The Binance Teardown: Crypto’s $4.3 Billion AML Lesson
Binance pleaded guilty to crypto's biggest AML failure, paid over $4.3 billion, and filed zero suspicious activity reports. Then its founder was pardoned. A full teardown.
On 23 October 2025, President Donald Trump pardoned Changpeng Zhao, the founder of Binance and the man who, two years earlier, had pleaded guilty to presiding over the largest anti-money-laundering failure in the history of cryptocurrency. By then Zhao had already served his four months, Binance had already paid its record penalties, and Bitcoin was trading near $79,900, roughly flat on the day as the market weighed a hawkish Federal Reserve and a September calendar full of macro landmines. The pardon undid none of it. What it did was close a loop that, for anyone who works in crypto compliance, still defines the whole subject.
The Binance case is the most complete, most expensive, and most quotable teardown of how know-your-customer (KYC) and anti-money-laundering (AML) rules are meant to work, precisely because Binance switched almost every one of them off. This is the fifth entry in our regulation series on the topic. The earlier pieces explained the mechanics, the deepfake arms race, debanking, and whether the apparatus even works. This one reads a single case front to back, because if you want to understand what a suspicious activity report is, why sanctions screening matters, what a compliance monitor does, and what it costs to get all of it wrong, you do not need a textbook. You need the Binance file. And in 2026, with Zhao pardoned and Binance quietly trying to shed the monitor it accepted in 2023, the file is worth reopening.
What KYC and AML actually mean, and why it is not the SEC
Start with the vocabulary, because the Binance case turns on it. AML is the umbrella: the body of law and internal controls designed to stop criminal money from moving through the financial system. KYC is one component of AML, the identity layer, which requires a business to verify who its customer actually is before letting them transact and to keep checking over time. In the United States the identity duty traces to the Customer Identification Program rules under the USA PATRIOT Act and to the customer due diligence obligations layered on top of them. KYC answers who; AML answers whether this money is clean.
Money laundering itself runs in three stages that every compliance officer learns on day one: placement (getting dirty cash into the system), layering (moving it through enough hops to obscure its origin), and integration (spending it back out as apparently clean funds). Crypto is weakest as a placement tool and strongest at layering, because value can cross borders in seconds through pseudonymous addresses. That is the gap KYC and transaction monitoring are supposed to close.
Here is the correction that has to be made in almost every crypto story: the Securities and Exchange Commission does not police this. US AML authority sits with FinCEN, the Financial Crimes Enforcement Network, and with OFAC, the Office of Foreign Assets Control, both housed inside the Treasury and operating under the Bank Secrecy Act of 1970. The Justice Department prosecutes the criminal cases; the Commodity Futures Trading Commission covers derivatives; the SEC only enters where a token is a security. A crypto exchange that serves US customers is a money services business, and a money services business must register with FinCEN and run an AML program. Binance’s crime was not a securities offense. It was a Bank Secrecy Act offense, and that distinction is the spine of everything that follows.
That an exchange counts as a money services business is not a novelty invented to punish Binance. FinCEN said so as far back as its 2013 virtual-currency guidance and reaffirmed it in 2019: any business that accepts and transmits convertible virtual currency on behalf of others is a money transmitter, and money transmitters carry the full weight of Bank Secrecy Act duties, from registration to reporting. Binance ran for years as though that rule did not reach an exchange headquartered nowhere in particular. The bill for that assumption arrived in November 2023.
The $4.3 billion breakdown
On 21 November 2023, Binance pleaded guilty and agreed to pay the Justice Department more than $4.3 billion, a sum Attorney General Merrick Garland called one of the largest corporate penalties in US history. The number needs unpacking, because the headlines routinely stack figures that actually overlap. The DOJ total folded in a $3.4 billion settlement with FinCEN, the largest in Treasury history, and a $968 million settlement with OFAC, both credited against the DOJ figure rather than piled on top of it. Running in parallel was a separate civil case from the CFTC, which a federal court approved for $2.7 billion in December 2023, with Zhao personally paying $150 million on top of the $50 million he owed the DOJ.
