Revisiting AML from the recent Binance case

SK Lee
Coinmonks
6 min readNov 23, 2023

--

Binance: The Money Laundering and Sanctions Violations

Recently, Binance, a prominent player in the cryptocurrency industry, along with its Chief Executive Officer, Chengpeng Zhao, have admitted to breaching U.S. anti-money laundering regulations. The U.S. Justice Department announced that the company has agreed to pay fines exceeding $4 billion.

The U.S. government lodged accusations against Binance for enabling illicit financial activities by failing to register as a money transmitting business. The company allegedly facilitated transactions advantageous to cybercriminals, terrorists, and child exploiters. The accusations further extend to the company’s profiteering from unauthorized transactions involving U.S. users and individuals residing in countries under sanctions, including Iran, Cuba, Syria, and regions in Ukraine under Russian occupation. Over a four-year period, Binance purportedly facilitated trades exceeding $898 million between U.S. and Iranian users.

The fine of $4 billion stands as one of the largest corporate penalties in U.S. history. In addition to this, Zhao has agreed to pay a separate fine of $50 million. Despite the severity of his offenses, which could warrant a ten-year prison sentence, it remains uncertain which sentence federal prosecutors will recommend.

Documents associated with the plea reveal that Binance’s executives had received warnings about the legal risks ensuing from insufficient protocols to identify or report suspicious transactions. Reports suggest that one compliance employee even pointed out the ease with which illegal funds could be laundered through Binance.

Why Targeting Crypto Exchanges

Cryptocurrency exchanges have been targeted by criminals for money laundering and circumventing sanctions restrictions due to several inherent characteristics of the cryptocurrency ecosystem.

Anonymity and Pseudonymity: Cryptocurrencies offer a level of anonymity or pseudonymity, which can make it difficult to identify the parties involved in a transaction. This can be attractive to criminals who wish to hide their identities.

Global, Borderless Transactions: Cryptocurrencies can be sent across borders swiftly and without the need for a central intermediary, like a bank. This makes it harder for authorities to monitor and regulate transactions.

Decentralization: The decentralized nature of blockchain technology, which underpins most cryptocurrencies, means there is no central authority overseeing transactions. This can make it easier to evade regulations and sanctions.

There are also some common tricks used by criminals and terrorists in abusive use of cryptocurrency and exchanges.

Use of Unhosted Wallets: Criminals may use unhosted wallets (wallets not provided by a Virtual Asset Service Provider “VASP”) to perform transactions, making it harder for authorities to track these transactions, especially the Travel Rules cannot be effectively applied.

Layering: Similar to traditional money laundering, criminals may use a technique called layering. They conduct a series of rapid transactions across multiple exchanges and currencies to make the funds harder to trace. It is also done with a number of unhosted wallets further spreading the funds making it more difficult to be effectively traced.

Mixing and Tumbling Services: These services mix potentially identifiable or ‘tainted’ cryptocurrency funds with others, making it harder to trace back to the original source.

Use of Privacy Coins: Some criminals use privacy coins, like Monero or Zcash, which have enhanced privacy features that make transactions more difficult to trace.

Chain Hopping: This involves quickly moving funds between different cryptocurrencies to obscure the funds’ original source and make tracking more difficult.

Jurisdiction Arbitrage: Criminals may exploit jurisdictions with weaker regulations and enforcement, moving funds through exchanges in these locations.

Key Factors Contributing to Regulatory Breaches and Failures Among Crypto Exchanges

The recent cases of Binance and other cryptocurrency exchanges that have faltered over the past years reveal several commonalities that led to breaches of AML rules and other financial regulations. These breaches precipitated the eventual downfall of such exchanges.

Management and Leadership Failures: One of the fundamental causes lies at the level of top management and leadership. An insufficient understanding or prioritization of AML regulations often exists. This negligence could stem from an inadequate comprehension of regulatory requirements or a misguided focus on rapid growth at the expense of compliance. Given that the creation of a fully compliant AML framework necessitates seasoned AML compliance experts, the scarcity of such professionals in the crypto exchange market compounds this challenge.

Inadequate Risk Management: A robust risk assessment framework is crucial for the identification of potential money laundering and sanction violations. However, inadequate or poorly executed risk management strategies can lead to breaches if identified risks aren’t appropriately addressed. The unique nature, technologies, and innovative transactions associated with crypto exchanges exacerbate the challenge of constructing a robust risk management framework.

Insufficient KYC/AML Procedures: Binance’s charges of evading laws requiring customer identification and avoiding business with criminals or sanctioned individuals highlight a possible deficiency in their KYC and AML procedures. These procedures’ adequacy often hinges on the presence of a robust risk management framework and skilled compliance experts within the organization.

Lack of Effective Controls: Binance allegedly permitted customers from sanctioned countries, including Iran, Cuba, and Syria, to access their platform, indicating a lack of effective controls to prevent access by individuals in sanctioned regions. It’s not uncommon for the level of ID verification to vary among crypto exchanges, leading to inadequate follow-up measures to ensure full compliance with relevant requirements.

Inadequate Transaction Monitoring: Charges against Binance for failing to report suspicious transactions involving terrorist groups suggest inadequacies or improper utilization of their transaction monitoring systems. Notably, transaction monitoring is only effective when paired with a robust investigation process to follow-up on high-risk alerts and cases, a common shortfall among crypto market players.

Rapid Growth Without Corresponding Compliance Infrastructure: Binance’s rapid growth and global reach might have outpaced its capacity to implement and enforce effective compliance measures. Rapid expansion can put a strain on existing systems, particularly if growth strategies don’t account for corresponding enhancements to compliance infrastructure. With not all crypto exchanges subject to regulation, regulatory arbitrage remains a common issue.

Regulatory Complexity Across Jurisdictions: As a global entity, Binance must comply with the legal and regulatory requirements of multiple jurisdictions. These requirements can vary greatly and can lead to oversights and noncompliance if not managed effectively.

A Reminder for All

In the aftermath of these cases, it’s crucial for all crypto exchanges to scrutinize their own compliance procedures and ensure they are adequately addressing the potential risks associated with their operations. The Binance case serves as a stark reminder of the importance of adhering to AML regulations and the severe consequences that can result from noncompliance. It underscores the urgent need for cryptocurrency exchanges to build robust regulatory compliance frameworks and foster a culture that prioritizes ethical conduct and regulatory adherence.

--

--

SK Lee
Coinmonks

FinTech & RegTech Activist | Risk & Compliance Facilitator | Mentor