h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

Crypto KYC and AML in 2026: How the Rules Actually Work

KYC and AML are the price of every crypto on-ramp. Here is what identity checks actually require in 2026, who enforces them, and where the system breaks.

Every time you open an account on a regulated crypto exchange, you hand over a photo of a government ID and a selfie before you can buy a single dollar of Bitcoin. That friction is not an accident or a design flaw. It is Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance, the legal machinery that decides who is allowed onto the on-ramp between the banking system and the blockchain. In 2026 that machinery is stricter, more expensive, and more contested than at any point in crypto history.

The numbers explain the pressure. The years from 2023 through 2026 delivered the largest AML enforcement wave the industry has seen: a $4.3 billion guilty plea from Binance, a $504 million resolution from OKX, and a KuCoin settlement that pushed its founders out. At the same time, Chainalysis reported that illicit cryptocurrency addresses received at least $154 billion in 2025, and a data breach at Coinbase showed the other edge of the sword: the identity documents you surrender for KYC become a target the moment they are stored. This explainer walks through what KYC and AML actually mean (they are not the same thing), what happens when you sign up, who writes and enforces the rules, and the widening fault line between financial surveillance and privacy.

KYC and AML Are Not the Same Thing

People use the phrase KYC/AML as if it were a single word, but the two terms describe different things. AML is the umbrella: the entire body of law, regulation, and internal controls designed to stop the financial system from being used to launder criminal proceeds or fund terrorism. KYC is one component inside that umbrella, the identity piece that answers a narrow question: who is this customer, and are they who they claim to be?

Money laundering is usually described in three stages. Placement puts dirty cash into the financial system; layering moves it through a maze of transactions to obscure its origin; integration brings the now-clean money back out as apparently legitimate wealth. Crypto is attractive to launderers mainly at the layering stage, because value can cross borders in minutes without a bank in the middle. AML controls try to interrupt every stage. KYC handles the front door by verifying identity at onboarding. Transaction monitoring acts like the security camera inside the building, watching for suspicious behavior after the customer is through the door. Sanctions screening checks names and wallets against blacklists. Suspicious Activity Reports feed intelligence to the government. KYC is necessary for AML, but it is not sufficient on its own, and treating the two as identical is the mistake that gets compliance programs, and this article’s readers, into trouble.

Where the Rules Come From: FATF, FinCEN, and the Alphabet Soup

The rules originate in a layered stack of standard-setters and enforcers. At the top sits the Financial Action Task Force (FATF), founded by the G7 in Paris in 1989 and now the global reference point for AML standards through its 40 Recommendations. FATF has no direct legal power; it writes standards and grades countries, publishing a grey list of jurisdictions under increased monitoring and a black list of the worst offenders (currently Iran, North Korea, and Myanmar). In October 2018 it amended Recommendation 15 to bring virtual assets and virtual asset service providers into scope, and in June 2019 it extended the Travel Rule to crypto. Its seventh targeted update, published on 16 July 2026 and drawing on 147 jurisdictions, found that 83 percent now have Travel Rule legislation, up from 73 percent a year earlier, but that nearly half of the countries that legislated have taken no supervisory or enforcement action. The law is on the books; the enforcement is not yet behind it.

In the United States the foundational statute is the Bank Secrecy Act of 1970. The agency that writes and enforces the AML rules is FinCEN, a bureau of the Treasury, and crypto exchanges are treated as Money Services Businesses (MSBs) that must register with it. Sanctions are handled by a separate Treasury office, OFAC, and criminal cases are investigated by IRS Criminal Investigation and the Department of Justice. Here is a point that trips up even sophisticated readers: the SEC does not run crypto KYC or AML. The SEC and the CFTC touch the securities and commodities dimensions of digital assets, but the anti-money-laundering authority sits with FinCEN and OFAC under the Bank Secrecy Act, not with the securities regulator. The European Union runs a parallel stack in which market conduct falls under MiCA while AML lives in its own separate regime, a distinction that matters more every year as the two regions diverge. For readers tracking the deadlines and hearings that move these rules, our guide to the autumn regulatory countdown maps the calendar.

