Coin Swap Services: AML Risks and Accounting Implications
Coin swap services have moved from a niche privacy tool to a mainstream compliance problem. As centralised exchanges tighten know-your-customer requirements, illicit actors are routing funds through no-KYC conversion platforms that leave no identity trace. A September 2026 briefing from blockchain analytics firm Elliptic sets out the mechanics, the scale of the risk, and — critically — the indirect sanctions exposure that now threatens any firm touching dollar stablecoins. For accounting teams and compliance officers who rely on crypto accounting software to flag suspicious flows, this briefing changes the baseline.
What Coin Swap Services Are and Why They Matter
A coin swap service converts one cryptocurrency into another without requiring the user to create an account, submit identity documents, or interact with a regulated intermediary. There is no order book, no custodian, and no AML check. The user sends one asset; the service returns a different one, often within minutes.
Why centralised exchanges are no longer the preferred off-ramp
Centralised exchanges require AML registration, customer due diligence, and transaction monitoring. That compliance infrastructure creates exactly the kind of audit trail that bad actors want to avoid. Coin swap services, by design, exist outside that perimeter. They are not necessarily illegal in every jurisdiction, but their structural absence of identity controls makes them attractive to anyone seeking to obscure the origin of funds.
Elliptic's briefing notes that the rising adoption of these services tracks directly with tighter enforcement at centralised venues. As one door closes, another opens — and the door that opens has no KYC requirement attached.
How funds move through a coin swap chain
The typical pattern involves multiple sequential swaps. A wallet holding proceeds from a sanctioned actor converts into one asset, swaps again into a second, and eventually arrives at a widely accepted asset — often a US dollar stablecoin — held in a wallet that looks clean at first glance. Each swap adds a hop between the origin and the destination, diluting the apparent connection to the illicit source.
For compliance teams, the challenge is that a single-hop screen — checking only the immediate counterparty — will miss the link entirely. The risk is real even if the firm never directly transacted with a sanctioned entity.
Indirect Sanctions Exposure: The Compliance Risk That Travels
Indirect exposure is the concept that sits at the centre of Elliptic's briefing. It arises when a wallet or transaction is connected to a sanctioned entity not directly, but through one or more intermediate steps. Regulated firms can acquire this exposure without ever knowingly touching a restricted party.
How indirect exposure reaches a clean wallet
Consider a sequence of three transactions. The first moves value from a wallet linked to a sanctioned actor. The second runs it through a coin swap service. The third lands the converted asset in a wallet used by an otherwise legitimate counterparty. The legitimate firm then transacts with that wallet. The sanctions link is now three hops back, but it exists, and in the United States, OFAC's strict liability standard means intent is not a defence.
Elliptic explicitly highlights this multi-hop dynamic. Their tooling is designed to assess how closely a wallet or transaction is connected to sanctioned entities across multiple hops and across multiple chains — not just on a single ledger. That cross-chain dimension matters because coin swap services frequently route through bridging infrastructure, making a single-chain screen insufficient.
The stablecoin dimension
Elliptic's research identifies a specific and significant data point: Iran-linked actors have acquired US dollar stablecoins worth at least half a billion dollars. This is not a theoretical risk. Sanctioned actors are actively using coin swap services to access dollar-denominated value, and they are holding it in stablecoin form.
The implications spread in two directions. First, stablecoin issuers carry an obligation to detect and freeze addresses linked to sanctioned jurisdictions — the OFAC framework applies to them as US-nexus entities regardless of where the end user is located. Second, any firm that accepts, settles in, or holds dollar stablecoins as part of its treasury or client operations may be sitting on indirect exposure without knowing it. This is no longer a risk confined to crypto-native firms; it applies to any corporate treasury that has adopted stablecoin settlement.
The broader regulatory context reinforces the urgency. Read our coverage of OFAC sanctions against Xinbi Guarantee and what they mean for crypto accounting teams for a parallel enforcement example where stablecoin flows were central to the illicit activity.
Accounting and Audit Implications for Firms
The compliance risk described above has direct accounting consequences that firms cannot treat as a legal team problem alone.
Asset recognition and impairment
Under both IFRS and US GAAP, a firm holds a digital asset at its recognised value until there is evidence that recovery is impaired. If a stablecoin or other digital asset in a firm's treasury is subsequently linked to a sanctioned source, the asset may become non-transferable — effectively frozen — pending investigation. That triggers an impairment review. The accounting entry cannot wait for the legal outcome; the moment the asset is restricted, the balance sheet treatment changes.
Firms using digital asset accounting software need to confirm that their systems can flag assets under review and suspend them from normal valuation workflows. A frozen asset valued at par is a misstatement.
