CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Crypto Money Laundering Typologies: What Compliance Teams Must Know

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING Crypto Money Laundering Typologies:What Compliance Teams Must Know

Money laundering typologies in crypto are no longer edge cases reserved for specialist investigators. As digital assets move deeper into mainstream finance, accounting firms, auditors, and CFOs handling client portfolios need a working understanding of how illicit behaviour is classified on-chain, and what red flags their crypto accounting software and compliance workflows should be catching. This article unpacks the core typologies, how blockchain analytics surfaces them, and what the practical implications are for your firm.

Crypto Money Laundering Typologies: What Compliance Teams Must Know

What a Typology Actually Is

In the context of cryptoassets, a typology is a formal classification applied to a specific pattern of on-chain behaviour that is associated with financial crime. Each typology represents a distinct risk profile: a recognisable sequence of wallet interactions, fund flows, or exchange activity that, when viewed together, signals potential illicit conduct.

Typologies matter because they move the compliance conversation away from vague, anecdotal concerns about crypto crime and toward something auditable and actionable. A well-documented typology comes with its own list of red flags, its own data signatures, and, increasingly, its own regulatory treatment.

Why Crypto Creates Specific Typology Risk

Traditional money laundering relies on layering transactions through opaque financial systems. Crypto introduces several structural features that criminals exploit: wallet creation requires little or no identity verification on many platforms; pseudonymous addresses provide a layer of separation from real-world identities; and jurisdictional fragmentation means a transaction can touch several regulatory regimes in seconds.

Weak or absent Customer Due Diligence at certain exchanges or wallet providers compounds this. Where a platform applies minimal KYC, it becomes a natural congregation point for illicit fund flows, and that concentration is precisely what blockchain analytics is designed to detect.

Three Core Typologies on the Blockchain

Blockchain analytics firms and regulators have catalogued a growing library of typologies. Three appear consistently across enforcement actions and guidance from bodies such as the Financial Action Task Force (FATF) and FinCEN.

Unlicensed and Non-Compliant Exchange Abuse

Exchanges are the primary on-ramps and off-ramps between fiat and crypto ecosystems. That liquidity function makes them attractive to criminals who need to convert illicit proceeds into ostensibly clean funds, whether into another cryptocurrency or back into fiat currency.

The typology centres on routing funds through exchanges that operate without proper licensing or that apply inadequate AML controls. Because these platforms do not collect meaningful identity information or file Suspicious Activity Reports (SARs), they create a compliance gap that bad actors actively seek out.

The US Department of Justice's 2018 indictment of Payza, an unregistered money service business, illustrated the scale of damage possible: the platform was alleged to have facilitated the laundering of up to $250 million through Bitcoin and other cryptocurrencies. Payza is cited in the source material as a documented example of this typology in action.

For accounting teams, the practical implication is clear. Any client transacting through an exchange that cannot demonstrate adequate licensing and AML controls carries elevated counterparty risk. That risk needs to be reflected in your client onboarding assessments and, where relevant, in the disclosures attached to financial statements covering digital asset holdings. Your crypto bookkeeping software should be able to tag transactions by counterparty risk tier, not merely record them.

Cryptocurrency ATM Exploitation

Crypto ATMs offer a fast, relatively accessible conversion mechanism between cash and digital assets. They serve a legitimate financial inclusion purpose in many markets, but they also present a well-documented laundering vector.

The typology works because ATMs can accept physical cash with limited identity checks, particularly older machines or those operating in jurisdictions with lighter touch ATM-specific regulation. A criminal can deposit dirty fiat, receive cryptocurrency to a wallet they control, and then move those funds onward through additional layers of transactions. The reverse is also possible: illicit crypto proceeds are converted to cash through an ATM, severing the on-chain trail.

FinCEN has issued guidance addressing crypto ATM operators as money service businesses, requiring them to register and maintain AML programmes. Firms advising clients who operate ATM networks, or who use them as part of treasury operations, should ensure those clients can demonstrate compliance with applicable MSB registration and SAR filing obligations.

Cluster-Based Wallet Structuring

The third typology is subtler and, for that reason, often harder to catch without dedicated tooling. It involves individuals or entities maintaining multiple wallets within the same exchange or wallet provider, where at least some of those wallets are linked to high-risk clusters: addresses associated with dark-web markets, sanctioned entities, or offshore gambling platforms.

The behaviour itself is not inherently illegal. Holding multiple wallets is routine for legitimate treasury management. What makes this a typology is the pattern: the co-mingling of low-risk wallets with wallets that interact with known illicit clusters, combined with movement of funds between them in ways that obscure the trail. Blockchain analytics identifies these connections by mapping wallet clusters and assigning risk scores based on the full graph of interactions, not just direct counterparties.

For auditors, this matters when assessing the completeness and accuracy of a client's digital asset disclosures. If a client's reported holdings sit alongside wallets touching sanctioned clusters, the auditor's liability exposure changes materially.

How Blockchain Analytics Identifies Typologies

Every transaction on a public blockchain is permanently recorded and openly readable. Blockchain analytics works by ingesting this public data, mapping wallet addresses into clusters of likely shared ownership, and then scoring those clusters against known risk indicators.

The Red Flag Framework

Each typology generates its own set of red flags. For the non-compliant exchange typology, red flags might include: transactions routed through addresses on sanctions lists, counterparty exchanges with no verifiable regulatory registration, or transaction volumes inconsistent with the client's stated business activity. For the ATM typology, red flags include repeated small cash deposits at multiple ATM locations within short time windows, a pattern that mirrors the structuring behaviour associated with traditional cash smurfing.

