CRF ¦ Crypto-Asset Misuse in Financial Crime: Strategic Findings and Typologies

CRF ¦ Crypto-Asset Misuse in Financial Crime: Strategic Findings and Typologies

Crypto-assets and financial crime: how laundering schemes are evolving

The misuse of crypto-assets for financial crime is becoming more diverse, more cross-border and more closely connected to the traditional financial system. Bitcoin and Ether remain the assets most frequently associated with suspicious activity, but stablecoins, virtual IBANs, decentralised platforms, cross-chain bridges and informal intermediaries are increasingly part of the same transaction chains.

A review of suspicious activity and transaction reporting received during 2025 by Luxembourg’s Financial Intelligence Unit (FIU) identified five broad patterns: laundering through crypto-assets, fraud involving crypto-assets, illicit fund movement through intermediaries, indirect exposure to illicit addresses and direct transactions with illicit addresses.

The findings are sample-based and illustrative rather than statistically representative. They nevertheless provide a useful view of the risks facing banks, payment institutions, crypto-asset service providers (CASPs), investment firms and other obliged entities.

The central role of the predicate offense

Crypto-assets are not themselves a predicate offense. They are instruments, payment mechanisms and channels that can be used before, during or after the commission of an underlying crime.

Where the source of funds could be established, fraud and scams featured prominently. Social engineering fraud, investment scams, cyber-enabled fraud and account compromise were among the principal sources of illicit proceeds entering crypto-asset services. Other identified or suspected predicate offenses included drug trafficking, tax crime, theft, ransomware, the distribution of child sexual abuse material and terrorist financing.

In many cases, however, the available information did not establish the underlying offense. This does not eliminate money laundering concerns. Unexplained transfers, rapid conversion between fiat currency and crypto-assets, inconsistent customer activity and the use of multiple intermediary wallets may still indicate concealment, layering or integration of criminal proceeds.

The distinction matters for financial crime controls. A provider should not wait for the predicate offense to be proven before assessing whether the transaction pattern is inconsistent with the customer’s profile or indicative of laundering. At the same time, indirect blockchain exposure must be assessed carefully. A connection to a risky address can be an important indicator, but it does not automatically prove intentional money laundering, sanctions evasion or terrorist financing.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Crypto-assets are increasingly being used to move, conceal and integrate proceeds linked to fraud, scams, drug trafficking, tax crime, cybercrime and other predicate offenses. Bitcoin and Ether remain prevalent, while stablecoins, virtual IBANs, decentralised platforms, cross-chain bridges and intermediary wallets add complexity to laundering schemes.

The strongest warning signs often arise from the combination of unexplained funding, rapid fiat-to-crypto or crypto-to-fiat conversions, wallet hopping, money mule activity and exposure to illicit addresses. Effective detection requires institutions to connect on-chain and off-chain information, assess the customer’s legitimate purpose and distinguish accidental exposure from deliberate participation."

Bitcoin, Ether and the growing use of stablecoins

Native cryptocurrencies dominated the reported cases. More than 60% of the cases involved cryptocurrencies, and approximately 90% of those cases involved Bitcoin, Ether or both.

Stablecoins were the second most frequently observed asset type. Their relative price stability and broad market acceptance make them useful for cross-border transfers, remittances and movement between fiat and crypto-asset systems. They are also commonly used alongside Bitcoin and Ether rather than as a replacement for them.

This combination creates a recurring laundering pattern. Funds may enter a crypto-asset platform in fiat currency, be converted into a stablecoin, transferred through several wallets and later exchanged for another cryptocurrency before being converted back into fiat. Each step may serve a commercial purpose in isolation, but the overall sequence can indicate an attempt to distance the proceeds from their original source.

Corporate funds converted through crypto-asset platforms

One recurring pattern involved foreign companies operating in sectors such as construction, transport and wholesale. Corporate accounts, including accounts linked to virtual IBANs, were used to send substantial amounts of fiat currency to trading accounts at legitimate centralised exchanges.

The funds were then converted into cryptocurrencies or stablecoins, particularly USDT and USDC. Customers sometimes described the activity as payment of business invoices or treasury management. Yet the stated purpose did not always correspond with the company’s business model, the size or timing of the transfers, or the absence of a clear commercial counterparty.

The risk is particularly acute where a virtual IBAN functions only as a payment channel before funds move to a crypto-asset platform. A business that receives or sends large sums through a payment account and promptly converts them into crypto-assets without a transparent economic rationale may be using the financial system to layer or reposition proceeds.

Relevant warning signs include unexplained transfers between a company account and a personal or corporate exchange account, significant activity shortly after account opening, irregular high-value deposits, limited evidence of genuine trading and a mismatch between the customer’s stated business and its crypto-asset activity.