Transaction monitoring integration with the general ledger
The gap that coin swap services exploit is not just a KYC gap — it is a data gap. Most crypto bookkeeping software records what goes in and what comes out. It records counterparty addresses. What it often does not do is assess the risk heritage of those addresses across multiple hops and chains before recording the entry as clean.
Best practice now requires that transaction monitoring output, specifically the risk score or sanction flag generated by a blockchain analytics provider, is captured as metadata alongside each ledger entry. If that metadata subsequently changes — because a counterparty address is newly designated — the firm needs a workflow that triggers a review of every historical entry associated with that address. That is a process design question as much as a software question, and it needs to be answered before an enforcement action, not after.
Disclosure obligations and going-concern considerations
For auditors, coin swap exposure introduces a disclosure question. If a client holds material stablecoin balances and has no documented process for multi-hop sanctions screening, the auditor should be asking whether that represents an unquantified contingent liability. Depending on materiality, it may require disclosure in the notes to the financial statements. In extreme cases, where a firm's stablecoin holdings are large relative to equity and the screening gap is significant, the auditor may need to consider whether a going-concern flag is warranted.
This is not an abstract scenario. Enforcement actions for sanctions violations in the digital asset space have resulted in penalties that exceeded the firms' net assets. The accounting profession needs to treat indirect sanctions exposure as a measurable risk, not a background legal concern.
Practical Steps for Compliance and Finance Teams
The Elliptic briefing is a diagnostic. The response needs to be operational.
Reviewing your current screening configuration
Most compliance teams have configured their blockchain analytics tools to flag direct exposure — wallets on sanctions lists, addresses associated with known illicit actors. The coin swap risk requires extending that configuration to indirect exposure across multiple hops. Teams should review the hop-depth settings in their current screening rules and confirm whether cross-chain tracing is enabled. If the firm's current tooling cannot perform multi-hop, multi-chain analysis, that is a capability gap that needs to be escalated to procurement.
Stablecoin treasury review
Any firm holding US dollar stablecoins in its treasury — whether for settlement, yield, or liquidity purposes — should run a retroactive screen of the inbound flows that funded those holdings. The screen should look back at least twelve months and apply indirect exposure criteria, not just direct sanctions matching. The results should be documented and retained as evidence of a reasonable compliance posture.
Legislative developments on the horizon will sharpen these obligations further. Our analysis of how the CLARITY Act targets non-decentralised DeFi operators and their AML obligations shows how the regulatory perimeter around conversion services is already being redrawn in statute.
Updating AML policies and procedures
Written AML policies at most firms still describe the risk landscape as it existed when centralised exchanges were the primary conversion venue. That description is now incomplete. Policies should be updated to name coin swap services explicitly as a high-risk typology, describe the multi-hop exposure mechanism, and set out the firm's approach to detecting and managing it. Without that written update, a firm that suffers an enforcement action cannot demonstrate that it had identified the risk as material.
Frequently Asked Questions
What is a coin swap service and how does it differ from a centralised exchange?
A coin swap service converts one cryptocurrency into another without requiring user registration or identity verification. A centralised exchange requires account creation, customer due diligence, and operates under AML licensing. Coin swap services are not regulated as exchanges in most jurisdictions, which is precisely what makes them attractive to those seeking to obscure fund origins.
How can a firm become exposed to sanctions risk through coin swap services without transacting with a sanctioned party directly?
When funds pass through one or more coin swap services before reaching a firm's counterparty, the sanctions link travels with the funds but is separated by intermediate transactions. OFAC's strict liability standard in the US does not require intent for a violation, so indirect exposure several hops back can still constitute a breach if the link exists.
Why does the stablecoin finding in the Elliptic briefing matter for corporate treasurers?
Elliptic's research shows that Iran-linked actors have acquired at least half a billion dollars in US dollar stablecoins. Corporate treasurers holding stablecoins for settlement or liquidity may be holding assets with an indirect sanctions link if their inbound flows were not screened for multi-hop exposure. The risk is not confined to crypto-native businesses.
What accounting treatment applies if a digital asset is frozen due to a suspected sanctions link?
Once an asset is restricted and cannot be transferred, it is no longer recoverable at par in the normal course. That triggers an impairment review under both IFRS and US GAAP. The asset should be assessed for its recoverable or realisable value in a restricted state, and the financial statements should reflect any impairment. Valuing it at par while it is frozen would be a misstatement.
What should accounting firms ask clients about coin swap exposure during an audit?
Auditors should ask whether the client has a documented process for multi-hop sanctions screening, whether that process covers cross-chain flows, and whether retroactive screening of stablecoin inflows has been performed. If material stablecoin balances exist and no such process is in place, the auditor should consider whether an unquantified contingent liability requires disclosure in the notes.
Source: Elliptic