| Authority | Amount | What it resolved |
|---|---|---|
| Justice Department | More than $4.3 billion | Bank Secrecy Act, unlicensed money transmission, sanctions (IEEPA) |
| FinCEN (Treasury) | $3.4 billion | AML program failures; largest Treasury settlement to date (credited against the DOJ total) |
| OFAC (Treasury) | $968 million | Apparent sanctions violations (credited against the DOJ total) |
| CFTC (separate civil case) | $2.7 billion | Illegal derivatives offered to US persons; supervision failures |
| Changpeng Zhao (DOJ) | $50 million and four months | Failure to maintain an effective AML program |
| Changpeng Zhao (CFTC) | $150 million | Same conduct, civil liability |
| Samuel Lim, former chief compliance officer (CFTC) | $1.5 million | Aiding and abetting the violations |
Read the table as a map of the AML architecture, because each authority polices a different seam. FinCEN owns the program duties: registration, monitoring, reporting. OFAC owns sanctions. The DOJ brings the criminal weight when the failures are willful. The CFTC owns the derivatives that Binance offered US customers without permission. One firm managed to breach all four at once. And Binance was the biggest of a wave, not a one-off: in early 2025 OKX pleaded guilty and paid more than $504 million, and KuCoin more than $297 million, for parallel failures to register and to run real programs. Binance remains the reference case, because of its scale and because its own staff documented the intent so thoroughly.
Zero suspicious activity reports
If you remember one fact from the Binance file, make it this one: the company processed more than 100,000 transactions that it should have flagged, and it never filed a single suspicious activity report. That is the number that makes compliance professionals wince, because of what it says about the plumbing.
A suspicious activity report, or SAR, is the workhorse of the whole AML regime. A money services business must file one with FinCEN within 30 days of detecting a transaction of $2,000 or more that it suspects involves illicit funds or has no apparent lawful purpose. Filing is confidential, and tipping off the customer that a report was filed is itself a federal crime. Records must be kept for five years. There is a sibling report for cash, the currency transaction report, or CTR, triggered by any cash transaction over $10,000 and due within 15 days; it matters less for a crypto-native exchange, but it is part of the same furniture.
Behind the report sits the thing that generates it: transaction monitoring. A working system watches for patterns that map to known laundering behaviour, such as structuring deposits to stay under thresholds, funds that arrive and leave within minutes, sudden spikes that do not fit a customer’s profile, and, in crypto specifically, flows to and from mixers, freshly created wallets, or addresses that on-chain analytics have tied to theft, ransomware, or sanctioned entities. None of it works without the identity layer underneath, because a flagged transaction is only actionable if you know whose it is. Binance had the transaction data. It had chosen not to build the layer that turns data into a report.
The reason zero is such a damning figure is that a functioning program cannot produce zero. Real monitoring generates false positives by the thousand; analysts triage them, and a slice becomes SARs. An exchange the size of Binance, handling the volume it handled and filing nothing at all, was not running a program that happened to miss things. It was running no program at all. Treasury Secretary Janet Yellen put it plainly: Binance, she said, was allowing illicit actors to transact freely, supporting activities from child sexual abuse, to illegal narcotics, to terrorism. The transactions flowed; the reports never did.
The five pillars Binance never built
US law does not ask a money services business to be perfect. It asks it to build a program with five specific pillars. The first four come from the original Bank Secrecy Act framework: a designated compliance officer with real authority, written internal controls, ongoing staff training, and independent testing of the whole system. The fifth pillar, risk-based customer due diligence and beneficial-ownership identification, was added by FinCEN’s 2016 customer due diligence rule and took effect in 2018. Together they are the checklist an examiner walks through. Binance failed on every line.
| Pillar | What the BSA requires | Where Binance fell short |
|---|---|---|
| Compliance officer | A named, empowered AML officer | Compliance was under-resourced and overruled by growth targets |
| Internal controls | Written policies, monitoring, escalation | No systematic transaction monitoring; red flags waved through |
| Training | Ongoing AML training for staff | Employees joked about laundering in internal chats |
| Independent testing | Regular independent audit of the program | No effective independent review |
| Customer due diligence | Verify identity and beneficial owners, risk-rate customers | No mandatory KYC for all users until August 2021; sub-accounts bypassed it |
The customer due diligence pillar deserves attention, because it is where KYC lives. Standard due diligence means verifying identity and risk-rating the customer; enhanced due diligence, or EDD, means digging deeper for higher-risk cases such as large institutional clients or users in high-risk jurisdictions. Binance did not require full identity verification from all users until August 2021, years into its life as the world’s largest exchange, and even then, as the next sections show, the wealthiest customers were routed around the checks.
