h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

Does Crypto KYC and AML Actually Work in 2026?

Crypto's anti-money-laundering machine has never been heavier or more expensive. We weigh what it catches against what it costs, and ask whether it actually works.

On September 3, 2026, Standard Chartered became the first globally systemic bank to offer institutional spot Bitcoin and Ether trading in the United Arab Emirates, routing crypto through the same foreign-exchange desks that move currency for the world’s largest funds, as CoinDesk reported. Bitcoin was trading near $81,000, up more than 5 percent on the day, according to CoinGecko, while the stablecoins that now settle most on-chain value stood in the hundreds of billions of dollars in circulation. Money is flowing into regulated crypto faster than at almost any point in the asset class’s history.

Behind nearly every one of those regulated on-ramps sits the same machine. Before a bank, an exchange, or a stablecoin issuer will touch your funds, it asks two questions: who are you, and where did this money come from. That machine is Know Your Customer (KYC) and Anti-Money Laundering (AML), and in 2026 it has never been heavier, more expensive, or more scrutinized. Compliance now costs the financial industry hundreds of billions of dollars a year, and crypto firms have paid billions more in penalties for getting it wrong.

Which raises the question this piece is about. Not how the rules work, we have covered that ground before, but whether they work. Does all of this identity checking and transaction reporting actually stop criminals from laundering money, or is it an expensive ritual that mostly inconveniences honest users while illicit flows route around it? The honest answer is: some of both, and the balance is more uncomfortable than either regulators or crypto libertarians like to admit.

KYC and AML are not the same thing

Start with the vocabulary, because the two terms get used interchangeably and they should not be. AML is the umbrella: the whole body of law, regulation, and internal controls meant to stop the financial system from being used to launder the proceeds of crime. In the United States it traces to the Bank Secrecy Act of 1970. KYC is one component inside that umbrella, the identity piece, the part where a firm confirms you are who you claim to be. In US law the formal version is the Customer Identification Program required by Section 326 of the USA PATRIOT Act, layered with Customer Due Diligence rules.

Under the American framework, a compliant AML program rests on what practitioners call the five pillars:

  • A designated compliance officer
  • Written internal controls and policies
  • Ongoing employee training
  • Independent audit of the program
  • Risk-based customer due diligence, including beneficial-ownership checks

That last pillar, added by the 2016 Customer Due Diligence Final Rule and effective in 2018, is why bankers still call it “the fifth pillar.”

Money laundering itself is usually described in three stages: placement (getting dirty value into the system), layering (moving it through enough transactions to obscure the trail), and integration (bringing it back out looking clean). Crypto’s reputation is strongest at the layering stage, where mixers, chain-hopping, and thousands of automated hops can fragment a trail. It is weakest, as we will see, at the moment that laundered value tries to touch a regulated exchange and become spendable in the real economy.

Who actually enforces this, and it is not the SEC

Here is the single most common misunderstanding in crypto regulation, and it matters directly for judging whether the system works: in the United States, AML is not the Securities and Exchange Commission’s job. The SEC polices whether a token is a security. Anti-money-laundering authority sits with the Financial Crimes Enforcement Network (FinCEN), a bureau of the Treasury, and with the Office of Foreign Assets Control (OFAC), which runs the sanctions lists.

A crypto exchange operating in the US is legally a money services business (MSB). It must register with FinCEN, maintain an AML program, and comply with the Bank Secrecy Act, exactly like any money transmitter. Banking regulators (the OCC, FDIC, and Federal Reserve) supervise the banks that serve those firms. The SEC and the CFTC enter only through the separate securities or commodities dimension. When a headline says an exchange was fined “for money laundering,” the action almost always came from FinCEN, OFAC, or the Department of Justice, not the securities regulator.

This distinction is not pedantry. If you want to know whether the AML regime works, you have to read FinCEN filings, OFAC designations, and DOJ prosecutions, not securities cases. And those are the numbers that tell a genuinely mixed story.

