OKX’s $504 Million Lesson: When Crypto KYC Is Just Paper
OKX pleaded guilty and paid over $504 million for years of AML failures, then relaunched in the US weeks later. Here is what the case shows about how crypto KYC and AML actually work in 2026.
In April 2025, OKX did something that looked strange for a company that had just admitted to years of criminal conduct: it opened a shiny new office. The exchange launched a United States trading platform and a self-custody wallet, set up a regional headquarters in San Jose, California, and named a former Barclays executive, Roshan Robert, as its US chief executive, according to Fortune. The relaunch came barely two months after OKX’s operator pleaded guilty in Manhattan federal court and agreed to pay more than $504 million for breaking American anti-money-laundering law, as the Department of Justice announced.
The paradox is the story. OKX had know-your-customer rules on paper. It had a policy that said US residents were not allowed to trade. What it did not have, for most of seven years, was a working system to enforce any of it, and at least one employee actively coached American users on how to lie their way past the controls that did exist, per Finance Magnates. That gap, between compliance on paper and compliance in practice, is the clearest lesson crypto got in 2026 about what KYC and AML actually require.
It also arrives at an awkward moment. Bitcoin is trading near $85,700, close to an eight-month high, per CoinGecko, and the market has spent September shrugging off a Federal Reserve that rallied even after a hike to a 3.75 to 4 percent target. Washington’s appetite for crypto enforcement has cooled, and the mood in 2026 is lighter than the crackdown years that produced the OKX plea. But the machinery that caught OKX has not been dismantled, and the monitor overseeing its cleanup runs until 2027. This piece uses the OKX case to explain how crypto KYC and AML really work, who enforces them (it is not the Securities and Exchange Commission), and whether any of it stops crime.
What OKX actually admitted
Aux Cayes FinTech Co. Ltd., the Seychelles-based company that operates OKX (founded in 2017 by Star Xu and owned by OK Group), pleaded guilty on 24 February 2025 to a single count: operating an unlicensed money transmitting business, a violation of Section 1960 of the federal criminal code. It agreed to forfeit $420.3 million and pay an $84.4 million fine, more than $504 million in total, according to the Justice Department. Prosecutors said OKX facilitated more than $5 billion in suspicious transactions and criminal proceeds over a span of more than seven years.
The detail that makes this a KYC story rather than a generic fraud story: OKX did not deploy commercially available software to monitor and detect suspicious activity until around May 2023, years into serving a global market, per Finance Magnates. Its official policy barred US persons, yet the company knew Americans were opening and using accounts, and one employee told US-based customers they could get around the restriction by simply lying about their country of residence.
“For over seven years, OKX knowingly violated anti-money laundering laws and avoided implementing required policies to prevent criminals from abusing our financial system,” said Matthew Podolsky, then the Acting US Attorney for the Southern District of New York, in the office’s announcement. Note the wording: not that OKX laundered money itself, but that it built no barrier to stop others from doing so. That distinction is the whole of anti-money-laundering law.
KYC and AML, and why this is not an SEC case
The two acronyms get used interchangeably, but they are not the same thing. Anti-money laundering (AML) is the umbrella: the body of law and controls meant to stop criminal money from moving through the financial system, anchored in the United States by the Bank Secrecy Act of 1970. Know-your-customer (KYC) is one component of AML, the identity layer, drawn from the Customer Identification Program rules under Section 326 of the USA PATRIOT Act and the customer due diligence rules that followed. Every KYC check is part of AML; AML is much bigger than KYC.
Here is the part that trips up even seasoned crypto readers: in the US, this is not the SEC’s job. Crypto AML is enforced by the Financial Crimes Enforcement Network (FinCEN) and, for sanctions, the Office of Foreign Assets Control (OFAC), both part of the Treasury, with the Justice Department bringing the criminal cases. The SEC polices whether a token is a security; it does not run the anti-money-laundering regime. The OKX, KuCoin, and Binance cases were all Treasury-and-DOJ matters, charged under money-transmission and Bank Secrecy Act law, not securities law. Getting that right matters, because the AML rules apply regardless of how any token is classified.