What Actually Happens When You Sign Up

Onboarding is a five-step pipeline, most of it invisible to the user:

  • Collect identifying information: legal name, date of birth, residential address, and a government ID number.
  • Verify the document, running optical character recognition and authenticity checks, and increasingly reading the NFC chip in a passport to confirm it is genuine rather than a printout.
  • Run a liveness check, matching a selfie or short video against the ID photo to defeat the reuse of stolen or purchased documents.
  • Screen the applicant against sanctions lists, politically exposed persons databases, and adverse-media feeds.
  • Assign a risk rating that governs how closely the account will be watched.

Most of this plumbing is outsourced to identity vendors such as Jumio, Onfido, Sumsub, and Persona, with the exchange layering its own risk engine on top. For a clean, low-risk retail user the whole process can finish in minutes; a flagged applicant may wait days or be rejected outright. The cost of skipping any of it is now brutally concrete. OKX admitted that from its founding around 2017 until roughly November 2022 it let retail customers create accounts and trade without completing KYC at all, facilitating transactions for people it could not identify while more than $1 trillion moved across the platform. That is precisely the blind spot KYC exists to close, and it is why the onboarding wall keeps getting higher.

Friction is the whole design, and it carries a cost the industry rarely advertises: every extra document request, every rejected selfie, every account frozen for review pushes some users toward venues that ask fewer questions. Compliance teams call this the balloon problem, because squeezing risk out of the regulated market tends to inflate it somewhere less visible. Exchanges also geoblock entire countries, screen out connections arriving through anonymizing networks, and re-verify customers whose behavior changes, so onboarding is less a one-time gate than a relationship that can be reopened at any moment. The tension between keeping the funnel wide enough to grow and tight enough to stay licensed is the central operational problem of running a modern exchange.

Customer Due Diligence and the Fifth Pillar

Underneath the onboarding screen sits a formal framework. A compliant US AML program is built on pillars. The classic four are a designated compliance officer, written internal policies and controls, ongoing employee training, and independent testing or audit. FinCEN’s Customer Due Diligence rule, finalized in 2016 and effective in 2018, added a fifth pillar: risk-based Customer Due Diligence, including the obligation to identify the beneficial owners behind legal-entity customers so that shell companies cannot hide the human ultimately in control.

Due diligence is not one-size-fits-all. Standard Customer Due Diligence (CDD) applies to ordinary customers, while Enhanced Due Diligence (EDD) applies to higher-risk ones: politically exposed persons, very large accounts, customers in high-risk jurisdictions, and anyone whose funds touch mixers or privacy tools. EDD means documenting source of funds and source of wealth and monitoring the relationship more closely. The whole point is to concentrate scrutiny where the risk actually is, a principle FATF calls the risk-based approach.

Risk tierTypical customerVerification depthOngoing monitoring
LowSmall retail buyer, domestic, modest volumeStandard CDD: ID, address, livenessAutomated alerts only
MediumActive trader, higher volume, some cross-border flowStandard CDD plus periodic reviewThreshold-based review, refreshed KYC
HighPEP, high-net-worth, high-risk jurisdiction, mixer exposureEnhanced Due Diligence: source of funds and wealthManual review, senior sign-off, close watch

Sanctions Screening: The OFAC Tripwire

Sanctions screening is the part of AML with the least tolerance for error. OFAC maintains the Specially Designated Nationals (SDN) list, and dealing with anyone on it is a strict-liability violation, meaning a firm can be penalized even if it had no idea the counterparty was sanctioned. Since 2018 OFAC has added cryptocurrency wallet addresses directly to the SDN list, starting with addresses tied to Iranian ransomware operators, which turned sanctions compliance into an on-chain problem overnight.