AuthorityRole in crypto AML
FinCEN (Treasury)Administers the Bank Secrecy Act; MSB registration, SAR and CTR rules, primary AML enforcement
OFAC (Treasury)Sanctions lists; designating addresses, entities, and jurisdictions
DOJCriminal prosecution of firms and individuals for BSA and sanctions violations
OCC, FDIC, Federal ReserveSupervise the banks that serve crypto firms
SEC and CFTCOnly the securities or commodities dimension, not AML itself

What the machine does to you

For a user, the AML regime shows up as friction. When you open an account at a regulated exchange, the Customer Identification Program kicks in: name, date of birth, address, a government ID, and increasingly a live selfie matched against the ID through liveness detection. That is baseline Customer Due Diligence. If you trip a risk flag, such as large volumes, a high-risk jurisdiction, or politically exposed person status, you move to Enhanced Due Diligence, which means more documents and pointed questions about your source of funds.

After onboarding, the monitoring never stops. Every transaction runs against sanctions screening and behavioral models. Two reports drive the back end. A Currency Transaction Report is mandatory for cash transactions over $10,000, filed within 15 days, a threshold unchanged since 1970. A Suspicious Activity Report is filed when a firm spots suspicious activity at or above $2,000 at an MSB, within 30 days of detection. Records are kept for five years. The Travel Rule requires identifying information to travel alongside transfers at or above $3,000. And crucially, tipping off a customer that a report has been filed is itself a federal crime.

Report or ruleTriggerDeadline or rule
Currency Transaction Report (CTR)Cash transaction over $10,000File within 15 days
Suspicious Activity Report (SAR)Suspicious activity at or above $2,000 (MSB)File within 30 days of detection
RecordkeepingUnderlying customer and transaction dataRetain for 5 years
Travel RuleTransfers at or above $3,000Identifying data must travel with the transfer
MSB registrationOperating as a money transmitterRegister with FinCEN within 180 days
Tipping offTelling a customer a SAR was filedFederal crime

That is the cost you feel as a user. The cost the industry feels is far larger, and it is where the effectiveness debate really begins.

The case that it works: blockchain never forgets

Now the benefit side, and it is real. The strongest argument for the current regime is not the paperwork; it is what happens when the paperwork meets a public ledger. Every Bitcoin transaction and most stablecoin transactions are permanently recorded and visible to anyone. When investigators can attach a real-world identity to even one address in a chain, using KYC data that an exchange collected, the permanence of the blockchain turns into an evidentiary goldmine that traditional cash never offered.

The canonical example is the 2016 Bitfinex hack. A thief took 119,754 Bitcoin, which sat for years apparently beyond reach. Then, in February 2022, the DOJ seized more than $3.6 billion of it, at the time the largest financial seizure in the department’s history, and arrested Ilya Lichtenstein and his wife Heather Morgan, as CNBC reported. Investigators had followed the coins across the public ledger and waited for them to touch regulated off-ramps where identities attach. By the time the couple was sentenced in late 2024, the recovered Bitcoin had appreciated to roughly $10 billion, according to TRM Labs. Lichtenstein, who later admitted he was the original hacker, received five years; Morgan received eighteen months.

Jonathan Levin, co-founder and chief executive of Chainalysis, has made this the core of the industry’s pitch to lawmakers. In 2025 testimony to the Senate Banking Committee, he argued that blockchain’s “transparency, speed and programmability” give oversight a fundamentally new model, one built on publicly available information, and that it lets investigators follow the money, freeze assets, and seize them faster than in traditional finance, as PYMNTS reported. Three firms, Chainalysis, Elliptic, and TRM Labs, have built large businesses on exactly that premise, selling tracing tools to agencies in more than 70 countries.

