5 Emerging Cryptoasset Financial Crime Typologies: What Firms Must Track
Elliptic's updated research into cryptoasset financial crime typologies, released in September 2026, delivers a clear signal for compliance professionals: the methods criminals use to exploit digital assets have evolved substantially since Elliptic first mapped the landscape in 2018, and the single most consequential driver of that evolution is regulation itself. As KYC requirements tighten on mainstream exchanges, illicit actors are migrating systematically toward venues that impose no identity checks at all. For accounting firms, auditors, and CFOs managing digital asset books, that structural shift has direct consequences for how transaction monitoring is configured and how crypto accounting software is set up to flag risk.
Why the 2018 Benchmark Still Matters
Elliptic's original 2018 typologies guide was one of the first attempts to document, in a structured way, how criminal actors were using cryptoassets for money laundering, sanctions evasion, and fraud. It gave compliance teams a shared vocabulary and a baseline against which to calibrate controls. The 2026 update is not a wholesale replacement of that framework. Rather, it layers on the significant regulatory, technological, and enforcement developments that have occurred in the intervening years and shows precisely where criminal behaviour has adapted in response.
That evolutionary framing is important for professional practices. Typologies research is not purely academic. It informs risk appetite statements, SAR/STR filing thresholds, customer due diligence policies, and, increasingly, the configuration logic inside digital asset accounting software that categorises counterparties and flags unusual flows. A typology that was accurate in 2018 may now produce false negatives if it has not been updated to reflect how obfuscation techniques have changed.
The Central Finding: Regulation Reshaping Criminal Geography
The most structurally significant finding in the 2026 research is the relationship between regulatory tightening and the displacement of illicit activity. As more exchanges have introduced robust KYC programmes, often under pressure from FATF, the EU's MiCA travel rule provisions, FinCEN in the United States, and equivalent national frameworks, criminals have responded by routing transactions through platforms and protocols that either cannot or do not apply identity verification.
Unregulated Services as the New Default
Unregulated services, ranging from certain decentralised exchange interfaces and cross-chain bridges to peer-to-peer platforms operating outside licenced perimeters, have become the preferred on-ramp and off-ramp for illicit flows. This is not a new observation in isolation, but the scale and systematisation of the shift is notable. Elliptic's research frames this as a direct and measurable consequence of compliance pressure on the regulated sector rather than a coincidental trend.
For compliance teams, this has a practical implication. Transaction monitoring that focuses primarily on flows through regulated exchanges may now systematically underweight risk originating from non-KYC venues. Controls built on the assumption that the highest-risk counterparties are centralised exchanges with weak compliance programmes need to be recalibrated. The risk has migrated upstream, to the layer before assets touch a regulated venue.
What This Means for Counterparty Risk Classification
When a client's digital asset wallet receives funds that can be traced, even partially, through a non-KYC bridge or a decentralised exchange with no identity layer, that chain of custody matters for both AML purposes and for the integrity of the accounting record. A transaction that appears clean at the point of receipt may carry upstream exposure that only on-chain analytics can surface. This is a core reason why the choice of crypto accounting software or digital asset accounting software is now partly a compliance decision, not just a bookkeeping one. The system needs to ingest blockchain data, not just exchange-reported transaction records.
The Five Emerging Typology Trends
Elliptic's whitepaper groups its findings into five broad emerging trends. The source document does not publish the complete detail of each trend in its public-facing excerpt, but the research framework and the headline pattern are clear. The five areas reflect how criminal technique has evolved across the dimensions of obfuscation, platform selection, asset type, and scale.
Trend 1: Systematic Displacement to Non-KYC Venues
As covered above, this is the dominant structural shift. The practical implication for firms is that suspicious activity reporting frameworks need to treat transactions routed through non-KYC intermediaries as a heightened risk indicator in their own right, regardless of whether the underlying asset or the receiving address shows other red flags.