The mechanics follow from there. A crypto exchange that touches US customers is a money services business (MSB) and must register with FinCEN, generally within 180 days of starting up. Money laundering itself is usually described in three stages: placement, getting illicit money into the system; layering, obscuring its trail through many transactions; and integration, bringing it back out as apparently clean funds. Crypto is arguably weakest, from a launderer’s point of view, at the layering stage, because a public blockchain records every hop for anyone with the right tools to follow.
The five pillars, and how OKX missed them
US regulators expect any obligated institution to run an AML program built on five pillars: a designated compliance officer, written internal controls, ongoing staff training, independent testing or audit, and risk-based customer due diligence with beneficial-ownership checks (the fifth pillar, added by the 2016 CDD Final Rule). OKX’s plea reads like a checklist of what happens when those pillars are hollow.
| AML pillar | What it requires | Where OKX fell short |
|---|---|---|
| Compliance officer | A named person accountable for the AML program | The program ran for years without effective ownership or enforcement |
| Internal controls | Systems to detect and block suspicious activity | No commercial transaction-monitoring software until around May 2023 |
| Training | Staff trained to spot and stop laundering | Staff instead coached US users on how to bypass restrictions |
| Independent audit | Regular outside testing of the controls | Gaps left unaddressed for more than seven years |
| Risk-based CDD | Verify identity and owners, screen for risk | Served US customers its own policy banned, without adequate checks |
Read together, the failures compound. No automated monitoring until 2023 meant the internal-controls pillar barely existed. Staff coaching users to falsify data is the opposite of a compliance culture. Serving a market the company had formally banned is a risk-based due-diligence failure at the most basic level. The pillars are not decoration; they are the difference between an exchange and a laundromat, and a program that satisfies four of five is not four-fifths compliant, it is exposed.
Section 1960, or how the US reaches an offshore exchange
The charge in every one of these cases was not money laundering in the cinematic sense. It was operating an unlicensed money transmitting business under Section 1960 of Title 18 of the US Code. The statute makes it a crime to run a money-transmitting business without the required state licenses or FinCEN registration, or one that moves funds the operator knows come from crime. It is the government’s favored tool against offshore exchanges precisely because it does not require proving the platform laundered any particular dollar. It is enough that the business operated in the US without the license and the controls the law demands.
That is why the standard offshore defense, we do not serve Americans, so US rules do not apply to us, keeps collapsing. OKX’s plea shows the mechanism: the company knew US traders were on the platform, its own staff helped them stay, and it collected the fees. A geoblock that exists on the terms-of-service page but not in the matching engine is not a control. Jurisdiction follows the customers and the dollars, not the address on an incorporation certificate in the Seychelles. Any exchange that quietly welcomes US volume while claiming to shut it out is, in the eyes of the Southern District of New York, an unlicensed money transmitter operating on American soil.
What a real KYC check does, and what paper KYC skips
A functioning KYC check has four moving parts. Document verification asks whether the identity document is genuine. Liveness or biometric checks ask whether a real, present person is behind it, not a photo or a deepfake. Sanctions and politically-exposed-person screening asks whether serving this customer is forbidden. And ongoing transaction monitoring asks whether the account’s later behavior looks like laundering. Vendors such as Sumsub, Jumio, Onfido, and Persona sell the first three; blockchain analytics firms handle much of the fourth. Standard customers get customer due diligence (CDD); higher-risk ones, large accounts, users in risky jurisdictions, or politically exposed persons, get enhanced due diligence (EDD), which means more documentation, source-of-funds questions, and closer watching.
Now compare that to what the DOJ actually found. BitMEX, the template for this whole run of cases, required only an email address to open an account and start trading, according to the Justice Department. OKX ran without automated monitoring until 2023 and let staff walk users past its checks. When someone says an exchange had KYC, the only question that matters is whether the check was enforced or merely displayed. A static onboarding form that nobody follows up on, an ID upload that is never screened against a watchlist, a monitoring rule that fires and is ignored: those are the artifacts of paper KYC, and they are worth exactly nothing when prosecutors come to read the logs.
