CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

TRM Labs Alleges HTX Wallet Rotation: What Accounting Firms and CFOs Must Act On Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING TRM Labs Alleges HTX Wallet Rotation:What Accounting Firms and CFOs Must ActOn Now

Blockchain intelligence firm TRM Labs has published findings alleging that HTX, the crypto exchange previously known as Huobi, is systematically rotating wallet addresses to stay one step ahead of transaction-screening systems. If the allegation is accurate, it represents a deliberate attempt to frustrate the very controls that regulated financial institutions and their accounting teams rely on to assess counterparty risk. For any firm whose clients hold assets on, transact through, or settle against HTX, the disclosure demands an immediate compliance review.

TRM Labs Alleges HTX Wallet Rotation: What Accounting Firms and CFOs Must Act On Now

What TRM Labs Has Alleged

TRM Labs, a blockchain analytics provider used by financial institutions and law-enforcement agencies worldwide, claims that HTX is cycling through new deposit and withdrawal addresses at a rate designed to outpace the refresh cycles of standard screening databases. The core assertion is that by the time a wallet address is flagged, attributed, and added to a sanctions or risk list, HTX has already migrated activity to a fresh address cluster, rendering the prior attribution commercially useless for real-time due diligence.

How Wallet Rotation Undermines Screening

Traditional transaction-monitoring frameworks assign risk scores to known wallet addresses. Those scores depend on attribution data: linking an address to a named entity, a jurisdiction, or a prior enforcement action. Wallet rotation attacks this dependency directly. When an exchange continually issues new addresses, attribution lags behind activity. A compliance team running a screening check against yesterday's database may clear a transaction that was, in practice, passing through an already-identified risk cluster. The speed of rotation, TRM contends, is not incidental but structured to exploit that lag.

This matters because correspondent-style relationships between institutional clients and exchanges like HTX often involve aggregated settlement flows. A single omnibus address that clears rapidly and is then retired can move significant value before any screening alert fires. For accounting teams reconciling on-chain transactions, a rotating address pool also fragments the audit trail, making it harder to reconstruct beneficial ownership chains from ledger data alone.

HTX's Regulatory and Enforcement Background

HTX operates in a complex regulatory environment. The platform has faced restrictions in several jurisdictions, including Canada, and has been a recurring subject of discussion at financial intelligence units concerned with offshore exchange activity. The exchange is associated with Justin Sun, who himself is the subject of an ongoing civil enforcement action brought by the US Securities and Exchange Commission. None of that constitutes a finding of guilt on the specific wallet-rotation allegation, but it does establish a pattern of regulatory friction that compliance teams must weigh when assessing counterparty risk.

Jurisdiction-Specific Exposure

For firms operating under EU AML directives or the Markets in Crypto-Assets Regulation, any relationship with an exchange flagged by a credible blockchain intelligence provider triggers enhanced due-diligence obligations. Under MiCA's transfer-of-funds rules, which apply to crypto-asset service providers authorised in the EU, originators and beneficiaries must be identifiable. Where an exchange's address infrastructure is alleged to be deliberately opaque, meeting that obligation becomes structurally difficult. UK-regulated firms face equivalent pressure under the Money Laundering Regulations 2017 and the Financial Conduct Authority's guidance on cryptoasset businesses.

US-based accounting firms advising clients with HTX exposure should consider the Bank Secrecy Act's suspicious activity reporting thresholds. The allegation that a counterparty is structuring its technical infrastructure to evade detection is precisely the kind of red flag that the Financial Crimes Enforcement Network identifies as requiring a suspicious-activity report, regardless of whether any individual transaction is itself sanctioned.

Accounting and Audit Implications

The allegations carry direct consequences for how accounting firms and CFOs handle balances and transactions linked to HTX.

Balance Sheet Presentation and Impairment Risk

Under IFRS and US GAAP, digital assets held on an exchange are typically presented as intangible assets or, where fair-value-through-profit-or-loss treatment applies, as financial assets. An exchange facing credible AML allegations is a material indicator that the recoverability of those assets may be impaired. Auditors are required to consider whether the going-concern status of a custodian, or any regulatory action that could freeze or confiscate assets, represents an impairment trigger. A blockchain intelligence report of this significance, published by a firm with law-enforcement credibility, qualifies as a subsequent event that auditors must assess.

Transaction-Level Reconciliation Challenges

Rotating wallet addresses create a direct problem for crypto bookkeeping software and digital asset accounting software workflows. Most reconciliation pipelines rely on address-to-entity mapping to categorise transactions correctly: distinguishing an internal transfer from a third-party receipt, or a fee payment from a withdrawal. When an exchange retires addresses frequently, those mappings break. A transaction that appears in on-chain data as originating from an unknown address may actually be an HTX withdrawal, but without current attribution data, the accounting system cannot confirm it. This produces unreconciled items, potential misclassification of transaction types, and gaps in the audit trail that external auditors will flag.

Firms using crypto accounting software to manage client portfolios should verify that their address-attribution data is sourced from providers who update frequently enough to track the rotation patterns described by TRM. Static or infrequently updated databases are inadequate for this threat model. This is one reason why the choice of underlying blockchain intelligence feed matters as much as the accounting interface itself.