The most contested case remains Tornado Cash. OFAC sanctioned the mixer’s smart-contract addresses in August 2022, an unprecedented move because it blacklisted immutable code rather than a person or company. After a Fifth Circuit ruling that immutable smart contracts are not property OFAC can sanction, the agency formally removed Tornado Cash from the list in March 2025. Delisting the tool did not end the human exposure, though. In August 2025 a jury convicted developer Roman Storm of conspiracy to operate an unlicensed money-transmitting business, while deadlocking on the money-laundering and sanctions counts; the DoJ has since moved for a retrial on the unresolved charges in late 2026. Screening today happens in real time and on-chain: before crediting a deposit, exchanges check the sending address against clusters of known-bad wallets, and a single tainted hop can freeze an account.

Transaction Monitoring and the SAR Machine

Onboarding is a snapshot; monitoring is the film. Once an account is live, automated systems watch for structuring (breaking large sums into smaller ones to dodge thresholds), sudden velocity spikes, round-number patterns, and exposure to high-risk counterparties. When something looks wrong, the obligation shifts from watching to reporting. US rules define two core reports. The Currency Transaction Report (CTR) covers cash transactions above $10,000, a threshold that has not moved since 1970. The Suspicious Activity Report (SAR) covers suspicious transactions of $2,000 or more at an MSB and must be filed within 30 days of detection. Records must be kept for five years, and SARs are strictly confidential; tipping off a customer that one was filed is itself a crime.

Binance’s cardinal sin was here. Across years of enormous volume it never filed a single SAR, and FinCEN’s resulting $3.4 billion civil penalty was the largest in the bureau’s history at the time. The lesson for every compliance officer was blunt: a monitoring program that never surfaces anything is not evidence of clean customers, it is evidence of a broken program.

The flip side of that lesson is over-reporting. Because failing to file is what draws penalties, many institutions file defensively, generating a flood of alerts that human analysts cannot fully work through. Industry surveys routinely find that the large majority of monitoring alerts are false positives, which buries genuine signals under noise and inflates compliance headcount. That is why exchanges are pouring money into machine-learning models that rank alerts by risk, and why the same blockchain-analytics feeds used at onboarding now drive real-time monitoring. The aim is not to file more reports but to file better ones, though regulators have made clear that a quiet queue is never a defense.

ReportTrigger or thresholdFiling deadlinePurpose
MSB registrationActing as a money transmitter in the USWithin 180 days of startingBrings the firm under BSA obligations
CTRCash or cash-equivalent over $10,00015 daysReports large currency movements
SARSuspicious activity of $2,000 or more (MSB)30 days from detectionFeeds financial intelligence to FinCEN
Travel Rule recordTransfer at or above $3,000 (US)Passed with the transferAttaches sender and recipient identity

The Travel Rule: Making Crypto Transfers Carry ID

The Travel Rule is FATF Recommendation 16, originally written for bank wire transfers and extended to crypto in 2019. It requires that when a regulated provider sends a transfer above a threshold, it pass the originator’s and beneficiary’s identifying information to the receiving provider, so identity travels alongside value. FATF’s model threshold is USD or EUR 1,000; the US recordkeeping threshold under the Bank Secrecy Act is $3,000. The data is meant to move in a standard format called IVMS 101.

The European Union went further than the FATF baseline. Its Transfer of Funds Regulation, in force since 30 December 2024, applies the Travel Rule to crypto with no minimum threshold at all, so every transfer between regulated providers carries identity data. Two problems dog the rule in practice. The first is the sunrise problem: because jurisdictions adopted it at different times and use incompatible messaging systems, providers cannot always exchange the required data, and compliance is patchy across borders. The second is self-hosted wallets. The rule binds intermediaries, not peer-to-peer transfers between private wallets, which leaves an obvious gap that regulators are now trying to close. We cover the mechanics and the global rollout in depth in our companion piece on FATF crypto guidance and the Travel Rule.

How Compliance Went On-Chain: The Analytics Layer

A persistent myth holds that crypto is anonymous. Public blockchains are pseudonymous, not anonymous, and the difference is everything for AML. Every transaction is permanent and visible to anyone, which in some respects makes crypto more traceable than cash. The industry that exploits this is blockchain analytics. Firms such as Chainalysis, Elliptic, and TRM Labs cluster addresses, label entities, and assign risk scores to wallets, then sell that intelligence through APIs that exchanges wire directly into onboarding and monitoring. It is the reason a figure like total illicit volume can even be estimated.