SARs, CTRs, and the thresholds that trigger them
The heart of AML is not the ID check; it is the reporting. An obligated institution must file a Suspicious Activity Report (SAR) when it sees activity that looks like laundering or fraud, generally for anything at or above $2,000 at a money services business, within 30 days of detection. It must file a Currency Transaction Report (CTR) for cash movements over $10,000, within 15 days. It must keep records for five years, and it must follow the Travel Rule, passing originator and beneficiary information alongside transfers at or above $3,000. Tipping off a customer that they are being reported is itself a crime.
| Obligation | Trigger or threshold | Deadline or rule |
|---|---|---|
| Register as an MSB with FinCEN | Operating a money-transmitting business | Within 180 days of starting |
| File a Suspicious Activity Report (SAR) | Suspicious activity, generally $2,000 or more | Within 30 days of detection |
| File a Currency Transaction Report (CTR) | Cash transactions over $10,000 | Within 15 days |
| Follow the Travel Rule | Transfers of $3,000 or more | Send originator and beneficiary information |
| Retain records | All of the above | Keep for 5 years |
| Do not tip off | A customer who is the subject of a SAR | Disclosure is itself a crime |
Binance’s failure was the starkest version of getting this wrong: it processed enormous volumes and never filed a single SAR before its 2023 plea, per the Justice Department. OKX’s failure was the monitoring gap that made SARs impossible, because you cannot report suspicious activity you have built no system to see. The reporting burden is not unique to AML, either. The US also leans on exchanges to report customer activity to the tax authorities, a parallel regime HOGE Wire examined in its look at the 2026 crypto tax bill. Both regimes share one logic: the intermediary is the chokepoint, so the intermediary does the paperwork.
The enforcement wave: BitMEX, Binance, KuCoin, OKX
OKX was not an outlier; it was the fourth act in a run of guilty pleas by offshore exchanges, all charged under the same money-transmission and Bank Secrecy Act law, all sharing the same flaw: KYC that existed on paper, in a weak form, or not at all.
| Exchange (operator) | Resolved | Penalty | Core failure | Outcome |
|---|---|---|---|---|
| BitMEX (HDR Global) | Founders 2022; entity Jan 2025 | $100M corporate fine ($10M each founder) | Only an email needed to trade | Two years’ probation |
| Binance | Nov 2023 | More than $4.3B | Never filed a single SAR | CZ guilty; monitors imposed; later pardoned |
| KuCoin (Peken Global) | Jan 2025 | More than $297M | No effective AML/KYC; unregistered | Out of US 2+ years; founders removed; barred 2026 |
| OKX (Aux Cayes FinTech) | Feb 2025 | More than $504M | No monitoring until 2023; staff coached evasion | Consultant to 2027; relaunched US Apr 2025 |
BitMEX set the pattern. Its founders pleaded guilty to Bank Secrecy Act violations in 2022 and paid $10 million each, and the corporate entity was fined $100 million and sentenced to two years’ probation in January 2025 (DOJ). Binance was the giant: more than $4.3 billion in November 2023, with founder Changpeng Zhao personally pleading guilty to a Bank Secrecy Act violation. KuCoin’s operator, Peken Global, another Seychelles company, pleaded guilty in January 2025, paid more than $297 million, agreed to leave the US for at least two years, and saw founders Chun Gan and Ke Tang pushed out (DOJ); a CFTC order in March 2026 then barred it from the US market permanently. OKX closed the set.
The line that defined the era came from then-Attorney General Merrick Garland at the Binance announcement: “Using new technology to break the law does not make you a disruptor. It makes you a criminal.” The through-line across all four cases is the same, and it is the opposite of a technology problem. These were policy choices: to skip the license, to skip the monitoring, to treat identity as a formality. The blockchain did not launder anyone’s money. The exchanges chose not to look.
