CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Mexico Hunts Illegal Crypto Mines: AML and Accounting Risks for Firms

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Mexico Hunts Illegal Crypto Mines: AMLand Accounting Risks for Firms

Mexican authorities have shut down a clandestine cryptocurrency mining operation in rural northern Puebla and announced a sweep across neighbouring states to find more. The site, powered by electricity stolen from the Nuevo Necaxa hydroelectric dam, ran 300 computers and, according to officials, may have served as a vehicle to launder proceeds from other criminal activity. For accounting firms, auditors, and CFOs, the story is not just a law-enforcement curiosity: it exposes a specific typology that needs to land on your AML risk register.

Mexico Hunts Illegal Crypto Mines: AML and Accounting Risks for Firms

What Happened in Puebla

Puebla's Public Security Secretariat dismantled the operation and, in the wake of the seizure, its head, Francisco Sánchez, confirmed plans to extend the search to neighbouring Mexican states. The mining site was deliberately placed in an isolated, remote location, which Sánchez explained was a deliberate operational choice: large-scale mining generates significant noise and heat, so operators seek out spots where both are unlikely to attract attention.

The power source was the Nuevo Necaxa dam, a piece of public infrastructure whose electricity was redirected to the site without authorisation. That distinguishes this case from legitimate miners who pay commercial electricity tariffs and factor those costs, along with cooling expenses and local regulatory requirements, into their operating models.

The Money Laundering Dimension

Puebla's authorities have gone further than simply alleging electricity theft. They suspect the mine was used to legitimise and layer proceeds from other illegal activity. That is a classic layering mechanism: generate a plausible, hard-to-audit source of crypto income (mining rewards), then commingle it with proceeds from separate criminal enterprises. The on-chain result looks indistinguishable from legitimate mining output unless the underlying electricity theft and ownership structure are exposed through off-chain investigation.

A Separate, Violent Case Linked to Bitcoin

In an unrelated but telling development, Mexican prosecutors have charged two individuals in connection with the murders of Jonathan Meléndez, his pregnant wife Ana Paula Barragán, their three-year-old daughter Sofía, and a 21-year-old nanny, Aleyda Romero. According to prosecutors, the motive was a Bitcoin stash the perpetrators believed was worth millions. Diego Sebastián "N" and Gerardo "N" were arrested on 2 September. No Bitcoin was ultimately stolen, and witness accounts pointed to a device holding approximately 3 million pesos in crypto, equivalent to around $177,000. The case underscores how the perceived concentration of crypto wealth can itself generate physical-security and operational risks for holders.

Why This Is an AML Typology, Not Just a Crime Story

Illegal mining operations like the one in Puebla represent a distinct AML typology that financial institutions, virtual asset service providers (VASPs), and their accountants should be tracking. Several characteristics make it worth codifying in your risk framework.

Electricity Theft as a Cost-of-Crime Signal

Legitimate mining businesses carry substantial, verifiable electricity costs on their books. When a mining entity's financial statements show mining revenues without commensurate energy expenditure, or when that expenditure is routed through opaque third-party contracts, that is a red flag. Auditors reviewing mining clients should request utility contracts, meter data, and site inspection records as standard procedure, not as an exception.

Geographic Isolation and Beneficial Ownership

The Puebla operation was intentionally remote. That geographic choice also tends to correlate with weak corporate registration environments, nominee ownership structures, and minimal regulatory oversight. When onboarding a mining entity domiciled in a jurisdiction with limited infrastructure oversight, enhanced due diligence on beneficial ownership is not optional: it is the minimum threshold.

The Layering Risk in Mining Rewards

Mining rewards present a particular challenge for transaction monitoring systems. Unlike a deposit from an unknown wallet, a mining reward originates from a protocol-level coinbase transaction and does not carry a straightforward counterparty. That can create a false sense of cleanliness. The Puebla case illustrates why origin-of-funds analysis for mining clients cannot stop at the on-chain source: it must extend to the off-chain operating model, including land rights, energy contracts, and corporate structure. Understanding how to flag precisely these flows is part of the framework covered in our analysis of how AML controls must flag high-risk crypto flows.

Accounting Implications for Mining Entities

For firms that provide audit or accounting services to crypto mining clients, this enforcement action sharpens several existing obligations.

Revenue Recognition and Cost Matching

Under both IFRS and US GAAP, mining rewards are recognised as revenue at fair value on the date they are received. That is straightforward. What is less straightforward is the cost side. A mining entity with no electricity costs, no cooling costs, and no depreciation on infrastructure is not running a business: it is running something else. Where those costs are absent or implausibly low relative to the scale of mining activity, auditors face a going-concern and misstatement risk that needs to be documented and escalated.

Asset Provenance and the Clean-Hands Problem

If a client has received mining rewards from an operation later found to be criminally run, the crypto assets on their balance sheet carry a provenance problem. Proceeds of crime legislation in most jurisdictions, including Mexico's own anti-money laundering framework, can subject those assets to civil forfeiture regardless of whether the holder was a knowing participant. Accounting firms that signed off on financial statements treating those assets as clean face potential professional liability.

Disclosure Obligations

Where a mining client is subject to an active investigation, that fact is almost certainly a contingent liability requiring disclosure under IAS 37 (or ASC 450 under US GAAP). If a firm becomes aware of such an investigation through public sources or client communications, continuing to prepare financial statements without requiring that disclosure is a material omission.