The 2026 Chainalysis Crypto Crime Report found that illicit addresses received at least $154 billion in 2025, a 162 percent jump driven largely by sanctioned entities, though that still amounts to under 1 percent of all on-chain volume. Stablecoins now account for roughly 84 percent of illicit transaction value, and the value flowing to sanctioned entities surged 694 percent as nation-state actors folded crypto into their financial infrastructure. The transparency cuts both ways. The same public ledger that lets investigators trace stolen funds across the world also means that once an address is linked to your KYC identity, your entire financial history sits in permanent public view. Traceability is a compliance dream and a privacy nightmare at the same time.

Traceability has limits, and criminals probe them constantly. Privacy coins such as Monero break the address-clustering techniques that analytics firms depend on, which is exactly why regulators are moving to bar them. Cross-chain bridges, coin swaps, and mixers add hops that make tracing slower and more probabilistic, and attribution is rarely a clean line from wallet to name. A risk score is a statistical judgment, not proof, and the same tools that clear an innocent address can also flag one by association when funds pass through a tainted intermediary. The result is a running arms race between obfuscation and attribution, with compliance teams, law enforcement, and launderers all iterating on the same public data.

What Non-Compliance Costs: The 2023 to 2026 Enforcement Wave

For a decade many exchanges treated AML as a problem to grow past. That era is over. In November 2023 Binance and its founder Changpeng Zhao pleaded guilty to Bank Secrecy Act violations and agreed to pay more than $4.3 billion, split largely between a $3.4 billion FinCEN penalty and a $968 million OFAC penalty, with Zhao personally fined $50 million and forced to step down. Announcing the case, US Attorney General Merrick Garland said that using new technology to break the law does not make you a disruptor, it makes you a criminal. The message landed.

The wave kept building. OKX pleaded guilty in February 2025 and paid more than $504 million. KuCoin resolved similar Bank Secrecy Act failures for more than $297 million in January 2025, agreeing to exit the US market for at least two years while two of its founders stepped aside. Regulators across the financial sector handed down well over a billion dollars in AML, KYC, and sanctions penalties in the first half of 2025, a steep jump from a year earlier, and anti-money-laundering enforcement, not securities classification, became the compliance risk exchanges feared most. There was also a political recalibration: under the current US administration several civil actions, including the case against Kraken, and the Binance criminal probe wound down, and OFAC delisted Tornado Cash, narrowing enforcement toward hard AML and sanctions matters rather than securities-classification fights.

FirmResolvedPenaltyCore failure
BinanceNov 2023Over $4.3 billionNo effective AML program, zero SARs filed
OKXFeb 2025Over $504 millionUnlicensed transmission, no KYC for years
KuCoinJan 2025About $297 millionBSA failures, unregistered MSB

Your ID Is the Honeypot: The Coinbase Breach

KYC forces every regulated exchange to hold a concentrated pile of exactly the data criminals want: legal names, home addresses, government ID photographs, and partial identifiers. That pile is a honeypot, and in 2025 one of them was cracked. Coinbase disclosed in May 2025 that bribed overseas customer-support contractors had copied the personal data of around 69,461 customers, roughly 1 percent of its users, between December 2024 and May 2025. The attackers demanded a $20 million ransom; chief executive Brian Armstrong publicly refused to pay and instead offered a $20 million bounty for information leading to the perpetrators, while the company estimated remediation and reimbursement costs of $180 million to $400 million.

The damage does not stop at inbox spam. Once a criminal knows your home address and that you hold crypto, you become a target for precision phishing and, at the extreme, for physical coercion, the so-called wrench attacks that have risen sharply. The bounty response echoes the wider market for paying researchers and informants to surface threats, a dynamic we examine in our look at how crypto bug bounties are actually priced and paid. The structural problem is simple and uncomfortable: every KYC mandate multiplies the number of databases holding your identity, so more compliance can mean more honeypots, not fewer.