The enforcement wave: $4.3 billion, and never a single report

The second pillar of the case that it works is deterrence through enforcement, and 2023 to 2025 produced the largest crypto AML penalties in history. In November 2023, Binance, the world’s largest exchange, agreed to pay more than $4.3 billion to settle Bank Secrecy Act and sanctions violations, a $3.4 billion FinCEN penalty (then the largest the bureau had ever levied) plus $968 million to OFAC. Founder Changpeng Zhao pleaded guilty, paid a $50 million personal fine, and stepped down, per the Department of Justice. The detail that stuck with compliance officers: over years of moving enormous volumes, Binance had never filed a single Suspicious Activity Report. Attorney General Merrick Garland put it bluntly: “Using new technology to break the law does not make you a disruptor. It makes you a criminal.”

It kept going. In January 2025, KuCoin’s operator pleaded guilty and agreed to pay about $297 million, exiting the US market for two years, according to the US Attorney for the Southern District of New York. In February 2025, OKX pleaded guilty to running an unlicensed money-transmitting business and agreed to more than $504 million, having processed over $1 trillion in US transactions while unregistered and, for years, without KYC for retail users, as prosecutors detailed. Compliance analysts now describe AML as having overtaken securities law as the single biggest regulatory risk for a crypto exchange.

FirmDatePenaltyKey finding
BinanceNov 2023Over $4.3 billionNever filed a single SAR; founder pleaded guilty and stepped down
KuCoin (Peken Global)Jan 2025About $297 millionUnlicensed money transmission; two-year US exit
OKXFeb 2025Over $504 millionOver $1 trillion processed unregistered; no retail KYC for years

These are genuine wins for the regime: billions clawed back, guilty pleas from the biggest names in the industry, and a clear signal that “we are just a technology platform” is no defense. If enforcement is the metric, the machine works.

The case that it does not: the 0.2 percent problem

Then you look at the denominator, and the picture inverts. The most-cited estimate of AML effectiveness, which traces to United Nations data and is reprised by Coin Center, holds that of all the criminal proceeds laundered through the global financial system, law enforcement seizes or freezes on the order of 0.2 percent. Put differently, roughly 99.8 percent gets through. That figure predates crypto and describes the whole system, banks included, but it is the baseline against which every compliance dollar has to be judged.

In September 2025, Coin Center’s Peter Van Valkenburgh and the cryptographer Ian Miers made that case directly in a report titled Tear Down this Walled Garden. Their conclusion: the surveillance-based identity regime is simultaneously costly, privacy-invasive, and ineffective at deterring illicit finance, imposing what they call enormous costs and privacy burdens for negligible benefit in stopping crime. US financial institutions spend more than $26 billion a year on AML compliance, they estimate, with the largest banks spending upward of $10 billion each, all to intercept a sliver of criminal money.

Crypto’s own numbers cut both ways here. Chainalysis found that illicit addresses received at least $154 billion in 2025, an all-time high and a 162 percent jump driven mostly by sanctions evasion, as The Defiant reported. Yet the same firm stresses that illicit activity remained under 1 percent of all on-chain volume. Both facts are true at once. The regime neither stops most laundering nor, in crypto specifically, is drowning in it. What it reliably does is generate cost.

The reporting deluge and the false-positive trap

Nowhere is that cost clearer than in the reporting numbers. US financial institutions filed more than 4.1 million Suspicious Activity Reports in 2025, a record year, and by the SAR’s thirtieth anniversary in April 2026 more than 47 million had been filed in total, according to Forvis Mazars. That is an enormous, ever-growing pile of reports pointed at a single Treasury bureau.

The problem is not the volume; it is the signal-to-noise ratio. Industry analyses put AML transaction-monitoring false-positive rates at 85 to 95 percent, with more than half of banks running rates above 20 percent and a quarter above 40 percent, per Facctum’s 2026 review. Only a low single-digit share of alerts, roughly 1 to 5 percent, ever convert into an actual SAR, and only a fraction of those lead anywhere. A single large bank may review 50,000 alerts a year, of which 47,500 are false positives, at a cost of $500 to $1,500 each.