The monitor, and life after the plea
A guilty plea is rarely the end of the story; the more consequential part is the monitor. OKX agreed to keep an external compliance consultant, which it had voluntarily retained in early 2024, in place through February 2027 to overhaul its AML and KYC programs, per Yahoo Finance. The company is careful to note there was no government-appointed monitor and no charges against individual employees, which distinguishes it from Binance, which took on both DOJ and FinCEN monitors as part of its far larger settlement. A compliance monitor is simply an outside firm that reports on whether the company is actually fixing what it broke: building the transaction-monitoring it lacked, staffing a real compliance function, testing the controls. It is the mechanism that turns a one-time fine into years of supervised change.
Then came the reset. Two months after the plea, OKX was back, licensed and compliance-first, in San Jose. In a February 2025 statement, the exchange said it had only “a small percentage of customers who were able to use our international services due to historical compliance gaps,” and Star Xu said the goal now was to make OKX “the gold standard of global compliance at scale across different markets and their respective regulatory bodies,” per CryptoSlate. Whether the gold-standard language holds up is a question for the monitor, not the marketing team. KuCoin’s founders got no such second act; they were removed. The range of outcomes, from a supervised relaunch to a permanent bar, is the real menu of consequences an exchange faces when its KYC turns out to be paper.
A softer climate, but the machine still runs
The political weather has changed since these pleas landed. President Trump pardoned Changpeng Zhao in October 2025. OFAC delisted the Tornado Cash smart contracts in March 2025 after a court loss. Several crypto probes and civil cases from the prior era were dropped. And in September 2026, the market-structure CLARITY Act failed a Senate cloture vote, leaving the digital-asset rulebook improvised rather than codified.
None of that repealed the Bank Secrecy Act. OKX’s monitor still runs to 2027. KuCoin’s permanent CFTC bar landed in March 2026, well into the friendlier climate. The anti-money-laundering regime is statutory, and it is carried out by career prosecutors and Treasury officials rather than by whichever administration sets the tone. That is the subtle point exchanges took from the OKX case. Enforcement is not over; the register of open matters simply gets shorter and quieter. The cost of paper KYC did not fall. It is still a nine-figure check plus years of an outside firm reading your compliance email.
Does any of this actually stop crime?
The uncomfortable question is whether the whole apparatus works, and the honest answer is mixed. On one side, the blockchain is evidence. Every one of OKX’s $5 billion in suspicious flows sat on a public ledger, traceable by the same analytics tools that now underpin most crypto investigations; the transparency that makes crypto attractive to launderers is also what convicts them. On the other side, the numbers are not flattering. Chainalysis put illicit crypto flows at a record $154 billion in 2025, up 162 percent, though still under 1 percent of all on-chain volume, and it called even that a lower-bound estimate in its 2026 crime report.
The money also moved. Stablecoins now carry about 84 percent of illicit crypto transaction value, up from 63 percent the year before, and flows to sanctioned entities jumped 694 percent, per the same report. Tighter enforcement at the regulated front door pushes activity toward stablecoins and self-custodied wallets, where the KYC gate does not sit. The rise of smart, self-custodial wallets, which HOGE Wire mapped in its account-abstraction field guide, is exactly the perimeter where an exchange-centric AML model runs out. Issuers can still freeze or seize many stablecoins, an off-switch HOGE Wire examined in its look at crypto’s kill-switch reckoning, which is why sanctioned actors increasingly favor coins engineered to resist it.
Peter Van Valkenburgh of Coin Center argues the regime “does remarkably little to prevent illicit finance,” while imposing more than $26 billion a year in US compliance costs; by one United Nations estimate cited in his research, roughly 0.2 percent of criminal proceeds are ever seized. The OKX case cuts both ways here. The fine was large and the conduct was real, but the $5 billion had already flowed by the time the plea was entered. A control that catches the wrongdoing only after the money is gone is a deterrent and a punishment, not a prevention. Supporters would say the deterrent is precisely the point, and the run of nine-figure pleas is the evidence.
Europe’s harder line
Where the US relies on case-by-case prosecutions, Europe is writing the controls into statute. The Transfer of Funds Regulation, the EU’s version of the Travel Rule, has applied since December 2024 with no minimum threshold, so information travels with every crypto transfer between regulated firms (EUR-Lex). The Anti-Money Laundering Regulation, or AMLR, takes full effect on 10 July 2027 and will ban anonymous crypto accounts and privacy coins outright (EUR-Lex). And a new supervisor, the Anti-Money Laundering Authority (AMLA) in Frankfurt, chaired by Bruna Szego, is preparing to directly supervise 40 of the highest-risk institutions from 2028, with crypto flagged as an explicit priority, according to the authority.
