CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Cross-Chain Crime: What the Elliptic Report Means for Crypto AML and Accounting

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING Cross-Chain Crime: What the EllipticReport Means for Crypto AML andAccounting

Ransomware groups and hackers are no longer constrained by individual blockchains. According to Elliptic's State of Cross-Chain Crime report, decentralized exchanges and cross-chain bridges have become the preferred plumbing for moving illicit funds across assets and networks, creating a category of laundering risk that traditional transaction monitoring was never built to catch. For accounting firms, auditors, and CFOs with digital asset exposure, that gap is a liability that sits squarely on your desk.

Cross-Chain Crime: What the Elliptic Report Means for Crypto AML and Accounting

What Cross-Chain Crime Actually Means

The phrase sounds technical, but the mechanics are straightforward. A criminal starts with proceeds on one blockchain, perhaps Bitcoin from a ransomware payment, and uses a bridge or a decentralized exchange to convert those funds into a different asset on a different network. Each hop obscures the audit trail. Repeat the process two or three times and the connection between the original crime and the eventual cash-out becomes extremely difficult to reconstruct without purpose-built blockchain analytics.

The role of bridges and DEXs

Cross-chain bridges were designed to let legitimate users move assets freely between ecosystems. Wrapped tokens, the mechanism that lets Bitcoin "exist" on Ethereum or another smart-contract chain, are a core part of this infrastructure. The same permissionless design that makes bridges useful for DeFi participants also makes them attractive to bad actors. There is no central counterparty performing know-your-customer checks at the point of the swap, and settlement is near-instant.

Decentralized exchanges compound the problem. A DEX swap leaves an on-chain record, but the record links wallet addresses rather than verified identities. Without analytics capable of following funds across chain boundaries, a compliance team reviewing a single-chain transaction history may see clean incoming funds with no idea those funds passed through three bridges and two DEX swaps on their way in.

Criminal typologies highlighted in the report

Elliptic's research identifies ransomware groups and hackers as the primary abusers of cross-chain infrastructure. Both categories generate large, sudden inflows that are immediately conspicuous on a single chain, which creates a strong incentive to disperse funds across multiple networks as quickly as possible. The report also points to the sheer scale involved: billions of dollars in crypto have been moved this way, making cross-chain laundering a systemic concern rather than an edge case.

Why Existing Compliance Frameworks Struggle

Most AML programs in the crypto space were designed around a single-chain model. Transaction monitoring rules look for suspicious patterns within one ledger. Blockchain analytics tools integrated into onboarding or ongoing monitoring workflows may not natively follow a wrapped-token hop to a second chain, let alone a third. That architectural gap is precisely what sophisticated threat actors exploit.

The wrapped-token accounting blind spot

From a pure accounting perspective, wrapped tokens introduce their own complexity before you even get to the AML question. When a client holds Wrapped Bitcoin (WBTC) rather than native BTC, the accounting treatment depends on whether the wrapper is treated as a separate asset, how the custodial arrangement for the underlying collateral is classified, and whether the wrapping event itself constitutes a disposal for tax purposes. Layer an AML concern on top, and the wrapped token becomes a dual problem: hard to account for and hard to screen.

Gaps in transaction monitoring

Standard rule-based monitoring flags velocity, round-number transactions, and interactions with known-bad addresses. Cross-chain flows can be structured to stay below velocity thresholds on each individual chain while moving material amounts in aggregate. Without cross-chain analytics that stitches the journey back together, compliance officers may never see the full picture. The Elliptic report frames this as the "new frontier" of crypto laundering, and regulators across multiple jurisdictions are clearly taking note.

Regulatory Pressure Is Building

The timing of this report matters. Across major jurisdictions, AML supervisors are intensifying scrutiny of virtual asset service providers and the professional firms that serve them. The Financial Action Task Force's Travel Rule framework, which requires originator and beneficiary information to accompany crypto transfers, is increasingly enforced, but it was designed for custodial transfers between VASPs. It does not map cleanly onto a DEX swap or a bridge transaction where there is no intermediary VASP to collect and transmit data.