When these signals are detected, the relevant data can be packaged and passed to regulatory authorities, including FinCEN, OFAC, or the relevant national financial intelligence unit, for follow-up. The firm providing the blockchain analytics is not making the enforcement determination; it is flagging the pattern and preserving the evidence trail.

Implications for Digital Asset Accounting Software Selection

Not all digital asset accounting software is built with compliance-grade analytics in mind. A platform that simply imports transaction history and calculates gain/loss figures does not, on its own, surface typology risk. Accounting firms advising clients with material crypto holdings should be asking vendors two pointed questions: does the platform integrate with blockchain analytics providers that maintain typology libraries, and does it produce audit-ready outputs that map transactions to risk classifications?

The FATF's periodic typologies reports, as well as FinCEN's SAR filing data, both point to a compliance environment where the expectation on reporting entities is rising. Firms that rely solely on internal reconciliation tools, without any link to on-chain risk scoring, are building on an increasingly fragile foundation. Regulators are unlikely to accept "our accounting software didn't flag it" as a mitigant.

Regulatory Context: FATF, FinCEN, and the Evolving Standard

The Financial Action Task Force publishes dedicated typologies reports covering the cryptoasset sector. These documents consolidate case studies and red flag indicators from member jurisdictions and set the benchmark for what a "risk-based approach" looks like in practice. National regulators, including FinCEN in the United States, build their own guidance on this foundation.

The US Regulatory Position

In the US, virtual asset service providers (VASPs) are treated as money service businesses under the Bank Secrecy Act. That means registration with FinCEN, implementation of an AML programme, SAR filing, and adherence to the Travel Rule for qualifying transfers. Failures on any of these fronts create both criminal and civil liability, not just for the VASP itself, but potentially for the accounting or advisory firm that signed off on the client's compliance posture without adequate due diligence.

The legislative picture is also shifting. Read our coverage of how the revised CLARITY Act targets DeFi AML obligations for the most recent developments on how Congress is extending the compliance perimeter to decentralised platforms. Separately, enforcement is already moving: our analysis of OFAC's sanctions action against Xinbi Guarantee and its crypto accounting implications shows how quickly wallet-level exposure can become a firm-level liability.

What Accounting Firms and CFOs Should Do Now

Understanding typologies at a conceptual level is not sufficient. The compliance obligation for accounting and advisory firms is to operationalise that understanding: to embed it in client onboarding, in ongoing monitoring, and in the technology stack used to manage digital asset records.

Practical Steps for Firms

First, map your client base against typology risk. Which clients operate or interact with crypto ATMs? Which hold assets on exchanges you cannot independently verify as licensed? Which have wallet addresses that have not been screened against sanctions lists and high-risk cluster databases? These questions should be part of your periodic client risk review, not a one-time onboarding checkbox.

Second, review your software stack. If your current crypto bookkeeping or accounting tools do not produce transaction-level risk classifications linked to a typology framework, that is a gap. The minimum standard should be on-chain screening against sanctions lists; the emerging standard includes typology-aware risk scoring.

Third, document your methodology. Regulators and auditors increasingly expect firms to be able to demonstrate, with evidence, that they considered typology risk and applied a proportionate response. A written AML risk assessment that references FATF typology guidance and maps it to your client portfolio is defensible. A spreadsheet of transaction hashes with no risk layer is not.

Fourth, stay current. Typologies evolve as criminal actors adapt to analytics tooling. FATF updates its guidance periodically; FinCEN issues advisories when new patterns emerge. Building a process to monitor these updates, and to refresh your client risk assessments accordingly, is now a core part of a credible AML programme for any firm active in the digital asset space.

Crypto Money Laundering Typologies: What Compliance Teams Must Know

Frequently Asked Questions

What is a money laundering typology in the context of crypto?

A typology is a formal classification of a specific pattern of on-chain behaviour linked to financial crime. It describes a recognisable sequence of transactions, wallet interactions, or exchange activity that, taken together, signals a meaningful risk of illicit conduct such as layering or placement of criminal proceeds.

Which regulatory body sets the standard for crypto AML typologies?

The Financial Action Task Force (FATF) is the primary international standard-setter. It publishes dedicated typologies reports for the virtual asset sector. In the US, FinCEN operationalises FATF guidance through Bank Secrecy Act regulations and periodic advisories covering specific typologies observed in SAR filings.

Does my accounting firm have AML obligations if we advise crypto clients?

This depends on your jurisdiction and the specific services you provide. In the US, accounting firms that act as intermediaries for crypto transactions or that have defined AML programme obligations under applicable rules must comply with those requirements. Even where a direct legal obligation does not apply, professional standards and reputational risk create a strong practical incentive to conduct proper due diligence on client crypto activity, including typology screening.

What red flags should crypto accounting software be able to detect?

At a minimum, the software or an integrated analytics layer should flag transactions with addresses on OFAC sanctions lists, counterparty wallets linked to known illicit clusters such as dark-web markets, structuring patterns at ATMs or exchanges, and transaction volumes inconsistent with a client's stated activity profile. The specific red flags vary by typology, but sanctions screening is the baseline expectation from most regulators.

How often should firms update their typology risk assessments?

There is no universal prescribed frequency, but FATF guidance and FinCEN advisories both emphasise a risk-based, ongoing approach rather than a static annual review. At a minimum, assessments should be refreshed when FATF or FinCEN publish new typology guidance, when a client's activity profile changes materially, or when a new enforcement action reveals a pattern that applies to your client base.

Source: Elliptic

GLOBALUSGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Crypto in Conflict: Sanctions Risk, DeFi Fundraising, and What Firms Must Know
AML/KYC & Licensing
Coin Swap Services: AML Risks and Accounting Implications
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $8.4B Illicit Marketplace Means for Crypto Accounting
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $36B Scam Marketplace Means for Crypto Accounting