There is a structural incentive baked in. Because failing to file a report carries penalties (recall Binance’s zero), firms file defensively, flagging anything remotely ambiguous to cover themselves. The result is a firehose of low-quality reports, and a system that measures activity, reports filed, far more easily than it measures outcomes, crimes actually stopped. The cost ledger below lines up what the regime spends against what it demonstrably catches.

What the regime costs and catchesFigure (2025 to 2026)
US AML compliance spendMore than $26 billion per year
Transaction-monitoring false positives85 to 95 percent of alerts
Alerts that become a SARRoughly 1 to 5 percent
SARs filed in 2025More than 4.1 million (record)
Laundered proceeds seized (all finance)On the order of 0.2 percent
Illicit share of on-chain crypto volumeUnder 1 percent
Illicit crypto received in 2025At least $154 billion (record)

The honeypot problem: your KYC data is the target

There is a cost the effectiveness debate often skips: the identity data itself becomes a liability. To satisfy KYC, every regulated exchange assembles a database of exactly what an identity thief wants, names, addresses, dates of birth, government-ID scans, sometimes partial Social Security numbers and biometric selfies, all in one place. Regulation mandates the honeypot; it does nothing to make the honeypot safe.

In May 2025, Coinbase disclosed that criminals had bribed overseas support contractors to copy the personal data of roughly 69,461 customers, about 1 percent of its base, including government-ID images, as CoinDesk reported. The attackers demanded a $20 million ransom. Chief executive Brian Armstrong refused and instead offered a $20 million bounty for information leading to the perpetrators; the company estimated remediation could cost between $180 million and $400 million. No coins were stolen from the protocol. The breach was entirely in the KYC layer that regulation requires firms to build.

For users, the lesson has pushed some toward self-custody: holding your own keys in a well-run multisig arrangement so that a single exchange breach cannot expose both your money and your identity at once. And when a hack does happen, the growing market in recovery bounties has become one of the more effective ways to claw funds back, at times more effective than the formal reporting chain. None of that dissolves the underlying tension: the more identity data the rules force firms to hoard, the bigger the target they paint on their own backs.

Displacement: squeeze here, and it moves there

The sharpest critique of the regime is not that it does nothing; it is that it mostly relocates activity. Squeeze one venue and the flows move to another. The 2026 crime data shows the pattern clearly. Bitcoin, once around 70 percent of illicit crypto volume, has fallen to roughly 7 percent; stablecoins now carry about 84 percent of illicit transaction value. Value flowing to sanctioned entities jumped 694 percent year over year to about $104 billion, led by Russia’s ruble-pegged A7A5 token, Iran’s Revolutionary Guard, and North Korean hacking crews, as CoinDesk reported from the Chainalysis data.

Mixers tell the same story. In August 2022, OFAC sanctioned the smart-contract addresses of Tornado Cash, the first time it had sanctioned software rather than a person or a company. A federal appeals court later ruled in the Van Loon case that immutable contracts are not property OFAC can designate, and the Treasury delisted the addresses in March 2025. Developer Roman Storm was convicted in August 2025 of running an unlicensed money-transmitting business, but the jury deadlocked on the money-laundering and sanctions counts; his retrial on those charges has now been pushed to April 2027, according to The Block. The code kept running the entire time. Sanctioning it moved some users; it did not switch it off.

This is the whack-a-mole problem in one paragraph: enforcement can shut a company, jail a founder, and freeze a wallet, but it struggles against permissionless software and jurisdiction-hopping actors. The flows adapt faster than the rules can be rewritten.

The 2026 US rulebook: GENIUS and the stablecoin turn

The response in Washington has been to extend the perimeter, not shrink it. The centerpiece is the GENIUS Act of 2025, the first federal framework for payment stablecoins. It treats permitted payment stablecoin issuers as Bank Secrecy Act financial institutions, which means full AML programs, sanctions compliance, and the ability, in some readings the obligation, to freeze tokens.