Crypto-assets and real estate investment

Crypto-assets can also be laundered through property transactions. A customer may convert digital assets into fiat currency and use the proceeds as an equity contribution for a loan-financed real estate purchase.

The property then provides an apparently legitimate asset that can be held, sold or refinanced. The involvement of several regulated and professional actors – including crypto-asset providers, banks, lenders and notaries – creates opportunities for detection, provided that the source of wealth and source of funds are examined across the entire transaction chain.

A credible explanation for the original acquisition of the crypto-assets, a consistent trading history and evidence of legitimate wealth may reduce the risk. By contrast, a recent transfer from unidentified wallets, rapid conversion to fiat and immediate use in a property purchase may indicate an attempt to integrate criminal proceeds into the legitimate economy.

Diversion of business assets into personal crypto accounts

Another laundering and asset-diversion pattern involves legitimate company revenue being transferred from a corporate bank account to an owner’s or employee’s personal exchange account or wallet.

The funds may be converted into crypto-assets for personal use, concealed from tax authorities or removed from the company without a legitimate business purpose. False information about tax residence may further support tax evasion or concealment of taxable income.

The risk is not limited to outright theft. A transaction can be suspicious where company funds are described as remuneration, a loan or an investment but are not supported by accounting records, corporate approvals or a coherent commercial explanation. The subsequent use of a personal wallet, particularly one that receives funds from unrelated third parties, can strengthen the suspicion of misappropriation or laundering.

Fraud proceeds moving through wallets

Fraud-related cases frequently involved rapid transfers through multiple wallets. Victims initially sent Bitcoin, Ether or stablecoins to addresses controlled by fraudsters. The funds were then split, converted and routed through decentralised exchanges, instant swap services, cross-chain bridges, non-custodial wallets and other intermediary addresses.

This process, often described as wallet hopping, can make it more difficult to identify the destination and ownership of the proceeds. It does not automatically establish laundering, because legitimate users may also move assets between wallets. Suspicion increases when the wallets are newly created, lightly used or apparently unrelated, and when the transfers are followed by mixer or tumbler exposure, cross-chain conversion or rapid attempts to cash out.

Investment scams were a significant example. Victims were promised high or guaranteed returns and sent substantial amounts of crypto-assets to scam-related addresses. Small payments were sometimes returned to create confidence and encourage further investment. The funds were subsequently transferred through additional addresses and platforms.

The transaction data may be reinforced by complaints, customer communications, website information, social media activity and evidence that several victims sent funds to the same wallet cluster.

Account takeover and identity fraud

Crypto-asset accounts are also targeted through phishing, vishing and other forms of account takeover. Once access is obtained, criminals may transfer assets to previously whitelisted external addresses, reducing the likelihood that the transaction will be blocked or subject to additional verification.

Stolen assets may then be divided between several addresses, converted into other crypto-assets or moved across blockchain networks. Cross-chain bridges can transfer funds from one network to another, for example from Ethereum to TRON, complicating tracing and screening.

A separate risk arises when fraudulent exchange accounts are opened with forged or stolen identity documents. Artificially generated documents and deepfake technology may make onboarding fraud harder to detect. Technical and behavioural data can help identify linked accounts, including recurring IP addresses, device identifiers, residential addresses and common patterns of use.

Payment accounts integrated into crypto-asset platforms may allow the fraudulent account to acquire crypto-assets quickly. The assets may then be sent to services operating through encrypted messaging applications, including services with limited or no effective customer identification controls.

Transit accounts and money mules

Personal exchange accounts may be used as transit accounts rather than for genuine investment or trading. Funds enter through fiat-to-crypto or crypto-to-fiat activity and leave shortly afterwards, often without a plausible explanation.

Three transaction patterns are especially relevant:

  • Fiat-in/crypto-out (FICO) activity may involve a bank or payment account funding a crypto purchase before the assets are transferred elsewhere.
  • Crypto-in/fiat-out (CIFO) activity may involve incoming assets from unrelated wallets followed by rapid conversion and withdrawal.
  • Fiat-in/fiat-out (FIFO) activity may involve funds entering and leaving the exchange without any meaningful trading activity.

Circular movements are particularly informative. A customer may deposit a small amount of fiat currency, return it to the originating account or another account under their control and then cease using the exchange. This suggests that the platform may have served as a conduit rather than an investment service.

Money mules add another layer. They may knowingly or unknowingly allow third parties to use their bank accounts, payment instruments, exchange accounts or wallets. Funds can move between personal exchange accounts, online payment services, credit cards, virtual debit cards and non-custodial exchanges. If one route is rejected, the money may be redirected through further third parties.

A mule may appear to have a low-risk customer profile, but unusual incoming transfers from unrelated persons, rapid onward payments, a lack of trading activity and repeated use of multiple financial products can indicate coordinated activity.