The Privacy Fault Line: Mixers, Self-Custody, and DeFi

The deepest tension in this whole system is architectural. KYC and AML were designed for a world of intermediaries: banks and exchanges that sit between the customer and the money and can be compelled to check identity. Crypto lets value move without an intermediary, which raises a question the old framework never had to answer: what happens when there is no provider to do the KYC? Regulators have answered by squeezing the tools and the choke points. In October 2023 FinCEN proposed designating convertible virtual currency mixing as a class of transactions of primary money laundering concern under Section 311 of the USA PATRIOT Act, the first time it aimed the tool at an activity rather than an institution or country. For self-custody and DeFi, where there is no onboarding desk, the strategy is to lean on the fiat on-ramps and off-ramps instead.

Not everyone accepts that the tradeoff is worth it. Peter Van Valkenburgh of the research group Coin Center has argued that the existing AML and KYC regime does remarkably little to prevent illicit finance, and that the system imposes enormous costs and privacy burdens for negligible benefit in stopping crime, putting US compliance costs alone at more than $26 billion a year. Whether or not one shares that conclusion, the regime increasingly collides with self-custody, where the user holds their own keys and there is no institution to interrogate. The same debate runs through the design of smart-account wallets and account abstraction, which push more control to the individual and further from the regulated intermediary that AML law was written to police.

The critique is not only about cost. Civil-liberties advocates argue that bulk financial surveillance sits uneasily with constitutional privacy protections, pointing to the decades-old legal doctrine that data handed to a third party, such as a bank, loses its expectation of privacy. Crypto revived that debate because self-custody lets a person hold value with no third party at all, which forces the question of whether the government can require identification for a purely peer-to-peer transfer. There is also the debanking problem: when compliance risk runs too high, the easiest move for a bank or an exchange is to drop the customer entirely, and whole categories of lawful users, from privacy researchers to residents of high-risk countries, can find themselves quietly cut off.

The EU’s Harder Line: AMLR, AMLA, and the Anonymity Ban

While the US narrowed its focus, the European Union sharpened its posture. Europe is moving from a patchwork of directives that each member state transposed differently to a single directly applicable regulation. The Anti-Money Laundering Regulation, known as the AMLR, applies in full from 10 July 2027, and a new central supervisor, the Anti-Money Laundering Authority (AMLA) based in Frankfurt, launches in 2026 and will directly oversee up to 40 of the highest-risk firms across at least six countries. For crypto specifically, the package bans anonymous crypto accounts and services that enable transaction anonymization, which effectively bars regulated providers from handling privacy coins, and it tightens checks on transfers between custodial platforms and self-hosted wallets above 1,000 euros.

It is worth keeping the two European frameworks straight, because they are constantly confused. MiCA governs market conduct, licensing, and prudential requirements for crypto-asset service providers; the AML obligations sit in the separate AMLR and AMLA stack, alongside the Transfer of Funds Regulation that carries the Travel Rule. The EU AML supervisor is AMLA working with national financial intelligence units, not the markets regulator, just as in the US the AML authority is FinCEN rather than the SEC.

FeatureUnited StatesEuropean Union
Core AML rulemakerFinCEN (Treasury), under the BSAAMLR plus AMLA (from 2026)
Sanctions bodyOFACEU restrictive measures, national authorities
Travel Rule threshold$3,000No minimum, since Dec 2024
Privacy coinsMixers targeted, no blanket banAnonymous accounts and privacy coins banned from 2027
Direction of travelNarrowing to hard AML and sanctionsBroadening and centralizing

Sanctioned States and the Stablecoin Rail

The reason AML enforcement keeps escalating is that the threat has professionalized. The 2026 crime data describes not scattered fraudsters but industrialized, state-linked operations. A ruble-backed stablecoin called A7A5 processed $93.3 billion in under a year, acting as a bridge for Russian businesses to reach global markets despite sanctions, and Iranian on-chain activity is increasingly dominated by the state, with the Islamic Revolutionary Guard Corps and its networks accounting for over half of value received in the fourth quarter of 2025. Stablecoins, prized by ordinary users for cheap cross-border transfer, are prized by sanctioned actors for the same reasons, which is why they now carry the bulk of illicit flow.

