FATF ¦ Targeted Report on Stablecoins and Unhosted Wallets - Peer-to-Peer Transactions

FATF ¦ Targeted Report on Stablecoins and Unhosted Wallets - Peer-to-Peer Transactions

Stablecoins, unhosted wallets and the new front line in financial crime risk

Stablecoins have moved from a niche virtual asset product to core market infrastructure. Their appeal is obvious: price stability, fast settlement, broad interoperability and deep liquidity. Those same qualities also make them highly attractive to criminals. By mid-2025, more than 250 stablecoins were in circulation, with total market capitalisation above USD 300 billion and daily trading volumes exceeding Bitcoin. The market is dominated by fiat-backed, centrally governed tokens, especially USD-referenced stablecoins, which are widely used across multiple blockchains and increasingly integrated with the traditional financial system.

That growth has brought a parallel rise in abuse. Stablecoins are widely used in money laundering, terrorist financing, proliferation financing, sanctions evasion and cyber-enabled crime. They are often not the only asset used in a scheme, but they are frequently the asset that makes the movement of value fast, liquid and hard to stop. In many cases, they sit in the middle of a longer chain of transactions designed to obscure origin, ownership and purpose.

Why stablecoins are so useful to threat actors

The criminal value proposition is straightforward. Stablecoins reduce volatility risk while preserving the speed and reach of virtual assets. They can be transferred quickly across borders, exchanged on multiple chains, layered through wallets and protocols, and converted back to fiat through compliant or non-compliant off-ramps. They are also commonly used on secondary markets, where identity controls can be weaker and oversight more fragmented.

Illicit actors use stablecoins for many of the same reasons legitimate users do. But criminals are especially drawn to the combination of high liquidity and interoperability. In practice, that means stablecoins can be used to move proceeds from fraud, drugs, ransomware, sanctions breaches and other predicate crimes with less friction than more volatile assets. They are also increasingly the asset of choice for cashing out stolen funds after layering through mixers, bridges, decentralized exchanges and OTC brokers.

Reporting suggests that stablecoins are the most popular virtual asset used in illicit transactions. In some cybercrime data, they account for the vast majority of illicit virtual asset transaction volume. That does not mean every stablecoin transfer is suspicious. It does mean the sector deserves more scrutiny than many firms and supervisors have historically applied.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Stablecoins have become a major tool in both legitimate payments and illicit finance because they combine price stability, fast settlement, and broad interoperability. Their use through unhosted wallets and peer-to-peer transfers creates a persistent blind spot, especially when transactions move across chains and bypass regulated intermediaries.

Financial crime teams should treat stablecoin activity as a core risk area, not a niche one. Stronger controls at issuance and redemption, better blockchain analytics, and closer cooperation between firms and authorities are essential to detect misuse early and reduce exposure."

The role of unhosted wallets and peer-to-peer transfers

The highest-risk feature in this space is not stablecoins alone. It is stablecoins moving peer-to-peer through unhosted wallets. These transfers happen without a regulated intermediary and therefore outside the usual AML/CFT controls that apply to VASPs and financial institutions. The public blockchain may show the transfer, but the people behind the addresses are often hidden behind pseudonymity, multiple hops, fresh wallets and cross-chain movement.

That creates a structural blind spot. There is no obliged entity in the middle to collect originator and beneficiary information, no automatic filing obligation on the transfer itself, and often no reliable visibility into the real-world identity of the parties. Criminals exploit this gap by layering stablecoins through chains of unhosted wallets, then moving them through P2P markets or informal brokers until they reach fiat or goods.

The risk is amplified when transactions cross borders. Stablecoins settle almost instantly, often outside the originating jurisdiction before investigators can act. When the funds move through wallets that are transactionally distant from Travel Rule-covered wallets, attribution becomes harder and intervention slows down. Public blockchains may preserve the data, but they do not provide the context required for effective supervision on their own.

Criminal use cases span the full spectrum of financial crime

Stablecoins are being used across a broad range of typologies. Organised crime groups have used them to settle drug purchases, pay suppliers of synthetic drug precursors and layer proceeds through multiple wallets and exchanges. Fraud networks use stablecoins to receive proceeds from investment scams, romance scams, impersonation fraud and sextortion. Professional money launderers use them for chain-hopping, smurfing and cross-chain transfers, often in conjunction with unlicensed OTC brokers and platforms with weak controls.

Terrorist financiers increasingly rely on stablecoins as well. Donations are solicited via encrypted messaging platforms and social media, then dispersed through rotating wallets, small-value transfers and multiple service providers to avoid attention. Some campaigns use recycled QR codes, domains and change addresses to keep donation flows alive even after takedowns. The pattern is usually not one large transfer but many small ones designed to stay below detection thresholds.

The most concerning state-linked use cases involve sanctions evasion and proliferation financing. North Korean actors have used stablecoins as part of laundering and cash-out chains following major thefts, converting stolen virtual assets into stablecoins before moving them through OTC brokers or P2P platforms. Iranian actors have also been assessed to use virtual assets, including stablecoins, to finance procurement of drone components and other high-tech equipment. In some cases, stablecoins are not just a laundering tool, they are the payment rail itself for prohibited goods and services.