The chat logs
What separates a fine from a criminal case is intent, and intent is where Binance’s own employees convicted the company. The CFTC complaint, filed in March 2023, quotes internal chats that read less like negligence than like a running commentary on it. Reviewing transactions tied to Hamas in 2019, chief compliance officer Samuel Lim reasoned that small sums were not worth the trouble because a user could barely buy an AK47 with 600 bucks. Of Russian clients, Lim wrote in the same reporting, “Like come on. They are here for crime.” A colleague responsible for money-laundering reporting summed up the house position: “we see the bad, but we close 2 eyes.”
Those lines are not color. They are the legal turning point. A compliance failure born of incompetence is a civil matter; a failure the staff can be shown to have understood and shrugged off is willful, and willfulness is what unlocks criminal charges and prison. Lim eventually settled with the CFTC for $1.5 million for aiding and abetting the violations. A real compliance culture escalates a flagged transaction; Binance’s culture, in its own words, closed two eyes.
The whales and the sub-account trick
Binance told the public it did not serve US customers. In private it worked to keep the most lucrative ones. The CFTC alleged that Binance actively courted US-based market makers and high-volume traders, the whales, while coaching them to evade its own controls, including guidance on using VPNs to disguise their location and help setting up offshore shell entities. The mechanism that made it work is a small piece of exchange architecture worth understanding: the sub-account.
Prime brokers were allowed to open sub-accounts that sat underneath a verified parent account but were not themselves subjected to KYC. An unscreened trader could then ride the rails of a screened one. This is the textbook reason onboarding KYC exists in the first place: not to inconvenience an ordinary user, but to make sure that every entity actually moving money has been identified and risk-rated. A single unchecked sub-account is a hole in the hull. The leveraged products those whales traded were also the heart of the CFTC’s charge, because offering crypto derivatives to US persons without registration is illegal, a jurisdictional line that today’s perpetual-futures venues still have to manage carefully.
Sanctions: matching Americans with Iran and North Korea
The OFAC side of the case is the one with national-security teeth. Binance’s matching engine paired US users with counterparties in comprehensively sanctioned jurisdictions, including Iran, North Korea, Syria, and the Crimea region of Ukraine, and the platform failed to stop transactions involving designated terrorist groups: Hamas’ Al-Qassam Brigades, Palestinian Islamic Jihad, Al Qaeda, and ISIS. Sanctions compliance is a distinct discipline from KYC. It means screening every customer and counterparty against OFAC’s list of specially designated nationals, geofencing sanctioned territories, and blocking or rejecting prohibited transactions. Sanctions liability is also strict: you can breach it without meaning to, which is exactly why the screening has to be automatic and constant.
North Korea is the apex case here, and not a historical one. State-linked operators remain the most sophisticated sanctions-evasion actor in crypto, laundering the proceeds of exchange hacks through mixers and stablecoins, and the value flowing to sanctioned entities rose sharply again in 2025. Our post-mortem on North Korea’s crypto operations traces how far inside companies that threat now reaches, from stolen keys to salaried infiltrators. An exchange that lets Americans trade with Pyongyang, even passively through a matching engine, is not committing a paperwork error. It is a link in that chain.
The monitor nobody wants
Money and prison make the headlines, but the part of the settlement that reshapes a company day to day is the monitor. As part of the resolution Binance accepted an independent compliance monitor for the Justice Department, running three years, and a separate five-year monitor for FinCEN. A corporate monitor is an outside firm, reported to be Forensic Risk Alliance in this case, that embeds inside the company, audits its controls, and reports back to the government. For the duration, a convicted firm effectively runs its compliance function with a government-appointed auditor reading over its shoulder.
What that auditor oversees is not a one-off fix but years of catch-up work. Remediation on this scale means rebuilding KYC from the ground up, re-screening an existing customer base that was never properly checked, running lookbacks over historical transactions to file the reports that should have gone in at the time, and standing up the monitoring pipeline that was missing all along. This is the expensive, unglamorous core of AML, and it is the part a fine alone never buys. It is also why lifting a monitor early is such a prize: it signals that the government believes the rebuild is finished.