In April 2026, FinCEN and OFAC jointly issued a proposed rule spelling out those AML and sanctions-compliance duties for stablecoin issuers, the first time US law has mandated sanctions-compliance programs for this class of firm. The logic follows the crime data: if stablecoins now carry most illicit value, the issuers, who can see and in principle freeze their own tokens, become the natural control point. Tether and Circle have both frozen addresses at law-enforcement request many times over.

Whether this works better than the exchange-centric model is the open question. Issuer-level freezing is fast and effective against known-bad addresses, which is precisely why sanctioned actors increasingly favor tokens they believe are harder to freeze. The regulatory calendar that will settle much of this runs through the autumn and into winter; we map the key dates in our September countdown.

The EU takes a harder line

Europe has gone further and faster. Its Anti-Money Laundering Regulation (Reg 2024/1624), which takes full effect on 10 July 2027, will ban anonymous crypto accounts and prohibit regulated crypto firms from dealing in privacy-enhancing coins such as Monero. A new Frankfurt-based supervisor, the Anti-Money Laundering Authority (AMLA), chaired by Bruna Szego, will from 2028 directly supervise up to 40 of the highest-risk institutions, crypto firms among them. The EU’s Transfer of Funds Regulation, its version of the Travel Rule, already applies with no minimum threshold at all, tighter than the US line of $3,000.

One point that trips up newcomers: MiCA, the EU’s flagship crypto law, is not the AML rulebook. MiCA governs market conduct, licensing, and stablecoin prudential rules. Anti-money-laundering obligations sit separately in the AMLR, in AMLA, and in the Transfer of Funds Regulation. A firm can hold a MiCA license and still fail its AML supervision, and a MiCA license does not by itself guarantee it a bank account.

DimensionUnited StatesEuropean Union
Lead AML authorityFinCEN and OFAC (Treasury)AMLA (Frankfurt) and national FIUs
Core rulebookBank Secrecy Act; GENIUS Act for stablecoinsAMLR (2024/1624) and the Transfer of Funds Regulation
Travel Rule threshold$3,000No minimum threshold
Anonymous accountsRestricted in practiceBanned from 10 July 2027
Privacy coinsNot bannedProhibited for regulated firms (2027)
Direction of travelLoosening edges, extending rules to issuersTightening broadly, centralizing supervision

The philosophical split is real. The US is, for now, loosening some edges (OFAC delisted Tornado Cash, and the administration dropped several crypto cases) while extending AML to stablecoin issuers. The EU is tightening across the board and betting on centralized supervision. Both are wagers on the same unproven proposition: that more comprehensive identity coverage will finally move the 0.2 percent number.

Can it be fixed? zk-proofs and reusable identity

If the current model is costly, leaky, and a honeypot, what would a better one look like? The most credible answers point in the same direction: prove less, reuse more, and stop copying raw documents into a hundred separate databases.

Reusable identity is the near-term fix. Under the EU’s revised eIDAS 2.0 regulation, every member state must offer a European Digital Identity Wallet, letting a user verify once with a trusted issuer and then present cryptographic credentials, built on standards like W3C Verifiable Credentials, to any firm, without that firm ever storing the underlying documents. Done well, it collapses dozens of honeypots into one and shifts breach risk away from every individual exchange.

The more radical fix is cryptographic. Zero-knowledge proofs let a user prove a fact (I am over 18, I am not on a sanctions list, I am a unique human) without revealing the data behind it, ideally with a break-glass audit trail so a court order can still unmask a genuine suspect. Proof-of-personhood projects such as World have signed up tens of millions of users on exactly that pitch, though they have collided with data-protection regulators in several countries over how they collect biometrics. Coin Center’s argument is that regulators should treat these tools as first-class compliance, not force firms to keep hoarding plaintext identity. As of 2026, though, neither the Financial Action Task Force nor EU supervisors formally recognize zero-knowledge KYC as sufficient on its own; the standards are still being written. In parallel, non-custodial instruments like discreet log contracts on Bitcoin show that whole categories of finance can run without any intermediary collecting identity in the first place, which reframes the question from how to verify better to how much still needs an intermediary at all.