Implications for the VASP compliance stack

Regulators expect VASPs to maintain an effective risk-based approach. For cross-chain activity, that means the compliance stack needs tools capable of tracing funds across multiple ledgers, not just within one. Firms that rely on analytics covering only the chains where their primary product operates may have a material gap in their risk assessment. That gap, if identified during a supervisory review or a sanctions-related investigation, could result in enforcement action.

Recent enforcement activity around sanctions-designated wallets and illicit marketplaces, including OFAC actions against entities like Xinbi Guarantee, underscores how quickly cross-chain flows can become a sanctions-screening problem as well as an AML one. An entity that starts on one chain and bridges to another does not leave behind a clean, single-chain address for straightforward screening.

Practical Steps for Accounting Firms and CFOs

The Elliptic report provides guidance aimed at compliance professionals. Translating that into concrete actions for accounting firms and their corporate clients involves three distinct areas.

Upgrade your analytics coverage

If your current blockchain analytics tool does not offer cross-chain tracing, that is a gap requiring an urgent conversation with your provider or a procurement review. The minimum requirement is the ability to follow funds through bridges and DEX swaps and to attribute wrapped-token holdings to their originating chain. Firms operating as accountants or auditors for VASP clients should be asking their clients the same question about their own compliance stack.

Revisit your risk assessment for DeFi-exposed clients

Any client whose operations touch DeFi, whether as a user, a protocol operator, or a liquidity provider, carries cross-chain exposure by definition. Risk assessments that were written before bridges and DEXs became mainstream infrastructure need updating. The relevant factors include: which chains and bridges the client uses, whether the client's own transaction monitoring covers those chains, and what the client's policy is for flagging or refusing funds that arrive via bridge transfers from high-risk sources.

Accounting treatment for bridge and DEX transactions

Every bridge transfer and DEX swap generates accounting events. The tax and accounting treatment of these events is not settled in every jurisdiction, but the direction of travel from most tax authorities is that a swap or bridge event involving a change in the asset held is a disposal. That means each cross-chain hop may be a taxable event, and each one needs to be captured, valued at the point of the transaction, and recorded correctly in the ledger. Clients who have been ignoring the accounting complexity of their cross-chain activity are accumulating both a tax liability risk and a potential AML disclosure risk simultaneously.

Update client onboarding and ongoing monitoring procedures

Enhanced due diligence questionnaires for crypto-native clients should now ask specifically about cross-chain activity. Questions to add include: does the client use bridges or DEXs, which protocols, and has the client conducted a risk assessment of those protocols' own AML controls? Ongoing monitoring should flag large inbound transfers that arrive from bridge contract addresses rather than directly from another identified wallet, since bridge receipts warrant additional screening of the originating chain.

Cross-Chain Crime: What the Elliptic Report Means for Crypto AML and Accounting

What This Means for Digital Asset Accounting Software

For firms evaluating or upgrading their crypto accounting software, the cross-chain crime landscape adds a compliance dimension to what is often framed purely as a bookkeeping or reconciliation question. Software that can ingest data from multiple chains, correctly identify bridge and DEX transactions as discrete accounting events, and integrate with sanctions-screening outputs is no longer a premium feature set. It is a baseline requirement for any firm with multi-chain client exposure.

The ability to produce a complete, multi-chain transaction history for a client, one that shows every bridge hop and DEX swap in sequence, with timestamps and valuations, is increasingly what auditors and regulators will expect to see. Digital asset accounting software that cannot produce that output leaves both the firm and its clients exposed. The same applies to CFOs managing treasury positions that include DeFi or wrapped-token holdings: the accounting ledger and the AML audit trail need to be built from the same underlying data, not reconstructed separately after the fact.