That is the piece Binance is now trying to escape. In 2026 the exchange asked the DOJ to end the three-year monitor early, and prosecutors are weighing the request; the FinCEN monitor runs longer. The timing is not accidental. The Justice Department under the current administration has signaled broad skepticism about corporate monitors, with Criminal Division head Matthew Galeotti arguing that they can impose heavy costs and interfere with legitimate business, and Binance’s BNB token jumped above $950 on the prospect of the oversight being lifted. The monitor is the least visible part of AML enforcement and, arguably, the most consequential, because it is where a broken program is actually rebuilt rather than merely fined.
CZ: four months, then a pardon
Zhao’s own path through the case is the human core of it. In April 2024 a federal judge sentenced him to four months in prison, making him the first head of a global crypto empire jailed under US financial law. He reported to Lompoc II, a low-security facility on the California coast, and was released on 29 September 2024 after roughly 118 days. He had already agreed to pay his $50 million fine and to step away from managing the company he built; Richard Teng runs Binance today.
Then, on 23 October 2025, came the pardon. It helps to be precise about what a presidential pardon does and does not do. It forgives Zhao’s federal conviction and restores the civil rights he lost, and it removes the personal weight of the felony. It does not reverse Binance’s corporate guilty plea, claw back the $4.3 billion, or unmake the factual findings that the government spent years assembling. The record of what happened stands; only the punishment of the man at the top was undone.
The pardon’s shadow: USD1, MGX, and the conflict question
The pardon did not land in a vacuum, and this is where the 2026 story turns political. Months before it, an Abu Dhabi state fund, MGX, made a $2 billion investment into Binance that was settled using USD1, the stablecoin issued by World Liberty Financial, the Trump family’s crypto venture. Binance listed USD1, and the Wall Street Journal reported that the exchange had also helped build the technology behind it. The deal handed the young stablecoin roughly $2 billion in fresh liquidity and, by some estimates, $60 million to $80 million a year in reserve yield for World Liberty Financial.
Senator Elizabeth Warren branded the pardon corruption on stilts and, with Representative Adam Schiff, pushed for an investigation. Binance chief executive Richard Teng rejected the implication that the exchange had boosted a Trump-linked token to buy Zhao’s freedom, saying the choice to use USD1 was decided by MGX and that Binance did not partake in that decision. The president, for his part, told 60 Minutes that he did not know who Zhao was and called the prosecution a Biden witch hunt.
For the purposes of this piece the merits of that dispute matter less than the structural lesson: AML enforcement is now a political variable, not just a legal constant. The same administration delisted the Tornado Cash smart contracts from OFAC’s sanctions list in March 2025 and let other crypto cases wind down, and the retrial of Tornado Cash developer Roman Storm has slipped to April 2027. The rulebook did not change; the appetite to enforce it did.
Does any of it work?
The Binance case is a triumph for AML in one sense and an indictment of it in another. We examined the efficacy question at length separately, so here is the short version. The critics have a strong dataset: Chainalysis estimates that illicit addresses received at least $154 billion in 2025, up 162 percent, yet that is still under 1 percent of all on-chain volume, and about 84 percent of it now moves in stablecoins. Coin Center’s Peter Van Valkenburgh argues that the existing regime does remarkably little to prevent illicit finance, while US firms spend north of $26 billion a year on compliance and, by one UN estimate, roughly 0.2 percent of criminal proceeds are ever seized.
Part of that cost is structural waste. The overwhelming majority of the alerts a monitoring system throws are false positives, and only a small fraction ever ripen into a report an investigator acts on, which means teams of analysts spend their days clearing noise. Critics argue the burden also falls hardest on ordinary users and small firms, who absorb the friction and the data collection while the sophisticated actors the rules are aimed at route around them. Supporters counter that the deterrent effect and the evidentiary trail are worth the price. The Binance file, uncomfortably, hands both sides ammunition.
And yet the Binance prosecution is itself the counterargument. The entire case was built on the company’s own chat logs and on the permanent, public record of the blockchain. Transparency cut both ways: the same ledger that criminals use to move value is the ledger that let investigators reconstruct exactly what moved and when. The honest reading is that the regime is far better at building a case after the fact than at stopping the money in real time. Binance was caught; the criminal and terror-linked flow it waved through in the moment was not stopped.