Counterparty Onboarding and Ongoing Monitoring

For firms that onboard crypto exchanges as clients or as counterparties in fund structures, the TRM disclosure should trigger a formal review of the risk rating assigned to HTX. Enhanced due diligence, at minimum, means requesting current AML policy documentation, evidence of licensing in each jurisdiction where the exchange accepts users, and a satisfactory explanation of the address-management practices described in the TRM report. If HTX cannot provide adequate responses, the appropriate action under most AML frameworks is to exit the relationship or file a suspicious-activity report, depending on jurisdiction.

What Firms Should Do Immediately

The TRM disclosure is not a regulatory finding, but it is a credible intelligence report from a provider whose data is used by regulators and law enforcement. That status means it cannot be dismissed as speculative. The practical steps are concrete.

Short-Term Actions

First, map all current client exposures to HTX across your portfolio: direct balances held on the exchange, transactions that pass through HTX addresses, and any fund structures that list HTX as a counterparty or liquidity venue. Second, run those addresses through your blockchain intelligence provider and check that the attribution data is current. If your provider's HTX coverage is stale, that is itself a vendor-management issue requiring escalation. Third, review whether any open transactions are pending settlement against HTX addresses, and consider whether to pause those settlements pending a fuller review.

Fourth, document the review. Regulators assessing AML compliance after the fact will want to see evidence that your firm was aware of the TRM disclosure and took proportionate action. A dated internal memorandum setting out the steps taken and the conclusions reached is essential. This is also where robust crypto accounting software plays a structural role: firms with clean, timestamped audit trails demonstrating real-time screening are in a materially stronger position than those reconciling transactions retrospectively.

For context on how regulators are raising the bar on real-time monitoring, see our earlier analysis of how VARA, FCA, and HKMA are shifting toward real-time AML supervision. The expectation that firms detect and respond to emerging risk signals rapidly, rather than waiting for a formal enforcement action, is now firmly embedded in supervisory thinking across major jurisdictions.

The broader pattern of intelligence-led AML enforcement, where blockchain analytics firms surface allegations that then feed regulatory action, is also discussed in our review of FATF's public-private partnership report on crypto AML gaps. The HTX allegation is a live example of that dynamic playing out in real time.

TRM Labs Alleges HTX Wallet Rotation: What Accounting Firms and CFOs Must Act On Now

The Broader Signal for the Industry

Wallet rotation as an alleged evasion technique is not unique to HTX. It represents a class of behaviour that the blockchain analytics community has been tracking across multiple high-risk exchanges and mixing services. What distinguishes the TRM disclosure is the specificity of the attribution and the public nature of the claim. When a credible intelligence provider makes a public allegation of this kind, it accelerates the timeline for regulatory response: jurisdictions that were monitoring the situation quietly are now under pressure to act or explain their inaction.

For accounting firms advising clients across the digital asset spectrum, the episode underlines a structural truth: the adequacy of an AML programme is increasingly judged not just by the policies in place but by the technical infrastructure supporting them. Address-attribution data that is weeks old is not adequate for a counterparty alleged to be rotating wallets on a structured basis. Digital asset accounting software that cannot flag unrecognised address clusters in real time is not adequate either. The bar is rising, and firms that have not reviewed their tooling against this threat model should do so now.

Source: Protos

Frequently Asked Questions

What does wallet rotation mean in an AML context?

Wallet rotation refers to the practice of frequently generating new blockchain addresses and retiring old ones, so that transactions are spread across a large and constantly changing set of identifiers. In an AML context, this makes it harder for screening systems to attribute transactions to a known entity in real time, because the address-to-entity mapping that screening databases rely on is always at risk of being outdated.

Does the TRM allegation mean HTX is sanctioned?

No. TRM Labs is a private blockchain intelligence firm, not a regulatory authority. Its findings are intelligence inputs, not legal determinations. However, a credible public allegation from a provider used by law-enforcement agencies is a material risk signal that compliance teams are expected to act on, even before any formal enforcement action is taken.

How should an accounting firm update its risk rating for HTX?

The firm should treat the TRM disclosure as a trigger for enhanced due diligence under its existing AML policy. That means re-assessing HTX's risk tier, requesting up-to-date AML documentation from the exchange, verifying the current state of licensing across relevant jurisdictions, and documenting the outcome. If satisfactory responses are not obtained within a reasonable timeframe, the firm should consider whether to maintain the relationship and whether any suspicious-activity reporting obligations have been triggered.

What are the audit implications for clients with HTX balances?

Auditors should consider whether the TRM disclosure constitutes a subsequent event or an indicator of impairment for assets held on HTX. They should also assess whether the exchange's alleged address practices create material uncertainty about the recoverability of client funds, and document that assessment in their working papers. Where the exposure is significant, a disclosure in the financial statements may be appropriate.

Does rotating wallet addresses automatically constitute a sanctions violation?

Not automatically. Wallet rotation is not itself a listed prohibited activity under most sanctions regimes. However, if the rotation is used to facilitate transactions that would otherwise be blocked by sanctions screening, or to obscure the involvement of a sanctioned party, it would constitute a sanctions evasion technique with serious legal consequences for any firm that processed those transactions.

GLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Bitcoin ATM Scams: What Banks and Accounting Firms Must Do Now
AML/KYC & Licensing
HTX Rotating Wallets Under UK Sanctions: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
MetaMask hired suspected North Korean dev flagged months earlier
AML/KYC & Licensing
FATF Urges Faster Crypto AML Enforcement as Stablecoin Crime Grows