What Firms Should Do Now

The Puebla crackdown and the announced multi-state sweep create a defined window for firms with Latin American mining clients to act before a broader enforcement wave reaches their portfolios.

AML Risk Register Updates

Add illicit crypto mining as a named typology in your firm's AML risk register if it is not already there. The specific indicators to document include: mining revenues without corresponding utility contracts; corporate structures with no physical presence at the stated mining address; beneficial owners who cannot be independently verified; and geographic locations in areas with known infrastructure vulnerabilities.

Client File Review

Pull the onboarding files for any mining entity client operating in Mexico or adjacent jurisdictions. Check whether utility contracts, site lease agreements, and environmental or municipal permits were collected at onboarding. If they were not, request them now. A client that cannot or will not provide those documents warrants a suspicious activity report assessment, and in some jurisdictions an affirmative filing obligation.

Digital Asset Accounting Software Configuration

Firms using crypto accounting software to reconcile mining client books should ensure that the software's cost-basis and revenue-recognition workflows flag coinbase transactions separately from wallet-to-wallet receipts. The classification matters not just for tax but for the AML narrative: a transaction log that cannot distinguish mining rewards from received transfers is not fit for purpose in a regulated engagement. Robust digital asset accounting software should allow auditors to tag the origination type of every inflow and cross-reference it against off-chain cost records. This same discipline is relevant to broader enforcement contexts, as explored in our coverage of how enforcement actions shape crypto accounting obligations globally.

Physical Security Considerations for CFOs

The Meléndez murder case is a stark reminder that the perceived value of a crypto holding creates physical-security risks for individuals associated with it. CFOs and treasury functions holding Bitcoin or other assets on behalf of their entities should review whether those holdings are publicly attributable through corporate filings, social media, or press coverage, and whether internal controls limit knowledge of the custodial arrangements to a need-to-know basis.

The Broader Mexican Regulatory Context

Mexico's Fintech Law, enacted in 2018 and updated since, requires VASPs to register with the Comisión Nacional Bancaria y de Valores (CNBV) and comply with AML obligations under the LFPIORPI framework. Crypto mining, depending on its commercial scale and whether mined assets are sold through regulated channels, can engage those registration requirements. An operation that mines and then sells crypto peer-to-peer without CNBV authorisation is potentially operating as an unregistered VASP on top of its electricity theft exposure.

The announced multi-state sweep signals that Puebla's action was not a one-off. For firms advising clients across the Mexican market, the practical question is not whether further enforcement will happen but when, and whether your clients' documentation will withstand scrutiny when it does.

Mexico Hunts Illegal Crypto Mines: AML and Accounting Risks for Firms

Frequently Asked Questions

Does illegal crypto mining create AML exposure for my accounting firm?

Potentially, yes. If your firm prepares or audits financial statements for a mining entity later found to be conducting illegal operations, you face questions about whether red flags were present and ignored. Robust client due diligence, including verification of energy contracts and beneficial ownership, is your primary defence. Where red flags exist and a suspicious activity report is required under your jurisdiction's legislation, failing to file creates direct regulatory exposure for the firm.

How should mining revenues be treated if the underlying operation is later found to be criminal?

Assets derived from criminal activity are generally subject to forfeiture under proceeds of crime legislation, regardless of how they were recorded in the accounts. If a client's mining operation is found to have been criminally run, any crypto assets on the balance sheet traced to that operation may be void of value from a legal standpoint. The accounting firm's role is to ensure contingent liabilities and ongoing investigations are properly disclosed, not to guarantee the legal cleanliness of the assets themselves.

What is the layering risk specific to mining rewards?

Mining rewards originate from protocol-level coinbase transactions, which means they do not carry a visible counterparty on-chain. That can make them appear clean even when the underlying operation is funded by criminal proceeds. The layering risk arises when proceeds from other criminal activity are used to fund the mining operation (through stolen electricity, for example), and the resulting mining rewards are then treated as legitimate income. Transaction monitoring that stops at the on-chain source without examining the off-chain operating model will miss this.

Is crypto mining regulated in Mexico?

Mexico's Fintech Law and LFPIORPI framework establish registration and AML obligations for entities that deal in virtual assets commercially. Whether a mining operation falls under those requirements depends on its scale and how it disposes of mined assets. Mining entities that sell directly to customers or operate exchange-like functions without CNBV registration face regulatory exposure independent of any electricity theft.

What documents should I request when onboarding a crypto mining client?

At a minimum: the energy supply contract or utility account in the entity's name, the lease or title for the mining site, municipal or environmental permits where required, corporate ownership documents showing beneficial owners to the applicable threshold, and any existing regulatory correspondence with financial or energy regulators. For clients in jurisdictions with known infrastructure vulnerabilities, enhanced due diligence may also include third-party site verification.

Source: Protos

GeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $8.4B Illicit Marketplace Means for Crypto Accounting
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $36B Scam Marketplace Means for Crypto Accounting
AML/KYC & Licensing
AMF Mediator Report 2025: Crypto AML Disputes Jump 38%
AML/KYC & Licensing
NCA Warns of Innovative Crypto Laundering Tactics: What UK Firms Must Do Now