What the next Binance will have to do
Strip away the drama and the case is a specification for a compliant exchange. Any venue touching US customers has to register with FinCEN as a money services business, build the five pillars, run real KYC at onboarding (document verification, liveness checks, sanctions screening, and ongoing monitoring), comply with the Travel Rule, and file SARs and CTRs when the triggers hit. The thresholds are not secret; they are the reference points in the table below.
| Obligation | Trigger or threshold | Deadline |
|---|---|---|
| FinCEN registration | Operating as a money transmitter | Within 180 days of starting |
| Suspicious activity report (SAR) | Suspicious activity of $2,000 or more at an MSB | 30 days from detection |
| Currency transaction report (CTR) | Cash over $10,000 | 15 days |
| Travel Rule recordkeeping | Transfers of $3,000 or more (US) | At the time of transfer |
| Recordkeeping | All of the above | Retain for 5 years |
The rulebook has also hardened since 2023. The GENIUS Act made payment-stablecoin issuers Bank Secrecy Act institutions in their own right, with an obligation to be able to freeze and seize tokens on lawful order, which pushes compliance down into the settlement asset itself. In the European Union, the new Anti-Money Laundering Regulation and the authority created to enforce it, AMLA, based in Frankfurt, will ban anonymous crypto accounts and privacy-coin services from 2027, while the Transfer of Funds Regulation applies the Travel Rule with no minimum threshold at all.
- Register and licence first: operating an unregistered money transmitter is itself the offense, before any laundering happens.
- KYC binds the intermediary, not the protocol: the duty falls on the custodial business, which is why the debate over self-custody and where the exchange ends matters so much.
- Screening must be automatic: sanctions liability is strict, so manual review is not a defense.
- Keep the records: five years, because the case against you, or the case that clears you, will be built from them.
The frontier is trying to get the benefit without the surveillance. Zero-knowledge proofs and reusable digital identity aim to let a user prove they are verified and not sanctioned without handing the same identity documents to every exchange, an approach that would also shrink the honeypot of personal data that made recent exchange breaches so damaging. Where that cryptographic tooling actually ships is a live question, but the direction is set. The Binance file is the argument for why the destination matters.
Frequently Asked Questions
How much did Binance pay for its AML failures?
Binance agreed to pay the Justice Department more than $4.3 billion in November 2023, a figure that included a $3.4 billion FinCEN settlement and a $968 million OFAC settlement credited against it. A separate CFTC civil case added $2.7 billion. Founder Changpeng Zhao personally paid $50 million to the DOJ and $150 million to the CFTC, and former compliance chief Samuel Lim paid $1.5 million.
What is a suspicious activity report?
A suspicious activity report, or SAR, is a confidential filing a money services business must send to FinCEN within 30 days of detecting a transaction of $2,000 or more that it suspects involves illegal funds. Tipping off the customer is a crime, and records are kept for five years. Binance processed over 100,000 transactions it should have flagged and filed zero SARs.
Did Changpeng Zhao go to prison?
Yes. Zhao was sentenced to four months in April 2024, served about 118 days at a low-security facility in California, and was released in September 2024, becoming the first head of a major crypto exchange jailed under US financial law. President Trump pardoned him in October 2025, which forgives his conviction but does not reverse Binance’s corporate guilty plea or the penalties paid.
Is Binance still under a compliance monitor in 2026?
Binance accepted a three-year DOJ monitor and a five-year FinCEN monitor as part of its 2023 settlement. In 2026 it asked the Justice Department to end the three-year monitor early, and prosecutors are weighing the request; the FinCEN monitor runs longer. A corporate monitor is an outside firm that audits the company’s controls and reports to the government.
Does the SEC regulate crypto AML in the US?
No. US anti-money-laundering authority sits with FinCEN and OFAC inside the Treasury, under the Bank Secrecy Act, with the Justice Department prosecuting and the CFTC covering derivatives. The SEC only gets involved where a token qualifies as a security. Binance’s case was a Bank Secrecy Act matter, not a securities one.
Anneke de Vries is HOGE Wire’s regulation and policy correspondent, covering crypto compliance across the United States and the European Union.