Trend 2: Adaptation to Regulatory Events
Elliptic's research specifically calls out "significant events" as catalysts for changes in criminal behaviour. Major enforcement actions, the sanctioning of mixing services, and the collapse of specific platforms have historically triggered rapid adaptation. Criminals have shown they can pivot quickly to alternative infrastructure when a preferred tool is taken offline or sanctioned. For compliance teams, this means typologies need to be treated as living documents rather than fixed reference points. A control framework validated twelve months ago against the then-current landscape may already have gaps.
Trend 3: Exploitation of New Technology Layers
The eight years since Elliptic's original research have seen the emergence of decentralised finance, cross-chain bridges, layer-2 networks, and, most recently, AI-assisted on-chain activity. Each new technology layer has introduced new obfuscation surfaces. Bridges, in particular, complicate transaction tracing because they break the direct on-chain link between source and destination chains, creating analytical gaps that standard monitoring tools may not close without specialised cross-chain tracing capability.
This matters for crypto bookkeeping software configurations. If a client holds assets on multiple chains and uses bridges to move value between them, the accounting system needs to reconcile those cross-chain movements correctly, both for balance sheet accuracy and for the underlying AML audit trail. A bridge transfer is not a disposal in most accounting frameworks, but it is a transaction event that needs to be recorded, attributed, and, where necessary, screened.
Trend 4: Continued Evolution of Obfuscation Techniques
Chain-hopping, layering through multiple wallet addresses, and the use of privacy-enhancing protocols remain core techniques. What has changed is their combination and sequencing. Elliptic's research points to increasing sophistication in the layering phase, where value is moved through multiple intermediate steps specifically to defeat automated tracing. The implication for firms is that transaction monitoring thresholds set at a single-hop level may miss multi-hop laundering patterns that only become visible when the full transaction graph is reconstructed.
Trend 5: Scale and Professionalisation of Illicit Infrastructure
Financial crime in crypto has, in significant part, moved beyond opportunistic individual actors toward organised networks that operate professional-grade infrastructure. This includes dedicated money-laundering-as-a-service operations, crypto-native fraud ecosystems, and the kind of large-scale illicit marketplaces that have attracted enforcement action from OFAC and other agencies. The professionalisation of illicit infrastructure raises the analytical bar for compliance teams, because the patterns left in transaction data are deliberately engineered to look normal.
Accounting and Audit Implications
The typologies research has consequences that extend beyond the compliance function into accounting and audit practice directly.
For Accounting Firms and Auditors
When auditing a client's digital asset holdings, the adequacy of the client's own transaction monitoring is now an audit consideration. If a client's crypto accounting software does not ingest on-chain data and cannot surface upstream exposure from non-KYC venues, the auditor faces a limitation of scope that needs to be addressed. Firms should consider whether their standard audit programmes for digital asset clients include a review of the client's blockchain analytics capability, not just their exchange account statements.
Updated typologies also feed into the risk assessment phase of an audit. The nature of the risks of material misstatement for a client holding digital assets includes, under ISA 315 (Revised), an understanding of the entity's exposure to financial crime risk. Elliptic's research provides documented, citable evidence of the current risk landscape that can be referenced in audit working papers.
For firms that provide AML compliance services alongside accounting, the research is directly relevant to the periodic review of customer risk assessments. A customer risk rating methodology that was last reviewed before the scale of displacement to non-KYC venues became apparent may now be systematically underrating certain client profiles.
For CFOs and In-House Finance Teams
CFOs at firms holding digital assets on the balance sheet need to ensure that their internal controls address not just the custody and valuation of those assets, but also the provenance of incoming transfers. A transfer received from a counterparty that has routed funds through non-KYC infrastructure may carry a legal and reputational risk that is not visible from the ledger entry alone. The accounting record and the compliance record need to be linked.
This is also relevant to treasury policy. If a company is using stablecoins or other digital assets for operational payments, the policy should specify acceptable counterparty types and prohibit receipt from venues identified as high-risk in current typologies guidance. That policy needs to be operationalised in whatever digital asset accounting software the treasury function uses, ideally through automated flagging rather than manual review.
