporting period. What the data consistently shows is that older customers are disproportionately targeted, partly because they are more likely to use a bank's teller window, which is also the point where intervention is most feasible.

The Regulatory Response Across Key Jurisdictions

Supervisors have reached a shared conclusion: Bitcoin ATMs are exploited for fraud at a scale that warrants direct intervention. The responses differ in form but converge on the same direction of travel.

United States

ATM operators in the US are already required to run Bank Secrecy Act-compliant AML programs, but FinCEN has found that compliance quality varies significantly across the sector. Several US states have moved independently: Indiana, Tennessee, and Minnesota have implemented outright bans. Other states have acted to restrict or regulate kiosk operations. Proposed federal legislation would require operators to register, apply transaction limits, verify customer identities, display fraud warnings, and offer full refunds to new customers who report a problem within 30 days. Notably, that same legislation names blockchain analytics as a required control, a clear signal of where supervisory expectations are heading at the federal level.

On the information-sharing side, Section 314(a) of the PATRIOT Act allows law enforcement to request that FinCEN solicit information from banks on its behalf, and Section 314(b) permits voluntary bank-to-bank information sharing. Blockchain analytics significantly enriches both processes by giving banks the ability to provide on-chain evidence, not just fiat transaction records, when responding to or initiating a 314 query.

United Kingdom, Canada, and Australia

The UK's FCA licensing regime has left Bitcoin ATMs effectively banned: no operator has received registration, so any kiosk operating without it is doing so illegally. Australia has imposed transaction limits on operators. Canada's financial intelligence unit, FINTRAC, has described Bitcoin ATMs as a primary method for collecting and laundering fraud proceeds, and Canadian operators face reporting obligations under the country's Proceeds of Crime legislation. The US Federal Trade Commission has put the risk more plainly still, describing crypto ATMs as a preferred tool for fraud. Taken together, the international picture reflects a consistent supervisory consensus, not a patchwork of isolated reactions.

For context on how regulators and financial intelligence units are treating crypto ATM risk as a primary AML concern, the FATF's recent enforcement push on stablecoin and crypto crime provides useful background on the broader supervisory direction: how regulators and financial intelligence units are treating crypto ATM risk as a primary AML concern.

What Banks Can Do on the Fiat Side

A bank's first point of intervention is the cash withdrawal. The fraud runs on cash before it runs on cryptoassets, and that withdrawal is where trained staff can stop it. The behavioural signals tend to cluster around a recognisable pattern.

Red Flags at the Teller Window

Staff should be alert to customers who mention an instruction from a government agency, a bank fraud team, or a family member in distress as the reason for the withdrawal. An unusual single withdrawal, or a series of withdrawals calibrated just below reporting thresholds, also warrants closer attention: the latter pattern can indicate coaching by a fraudster trying to avoid a Suspicious Activity Report trigger. Because older customers disproportionately use the teller window rather than digital channels, branch staff are often better positioned to intervene than automated monitoring alone.

A short sequence of follow-up questions is usually sufficient to clarify the situation: who asked the customer to make the withdrawal, why, how did they make contact, and did they ask the customer to scan a QR code or deposit cash at a machine. Clear internal escalation rules matter here: staff need to know when they can approve a withdrawal, when they can hold it, and when it must go to the fraud team, with each decision recorded consistently.

What Blockchain Analytics Adds on the On-Chain Side

Once cash leaves the branch, a bank operating without on-chain visibility loses the thread entirely. That is precisely what the scam relies on. But the assumption that crypto funds are untraceable once they leave the kiosk is increasingly out of date.

Wallet Attribution and Exposure Screening

Public blockchains maintain a permanent, unalterable record of every transaction. Blockchain analytics tools attribute wallets and clusters to known entities, including specific crypto ATM operators. When a bank screens a customer's wallet or a counterparty's address, any exposure that traces back to a labelled kiosk, whether direct or several hops removed, becomes visible. For a bank that custodies cryptoassets or offers crypto services, that converts an intuition about kiosk involvement into a measurable, auditable risk indicator.

A December 2025 case illustrates the capability. The US Department of Justice secured a recovery of more than $200,000 after four elderly victims were defrauded by scammers posing as their banks' fraud teams and directed to deposit cash at Bitcoin ATMs. Investigators traced the funds on-chain to a wallet at an exchange based in the Seychelles. Attribution of wallets and transactions to known entities made that trail followable across wallets, exchanges, and multiple blockchain hops.

The Nested Operator Problem

One complication worth flagging explicitly: crypto ATM operators sometimes run as nested services, clearing their activity through an account at a larger exchange rather than presenting directly to the banking system. On-chain, the flows tend to resemble the host exchange rather than the underlying kiosk operator. A screening tool that stops at the exchange label will miss the nested operator entirely. Attribution quality, specifically the ability to identify the operator sitting behind the exchange account, is what determines whether the screen is meaningful or superficial.

Operator Due Diligence

Banks may also encounter crypto ATM operators as direct counterparties, when an operator seeks a bank account to fund its machines. On-chain activity should be central to that onboarding due diligence. The relevant questions are whether the operator's transaction flows match its stated business model, whether it shows direct exposure to high-risk wallets or sanctions-listed addresses, and whether its volumes and counterparty patterns are consistent with a legitimate kiosk business. Crypto bookkeeping software and digital asset accounting software that integrates on-chain data can support this process by making the operator's transaction history auditable rather than self-reported.