Europe keeps all of this separate from MiCA, its crypto market-conduct rulebook; a MiCA license is not an AML clearance, and firms have to satisfy both regimes. On the US side, the direction is similar even without new market-structure law. The GENIUS Act of 2025 pulled payment-stablecoin issuers into the Bank Secrecy Act as financial institutions, and a joint FinCEN and OFAC proposal in April 2026 would, for the first time, mandate sanctions-compliance programs by statute (Federal Register). The message on both sides of the Atlantic is the same: more rules, attached to more intermediaries, with the identity check as the entry point.
What it means for users and for exchanges
For users, the takeaway is that the check is supposed to be real. A compliant exchange will verify your ID and your face, screen you against sanctions lists, and monitor your activity, and a large or unusual transfer can trigger enhanced due diligence and a request to document the source of funds. That is not the exchange being difficult; it is the exchange staying out of an OKX-shaped hole. Self-custody is not banned, and moving your own coins between wallets you control is not a reportable event, but the moment you touch a regulated venue, the gate applies. The friction is the feature.
For exchanges and builders, the OKX lesson is blunt: monitoring is not optional, and compliance culture starts at the top. A platform can publish a flawless policy and still be a criminal enterprise if nobody enforces it, and the fastest route to a nine-figure penalty is to treat KYC as a form rather than a function. The audit-and-compliance industry that has grown up around this, from blockchain analytics vendors to specialist firms like the one HOGE Wire followed into central-bank digital-currency work, exists because regulators now expect controls to be tested, not merely written.
The comforting version of the OKX story is the redemption arc: plead, pay, hire a monitor, relaunch clean in San Jose. The truer version is the one in the plea documents. For most of seven years, the rules lived on the website and were absent from the code, and it took a $504 million check plus a monitor through 2027 to close the gap. In 2026, that is what crypto KYC actually costs when it turns out to be only paper.
Frequently Asked Questions
What did OKX plead guilty to, and how much did it pay?
OKX’s operator, the Seychelles-based Aux Cayes FinTech, pleaded guilty in February 2025 to operating an unlicensed money transmitting business under US law and agreed to pay more than $504 million, made up of $420.3 million in forfeiture and an $84.4 million fine. Prosecutors said the exchange facilitated more than $5 billion in suspicious transactions across a period of over seven years.
What is the difference between KYC and AML?
AML, or anti-money laundering, is the whole framework of laws and controls meant to stop criminal money from moving through the financial system. KYC, or know your customer, is one part of it: the identity layer that verifies who a customer is. Every KYC check sits inside AML, but AML also covers transaction monitoring, suspicious-activity reporting, sanctions screening, and recordkeeping.
Does the SEC regulate crypto AML in the United States?
No. Crypto anti-money-laundering rules are enforced by FinCEN and OFAC, both part of the Treasury, with the Justice Department bringing criminal cases. The SEC deals with whether a token is a security, which is a separate question. The OKX, Binance, and KuCoin cases were all money-transmission and Bank Secrecy Act matters, not securities cases.
Why do crypto exchanges ask for so much personal information?
Because a US-facing exchange is a regulated money services business and must verify identity, screen customers against sanctions lists, monitor transactions, and report suspicious activity. Skipping those steps is what led to the guilty pleas and penalties at OKX, Binance, KuCoin, and BitMEX. Higher-risk accounts also face enhanced due diligence, which can include questions about the source of funds.
Did OKX shut down after its guilty plea?
No. OKX kept operating globally and relaunched a licensed US platform in April 2025, roughly two months after the plea, with a new US chief executive and a headquarters in San Jose, California. It also agreed to keep an external compliance consultant reviewing its AML and KYC programs through February 2027.
Anneke de Vries is HOGE Wire’s regulation lead, covering crypto compliance, enforcement, and the rules that shape digital-asset markets.