For context on how sanctions enforcement intersects with these accounting obligations, see how the OFAC Xinbi sanctions reshaped crypto AML accounting workflows. And for the legislative dimension, our earlier coverage of what the revised CLARITY Act means for DeFi AML obligations covers the regulatory trajectory that is, in part, driving the criminal displacement Elliptic identifies.
Practical Steps for Compliance and Finance Teams
The research points toward a set of concrete actions rather than a general call to improve controls.
Review Counterparty Risk Typologies
Any risk typology document or customer risk assessment methodology that predates 2024 should be reviewed against the current landscape. Specifically, non-KYC venues and cross-chain bridges should be explicitly addressed as risk factors, not left to catch-all categories.
Audit Your Transaction Monitoring Coverage
Map the points in your clients' transaction flows where monitoring is applied and identify gaps. If monitoring is applied only at the exchange account level and not at the on-chain level, multi-hop obfuscation patterns will not be visible. The configuration of your crypto accounting software should be part of this review: does it ingest raw blockchain data, or only processed exchange reports?
Update SAR/STR Filing Guidance
Internal guidance on suspicious activity reporting should reflect the updated typologies. Specifically, routing through non-KYC venues should be listed as a red flag indicator, and the threshold for escalation where such routing is identified should be clearly specified.
Engage with Published Typologies as a Live Resource
Elliptic's commitment to publishing ongoing typologies research is stated explicitly in the whitepaper as part of its broader mission to support industry and regulators in preventing financial crime. Compliance teams should treat published typologies from credible blockchain analytics and regulatory sources as a recurring input to their risk assessment cycle, not a one-time reference.
Frequently Asked Questions
What is a cryptoasset financial crime typology?
A typology is a documented pattern or method by which criminals exploit a financial system or asset class. In the context of cryptoassets, typologies describe specific techniques such as chain-hopping, mixer use, or routing through non-KYC exchanges, along with the red flags that indicate a transaction may follow that pattern. Compliance teams use typologies to calibrate transaction monitoring rules and customer risk assessments.
Why does the displacement of crime to non-KYC venues matter for accountants?
When funds received by a client have passed through non-KYC venues, the audit trail is deliberately obscured. For an accountant or auditor, this creates a risk that the asset on the balance sheet carries undisclosed provenance risk. It also affects AML obligations: if a firm has received funds from a source later identified as illicit, the adequacy of the firm's due diligence at the time of receipt will be scrutinised. Crypto accounting software that only processes exchange-reported data will not surface this upstream exposure.
How often should a firm update its AML typologies framework?
Regulatory guidance varies by jurisdiction, but the general standard under FATF and most national AML frameworks is that risk assessments should be reviewed periodically and whenever there is a material change in the risk landscape. Given the pace of change documented by Elliptic's research, an annual review is a practical minimum, with additional ad hoc reviews triggered by major enforcement events or significant new guidance from relevant authorities.
Does typologies research apply to firms that only hold crypto on the balance sheet and do not offer crypto services?
Yes, though the scope of application differs. A firm holding digital assets for treasury or investment purposes still needs to understand the provenance of any assets it receives and the risk profile of counterparties it transacts with. If the firm is subject to AML obligations in its jurisdiction, those obligations apply to digital asset transactions. The typologies inform the risk assessment that underpins those obligations.
What should we look for when evaluating crypto accounting software from a compliance standpoint?
At a minimum, the system should ingest on-chain transaction data rather than relying solely on exchange-reported records. It should be able to flag transactions involving counterparties or intermediaries identified as high-risk in current typologies, including non-KYC venues and sanctioned addresses. Integration with a recognised blockchain analytics provider is a strong indicator of adequate coverage. The system should also maintain an audit-ready record that links each accounting entry to its underlying on-chain transaction.
Source: Elliptic