Bitcoin ATM Scams: What Banks and Accounting Firms Must Do Now

Implications for Accounting Firms and CFOs

The direct exposure for most accounting firms is not running a Bitcoin ATM. It is advising clients who may interact with them, processing books that include transactions originating from kiosks, or auditing financial institutions with crypto ATM-related risk in their AML frameworks.

Client Transaction Screening

Crypto accounting software that includes on-chain attribution data lets an accounting firm or CFO identify whether a client's crypto holdings include funds that trace back to a kiosk, and whether that kiosk is associated with known compliance failures. This matters both for AML purposes and for financial reporting: a client holding funds with a traceable connection to fraud proceeds carries contingent liability that should not be ignored in a balance sheet review or an audit.

AML Program Adequacy

For accounting firms advising banks or payment businesses on their AML programs, the regulatory direction is clear. The US proposed legislation naming blockchain analytics as a required control, FINTRAC's designation of Bitcoin ATMs as a primary laundering channel, and the FCA's effective de-licensing of UK kiosks all point toward an expectation that financial institutions have on-chain screening capability, not just fiat transaction monitoring. An AML program that lacks on-chain wallet screening is increasingly difficult to defend as adequate under current supervisory standards.

The UK Fraud Review's call for greater judicial and institutional awareness of crypto laundering typologies reinforces this point: the UK Fraud Review's call for greater judicial and institutional awareness of crypto laundering typologies makes clear that institutions relying solely on fiat-side controls will face increasing scrutiny.

SAR and Disclosure Obligations

When branch staff identify a suspected Bitcoin ATM scam, the bank's SAR filing obligation is triggered under BSA rules in the US, the Proceeds of Crime Act in the UK, and equivalent legislation in Canada and Australia. Accounting firms advising clients on compliance frameworks should confirm that their clients' escalation procedures are calibrated to capture kiosk-related red flags at the point of cash withdrawal, not only after a complaint is received. Timing matters: a SAR filed after funds have left the kiosk is significantly less useful to law enforcement than one filed before the withdrawal is completed.

Firms using digital asset accounting software with on-chain data integration are better placed to document the provenance of crypto assets on a client's books and to support SAR narratives with traceable transaction evidence when needed.

The Practical Checklist

Based on the regulatory signals across US, UK, Canada, and Australia, the following actions are defensible priorities for any financial institution or advisory firm with crypto-active clients.

Immediate Steps

First, review branch staff training to confirm that Bitcoin ATM scam typologies are covered explicitly, including the specific language and scenarios fraudsters use. Second, check that transaction monitoring rules include thresholds and patterns associated with structured cash withdrawals preceding kiosk deposits. Third, confirm that the firm's crypto accounting software or digital asset accounting software includes wallet screening with kiosk attribution, not just exchange-level labelling.

Medium-Term Steps

Review the AML program documentation to ensure it reflects current supervisory expectations on on-chain screening. If the firm advises crypto ATM operators directly, conduct a gap analysis against the BSA requirements and the emerging state-level rules. For audit engagements covering banks with crypto services, add Bitcoin ATM typology testing to the AML program review scope. Finally, track the progress of the proposed federal legislation in the US: if it passes, the blockchain analytics requirement will become a compliance baseline, not a competitive differentiator.

Source: Elliptic

Frequently Asked Questions

USUKCAGeneralEnforcementAML/KYC & Licensing

FAQ

Are Bitcoin ATM operators subject to AML rules in the United States?

Yes. Bitcoin ATM operators in the US are required to run Bank Secrecy Act-compliant AML programs, including customer identification, transaction monitoring, and suspicious activity reporting. FinCEN has found that compliance quality varies significantly across the sector, and several states have introduced additional restrictions or outright bans.

What is the legal status of Bitcoin ATMs in the United Kingdom?

The FCA requires any crypto ATM operator to be registered under the UK's cryptoasset registration regime. As no operator has successfully obtained that registration, Bitcoin ATMs are effectively banned in the UK. Any kiosk operating without FCA registration is doing so unlawfully.

How can a bank detect a Bitcoin ATM scam before the cash leaves the branch?

The primary signal is the cash withdrawal itself. Branch staff trained to recognise the typology can ask targeted questions: who directed the customer to make the withdrawal, why, and whether a QR code is involved. Structured withdrawal patterns, such as multiple transactions just below reporting thresholds, can also trigger monitoring alerts. Clear escalation procedures and contemporaneous recording of decisions are essential.

What is a nested crypto ATM operator and why does it matter for compliance?

A nested operator is a crypto ATM business that clears its transactions through an account at a larger, better-known exchange rather than presenting directly to the banking system. On-chain, the flows appear to originate from the host exchange, obscuring the underlying operator. A screening tool that only identifies the exchange label will miss the nested operator entirely. Blockchain analytics tools with detailed attribution can identify the nested operator behind the exchange account.

Does crypto accounting software need on-chain data to be useful for AML purposes?

For AML and compliance purposes, crypto accounting software that integrates on-chain attribution data is significantly more useful than software that records only fiat-equivalent values. On-chain data allows firms to identify whether a client's crypto holdings trace back to flagged kiosks, sanctions-listed wallets, or other high-risk sources, which is increasingly expected under current supervisory standards across the US, UK, Canada, and Australia.

Related articles

AML/KYC & Licensing
Approval Phishing Detection and Disruption: Compliance and Investigation Playbooks
AML/KYC & Licensing
Huione Group: World's Largest Illicit Marketplace and the USDH Stablecoin Risk
AML/KYC & Licensing
EU Sanctions 'Stern': Trickbot Boss and the $300M Ransom Trail
AML/KYC & Licensing
AI Governance in Compliance: The Accountability and Control Gap Regulators Are Already Watching