Firms that have covered the DeFi regulatory angle from a legislative perspective, including recent U.S. developments targeting non-decentralized DeFi operators, will find the cross-chain crime typologies in this report provide the enforcement-side context that legislative analysis alone cannot supply. The Revised CLARITY Act's AML requirements for DeFi operators and the cross-chain laundering methods described in this report are two sides of the same regulatory conversation. Similarly, the OFAC sanctions enforcement pattern around cross-chain illicit flows is directly relevant to the screening obligations discussed in our coverage of OFAC's sanctions against Xinbi Guarantee.

The Audit and Assurance Dimension

For auditors, cross-chain activity in a client's digital asset portfolio creates specific challenges at the financial statement level. Completeness is the primary assertion at risk. If a client's records show only native-chain transactions and do not capture the bridge or DEX legs of a multi-chain flow, the transaction history is incomplete by definition. Auditors need to obtain evidence that covers the full chain of custody, not just the final resting address. That may require requesting blockchain analytics reports generated by tools with cross-chain capability, rather than relying on client-prepared summaries of individual-chain activity.

Existence and valuation assertions are also affected. A wrapped token and its underlying native asset are economically related but legally and technically distinct instruments. The accounting policy chosen needs to be applied consistently, and the valuation at each bridge event needs to be documented. In a regulatory environment where cross-chain flows are under active scrutiny from both AML supervisors and tax authorities, the working paper trail for these positions needs to be robust.

Source: Elliptic

Frequently Asked Questions

What is a cross-chain bridge and why does it create AML risk?

A cross-chain bridge is a protocol that allows assets to move between separate blockchains, typically by locking the original asset on one chain and issuing a wrapped equivalent on another. The AML risk arises because most bridges operate without a central intermediary performing identity checks, making it possible to transfer funds across chains without the originator and beneficiary data that regulated financial institutions are required to collect and transmit under Travel Rule obligations.

Are wrapped tokens a separate asset for accounting purposes?

In most cases, yes. Wrapped tokens are technically distinct instruments from their underlying assets, even when they track the same price. Whether the act of wrapping constitutes a disposal for tax purposes depends on the jurisdiction, but accounting standards generally require wrapped tokens to be recognised and measured separately. The custodial arrangement for the collateral backing the wrapped token also needs to be assessed for off-balance-sheet or contingent liability treatment.

Does the FATF Travel Rule apply to DEX transactions?

The Travel Rule as currently implemented applies to transfers between virtual asset service providers. A DEX swap, where there is no VASP intermediary on one or both sides, does not fit neatly into that framework. This is a known gap that FATF and national regulators are actively working to address, but firms should not assume that DEX-routed transactions are exempt from AML obligations at the broader risk-assessment level simply because the Travel Rule mechanism does not apply directly.

What should an accounting firm do if a client's inbound funds arrived via a bridge transfer?

Treat the bridge contract address as a flag requiring additional investigation rather than a clean source. Use a blockchain analytics tool with cross-chain capability to trace the funds back to their originating address on the source chain, then screen that address against sanctions lists and assess the risk profile of the originating chain and protocol. Document your findings in the client file. If the originating source cannot be satisfactorily identified, escalate through your firm's AML escalation process before proceeding.

How does cross-chain activity affect a digital asset audit?

It directly challenges the completeness and existence assertions. If the client's records only reflect single-chain activity, the auditor cannot be satisfied that the transaction population is complete without obtaining cross-chain analytics evidence. Auditors should request blockchain analytics reports covering all chains the client operates on, including evidence of bridge and DEX transactions, and should assess whether the client's own accounting software captures these events as discrete, valued transactions rather than netting them or omitting them entirely.

GLOBAL#defi#wrapped_tokensEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Cross-Chain Bridge AML Risk: $540M Laundered Through RenBridge
AML/KYC & Licensing
Crypto in Conflict: Sanctions Risk, DeFi Fundraising, and What Firms Must Know
AML/KYC & Licensing
Lazarus Group Named in $540M Ronin Bridge Theft: AML and Sanctions Implications
AML/KYC & Licensing
FATF 7th Targeted Update: What Accounting Firms and CFOs Must Act On Now