Why the ecosystem creates its own vulnerabilities

Stablecoin risk is not limited to misuse after issuance. The ecosystem itself creates exposure points at every stage.

Issuers often sit at the center of the arrangement, particularly in centrally governed models. They may control issuance, redemption and, in some cases, the smart contract functions that allow freezing, blocking or burning tokens. That gives them meaningful risk management power, but also places them in the regulatory spotlight. If an issuer operates across borders or through multiple co-issuance structures, supervisors may struggle to determine who is responsible for what, especially when reserve custody, redemption and distribution are split across entities and jurisdictions.

Redemption is another pressure point. If stablecoins can be exchanged for fiat through unofficial channels, non-compliant intermediaries or informal OTC desks, criminals can bypass formal controls entirely. Even when a token is technically not being redeemed, the practical effect may be the same: value exits the virtual asset ecosystem without effective AML/CFT checks.

Cross-chain functionality adds another layer of complexity. Interoperability improves legitimate utility, but it also helps threat actors fragment transaction trails. Bridging, wrapping and unwrapping tokens across chains can weaken the usefulness of freezing and blacklisting functions, especially where centrally issued stablecoins circulate in wrapped form on other networks. The result is a fragmented enforcement picture that is difficult to manage without better analytics and faster cooperation.

Smart contract controls are becoming part of the compliance toolkit

One of the more important developments is the growing use of programmable controls in stablecoin smart contracts. Some issuers can allow-list or deny-list wallet addresses, freeze balances or block transactions in response to risk signals or lawful requests. These tools are not a complete solution, and they raise design, governance and fairness questions. But they are becoming central to the compliance conversation.

An allow-list approach is more preventive. It requires wallet holders to be verified before they can transact, which can reduce exposure to unhosted wallets and unknown counterparties. A deny-list approach is more reactive. It is useful for sanctions, law enforcement requests and known illicit addresses, but it generally acts after a risk has already been identified. Transaction limits, temporary freezes and other conditional controls can also reduce exposure, especially in higher-risk products or markets.

Different jurisdictions are already testing these models. Some require issuers and intermediaries to conduct customer due diligence (CDD) at issuance and redemption, monitor secondary market activity, and apply sanctions screening and Travel Rule controls. Others are examining how licensing should account for stablecoin-specific risk, including the possibility that open-ended circulation without visible intermediaries creates unacceptable exposure.

Blockchain analytics is necessary, but not enough

Blockchain analytics tools are part of the standard defensive stack. They help identify address exposure, trace funds across chains, detect links to sanctioned entities and flag suspicious patterns such as rapid conversions, repeated small transfers, or interaction with risky services. They are especially useful when combined with customer data, device intelligence, network metadata and traditional investigative methods.

Still, these tools have limits. They do not solve attribution by themselves, and they can struggle with sophisticated obfuscation, cross-chain fragmentation and constantly changing wallet infrastructure. Different providers also use different taxonomies and scoring methods, which can create inconsistent outputs. That means firms and supervisors should not treat analytics as a checkbox exercise. The real question is whether the tool, the workflow and the people using it are actually capable of reducing risk.

The most effective programs integrate analytics into ongoing monitoring, case management and escalation. They also make room for human judgment. A score alone is not enough. Investigators need context, and analysts need the technical capability to understand what the data is really saying.

Supervisors and firms need a more coordinated model

The stablecoin market is moving faster than many regulatory systems. That creates a real need for stronger licensing, clearer obligations and better cross-border cooperation. Jurisdictions should assign responsibility across issuers, intermediaries, custodians and other relevant participants using a risk-based approach. They should also make sure AML/CFT duties extend to reserve custodians and any entity that is functionally providing exchange, transfer or safekeeping services.

Supervision needs to be technical, not just formal. Regulators should assess how a stablecoin actually works, what controls are embedded in its design, how it behaves across chains, and what the issuer can do when a suspicious address is identified. In cross-border structures, supervisory colleges and information-sharing arrangements can help close gaps and reduce duplication. Without that, the ecosystem risks becoming a patchwork of uneven controls and regulatory arbitrage.

Public-private partnership also matters. The best typologies, indicators and controls often emerge when authorities and industry work together on live risk. Issuers, analytics firms, payment firms and investigators each see a different part of the picture. When those views are combined, the picture gets much clearer.

The bottom line for financial crime teams

Stablecoins are not inherently illicit, but they are a central instrument in financial crime typologies. The real challenge is whether firms, supervisors and law enforcement can keep up with the speed, liquidity and cross-border nature of the market.

The highest-risk areas are clear: unhosted wallets, peer-to-peer transfers, weakly supervised OTC activity, cross-chain movement, and redemption channels that sit outside formal controls. Any effective response must combine legal obligations, technical controls, analytics, supervision and rapid cooperation. In a market built for speed, delay is a vulnerability.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • FATF ¦ Targeted report on Stablecoins and Unhosted Wallets - Peer-to-Peer Transactions ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.