NFTs as a laundering mechanism

NFT transactions can also be incorporated into laundering schemes. In the cases identified, suspected money mules used e-money accounts to receive funds from unrelated third parties in different countries, transfer the funds rapidly and then purchase NFTs through exchange platforms.

The NFT purchase may create the appearance of an investment or digital asset transaction while serving as one step in a layering process. The risk is higher where the customer’s activity is inconsistent with their financial profile, the incoming funds are unrelated to the stated purpose of the account and the NFT purchases follow immediately after unexplained transfers.

Indirect exposure to illicit addresses

Blockchain analytics can identify indirect connections to addresses associated with sanctions, darknet markets, ransomware, stolen funds, terrorist financing or child sexual abuse material.

Indirect exposure may be incoming or outgoing. Funds may reach a customer through several intermediary wallets after originating from an illicit cluster. Alternatively, a customer’s assets may pass through intermediary addresses before reaching a risky destination.

The significance of the exposure depends on the distance, value, frequency, timing and context of the transactions. A single low-value connection several hops away may result from an incidental interaction with a service that has received tainted funds. Repeated convergence with a known illicit cluster, a short transaction path or a substantial share of the customer’s transaction value linked to stolen funds presents a more serious risk.

Ransomware and stolen-funds cases commonly involved long peel chains followed by rapid conversion into fiat and withdrawal to a bank account. The combination of lengthy layering, exposure to mixing services and immediate cash-out is consistent with laundering, although the underlying proceeds may originate from different types of cybercrime.

Exposure to sanctioned exchanges or jurisdictions also requires careful analysis. It may indicate sanctions evasion, but indirect exposure alone is not sufficient to establish intent. Providers should consider the applicable sanctions framework, the customer’s knowledge, the transaction path and the surrounding conduct.

Direct transactions with darknet, scam and CSAM addresses

Direct, unmediated interaction with an address linked to criminal activity creates stronger suspicion than remote or incidental exposure.

Reported cases included direct payments for child sexual abuse material, transactions with darknet markets associated with drugs, bot services or mixing services, transfers to drug vendors and payments to scam platforms. Bitcoin was frequently observed, and individual payments for illicit content were often relatively small.

Direct transactions with darknet markets may involve repeated deposits or withdrawals through a customer’s exchange account, followed by conversion into fiat and transfers to foreign bank accounts. Repetition, the nature of the destination and the absence of a legitimate explanation are important contextual factors.

Direct payments to scam addresses require a more nuanced assessment. The customer may be a perpetrator, a victim or an intermediary. Fraudulent websites promoted through social media, including campaigns using deepfake videos of celebrities, can persuade individuals to deposit crypto-assets in exchange for promised giveaways, promotional codes or investment returns. Transaction monitoring should therefore be combined with customer contact, complaints and other evidence before drawing conclusions about intent.

Cross-border risk and the need for connected controls

Most subjects in the reviewed cases were non-resident EU individuals or foreign companies. Luxembourg accounts and products often functioned as part of an international chain rather than as the location of the underlying criminal activity.

This cross-border character makes isolated product-level monitoring insufficient. A bank may see the fiat deposit, a payment institution may see the transfer, a crypto-asset provider may see the conversion, and a blockchain analytics provider may identify the connection to a risky address. Effective detection depends on linking these observations.

The most useful indicators are often cumulative. A newly opened exchange account, unexplained third-party funding, rapid FICO or CIFO activity, wallet hopping, use of non-custodial services, exposure to mixers, cross-chain transfers and immediate cash-out may together provide a strong basis for suspicion even if no single transaction is conclusive.

A broader approach to detection

Financial crime teams should assess both the predicate offense and the laundering mechanism. The key questions are where the funds originated, who controlled them, why they moved through particular products, whether the stated purpose is credible and how the assets were ultimately used.

Customer due diligence (CDD) should be supported by transaction monitoring that covers fiat and on-chain activity. Blockchain screening should distinguish direct interaction from indirect exposure and should evaluate address attribution, hop distance, transaction value, timing and repetition. Technical data, such as device identifiers and IP addresses, can help link apparently separate accounts.

The growing use of stablecoins, decentralised exchanges, instant swap services, bridges and Layer 2 networks does not make detection impossible. It does, however, require institutions to combine traditional financial intelligence with blockchain analysis and to cooperate across sectors and jurisdictions.

Crypto-assets are increasingly embedded in financial crime schemes that begin with fraud, theft, drug trafficking, tax crime or cybercrime and end with conversion, concealment or integration into the legitimate economy. Understanding that full chain – rather than treating crypto activity as a separate risk category – is essential to identifying the predicate offense, recognising money laundering and disrupting the flow of criminal proceeds.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • Cellule de Renseignement Financier (CRF) ¦ Crypto-Asset Misuse in Financial Crime: Strategic Findings and Typologies ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.