So, does it work?

Add it up honestly and the verdict is uncomfortable for everyone. The regime demonstrably works at the edges. On-chain permanence plus KYC at the off-ramp recovered $3.6 billion from Bitfinex and extracted $4.3 billion from Binance, outcomes that traditional finance rarely matches. Public ledgers really are a new and powerful evidentiary tool, and enforcement has ended the “we are just a platform” defense for good.

But at the level of the whole system, the numbers are humbling. Something close to 99.8 percent of laundered money still gets through. Compliance runs past $26 billion a year in the US alone, most of it spent clearing false positives. The mandated data has become a honeypot that breaches like Coinbase’s turn against the very customers it was collected to protect. And when regulators squeeze one rail, the flows migrate to stablecoins, mixers, and sanctioned tokens faster than the rules can follow.

The most defensible reading is that crypto did not break AML; it exposed what was already true of the whole system, that it catches a little, costs a lot, and mostly moves crime around, while adding one genuinely new capability, traceable ledgers, that the old cash-based system never had. The reforms now being written, stablecoin-issuer rules in the US, centralized supervision in the EU, zero-knowledge identity everywhere, are all bets on tilting that ledger. Whether any of them finally moves the 0.2 percent is the question that will define the next several years of crypto policy, and it does not stop at the calendar’s edge; the fights run straight into the regulatory countdown that carries past September into January. Until then, “does KYC work?” has the same answer it has had for a decade: it works just well enough to justify itself, and nowhere near well enough to end the argument.

Frequently Asked Questions

Is KYC the same as AML?

No. AML (Anti-Money Laundering) is the entire body of law and controls designed to stop money laundering; KYC (Know Your Customer) is one part of it, the identity-verification step where a firm confirms who you are. In the US, KYC is formally the Customer Identification Program under the PATRIOT Act, sitting inside the broader AML framework of the Bank Secrecy Act.

Which US regulator enforces crypto AML rules?

FinCEN and OFAC, both part of the Treasury, not the SEC. Crypto exchanges are money services businesses that must register with FinCEN and follow the Bank Secrecy Act. The SEC only enters through the separate question of whether a token is a security. Most money-laundering penalties against exchanges come from FinCEN, OFAC, or the Department of Justice.

Does crypto KYC actually stop money laundering?

Partly. It has enabled major recoveries, such as the $3.6 billion Bitfinex seizure, and multi-billion-dollar penalties like Binance’s $4.3 billion. But the UN estimates only about 0.2 percent of laundered proceeds are ever seized system-wide, and illicit crypto flows hit a record $154 billion in 2025, so the regime catches a small fraction while imposing very large costs.

Why do exchanges ask for so much personal data?

Regulation requires it. To meet KYC and Customer Due Diligence rules, exchanges must collect government ID, address, date of birth, and often a biometric selfie, then monitor your transactions. The downside is that this creates a concentrated database of sensitive information, a honeypot, as the 2025 Coinbase breach of about 69,461 customers’ records showed.

What are the CTR and SAR thresholds in the US?

A Currency Transaction Report is required for cash transactions over $10,000, filed within 15 days. A Suspicious Activity Report is filed for suspicious activity at or above $2,000 at a money services business, within 30 days of detection. Records are kept for five years, and the Travel Rule attaches identifying information to transfers of $3,000 or more. Tipping off a customer that a SAR was filed is itself a crime.

By Anneke de Vries, senior regulation correspondent at HOGE Wire.

Share 𝕏 Post Telegram