Governments have answered with named actions against the infrastructure. When Treasury moved against the Cambodia-based Huione Group, which it found had laundered at least $4 billion, Secretary of the Treasury Scott Bessent said the group had established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans. Cases like this explain why exchanges cannot treat sanctions screening as a checkbox: the counterparties on the other side of the trade may be running national treasuries, not basement scams, and the compliance stakes scale accordingly.

What Comes Next: Reusable KYC and Zero-Knowledge Proofs

Two problems are converging: KYC creates friction for users and honeypots for attackers. The emerging answer is to verify once and prove many times, without re-exposing the underlying documents. Reusable or portable KYC lets a user hold a verifiable credential in their own wallet and present a cryptographic proof of it to each new service, rather than uploading a passport again and again. Industry studies put the onboarding-cost savings from reusable credentials at roughly a third or more, and the model removes the central document store that becomes a breach target in the first place.

The more radical step is zero-knowledge KYC, where a user proves a fact (verified, not sanctioned, over 18, resident of a given country) without revealing the document behind it. The cryptography that makes this practical is the same family of proofs now being pushed toward heavier workloads, as we explore in our piece on whether zero-knowledge proofs can scale to real AI. Protocols including World ID, Civic, and on-chain attestation systems are early experiments in this direction. The caveats are real: reusable credentials shift trust to the issuer rather than removing it, regulators must accept a zero-knowledge attestation as satisfying Customer Due Diligence, and proof-of-personhood schemes raise their own surveillance worries. There is also a brand-new question on the horizon, as autonomous AI agents begin to transact on-chain: who is the customer when the customer is a bot, and whose identity anchors its activity? That puzzle is only beginning, but it will force the KYC framework to stretch in ways its 1970 authors never imagined.

Frequently Asked Questions

Do all crypto exchanges require KYC?

Most regulated, centralized exchanges do. In the United States any platform acting as a money services business must run KYC, and the same is true across the EU and most major markets. Non-custodial DeFi protocols and self-custody wallets generally do not, but the fiat on-ramps that connect them to the banking system do. Fully no-KYC centralized exchanges are increasingly rare and legally exposed, as OKX’s $504 million guilty plea made clear.

What is the difference between KYC and AML?

AML is the umbrella term for the entire body of law and controls designed to stop money laundering and terrorist financing. KYC is one component of AML, the identity-verification step that confirms who a customer is at onboarding. AML also includes transaction monitoring, sanctions screening, and suspicious activity reporting, so KYC is necessary for AML but not the whole of it.

Is my ID safe when I upload it for crypto KYC?

Not entirely. KYC forces exchanges to store ID photos, addresses, and partial identifiers, which turns them into a target. The May 2025 Coinbase breach, in which bribed contractors leaked data on about 69,461 customers, shows the honeypot risk clearly. Reusable and zero-knowledge KYC are being developed specifically to reduce how often you expose raw identity documents.

What is the crypto Travel Rule?

It is FATF Recommendation 16 applied to crypto. When a regulated provider sends a transfer above a threshold, it must share the sender’s and recipient’s identity data with the receiving provider. The threshold is USD or EUR 1,000 in FATF’s model and $3,000 under US rules, while the EU has applied it with no minimum threshold since December 2024.

Can you use crypto anonymously in 2026?

On a regulated exchange, no; KYC is mandatory. On-chain, transactions are pseudonymous rather than anonymous, and analytics firms can often link addresses back to identities. The EU will ban anonymous crypto accounts and privacy-coin services from 2027, and US regulators have targeted mixers, so genuine anonymity is shrinking rather than growing.

By Priya Reddy, senior regulation correspondent at HOGE Wire, covering AML, market structure, and the politics of financial surveillance.

Share 𝕏 Post Telegram